Method for detecting communication traffic, electronic device and computer program product
By using an improved method of Kalman filters in power communication networks to interrupt and resume the state updates of the filter units, the problem of false alarms caused by legitimate planned traffic impacts in dynamic baseline algorithms is solved, and fast and accurate communication traffic detection is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- INFORMATION & COMMUNICATION BRANCH STATE GRID JIBEI ELECTRIC POWER CO LTD
- Filing Date
- 2026-04-10
- Publication Date
- 2026-07-14
AI Technical Summary
In power communication networks, dynamic baseline algorithms can cause baseline model distortion due to legitimate planned business peaks, resulting in a large number of false alarms, reducing detection accuracy and operation and maintenance efficiency.
When the positive rate of change of the residuals of the communication traffic feature values is greater than the first threshold, the recursive update of the error covariance matrix of the main filter unit is interrupted, the baseline state vector and the error covariance matrix are obtained, and the auxiliary filter unit is started to process the data in parallel. When the negative rate of change of the residuals is greater than the second threshold and the absolute value of the most recent residual is less than the third threshold, the state vector of the main filter unit is replaced with the state vector of the auxiliary filter unit, and the update of the error covariance matrix is resumed.
It effectively avoids false alarms, improves the accuracy of communication traffic detection and operation and maintenance efficiency, reduces the workload of security operation and maintenance personnel, and ensures the stability and security of the power communication network.
Smart Images

Figure CN122395096A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of telecommunications technology, and in particular to a method for detecting communication traffic, an electronic device, and a computer program product. Background Technology
[0002] With the rapid development of smart grids and the Internet of Things for power, the power communication network, as the "nervous system" supporting intelligent dispatching, remote control, and wide-area protection, has become the cornerstone for ensuring the stable operation of the power grid.
[0003] Among related technologies, the commonly used dynamic baseline algorithm has a parameter self-adjustment and real-time status update mechanism to achieve continuous adaptive tracking of communication traffic changes.
[0004] However, in the context of power production, the inherent and legitimate planned business peaks can lead to sudden surges in planned business traffic over a short period. Dynamic baseline algorithms may misinterpret this as a new state requiring tracking, causing excessive adjustments to the baseline model parameters within a very short time. This results in the baseline trajectory being "skewed" by the short-term surge in traffic. After the planned business peak ends and communication traffic returns to normal levels, the severely distorted baseline model requires a long convergence period to recover to normal traffic levels. During this period, the monitoring system will continuously generate a large number of false alarms. These massive false alarms not only increase the workload of safety maintenance personnel but also easily lead to the omission of important safety events, resulting in a decrease in the accuracy of communication traffic detection and operational efficiency. Summary of the Invention
[0005] This application provides a communication traffic detection method, electronic device, and computer program product, which can solve the problems of low accuracy and low maintenance efficiency in related communication traffic detection methods.
[0006] To address the aforementioned problems, this application discloses a method for detecting communication traffic, the method comprising: If the positive rate of change of the residual of the communication traffic feature value is greater than the first threshold, the recursive update process of the error covariance matrix in the main filter unit is interrupted, and the state vector and error covariance matrix of the main filter unit are obtained as the reference state vector and reference error covariance matrix. The auxiliary filtering unit is activated and configured according to the reference state vector and the reference error covariance matrix; The auxiliary filtering unit and the main filtering unit are controlled to process the observation data of communication traffic feature values in parallel, so that the auxiliary filtering unit and the main filtering unit each perform iterative updates of the state vector. If the negative rate of change of the residual of the communication traffic feature value is greater than the second threshold, and the absolute value of the residual of at least the most recent two update cycles is less than the third threshold, the state vector in the main filter unit is replaced with the state vector currently output by the auxiliary filter unit, and the recursive update process of the error covariance matrix in the main filter unit is restored.
[0007] Optionally, the step of interrupting the recursive update process of the error covariance matrix in the main filtering unit when the positive rate of change of the residual of the communication traffic feature value is greater than a first threshold, and obtaining the state vector and error covariance matrix of the main filtering unit as the reference state vector and reference error covariance matrix, includes: The main filtering unit is used to obtain the dynamic baseline prediction value of communication traffic feature values in the current update cycle; Calculate the difference between the observed value of the communication traffic feature value in the current update period and the predicted value of the dynamic baseline, and use the difference as the residual of the communication traffic feature value in the current update period; The residual of the communication traffic feature value in the current update cycle is added to the first preset sliding window, and the positive rate of change of the residual of the communication traffic feature value is calculated based on the residual sequence in the first preset sliding window. If the positive rate of change of the residual of the communication traffic feature value is greater than the first threshold, the recursive update process of the error covariance matrix in the interrupt main filter unit is executed, and the state vector and error covariance matrix of the main filter unit are obtained as the reference state vector and reference error covariance matrix.
[0008] Optionally, the residual sequence in the first preset sliding window includes the residuals of the communication traffic feature values in at least two different update cycles; The step of calculating the positive rate of change of the residuals of the communication traffic feature values based on the residual sequence in the first preset sliding window includes: Based on the residual sequence in the first preset sliding window, the positive rate of change of the residuals of the communication traffic feature values is calculated, and the positive rate of change is: ; in, This indicates that the communication traffic characteristic value is in the current update cycle. The positive rate of change of the residuals; This indicates the length of the first preset sliding window; This represents the residual in the i-th update cycle of the first preset sliding window; This represents the residual in the (i-1)th update cycle of the first preset sliding window; This represents the positive change in the residual between adjacent update cycles.
[0009] Optionally, obtaining the state vector and error covariance matrix of the main filtering unit as the reference state vector and reference error covariance matrix includes: After interrupting the recursive update process of the error covariance matrix in the main filter unit, the first update period corresponding to the residual with a positive rate of change greater than the first threshold is determined. The time corresponding to the second update cycle that is before the first update cycle and adjacent to the first update cycle is determined as the index time; The state vector and error covariance matrix of the main filtering unit at the index time are copied and stored to obtain the reference state vector and the reference error covariance matrix.
[0010] Optionally, configuring the auxiliary filtering unit according to the reference state vector and the reference error covariance matrix includes: The initial value of the state vector in the auxiliary filtering unit is set as the reference state vector; The initial value of the error covariance matrix in the auxiliary filtering unit is set to the reference error covariance matrix; Set the process noise covariance matrix in the auxiliary filtering unit to zero.
[0011] Optionally, the step of replacing the state vector in the main filter unit with the state vector currently output by the auxiliary filter unit and restoring the recursive update process of the error covariance matrix in the main filter unit when the negative rate of change of the residual of the communication traffic feature value is greater than the second threshold and the absolute value of the residual in at least the most recent two update cycles is less than the third threshold includes: The residual of the communication traffic feature value in the current update period is added to a second preset sliding window, and based on the residual sequence in the second preset sliding window, the negative rate of change of the residual of the communication traffic feature value is calculated, wherein the negative rate of change is: ; in, This indicates that the communication traffic characteristic value is in the current update cycle. The negative rate of change of the residuals; This indicates the length of the second preset sliding window; This represents the residual in the i-th update cycle of the second preset sliding window; This represents the residual in the (i-1)th update cycle of the second preset sliding window; This represents the negative change in the residual between adjacent update cycles; If the negative rate of change of the residual of the communication traffic feature value is greater than the second threshold, and the absolute value of the residual of the most recent two update cycles is less than the third threshold, then the operation of replacing the state vector in the main filter unit with the state vector currently output by the auxiliary filter unit and restoring the recursive update process of the error covariance matrix in the main filter unit is performed.
[0012] Optionally, the method further includes: An initial value is set for the process noise covariance matrix of the main filter unit, and the initial value is controlled to decay exponentially according to a preset attenuation constant.
[0013] Optionally, setting an initial value for the process noise covariance matrix of the main filter unit and controlling the initial value to decay exponentially according to a preset attenuation constant includes: An initial value is set for the process noise covariance matrix of the main filter unit, and the initial value is controlled to decay exponentially according to a preset attenuation constant. The process noise covariance matrix of the main filter unit is: ; in, Indicates that the index is updated periodically; Indicates that the main filter unit is in the first... The process noise covariance matrix for each update cycle; This represents the initial value of the process noise covariance matrix; This represents the preset attenuation constant.
[0014] This application also discloses an electronic device, including a processor, a main filtering unit, an auxiliary filtering unit, and a storage unit; the storage unit is used to store executable instructions, which cause the data processing unit to perform the communication traffic detection method described above.
[0015] This application also discloses a computer program product, including a computer program / instruction, which, when executed by a processor, implements the communication traffic detection method described above.
[0016] The embodiments of this application have the following advantages: The communication traffic detection method provided in this application indicates that a steep positive step rise edge has appeared in the communication traffic characteristic value, consistent with the characteristics of planned service impact, when the positive rate of change of the residual of the communication traffic characteristic value is greater than a first threshold. In this scenario, interrupting the recursive update process of the error covariance matrix in the main filter unit can avoid the main filter unit from over-tracking and iteratively updating the observed data mutations caused by planned service events. This helps maintain the stability of the main filter unit's state vector and error covariance matrix before the event, thereby improving the reliability of the obtained baseline state vector and baseline error covariance matrix. After starting the auxiliary filter unit, configuring the auxiliary filter unit according to the baseline state vector and baseline error covariance matrix allows the auxiliary filter unit to operate based on information known before the event. Furthermore, starting from an undisturbed stable state, subsequent observation data processing is performed to achieve reliable state comparison and regression. When the negative rate of change of the residuals of communication traffic characteristic values is greater than the second threshold and the absolute value of the residuals in at least the most recent two update cycles is less than the third threshold, it indicates that the planned business impact event has ended. In this scenario, the state vector in the main filter unit is replaced with the current output state vector of the filter unit, and the recursive update process of the error covariance matrix in the main filter unit is restored. This enables the main filter unit to converge quickly and without overshoot to the new normal steady state after the event. This is beneficial for eliminating the persistent false anomaly alarm trails caused by convergence delay in related technologies, reducing the number of false alarms in the monitoring system, reducing the workload of security operation and maintenance personnel, and improving the accuracy of communication traffic detection and operation and maintenance efficiency. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This application provides a flowchart of the steps for a communication traffic detection method. Figure 1 ; Figure 2 This application provides a flowchart of the steps for a communication traffic detection method. Figure 2 ; Figure 3 This application provides a flowchart of the steps for a communication traffic detection method. Figure 3 ; Figure 4 This application provides a flowchart of the steps for a communication traffic detection method. Figure 4 ; Figure 5 This application provides a flowchart of the steps for a communication traffic detection method. Figure 5 ; Figure 6 This is a logic block diagram of a communication traffic detection device provided in an embodiment of this application. Detailed Implementation
[0019] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0020] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and are not limited in number; for example, a first object can be one or more. Furthermore, the term "and / or" in the specification and claims is used to describe the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. In the embodiments of this application, the term "multiple" refers to two or more, and other quantifiers are similar.
[0021] Method Implementation Examples Power communication networks carry diverse service traffic, ranging from production control to management information. Their network behavior exhibits high complexity and specific periodic patterns. Consequently, power communication networks face increasingly severe cybersecurity threats, with attack methods constantly evolving towards greater concealment and persistence. Therefore, real-time and accurate anomaly detection of network communication traffic, and timely identification and blocking of malicious behaviors such as penetration attacks and denial-of-service attacks, are urgent needs and key research areas in the field of cybersecurity protection for the power industry. In recent years, related technologies have widely introduced dynamic baseline algorithms based on artificial intelligence technologies such as machine learning and deep learning into the field of communication traffic analysis. Dynamic baseline algorithms possess parameter self-adjustment and real-time state update mechanisms to achieve continuous adaptive tracking of changes in communication traffic. One related technology constructs a cloud-edge collaborative detection framework. An online machine learning model is deployed at the edge to detect outbound communication traffic in real time, classifying the traffic into normal flows, alarm flows, and abnormal flows. The core of this approach is to use an automatic labeling mechanism to label uncertain alarm flows and generate training samples. The edge model is updated periodically, while the cloud aggregates data from various edge devices. After expert evaluation, a more accurate global model is trained and then distributed to the edge for model replacement. This method aims to solve the problems of slow offline model updates and limited online model samples, thereby enabling rapid response to new abnormal traffic.
[0022] However, dynamic baseline algorithms in related technologies have significant technical limitations when dealing with inherent, legitimate planned business peaks in power production scenarios. Specifically, during actual operation, power communication networks periodically or by command trigger operations such as primary / backup link switching, centralized issuance of planned remote dispatch instructions, and simultaneous status reporting by distributed protection devices. These operations cause drastic changes in communication traffic with large amplitudes and short durations within a very short period of time, but they are essentially legitimate business activities, not security threats. Dynamic baseline algorithms, such as Kalman filters, commonly used in related technologies, exhibit inherent flaws that are amplified when faced with sudden and legitimate planned traffic surges. Specifically, to continuously track changes in network status, dynamic baseline algorithms possess adaptive adjustment capabilities for their parameters or states. When a short-term, large-scale surge in planned traffic suddenly occurs, the dynamic baseline algorithm may misjudge it as a new state requiring tracking, leading to over-correction of the baseline model's parameters within a very short time. This causes the baseline trajectory to be "skewed" by the short-term surge in traffic. After the planned traffic peak ends and communication traffic returns to normal levels, the severely distorted baseline model requires a long convergence period to recover to normal traffic levels. During this period, the monitoring system will continuously generate a large number of false alarms—numerous false anomaly alarms targeting normal traffic—forming a lingering false anomaly trail. This problem can also occur in the solution described in one of the related technologies mentioned above, because its real-time detection and model update mechanism does not distinguish between malicious attacks and legitimate business flows, and the model is interfered with both during and after the event.
[0023] Furthermore, false anomaly trails can increase the workload of security operations and maintenance personnel in actual work. Moreover, a large number of false alarms can overwhelm truly critical threat alarms, causing important security incidents to be missed, severely reducing the credibility of the monitoring system. In addition, continuous false alarms can trigger unnecessary automated defense responses, such as mistakenly isolating normal business connections or restricting critical command traffic. This can affect the continuity and stability of power production operations and even cause unnecessary operational risks.
[0024] Therefore, there is an urgent need for a communication traffic detection method that enables the dynamic baseline model to be robust when encountering legitimate planned business impacts and to quickly and smoothly reset after the legitimate planned business impacts have ended, thereby fundamentally eliminating the generation of false anomaly trails and improving the accuracy and operational efficiency of real-time detection of power communication network security.
[0025] Among them, false anomaly trails refer to the phenomenon that the monitoring system continues to falsely report anomalies after the event ends because the dynamic baseline algorithm in the relevant technology overcorrects or delays convergence when dealing with legitimate planned business events.
[0026] To address the aforementioned problems, this application provides a method for detecting communication traffic, referring to... Figure 1 The method may specifically include the following steps: Step S101: When the positive rate of change of the residual of the communication traffic feature value is greater than the first threshold, the recursive update process of the error covariance matrix in the main filter unit is interrupted, and the state vector and error covariance matrix of the main filter unit are obtained as the reference state vector and reference error covariance matrix.
[0027] Step S102: Start the auxiliary filtering unit and configure the auxiliary filtering unit according to the reference state vector and the reference error covariance matrix.
[0028] Step S103: Control the auxiliary filtering unit and the main filtering unit to process the observation data of communication traffic feature values in parallel, so that the auxiliary filtering unit and the main filtering unit each perform iterative updates of the state vector.
[0029] Step S104: When the negative rate of change of the residual of the communication traffic feature value is greater than the second threshold, and the absolute value of the residual of at least the most recent two update cycles is less than the third threshold, replace the state vector in the main filter unit with the state vector currently output by the auxiliary filter unit, and restore the recursive update process of the error covariance matrix in the main filter unit.
[0030] The communication traffic detection method provided in this application can be applied to electronic devices, which can be deployed at power communication network nodes as a real-time security detection device for power communication network nodes. In some embodiments, the electronic device may include, but is not limited to, a dedicated power communication gateway, a network traffic monitoring device, an edge computing access node, a power communication network security protection device, an intelligent power communication terminal, a distribution automation terminal device, a power communication remote operation and maintenance terminal, a power Internet of Things edge gateway, a dedicated access server for power communication services, and a power communication intelligent monitoring terminal.
[0031] In the embodiments of this application, the electronic device includes a processor, a main filtering unit, an auxiliary filtering unit, and a storage unit. The processor is electrically connected to the main filtering unit, the auxiliary filtering unit, and the storage unit, respectively, and is used to execute the steps of the communication traffic detection method provided in this application.
[0032] In some embodiments, the storage unit is used to store executable instructions that cause the processor to execute the communication traffic detection method provided in this application; in some embodiments, the storage unit is also used to store a reference state vector and a reference error covariance matrix, so that the reference state vector and the reference error covariance matrix remain unchanged during the subsequent event duration without being affected by the recursive calculations inside the main filtering unit.
[0033] In some embodiments, the processor may be a data processing unit embedded in an electronic device; in some embodiments, both the main filtering unit and the auxiliary filtering unit are Kalman filters. The main Kalman filter refers to a linear recursive algorithm used for estimating the state of the monitored system, achieving optimal fusion of the model predictions and actual observations of the monitored system state through two steps: prediction and update. The auxiliary Kalman filter refers to a copy of the filter activated when the positive rate of change of the residuals of the communication traffic characteristic values exceeds a first threshold, used to generate a smooth baseline trajectory unaffected by events.
[0034] The monitored system refers to the target object whose state is estimated by the main filtering unit. In some embodiments, the monitored system refers to the power communication network traffic system.
[0035] In step S101, the communication traffic characteristic value refers to a quantitative indicator that can reflect the change pattern of the communication traffic of the monitored system and is used to characterize the current operating status of the monitored system. The communication traffic characteristic value may include, but is not limited to, network traffic rate, data packet transmission rate, bandwidth utilization, number of connections, message delay, jitter, and packets per second (PPS).
[0036] The residual refers to the difference between the actual observed value of the communication traffic characteristic and the dynamic baseline prediction value output by the main filter unit in the same update cycle. The residual directly reflects the instantaneous deviation between the actual observed value and the dynamic baseline prediction value of the communication traffic characteristic. The dynamic baseline prediction value refers to the model prediction value of the communication traffic characteristic value for the current update cycle, calculated by the main filter unit based on the state vector of the previous update cycle and using the observation matrix. The observation matrix is used to map the state vector of the monitored system to the observation space, establishing a linear relationship between the state vector of the monitored system and the actual observed value of the communication traffic characteristic.
[0037] The update cycle refers to the time interval between the main filter unit performing a complete prediction and update of the dynamic baseline prediction value of the communication traffic feature value. In the embodiments of this application, the update cycle is also the execution cycle of residual calculation, residual positive change rate calculation, and determining whether the residual positive change rate is greater than the first threshold.
[0038] The positive rate of change of the residuals of communication traffic characteristic values refers to the positive rate of change of the residuals of communication traffic characteristic values in the current update cycle, calculated based on the dynamic baseline prediction value output by the main filter unit. It is used to characterize the average intensity of the increase in residuals per unit time.
[0039] The first threshold is a pre-set critical value used to determine whether the rate of increase of the residual within a unit of time constitutes a legally planned event step edge, based on the statistical results of normal communication traffic fluctuations in the monitored system over a historical period. In some embodiments, the first threshold refers to the maximum value of the observed communication traffic characteristic values statistically determined during the normal communication traffic fluctuations of the monitored system over a historical period. The time window corresponding to the historical period must cover at least one complete typical business cycle; for example, for daily power dispatching services, the time window corresponding to the historical period should be no less than 24 hours, and for weekly business models, the time window corresponding to the historical period should be extended to at least one week.
[0040] In step S101, when the electronic device obtains the residual of the communication traffic feature value in each update cycle, it can calculate the positive rate of change of the residual of the current update cycle compared with the residual of the previous update cycle, and match the positive rate of change with the first threshold.
[0041] When the positive rate of change of the residual is greater than the first threshold, it indicates that the communication traffic characteristic value has a steep positive step rising edge that conforms to the planned business impact characteristics. In this scenario, the electronic device can execute the recursive update process of the error covariance matrix in the interrupt main filter unit, as well as the operation of obtaining the state vector and error covariance matrix of the main filter unit as the reference state vector and reference error covariance matrix.
[0042] The state vector refers to a set of variables maintained internally by the filtering unit that characterize the internal state of the monitored system. It is the optimal estimate of the true state of the monitored system. The error covariance matrix can specifically be the posterior error covariance matrix. The posterior error covariance matrix refers to the covariance matrix output by the filtering unit after completing the measurement update of the current update cycle, which characterizes the accuracy of the state vector estimation at this time.
[0043] Specifically, interrupting the recursive update process of the error covariance matrix in the main filter unit can be achieved as follows: In some embodiments, the processor in the electronic device generates a control signal and sends the control signal to the main filter unit. The control signal is used to instruct the main filter unit to interrupt the recursive update process of the error covariance matrix in the main filter unit.
[0044] In some embodiments, the electronic device further includes a filter unit control logic unit electrically connected to the processor. When the positive rate of change of the residual of the communication traffic characteristic value exceeds a first threshold, the processor sends a trigger signal to the filter unit control logic unit. The trigger signal instructs the filter unit control logic unit to interrupt the recursive update process of the error covariance matrix in the main filter unit. Upon receiving the trigger signal, the filter unit control logic unit generates a control signal and sends it to the main filter unit to interrupt the recursive update process of the error covariance matrix in the main filter unit. Specifically: The filter unit controls the logic unit to generate a binary control signal. And set it to the logical truth value; this control signal directly acts on the measurement update calculation loop of the main filter unit, forcing the posterior error covariance matrix of the main filter unit to be true. The update formula becomes invalid and its value remains constant. Specifically, this is achieved by executing the following in each update cycle: ,in, Indicates during the update cycle Combining communication traffic characteristics in the update cycle The uncertainty covariance matrix of the state estimate after updating the actual observations, which is also the posterior error covariance matrix. Indicates the previous update cycle The posterior error covariance matrix is the posterior error covariance matrix that was interrupted and locked in the update cycle before a steep positive step rising edge was detected. This operation is algorithmically equivalent to interrupting the posterior error covariance matrix from... arrive The standard recursive update process involves the Kalman gain. The calculation and feedback are interrupted. The recursive update process makes it no longer change over time, effectively fixing the Kalman gain. The calculation basis for this gain is that it determines the degree of confidence the main filter unit has in the new residual. Its core principle is that during sudden, large-scale legitimate planned business shocks, the huge residuals mainly originate from planned events rather than process noise. If allowed... Continue updating according to the standard Kalman filter formula. The system will continuously adjust due to persistent and large residuals, which the main filtering unit may misinterpret as an increase in process noise in the monitoring system. This leads to an erroneous amplification of the uncertainty estimate for future state prediction within the algorithm. The embodiments of this application address this by interrupting... The recursive update process can fundamentally sever this erroneous positive feedback chain, allowing the main filter unit to maintain its original confidence level in the accuracy of the monitoring system model before the event, avoiding over-reliance and tracking sudden changes in actual observations caused by legitimate planned events, thus laying the foundation for accurate processing in subsequent steps. In this embodiment, when the positive rate of change of the residuals of the communication traffic characteristic values exceeds a first threshold, the recursive update process of the error covariance matrix in the main filter unit is immediately interrupted, freezing the value of the error covariance matrix at the instantaneous state before the event. This algorithmically prevents the main filter unit from erroneously amplifying process noise estimation and state uncertainty due to large legitimate observation biases, which is beneficial for improving the purity and stability of the basic mathematical model characterizing the normal behavior pattern of the monitored system, and solves the fundamental problem of the baseline model being "pulled away" by communication traffic from sudden legitimate planned events.
[0045] The monitored system refers to the power communication system and its corresponding network equipment that are to be detected for abnormal communication traffic. The monitoring system refers to the detection system used to collect communication traffic, estimate status and determine anomalies in the monitored system. Specifically, the monitoring system includes electronic equipment deployed at nodes of the power communication network.
[0046] The state vector and error covariance matrix of the main filter unit are obtained as the reference state vector and reference error covariance matrix. Specifically, the processor or the filter unit control logic unit can copy the state vector and error covariance matrix of the main filter unit in the previous update cycle and store the copied content in a protected register or dedicated storage area in the storage unit to obtain the reference state vector and reference error covariance matrix. The reference state vector and reference error covariance matrix completely preserve the optimal estimate and confidence of the main filter unit of the normal network behavior mode before the event occurred, and serve as the gold reference benchmark for the subsequent recovery phase.
[0047] If the positive rate of change of the residual is less than or equal to the first threshold, it indicates that in the current update cycle, the positive fluctuation of the actual observed value of the communication traffic feature relative to the predicted value of the dynamic baseline is small, and the current communication traffic feature is in a normal business state. In this scenario, the electronic device can continue to perform residual calculation, calculation of the positive rate of change of the residual, and matching of the positive rate of change with the first threshold in the next update cycle.
[0048] In step S102, the electronic device can activate the auxiliary filtering unit and configure the state vector and error covariance matrix in the auxiliary filtering unit according to the reference state vector and reference error covariance matrix obtained in step S101, so that the auxiliary filtering unit degenerates into an optimal smoother in which both state and uncertainty remain constant, and only uses a fixed model to filter all input observation data during the event to generate a stable reference baseline trajectory that is not affected by sudden shocks.
[0049] It is understandable that when the positive rate of change of the residual of the communication traffic characteristic value is less than or equal to the first threshold, the electronic device does not need to perform the operations corresponding to steps S101 to S104. That is, when the positive rate of change of the residual of the communication traffic characteristic value is less than or equal to the first threshold, the auxiliary filtering unit in the electronic device will be in an unactivated state.
[0050] After configuring the auxiliary filtering unit in step S102, the electronic device can continue to execute step S103, controlling the auxiliary filtering unit and the main filtering unit to process the observed data of communication traffic characteristic values in parallel, so that the auxiliary filtering unit and the main filtering unit can each perform iterative updates of their state vectors. It is understood that during the iterative update of the state vector, the auxiliary filtering unit recursively updates its own error covariance matrix to generate a stable reference baseline trajectory unaffected by sudden shocks. During the iterative update of the state vector, the main filtering unit's error covariance matrix is interrupted in step S101, and therefore its own error covariance matrix will be interrupted in step S103 and will not undergo a recursive update process.
[0051] The observation data for communication traffic characteristics include actual observations, which in some embodiments are raw data of communication traffic characteristics acquired in real time from the power communication network.
[0052] In this embodiment of the application, during step S103, the electronic device will continuously calculate the residual of the communication traffic characteristic value and the negative rate of change of the residual based on the dynamic baseline prediction value output by the main filter unit and the actual observed value of the communication traffic characteristic value in each update cycle, and match the negative rate of change with the second threshold.
[0053] If the negative rate of change is greater than the second threshold, it indicates that the electronic device has detected a steep negative rate of change that meets the threshold requirements. Then, the absolute value of the residual is matched with the third threshold. If the absolute value of the residual in at least the most recent two update cycles is less than the third threshold, it indicates that the planned business impact event has ended and the communication traffic characteristic value has entered the recovery phase. In this scenario, the electronic device can execute step S104 to replace the state vector in the main filter unit with the state vector currently output by the auxiliary filter unit, and restore the recursive update process of the error covariance matrix in the main filter unit. This guides the main filter unit to converge quickly and without overshoot to the new normal steady state after the event. This helps to eliminate the persistent false abnormal alarm trails caused by convergence delay in related technologies, reduce the number of false alarms in the monitoring system, reduce the workload of security operation and maintenance personnel, and improve the accuracy and efficiency of communication traffic detection. Furthermore, in determining whether a planned service impact event has ended, the principle of the dual criterion combining the negative rate of change of the residual of the communication traffic characteristic value and the absolute value of the residual of the most recent two update cycles in this embodiment is that when a legitimate planned service ends, the decline of the communication traffic characteristic value is also rapid and has a clear pattern. The steepness of the falling edge corresponds to the steepness of the rising edge at the beginning of the event, and the residual after the decline stabilizes near the baseline before the event. This confirms that the monitored system has returned to the normal operating mode, which is beneficial to provide an accurate triggering time for step S104 to start the safe baseline recovery process, avoid false triggering or delayed triggering, and improve the accuracy and timeliness of the recovery of the main filter unit.
[0054] Replacing the state vector in the main filter unit with the current output state vector of the auxiliary filter unit allows the auxiliary filter unit's current output state vector to be injected into the main filter unit as the uniquely correct seed state vector. This forces the replacement of the main filter unit's state vector, which might be distorted due to event shocks, and helps reset the main filter unit's state vector to a smooth reference trajectory maintained by the auxiliary filter unit that is unaffected by shocks. Simultaneously, restoring the recursive update process of the error covariance matrix in the main filter unit helps it quickly return to a stable filtering and tracking state, avoiding estimation oscillations and misjudgments caused by sudden changes in the state vector, and improving the accuracy and reliability of the main filter unit's subsequent detection of communication traffic anomalies.
[0055] Understandably, after step S104, the electronic device can control the auxiliary filter unit to either turn it off or put it into a sleep state, thereby reducing the power consumption of the electronic device and improving its operating energy efficiency.
[0056] If the negative rate of change is less than or equal to the second threshold, or if the absolute value of at least one of the residuals in the most recent at least two update cycles is greater than or equal to the third threshold, it indicates that the current service disruption event has not ended and the communication traffic characteristic value has not entered the recovery phase. In this scenario, the electronic device can continue to calculate the residual of the communication traffic characteristic value and the negative rate of change of the residual based on the dynamic baseline prediction value output by the main filter unit and the actual observed value of the communication traffic characteristic value in the next update cycle, and match the negative rate of change with the second threshold until the negative rate of change of the residual of the communication traffic characteristic value is greater than the second threshold and the absolute value of the residuals in the most recent at least two update cycles is less than the third threshold, then step S104 is executed.
[0057] If, within a preset time period, the negative rate of change is consistently less than or equal to the second threshold, or if the absolute value of at least one of the residuals from the most recent two update cycles is greater than or equal to the third threshold, it indicates that the current communication traffic surge is not a legitimate planned service and may be caused by a malicious attack. In this scenario, in some embodiments, the electronic device can maintain its operating state until the anomaly of the monitored system is captured by other alarm logic. In some embodiments, the electronic device can also send alarm information to other alarm logic for relevant maintenance personnel to intervene and handle.
[0058] In some embodiments, the preset time period is equal to the maximum value of the planned business cycle corresponding to the monitored system. For example, the preset time period is from several seconds to tens of seconds.
[0059] The second threshold is a pre-set critical value used to determine whether the rate of decrease of the residual within a unit of time constitutes a legally planned event step edge, based on the statistical results of normal communication traffic fluctuations of the monitored system over a historical period. In some embodiments, the second threshold is equal to the first threshold.
[0060] The third threshold is a threshold determined based on the normal fluctuation level of the residuals of the monitored system over a historical period; in some embodiments, the third threshold is equal to the maximum value of the normal fluctuation amplitude of the residuals of the monitored system over a historical period.
[0061] To address the technical shortcomings of related technologies, such as the over-adjustment or response delay of traditional dynamic baseline algorithms leading to persistent false alarms when facing legitimate planned business impacts, this application improves the state control logic of the filtering algorithm to achieve robust maintenance and rapid, accurate recovery of the dynamic baseline prediction values of the main filtering unit. Specifically, the communication traffic detection method provided in this application indicates that when the positive rate of change of the residuals of communication traffic feature values exceeds a first threshold, it signifies a steep positive step rise in the communication traffic feature values, consistent with the characteristics of planned business impacts. In this scenario, interrupting the recursive update process of the error covariance matrix in the main filtering unit allows the main filtering unit to maintain its original confidence level in the system model before the event during the planned business event, preventing the main filtering unit from over-trusting and tracking the sudden changes in observed data caused by the planned business event. Subsequently, the state vector and error covariance matrix of the main filtering unit are obtained as the baseline state vector and baseline error covariance matrix. After activating the auxiliary filtering unit, it can be configured based on the baseline state vector and the baseline error covariance moment. This allows the auxiliary filtering unit to process subsequent observation data starting from a known and undisturbed stable state before the event, achieving reliable state comparison and regression. When the negative rate of change of the residuals of the communication traffic characteristic values is greater than the second threshold and the absolute value of the residuals in at least the last two update cycles is less than the third threshold, it indicates that the planned service impact event has ended. In this scenario, the state vector in the main filtering unit is replaced with the current output state vector of the filtering unit, and the recursive update process of the error covariance matrix in the main filtering unit is restored. This ensures that the dynamic baseline prediction value of the main filtering unit can converge quickly and without overshoot to the new normal steady state after the event. This helps to eliminate the persistent false anomaly alarm trails caused by convergence delay in related technologies, reduce the number of false alarms in the monitoring system, reduce the workload of security operation and maintenance personnel, and improve the accuracy and efficiency of communication traffic detection and operation and maintenance.
[0062] In an optional embodiment of this application, step S101, which involves interrupting the recursive update process of the error covariance matrix in the main filter unit when the positive rate of change of the residual of the communication traffic feature value is greater than a first threshold, and obtaining the state vector and error covariance matrix of the main filter unit as the reference state vector and reference error covariance matrix, includes: Step S1011: Use the main filtering unit to obtain the dynamic baseline prediction value of the communication traffic feature value in the current update cycle.
[0063] Step S1012: Calculate the difference between the observed value of the communication traffic feature value in the current update period and the predicted value of the dynamic baseline, and use the difference as the residual of the communication traffic feature value in the current update period.
[0064] Step S1013: Add the residual of the communication traffic feature value in the current update cycle to the first preset sliding window, and calculate the positive rate of change of the residual of the communication traffic feature value based on the residual sequence in the first preset sliding window.
[0065] Step S1014: If the positive rate of change of the residual of the communication traffic feature value is greater than the first threshold, execute the recursive update process of the error covariance matrix in the interrupt main filter unit, and obtain the state vector and error covariance matrix of the main filter unit as the reference state vector and reference error covariance matrix.
[0066] In this embodiment of the application, when determining whether the positive rate of change of the residual of the communication traffic feature value is greater than the first threshold, the electronic device can calculate the positive rate of change of the residual of the communication traffic feature value in the current update cycle through the operations of steps S1011 to S1013, and then match the positive rate of change with the first threshold. If the positive rate of change is greater than the first threshold, step S1014 is executed. Thus, when the monitored system performs planned service switching, such as primary and backup link switching, causing the communication traffic feature value to undergo a large jump in a very short time, resulting in the rate of change of the residual significantly exceeding the first threshold, the sudden change starting point of the communication traffic feature value can be captured in a timely manner. This application embodiment uses an intelligent identification layer based on the positive rate of change of residuals of communication traffic feature values as a technical means. This means calculates the positive rate of change of the real-time residual sequence per unit time within a first preset sliding window and sets a first threshold for judgment. When the positive rate of change exceeds the first threshold in a single update cycle, it is determined to be the starting point of the business impact. This technical means realizes accurate and timely identification of short-term, large-scale business impact events, provides a reliable trigger signal for subsequent differentiated processing, and thus separates such events from potential malicious attack alarms in advance.
[0067] Specifically, in step S1011, the electronic device can first utilize the state transition matrix to determine the state vector of the main filter unit in the previous update cycle. Predict the prior state vector of the main filter unit in the current update cycle. Then using the observation matrix ,Bundle This is mapped to the dynamic baseline prediction of communication traffic characteristics in the current update period: (1) in, This indicates the communication traffic characteristic value in the current update cycle. The dynamic baseline prediction value; Represents the observation matrix; This indicates the main filter unit in the current update cycle. The prior state vector.
[0068] In step S1012, the electronic device can calculate the difference between the observed value of the communication traffic feature value in the current update period and the predicted value of the dynamic baseline, and use this difference as the residual of the communication traffic feature value in the current update period: (2) in, This indicates the communication traffic characteristic value in the current update cycle. The residual; This indicates the communication traffic characteristic value in the current update cycle. The observed values.
[0069] In this embodiment of the application, to identify the starting point of the business impact, the electronic device uses a fixed length of The first preset sliding window sets the communication traffic characteristic value in the most recent The residual of each update cycle to Continuous monitoring, as can be understood, means that the communication traffic characteristic value in the first preset sliding window is most recently... The residuals from each update cycle form a residual sequence, which is a sequence of the differences between the observed values of communication traffic characteristics and the predicted values of the dynamic baseline in the current update cycle, formed in chronological order. It directly reflects the instantaneous deviation between the actual observed values of communication traffic characteristics and the predicted values of the dynamic baseline.
[0070] In step S1013, the electronic device can add the residual of the communication traffic feature value calculated in step S1012 in the current update period to the first preset sliding window to update the residual sequence in the first preset sliding window, and then calculate the positive rate of change of the residual of the communication traffic feature value based on the updated residual sequence in the first preset sliding window.
[0071] When the positive rate of change of the residual of the communication traffic characteristic value is greater than the first threshold, the electronic device can execute step S1014 to interrupt the recursive update process of the error covariance matrix in the main filter unit, and obtain the state vector and error covariance matrix of the main filter unit as the reference state vector and reference error covariance matrix.
[0072] In an optional embodiment of this application, the residual sequence in the first preset sliding window includes the residuals of the communication traffic feature value over at least two different update periods; step S1013, calculating the positive rate of change of the residuals of the communication traffic feature value based on the residual sequence in the first preset sliding window, includes: Step A11: Based on the residual sequence in the first preset sliding window, calculate the positive rate of change of the residuals of the communication traffic feature values, wherein the positive rate of change is: (3) in, This indicates that the communication traffic characteristic value is in the current update cycle. The positive rate of change of the residuals; This indicates the length of the first preset sliding window; This represents the residual in the i-th update cycle of the first preset sliding window; This represents the residual in the (i-1)th update cycle of the first preset sliding window, i.e. This represents the residual in the first preset sliding window that is adjacent to the i-th update cycle and precedes the i-th update cycle in the (i-1)-th update cycle; This represents the positive change in the residual between adjacent update cycles.
[0073] also, This function extracts the positive change in the residuals between adjacent update cycles, retaining the change only when the residuals between adjacent update cycles increase. When the residuals of adjacent update cycles decrease or remain unchanged Setting it to 0 achieves the goal of accumulating only the positive fluctuations of the residuals and filtering out negative interference.
[0074] In this embodiment of the application, the first threshold A steep rising edge used to distinguish normal fluctuations in communication traffic characteristics from planned traffic surges. The positive rate of change calculated within a single update cycle is defined if and only if... satisfy When the timing curve of the electronic device determines the characteristic value of the communication traffic shows a steep positive step rising edge that conforms to the characteristics of planned service impact, step S1014 is executed. The principle is that planned service switching, such as primary and backup link switching, will cause the traffic characteristics to undergo a large legal transition in a very short time, so that the positive change rate of the residual significantly exceeds the normal threshold, thereby realizing the timely capture of the sudden change starting point of the communication traffic characteristic value.
[0075] As an example, refer to Figure 2 The flowchart illustrates the steps of a communication traffic detection method provided in an embodiment of this application. Figure 2 The method may specifically include the following steps: Step S201: Calculate the positive rate of change of the residual.
[0076] Specifically, in each update cycle of the main filter unit, the electronic device calculates the positive rate of change of the residual of the communication traffic characteristic value through the operations of steps S1011 to S1013.
[0077] Step S202: Determine whether the positive rate of change of the residual exceeds the first threshold.
[0078] Specifically, if the positive rate of change is greater than the first threshold, the electronic device executes step S203; if the positive rate of change is less than or equal to the first threshold, the electronic device executes step S201 again in the next update cycle of the main filter unit.
[0079] Step S203: Generate a freeze control signal.
[0080] Specifically, when the positive rate of change is greater than the first threshold, the electronic device can generate a freeze control signal and transmit the freeze control signal to the main filter unit.
[0081] Step S204: Interrupt the recursive update process of the posterior error covariance matrix in the main filter unit.
[0082] Specifically, the electronic device forces the update formula of the posterior error covariance matrix of the main filter unit to become invalid and keep its value constant by freezing the control signal, thereby interrupting the recursive update process of the posterior error covariance matrix in the main filter unit.
[0083] Step S205: The posterior error covariance matrix in the main filtering unit is frozen.
[0084] It is understandable that after the recursive update process of the posterior error covariance matrix in the main filter unit is interrupted, the update formula of the posterior error covariance matrix of the main filter unit becomes invalid and its value remains constant, thus the posterior error covariance matrix in the main filter unit is in a frozen state.
[0085] In an optional embodiment of this application, step S101, which involves interrupting the recursive update process of the error covariance matrix in the main filter unit when the positive rate of change of the residual of the communication traffic feature value is greater than a first threshold, and obtaining the state vector and error covariance matrix of the main filter unit as the reference state vector and reference error covariance matrix, includes: Step S1015: After interrupting the recursive update process of the error covariance matrix in the main filter unit, determine the first update period corresponding to the residual with a positive rate of change greater than the first threshold.
[0086] Step S1016: Determine the time corresponding to the second update cycle that is before the first update cycle and adjacent to the first update cycle as the index time.
[0087] Step S1017: Copy and store the state vector and error covariance matrix of the main filtering unit at the index time to obtain the reference state vector and reference error covariance matrix.
[0088] In this embodiment, during the acquisition of the reference state vector and the reference error covariance matrix, the electronic device can, after interrupting the recursive update process of the error covariance matrix in the main filter unit, execute steps S1015 to S1017 to copy and store the state vector and error covariance matrix of the main filter unit at the index time, thereby obtaining the reference state vector and the reference error covariance matrix. This saves a precise snapshot of the state vector and error covariance matrix of the main filter unit in the update cycle before the occurrence of the service impact. This snapshot serves as the initial value for configuring the auxiliary filter unit in the subsequent step S102 and as the golden reference benchmark for restoring the main filter unit in step S104. This allows the auxiliary filter unit to process subsequent observation data starting from a stable state that is known before the event and has not been disturbed, thereby achieving reliable state comparison and regression.
[0089] In some embodiments, the operations corresponding to steps S1015 to S1017 can be performed in the same update cycle as the operation that interrupts the recursive update process of the error covariance matrix in the main filter unit. Internal execution, update cycle It could be the update cycle when the positive rate of change of the residual that first satisfies the communication traffic characteristic value is greater than the first threshold, representing the moment when the starting point of the business impact is officially confirmed.
[0090] After interrupting the recursive update process of the error covariance matrix in the main filtering unit, the electronic device can lock the index time through steps S1015 to S1016. Specifically, in step S1015, the electronic device can determine the first update period corresponding to the residual with a positive rate of change greater than a first threshold. Then, in step S1016, in the first update cycle Previously and in the first update cycle The time corresponding to the adjacent second update cycle is determined as the index time, which can be represented as: (4) in, Indicates the index time.
[0091] At the time of index determination Subsequently, the electronic device can execute step S1017, copying the state vector and error covariance matrix of the main filter unit at the index time and storing the copied content in a protected register or dedicated storage area in the storage unit to obtain the reference state vector and reference error covariance matrix; specifically: (5) in, Represents the reference state vector; Indicates the main filter unit at index time The state vector of the main filter unit at index time The state vector refers to the state of the main filter unit at index time. The posterior state vector obtained after completing the measurement update. It encapsulates the optimal estimate of the normal network behavior pattern learned by the detection system model up to the event occurrence, and its dimension corresponds to the internal state of the communication traffic characteristics of the monitored system.
[0092] (6) in, Represents the reference error covariance matrix; Indicates the main filter unit at index time The error covariance matrix, that is, the matrix in the main filter unit that is related to... The corresponding posterior error covariance matrix, the magnitude of which represents the confidence level or uncertainty level of the main filter unit in the state estimation.
[0093] In some embodiments, after obtaining the reference state vector and the reference error covariance matrix, the electronic device may also generate a completion flag for the operation of obtaining the reference state vector and the reference error covariance matrix: ( , ) (7) in, The function represents the These two parameters are copied from the main filter unit's dynamic runtime memory to a separate, protected register or dedicated storage area in the storage unit, ensuring they remain unchanged during subsequent event durations and are unaffected by recursive calculations within the main filter unit. This ensures that the update cycle at the start of a business impact is stable. Although the actual observed values of communication traffic characteristics have produced huge residuals, the baseline state vector and the baseline error covariance matrix have not been contaminated by this shock. The baseline state vector and the baseline error covariance matrix together constitute a complete mathematical description of the normal baseline of the main filter unit before the event. This application embodiment will... The copying and storage of these two parameters essentially preserves a precise snapshot of the state vector and error covariance matrix of the main filter unit in the update cycle before the business impact occurs. This snapshot serves as the initial value for configuring the auxiliary filter unit in subsequent step S102 and as the golden reference benchmark for restoring the main filter unit in step S104. This allows the auxiliary filter unit to process subsequent observation data starting from a stable state that is known before the event and has not been disturbed, thus achieving reliable state comparison and regression.
[0094] In one optional embodiment of this application, step S102, configuring the auxiliary filtering unit according to the reference state vector and the reference error covariance matrix, includes: Step S1021: Set the initial value of the state vector in the auxiliary filtering unit to the reference state vector.
[0095] Step S1022: Set the initial value of the error covariance matrix in the auxiliary filtering unit to the reference error covariance matrix.
[0096] Step S1023: Set the process noise covariance matrix in the auxiliary filtering unit to a zero matrix.
[0097] In some embodiments, the electronic device may start the auxiliary filtering unit in the same update cycle as the operation of acquiring the reference state vector and the reference error covariance matrix, i.e., the start time of the auxiliary filtering unit. After the auxiliary filtering unit is started, the electronic device can configure the auxiliary filtering unit through the operations corresponding to steps S1021 to S1023.
[0098] Specifically, after the auxiliary filtering unit is started, the electronic device can first define the state vector of the auxiliary filtering unit. Error covariance matrix and process noise covariance matrix .
[0099] After that, the electronic device at the start time The state vector is processed through step S1021. The initial value is set to the baseline state vector: (8) in, This represents the initial value of the state vector in the auxiliary filter unit.
[0100] Electronic devices at the start time The error covariance matrix is processed in step S1022. The initial values are set as the baseline error covariance matrix: (9) in, This represents the initial value of the error covariance matrix in the auxiliary filtering unit.
[0101] The baseline state vector and the baseline error covariance matrix represent the optimal state estimate and uncertainty measure of the normal network behavior mode of the monitored system by the main filter unit during the update cycle before the event, respectively. Through the configuration operations in steps S1021 and S1022, it is ensured that the starting point of the iterative update of the auxiliary filter unit is completely consistent with the state of the main filter unit before the impact.
[0102] Furthermore, the electronic device, through step S1023, processes the noise covariance matrix in the auxiliary filtering unit. Set as a zero matrix, the configuration formula is: (10) Here, the zero matrix represents a matrix where all elements are zero and its dimension is the same as the process noise covariance matrix in the main filter unit. Through the configuration operation in step S1023, the calculation of the prior error covariance matrix of the auxiliary filter unit can be simplified to: (11) in, This represents the prior error covariance matrix of the auxiliary filtering unit; This represents the state transition matrix pre-set for the monitored system; This indicates that the auxiliary filter unit is in the update cycle. The posterior error covariance matrix; This indicates that the auxiliary filter unit is in the update cycle. The posterior error covariance matrix.
[0103] Formula 11 eliminates the additional uncertainty increment introduced by the process noise covariance matrix in standard Kalman filtering. The principle behind this is that the sudden changes in communication traffic characteristic values caused by legitimate planned service disruptions are essentially deterministic mode switching rather than random disturbances inherent in the monitored system's dynamics. Setting the auxiliary filter unit to a zero matrix degenerates it into an optimal smoother where both state and uncertainty remain constant. During an event, only the observed data of communication traffic characteristics during the event are filtered using the auxiliary filter unit. Since the initial state of the auxiliary filter unit originates from an undisturbed normal baseline, and This makes the state estimation of the auxiliary filter unit... The evolution is mainly driven by observation updates and does not over-track abrupt changes in observation data, thereby generating a stable reference baseline trajectory that is not affected by sudden business events. This trajectory mathematically represents the deterministic evolution path that the state of the monitored system should follow when no shock occurs. Through the iterative update of the state vector by the auxiliary filtering unit, an accurate seed state vector can be provided for the recovery operation of the main filtering unit in step S104.
[0104] Among them, the process noise covariance matrix refers to the covariance matrix used to describe the inherent uncertainty of the system itself in the state transition model of the filtering unit. Its size affects the degree of confidence of the filtering unit in the dynamic baseline prediction value.
[0105] This application embodiment is based on a baseline maintenance technique using an auxiliary filtering unit that operates in parallel with the main filtering unit. During an event impact, this technique initiates an auxiliary filtering unit initialized with a baseline state vector and a baseline error covariance matrix. The process noise covariance matrix of the auxiliary filtering unit is forcibly set to zero, degenerating it into a deterministic smoother. This technique allows for continued filtering of the observed data during the event, even when the recursive update process of the main filtering unit's error covariance matrix is interrupted and adaptive learning is paused. This generates a smooth reference baseline trajectory unaffected by the impact, completely preserving the normal mode information before the event. This provides an accurate basis for determining the end of the event and the smooth recovery of the main filtering unit.
[0106] As an example, refer to Figure 3 The flowchart illustrates the steps of a communication traffic detection method provided in an embodiment of this application. Figure 3 The method may specifically include the following steps: Step S301: Obtain the baseline state vector.
[0107] Step S302: Obtain the benchmark error covariance matrix.
[0108] Specifically, the electronic device can obtain the reference state vector and the reference error covariance matrix through the operations corresponding to steps S1015 to S1017, which will not be elaborated here.
[0109] Step S303: Configure the initial value of the state vector in the auxiliary filtering unit.
[0110] Specifically, the electronic device can set the initial value of the state vector in the auxiliary filtering unit as the reference state vector.
[0111] Step S304: Configure the initial value of the error covariance matrix in the auxiliary filtering unit.
[0112] Specifically, the electronic device can set the initial value of the error covariance matrix in the auxiliary filtering unit to the reference error covariance matrix.
[0113] Step S305: Configure the process noise covariance matrix in the auxiliary filtering unit.
[0114] Specifically, the electronic device can set the process noise covariance matrix in the auxiliary filtering unit to a zero matrix.
[0115] Step S306: Control the auxiliary filtering unit to process the observation data during the event.
[0116] Specifically, the electronic device can control the auxiliary filtering unit and the main filtering unit to process the observation data of communication traffic characteristic values in parallel, so that the auxiliary filtering unit and the main filtering unit can each perform iterative updates of the state vector.
[0117] In an optional embodiment of this application, step S104, where the negative rate of change of the residual of the communication traffic feature value is greater than a second threshold, and the absolute value of the residual in at least the most recent two update cycles is less than a third threshold, involves replacing the state vector in the main filter unit with the state vector currently output by the auxiliary filter unit and restoring the recursive update process of the error covariance matrix in the main filter unit, including: Step S1041: Add the residual of the communication traffic feature value in the current update period to a second preset sliding window, and calculate the negative rate of change of the residual of the communication traffic feature value based on the residual sequence in the second preset sliding window. The negative rate of change is: (12) in, This indicates that the communication traffic characteristic value is in the current update cycle. The negative rate of change of the residuals is used to characterize the average strength of the decrease in the residual sequence per unit time. This indicates the length of the second preset sliding window; This represents the residual in the i-th update cycle of the second preset sliding window; This represents the residual in the (i-1)th update cycle of the second preset sliding window; This represents the negative change in the residuals between adjacent update cycles; furthermore, This function extracts the negative change in the residuals between adjacent update cycles.
[0118] Step S1042: If the negative rate of change of the residual of the communication traffic feature value is greater than the second threshold, and the absolute value of the residual of at least the most recent two update cycles is less than the third threshold, perform the operation of replacing the state vector in the main filter unit with the state vector currently output by the auxiliary filter unit and restoring the recursive update process of the error covariance matrix in the main filter unit.
[0119] Specifically, before step S1041, the electronic device can obtain the residual of the communication traffic feature value in the current update cycle using a method similar to steps S1011 and S1012; then, based on the residual of the communication traffic feature value in the current update cycle, the electronic device performs the operation of step S1041. After step S1041, the electronic device can also match the negative rate of change with a second threshold, and if the negative rate of change is greater than the second threshold, match the absolute value of the residual with a third threshold. If the negative rate of change of the residual of the communication traffic feature value is greater than the second threshold, and the absolute value of the residual in at least the most recent two update cycles is less than the third threshold, then step S1042 is performed to replace the state vector in the main filter unit with the state vector currently output by the auxiliary filter unit, and to restore the recursive update process of the error covariance matrix in the main filter unit.
[0120] In this embodiment, step S1041 is implemented based on continuous monitoring of the real-time residual sequence generated by the main filtering unit. To detect the negative steep falling edge that marks the end of a planned service impact, the electronic device uses a second preset sliding window with the same length as the first preset sliding window in step S1013, i.e. And calculate the negative rate of change of the residuals of the communication traffic characteristic values. The calculation process is shown in Formula 12.
[0121] Formula 12 calculates the reduction for each adjacent residual within the second preset sliding window. and through The function ensures that only positive decreases are accumulated, and the final result is... This characterizes the average intensity of the residual sequence decline per unit time. The calculation in Formula 12 is symmetrical to the positive rate of change calculated in Formula 3, aiming to capture the equally rapid characteristic change pattern during shock pullbacks. Before step S1042, a negative rate of change threshold, i.e., the second threshold, is preset. , The value and the first threshold Quite, usually satisfies Upon monitoring At that time, the electronic device can initially identify a potential negative step; however, this single condition is insufficient to reliably determine the end of the service event, as brief fluctuations may also produce a similar falling edge. Therefore, in this embodiment, a second determination condition is introduced, namely, in... The absolute value of the residuals of the communication traffic characteristic values over the subsequent N consecutive update periods. It must remain below a threshold defined by the normal fluctuation level before the event. (That is, the third threshold), where N is an integer greater than 1. Only when both of the above conditions are met simultaneously—that is, when the negative rate of change of the residual of the communication traffic characteristic value is greater than the second threshold, and the absolute value of the residual in at least the most recent two update cycles is less than the third threshold—can the electronic device finally determine that the planned service impact event has ended, and the communication traffic characteristic value begins to enter the recovery phase. The principle of this dual criterion is that when a legitimate planned service ends, the decline in the communication traffic characteristic value is also rapid and has a clear pattern. The steepness of the falling edge corresponds to the steepness of the rising edge at the beginning of the event, and the residual after the decline stabilizes near the pre-event baseline. This confirms that the monitored system has returned to normal operating mode, which helps to provide a precise trigger time for step S1042 to initiate the safe baseline recovery process, avoiding false triggering or delayed triggering, and improving the accuracy and timeliness of the recovery of the main filter unit.
[0122] In some embodiments, the third threshold is determined based on the statistical variance of the normal residual sequence of the monitored system over a historical period.
[0123] The electronic device has a negative rate of change greater than the second threshold for the residuals of the communication traffic characteristic values, and the absolute value of the residuals for at least the most recent two update periods is less than the update period of the third threshold. Step S1042 can be executed immediately. Specifically, the electronic device can output the posterior state vector of the auxiliary filtering unit. As the only correct seed state vector, it is used through the state injection operation: This operation forcibly replaces the current state vector within the main filter unit, which may be distorted due to event impacts. It resets the state vector of the main filter unit to a smooth reference trajectory maintained by the auxiliary filter unit that is unaffected by the impact. At the same time, it restores the recursive update process of the error covariance matrix in the main filter unit, which helps the main filter unit to quickly return to a stable filtering and tracking state, avoids estimation oscillations and misjudgments caused by sudden changes in the state vector, and improves the accuracy and reliability of the main filter unit in subsequent detection of communication traffic anomalies.
[0124] In one optional embodiment of this application, the communication traffic detection method provided in this application may further include: Step S105: Set an initial value for the process noise covariance matrix of the main filter unit, and control the initial value to decay exponentially according to a preset attenuation constant.
[0125] In this embodiment, after the electronic device replaces the state vector in the main filter unit with the state vector currently output by the auxiliary filter unit in step S104 and restores the recursive update process of the error covariance matrix in the main filter unit, it can also execute step S105 to set an initial value for the process noise covariance matrix of the main filter unit and control the initial value to decay exponentially according to a preset decay constant. This allows for a moderate and rapid adjustment of the state vector in the early stage of the recovery phase of the main filter unit, and makes the process noise covariance matrix decay exponentially according to the preset decay constant within several update cycles. This helps guide the dynamic baseline prediction value of the main filter unit to converge smoothly and without overshoot to a new normal steady-state level after the event, eliminates the persistent false abnormal alarm trail caused by convergence delay in related technologies, and reduces the number of false alarms in the monitoring system.
[0126] Among them, exponential decay refers to a mathematical decay method that causes the magnitude of the process noise covariance matrix to decrease rapidly to zero over time according to a negative exponential function, which is used to achieve smooth, overshoot-free convergence of the dynamic baseline prediction value of the main filter unit.
[0127] In one optional embodiment of this application, step S105, which involves setting an initial value for the process noise covariance matrix of the main filter unit and controlling the initial value to decay exponentially according to a preset attenuation constant, includes: Step S1051: Set an initial value for the process noise covariance matrix of the main filter unit, and control the initial value to decay exponentially according to a preset attenuation constant. The process noise covariance matrix of the main filter unit is: (13) in, Indicates that the index is updated periodically; Indicates that the main filter unit is in the first... The process noise covariance matrix for each update cycle; This represents the initial value of the process noise covariance matrix; This represents the preset attenuation constant.
[0128] In this embodiment, the electronic device can reconfigure a temporary process noise covariance matrix for the main filter unit. The initial value of this process noise covariance matrix is set to a large positive definite matrix to provide sufficient adjustment flexibility to the state vector in the early stage of the recovery phase of the main filter unit. Its evolution follows an exponential decay law as shown in Equation 13, wherein... From The initial recovery phase updates the periodic index. Starting from 0 and incrementing, each updated index corresponds to one update cycle. Corresponding update cycle , It is a preset attenuation constant that controls the exponential decay rate of the initial value, ensuring that the initial value of the process noise covariance matrix decays to a negligible level within a preset number of update cycles. In some embodiments, The value range is 0.2 to 1.0. The attenuation mechanism of Formula 13 makes the temporary process noise covariance matrix reconfigured by the main filter unit quickly approach the zero matrix within several update cycles. This allows the main filter unit to make moderate and rapid state corrections based on new observation data in the early stage of the recovery phase, and then gradually reduce the correction magnitude, guiding the dynamic baseline prediction value of the main filter unit to converge smoothly and without overshoot to the new normal steady-state level after the event. This fundamentally eliminates the persistent false anomaly trails caused by excessive correction or delayed convergence of the dynamic baseline in related techniques. It is the auxiliary filter unit in the update cycle The posterior state vector is obtained by iteratively updating the state vector of the auxiliary filter unit during the parallel processing of observation data of communication traffic feature values by the auxiliary filter unit and the main filter unit. The main filter unit during the update cycle The state vector is updated to the posterior state vector output by the auxiliary filtering unit after the state injection operation. ; Indicates the main filter unit in the th... The process noise covariance matrix of each update cycle serves as the update cycle index. The function is used to replace the standard process noise covariance matrix of the main filter unit; This represents the initial value of the process noise covariance matrix, which is set based on prior knowledge of the adjustment rate required for the recovery phase of the main filter unit.
[0129] Specifically, this application embodiment utilizes the process noise covariance matrix in the filtering unit to adjust the response speed of the filtering unit, and achieves a smooth transition from rapid correction to steady-state tracking through an exponential decay law. Specifically, the core gain of the filtering unit... The size of the value directly determines the degree of trust that the filtering unit has in the new observation data, and Calculation and process noise covariance matrix Positive correlation, that is The larger the value, the higher the uncertainty of the monitoring system model itself. The filtering unit will then trust the new observation data more and make a greater correction to the state.
[0130] Based on this principle, an initial value can be configured for the main filter unit in the early stages of the recovery phase after the event ends. Large temporary process noise covariance matrix This allows the initial gains to be restored. The corresponding magnitude is relatively large, allowing the main filter unit to quickly and fully correct the newly injected state vector, which may not yet be fully accurate, when it receives the first observation data after the event returns to normal. This rapidly eliminates the minor deviations that may be caused by the interruption of the error covariance matrix during the event and the state injection operation, quickly pulling the state vector closer to the real observation data.
[0131] However, if a large amount is maintained for a long time If the main filtering unit continuously overreacts to any observed noise, the state vector will oscillate or overshoot. Therefore, embodiments of this application introduce an exponential decay law. This ensures that the process noise covariance matrix follows a preset attenuation constant. It decreases rapidly over time. With... value decay, This also decreases accordingly, as the main filter unit's confidence in the observed data gradually decreases while its confidence in the monitoring system model gradually recovers. This results in a larger correction amplitude for the main filter unit in the initial recovery phase to quickly approximate the true value, followed by a gradual decrease in the correction amplitude to prevent overshoot. Finally, when... When the decay rate approaches zero, the main filter unit smoothly transitions to a normal tracking mode that relies on model predictions.
[0132] In this embodiment, the main filter unit achieves uninterrupted regression after the planned service ends through state vector injection and controlled attenuation mechanism. Specifically, at the end of the event, the state vector output by the auxiliary filter unit is injected into the main filter unit to reset its internal state vector. The main filter unit is also configured with a process noise covariance matrix with a large initial value and exponential attenuation according to a preset attenuation constant. This method ensures that the dynamic baseline of the main filter unit can converge quickly and without overshoot to a new normal steady state after the event, thereby eliminating the persistent false abnormal alarm trails caused by convergence delay or oscillation in related technologies, and significantly improving the accuracy and usability of the communication traffic detection method provided in this application.
[0133] As an example, refer to Figure 4 The flowchart illustrates the steps of a communication traffic detection method provided in an embodiment of this application. Figure 4 The method may specifically include the following steps: Step S401: Detect the negative rate of change of the residual.
[0134] Specifically, after step S103, the electronic device can continuously detect the negative rate of change of the residual of the communication traffic characteristic value through step S1041 in each update cycle.
[0135] Step S402: Determine whether the negative rate of change of the residual exceeds the threshold and the residual falls back.
[0136] Specifically, if the negative rate of change of the residual is greater than the second threshold and the absolute value of the residual in the most recent at least two update periods is less than the third threshold, the electronic device can determine that the negative rate of change of the residual exceeds the threshold and the residual falls back, and execute step S403; if the negative rate of change of the residual is less than or equal to the second threshold, or the absolute value of at least one of the residuals in the most recent at least two update periods is greater than or equal to the third threshold, the electronic device can determine that the negative rate of change of the residual does not exceed the threshold or the residual does not fall back, and repeat step S401.
[0137] Step S403: Determine if the event has ended.
[0138] Specifically, when the negative rate of change of the residual exceeds a threshold and the residual falls back, the electronic device can determine that the planned business event has ended.
[0139] Step S404: Obtain the state vector output by the auxiliary filtering unit.
[0140] Specifically, after the event is determined to be over, the electronic device can obtain the posterior state vector output by the auxiliary filtering unit in the current update cycle.
[0141] Step S405: Replace the state vector in the main filter unit with the state vector output by the auxiliary filter unit.
[0142] Specifically, electronic devices can use a state injection operation to forcibly replace the state vector in the main filter unit with the state vector output by the auxiliary filter unit.
[0143] Step S406: Configure the process noise covariance matrix of the main filter unit.
[0144] Specifically, the electronic device can configure the process noise covariance matrix of the main filter unit through the operation of step S1051.
[0145] Step S407: Control the main filter unit to converge to a new steady state.
[0146] Specifically, after configuring the process noise covariance matrix of the main filter unit, the electronic device can make the process noise covariance matrix of the main filter unit decay exponentially according to the preset decay constant within several update cycles. This helps to guide the dynamic baseline prediction value of the main filter unit to converge smoothly and without overshoot to the new normal steady-state level after the event.
[0147] Reference Figure 5 The flowchart illustrates the steps of a communication traffic detection method provided in an embodiment of this application. Figure 5 The method may specifically include the following steps: Step S501: Real-time detection of the positive rate of change of the residuals of communication traffic characteristic values.
[0148] Specifically, the electronic device can detect the positive rate of change of the residual of the communication traffic characteristic value in real time during each update cycle of the main filter unit through the operations corresponding to steps S1011 to S1013.
[0149] Step S502: Determine whether a steep positive step rise edge occurs.
[0150] Specifically, when the electronic device obtains the positive rate of change of the residual, it can match the positive rate of change with a first threshold. If the positive rate of change is greater than the first threshold, it is determined that a steep positive step rising edge has occurred, and step S503 is executed again; if the positive rate of change is less than or equal to the first threshold, it is determined that no steep positive step rising edge has occurred, and step S501 is executed again.
[0151] Step S503: Interrupt the recursive update process of the error covariance matrix in the main filter unit.
[0152] Specifically, in the event of a steep positive step rising edge, the electronic device can interrupt the recursive update process of the error covariance matrix in the main filter unit through the operation in step S101 above.
[0153] Step S504: Obtain the reference state vector and the reference error covariance matrix.
[0154] Specifically, the electronic device can obtain the reference state vector and the reference error covariance matrix through the operation of step S101 or steps S1015 to S1017.
[0155] Step S505: Start the auxiliary filtering unit and configure the auxiliary filtering unit.
[0156] Specifically, the electronic device can start the auxiliary filtering unit and configure the auxiliary filtering unit through the operation corresponding to step S102 or steps S1021 to S1023.
[0157] Step S506: Real-time detection of the negative rate of change of the residuals of communication traffic characteristic values.
[0158] Specifically, after step S505, the electronic device can control the auxiliary filtering unit and the main filtering unit to process the observed data of communication traffic feature values in parallel, so that the auxiliary filtering unit and the main filtering unit each perform iterative updates of their state vectors. During the parallel processing of the observed data of communication traffic feature values by the auxiliary filtering unit and the main filtering unit, the negative rate of change of the residuals of the communication traffic feature values is detected in real time during each update cycle of the main filtering unit. The specific method for detecting the negative rate of change of the residuals of the communication traffic feature values can be found in the detailed description of step S1041, and will not be repeated here.
[0159] Step S507: Determine whether the negative rate of change of the residual exceeds the threshold and the residual falls back.
[0160] Specifically, if the negative rate of change of the residual of the communication traffic characteristic value is greater than the second threshold, and the absolute value of the residual of the most recent at least two update cycles is less than the third threshold, the electronic device can determine that the negative rate of change of the residual exceeds the threshold and the residual falls back, and execute step S508; if the negative rate of change of the residual of the communication traffic characteristic value is less than or equal to the second threshold, or the absolute value of at least one of the residuals of the most recent at least two update cycles is greater than or equal to the third threshold, the electronic device can determine that the negative rate of change of the residual does not exceed the threshold or the residual does not fall back, and execute step S506 again.
[0161] Step S508: Determine if the event has ended.
[0162] Specifically, in the event of a steep negative step falling edge, the electronic device can determine that the planned business event has ended.
[0163] Step S509: Inject the seed state vector.
[0164] Specifically, the electronic device can use the posterior state vector currently output by the auxiliary filtering unit as the only correct seed state vector, and forcefully replace the current state vector inside the main filtering unit that may be distorted due to event impact through state injection operation.
[0165] Step S510: Restore baseline detection.
[0166] Specifically, the electronic device can restore the recursive update process of the error covariance matrix in the main filter unit, set an initial value for the process noise covariance matrix of the main filter unit, and control the initial value to decay exponentially according to a preset decay constant. This allows the main filter unit to achieve a moderate and rapid adjustment of the state vector in the early stage of the recovery phase, and to decay the process noise covariance matrix exponentially according to the preset decay constant within several update cycles. This guides the dynamic baseline prediction value of the main filter unit to converge smoothly and without overshoot to a new normal steady-state level after the event, eliminating the persistent false abnormal alarm trail caused by convergence delay in related technologies and reducing the number of false alarms in the monitoring system.
[0167] As an example, the implementation method of this application is described in conjunction with a specific application scenario and actual data. The monitoring system configuration and initial parameter settings include: assuming this monitoring system is deployed on the dispatch data network access router of a 220kV substation, monitoring the PPS (Power Segmentation Per Second) of the PPS leading to the main station's specific service virtual local area network (VLAN) as a communication traffic characteristic value. A master Kalman filter is used to perform dynamic baseline prediction on the PPS sequence. The relevant initial parameter settings are as follows: State vector It is 2-dimensional, representing the horizontal and trend components of PPS respectively.
[0168] The state transition matrix of the main Kalman filter Observation matrix .
[0169] Initial process noise covariance matrix of the main Kalman filter Observation noise covariance matrix .
[0170] First preset sliding window The length of the second preset sliding window for (That is, 5 update cycles, with a time interval of 1 second between each update cycle).
[0171] First threshold equal to the second threshold , .
[0172] Event-end residual stability determination parameters: continuous The absolute value of the residual in each update cycle is less than the third threshold, which is: (Based on historical normal fluctuation statistics).
[0173] The initial values of the temporary process noise covariance matrix during the recovery phase of the main Kalman filter are: Preset attenuation constant .
[0174] The specific implementation process may include the following steps: Step S601, during the update cycle Previously, the network was in a steady state, with PPS fluctuating around 1000. The state vector of the main Kalman filter... posterior error covariance matrix It is at a relatively small, stable value. At that time, due to the planned switching of the primary and backup protection control channels, the observed value of PPS... It surged to 5000 within 1 second. (Electronic device calculation) residual The positive rate of change is calculated based on the residuals from the most recent five update periods. .because The electronic device immediately detects a steep positive step rising edge and sends a control signal. Set to true.
[0175] Subsequently, the electronic device interrupted the posterior error covariance matrix in the master Kalman filter. The recursive update process makes it equal to Simultaneously, the main Kalman filter is updated during the update cycle. The state vector and the posterior error covariance matrix are copied and stored to obtain the baseline state vector. and the reference error covariance matrix .
[0176] Step S602, from Initially, the electronic device starts the auxiliary Kalman filter. The initial value of the state vector in the auxiliary Kalman filter is set to... The initial value of the posterior error covariance matrix in the auxiliary Kalman filter is set to... And force the process noise covariance matrix in the auxiliary Kalman filter to be... Set as .
[0177] exist During the event's duration, although the actual observed PPS remained high (e.g., 5000), the auxiliary Kalman filter, due to its model having no process noise and a normal initial state, maintained a high state vector. It will only adjust very slowly towards higher observations, generating a smooth, slowly rising reference trajectory, for example, in At that time, its state vector may only be Meanwhile, the main Kalman filter's state vector is interrupted due to the recursive update process of the posterior error covariance matrix. The response to high observation values was also greatly suppressed.
[0178] Step S603, planned switchover operation At the end of the time, the actual observed value of PPS dropped sharply from 5000 to 1500 within 1 second. (Electronic equipment calculation) negative rate of change of the residual Assuming ,because The electronic device marks a negative step. Subsequently, during the update cycle... The observed PPS values stabilized around 1000, corresponding to the absolute value of the residuals. All less than Therefore, during the update cycle The electronic device determines the event is over and records it. .
[0179] Step S604, during the update cycle The electronic device performs the recovery operation of the main Kalman filter.
[0180] State injection: Reading the auxiliary Kalman filter in The posterior state vector at time, for example Inject this value into the master Kalman filter: This state vector reflects the result of smooth evolution during the event and is not significantly different from the PPS observations around 1000 after the event, providing a good starting point for the recovery of the main Kalman filter.
[0181] Noise Attenuation Recovery: Configuring the Temporary Process Noise Covariance Matrix for the Master Kalman Filter In the first recovery cycle ( Corresponding update cycle ), This value is much larger than the normal value. Allowing the main Kalman filter to... The state vector is significantly corrected based on the observed values (approximately 1000). In the next recovery cycle ( , ), The noise level decays rapidly, taking approximately 5-6 recovery cycles. hour, The temporary process noise covariance matrix is compared with the original... At the same or even lower magnitudes, the process noise covariance matrix configuration of the master Kalman filter automatically reverts to normal. During this period, the dynamic baseline predictions of the master Kalman filter are smoothly and without overshoot guided to a new steady-state level (fluctuating around 1000 PPS) after the event.
[0182] In comparative studies that did not employ the communication traffic detection method provided in this application, the traditional Kalman filter or the Exponentially Weighted Moving Average Algorithm (EWMA) rapidly "raises" the dynamic baseline when faced with a step increase in PPS from 1000 to 5000. When PPS is at... When the value falls back to 1000, the raised dynamic baseline takes a relatively long time (tens of seconds) to slowly converge. During this period, the actual observed value remains lower than the raised dynamic baseline, resulting in continuous negative "false anomaly trail" alarms. Using the communication traffic detection method provided in this application, as described above, the dynamic baseline prediction value of the main Kalman filter is not pulled away during the event. At the end of the event, the starting point is quickly reset by injecting a smooth state into the auxiliary Kalman filter, and fast and stable convergence is achieved through the exponential decay of the initial value of the process noise covariance matrix. In the above example, in The subsequent dynamic baseline predictions of the master Kalman filter can quickly track the actual observations by about 1000 PPS, with residuals... Immediately return to the normal fluctuation range ( ), thus completely eliminating The false anomaly alerts after the switchover is completed provide robust handling of disruptions to legitimate business operations.
[0183] In summary, the communication traffic detection method provided in this application indicates that when the positive rate of change of the residual of the communication traffic feature value is greater than a first threshold, it indicates that the communication traffic feature value has experienced a steep positive step rising edge that conforms to the characteristics of planned service impact. In this scenario, interrupting the recursive update process of the error covariance matrix in the main filter unit can avoid the main filter unit from over-tracking and iteratively updating the observed data mutations caused by planned service events. This helps maintain the stability of the state vector and error covariance matrix of the main filter unit before the event, thereby improving the reliability of the obtained baseline state vector and baseline error covariance matrix. After starting the auxiliary filter unit, configuring the auxiliary filter unit according to the baseline state vector and baseline error covariance matrix allows the auxiliary filter unit to maintain the state vector and baseline error covariance matrix before the event. Starting from a known and undisturbed steady state, subsequent observation data is processed to achieve reliable state comparison and regression. When the negative rate of change of the residuals of communication traffic characteristic values is greater than the second threshold and the absolute value of the residuals in at least the most recent two update cycles is less than the third threshold, it indicates that the planned business impact event has ended. In this scenario, the state vector in the main filter unit is replaced with the current output state vector of the filter unit, and the recursive update process of the error covariance matrix in the main filter unit is restored. This enables the main filter unit to converge quickly and without overshoot to the new normal steady state after the event. This helps to eliminate the persistent false anomaly alarm trails caused by convergence delay in related technologies, reduce the number of false alarms in the monitoring system, reduce the workload of security operation and maintenance personnel, and improve the accuracy and efficiency of communication traffic detection and operation and maintenance.
[0184] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of this application are not limited to the described order of actions, because according to the embodiments of this application, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of this application.
[0185] Device Examples Reference Figure 6 This application provides a communication traffic detection device, the device comprising: The first control module 601 is used to interrupt the recursive update process of the error covariance matrix in the main filter unit when the positive rate of change of the residual of the communication traffic feature value is greater than the first threshold, and to obtain the state vector and error covariance matrix of the main filter unit as the reference state vector and reference error covariance matrix. The first configuration module 602 is used to start the auxiliary filtering unit and configure the auxiliary filtering unit according to the reference state vector and the reference error covariance matrix; The second control module 603 is used to control the auxiliary filtering unit and the main filtering unit to process the observation data of communication traffic feature values in parallel, so that the auxiliary filtering unit and the main filtering unit each perform iterative updates of the state vector. The second configuration module 604 is used to replace the state vector in the main filter unit with the state vector currently output by the auxiliary filter unit and restore the recursive update process of the error covariance matrix in the main filter unit when the negative rate of change of the residual of the communication traffic feature value is greater than a second threshold and the absolute value of the residual of at least the most recent two update cycles is less than a third threshold.
[0186] Optionally, the first control module includes: The first acquisition submodule is used to acquire the dynamic baseline prediction value of the communication traffic feature value in the current update cycle using the main filtering unit; The first calculation submodule is used to calculate the difference between the observed value of the communication traffic feature value in the current update period and the predicted value of the dynamic baseline, and to use the difference as the residual of the communication traffic feature value in the current update period. The second calculation submodule is used to add the residual of the communication traffic feature value in the current update cycle to the first preset sliding window, and calculate the positive rate of change of the residual of the communication traffic feature value based on the residual sequence in the first preset sliding window. The first control submodule is used to, when the positive rate of change of the residual of the communication traffic feature value is greater than a first threshold, execute the recursive update process of the error covariance matrix in the main filter unit to interrupt it, and obtain the state vector and error covariance matrix of the main filter unit as the reference state vector and reference error covariance matrix.
[0187] Optionally, the residual sequence in the first preset sliding window includes the residuals of the communication traffic feature values over at least two different update periods; the second calculation submodule includes: The calculation unit is configured to calculate the positive rate of change of the residuals of the communication traffic feature values based on the residual sequence in the first preset sliding window, wherein the positive rate of change is: ; in, This indicates that the communication traffic characteristic value is in the current update cycle. The positive rate of change of the residuals; This indicates the length of the first preset sliding window; This represents the residual in the i-th update cycle of the first preset sliding window; This represents the residual in the (i-1)th update cycle of the first preset sliding window; This represents the positive change in the residual between adjacent update cycles.
[0188] Optionally, the first control module further includes: The first determination submodule is used to determine the first update period corresponding to the residual with a positive rate of change greater than a first threshold after the recursive update process of the error covariance matrix in the interrupted main filtering unit is completed. The second determining submodule is used to determine the time corresponding to the second update cycle that is before the first update cycle and adjacent to the first update cycle as the index time; The second acquisition submodule is used to copy and store the state vector and error covariance matrix of the main filtering unit at the index time to obtain the reference state vector and the reference error covariance matrix.
[0189] Optionally, the first configuration module includes: The first configuration submodule is used to set the initial value of the state vector in the auxiliary filtering unit to the reference state vector; The second configuration submodule is used to set the initial value of the error covariance matrix in the auxiliary filtering unit to the reference error covariance matrix; The third configuration submodule is used to set the process noise covariance matrix in the auxiliary filtering unit to a zero matrix.
[0190] Optionally, the second configuration module includes: The third calculation submodule is used to add the residual of the communication traffic feature value in the current update period to a second preset sliding window, and calculate the negative rate of change of the residual of the communication traffic feature value based on the residual sequence in the second preset sliding window, wherein the negative rate of change is: ; in, This indicates that the communication traffic characteristic value is in the current update cycle. The negative rate of change of the residuals; This indicates the length of the second preset sliding window; This represents the residual in the i-th update cycle of the second preset sliding window; This represents the residual in the (i-1)th update cycle of the second preset sliding window; This represents the negative change in the residual between adjacent update cycles; The second control submodule is configured to perform the following operation when the negative rate of change of the residual of the communication traffic feature value is greater than a second threshold and the absolute value of the residual of the most recent at least two update cycles is less than a third threshold: replacing the state vector in the main filter unit with the state vector currently output by the auxiliary filter unit and restoring the recursive update process of the error covariance matrix in the main filter unit.
[0191] Optionally, the device further includes: The third configuration module is used to set an initial value for the process noise covariance matrix of the main filter unit and control the initial value to decay exponentially according to a preset attenuation constant.
[0192] Optionally, the third configuration module includes: The fourth configuration submodule is used to set an initial value for the process noise covariance matrix of the main filter unit, and control the initial value to decay exponentially according to a preset attenuation constant. The process noise covariance matrix of the main filter unit is: ; in, Indicates that the index is updated periodically; Indicates that the main filter unit is in the first... The process noise covariance matrix for each update cycle; This represents the initial value of the process noise covariance matrix; This represents the preset attenuation constant.
[0193] As the apparatus embodiment is basically similar to the method embodiment, it is described in a relatively simple manner. For relevant details, please refer to the description of the method embodiment.
[0194] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0195] This application also provides an electronic device, including a processor, a main filtering unit, an auxiliary filtering unit, and a storage unit; the storage unit is used to store executable instructions, which cause the processor to execute the communication traffic detection method described above.
[0196] This application also provides a computer program product, including a computer program / instructions, which, when executed by a processor, implement the communication traffic detection method described above.
[0197] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0198] Those skilled in the art will understand that embodiments of this application can be provided as methods, apparatus, or computer program products. Therefore, embodiments of this application can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of this application can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0199] Although preferred embodiments of the present application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present application.
[0200] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.
[0201] The foregoing has provided a detailed description of the communication traffic detection method, electronic device, and computer program product provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the method and its core ideas. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A method for detecting communication traffic, characterized in that, The method includes: If the positive rate of change of the residual of the communication traffic feature value is greater than the first threshold, the recursive update process of the error covariance matrix in the main filter unit is interrupted, and the state vector and error covariance matrix of the main filter unit are obtained as the reference state vector and reference error covariance matrix. The auxiliary filtering unit is activated and configured according to the reference state vector and the reference error covariance matrix; The auxiliary filtering unit and the main filtering unit are controlled to process the observation data of communication traffic feature values in parallel, so that the auxiliary filtering unit and the main filtering unit each perform iterative updates of the state vector. If the negative rate of change of the residual of the communication traffic feature value is greater than the second threshold, and the absolute value of the residual of at least the most recent two update cycles is less than the third threshold, the state vector in the main filter unit is replaced with the state vector currently output by the auxiliary filter unit, and the recursive update process of the error covariance matrix in the main filter unit is restored.
2. The method according to claim 1, characterized in that, When the positive rate of change of the residual of the communication traffic characteristic value is greater than a first threshold, the recursive update process of the error covariance matrix in the main filter unit is interrupted, and the state vector and error covariance matrix of the main filter unit are obtained as the reference state vector and reference error covariance matrix, including: The main filtering unit is used to obtain the dynamic baseline prediction value of communication traffic feature values in the current update cycle; Calculate the difference between the observed value of the communication traffic feature value in the current update period and the predicted value of the dynamic baseline, and use the difference as the residual of the communication traffic feature value in the current update period; The residual of the communication traffic feature value in the current update cycle is added to the first preset sliding window, and the positive rate of change of the residual of the communication traffic feature value is calculated based on the residual sequence in the first preset sliding window. If the positive rate of change of the residual of the communication traffic feature value is greater than the first threshold, the recursive update process of the error covariance matrix in the interrupt main filter unit is executed, and the state vector and error covariance matrix of the main filter unit are obtained as the reference state vector and reference error covariance matrix.
3. The method according to claim 2, characterized in that, The residual sequence in the first preset sliding window includes the residuals of the communication traffic feature values in at least two different update cycles; The step of calculating the positive rate of change of the residuals of the communication traffic feature values based on the residual sequence in the first preset sliding window includes: Based on the residual sequence in the first preset sliding window, the positive rate of change of the residuals of the communication traffic feature values is calculated, and the positive rate of change is: ; in, This indicates that the communication traffic characteristic value is in the current update cycle. The positive rate of change of the residuals; This indicates the length of the first preset sliding window; This represents the residual in the i-th update cycle of the first preset sliding window; This represents the residual in the (i-1)th update cycle of the first preset sliding window; This represents the positive change in the residual between adjacent update cycles.
4. The method according to claim 1, characterized in that, The step of obtaining the state vector and error covariance matrix of the main filter unit as the reference state vector and reference error covariance matrix includes: After interrupting the recursive update process of the error covariance matrix in the main filter unit, the first update period corresponding to the residual with a positive rate of change greater than the first threshold is determined. The time corresponding to the second update cycle that is before the first update cycle and adjacent to the first update cycle is determined as the index time; The state vector and error covariance matrix of the main filtering unit at the index time are copied and stored to obtain the reference state vector and the reference error covariance matrix.
5. The method according to claim 1, characterized in that, The configuration of the auxiliary filtering unit based on the reference state vector and the reference error covariance matrix includes: The initial value of the state vector in the auxiliary filtering unit is set as the reference state vector; The initial value of the error covariance matrix in the auxiliary filtering unit is set to the reference error covariance matrix; Set the process noise covariance matrix in the auxiliary filtering unit to zero.
6. The method according to claim 1, characterized in that, The step of replacing the state vector in the main filter unit with the current output state vector of the auxiliary filter unit and restoring the recursive update process of the error covariance matrix in the main filter unit when the negative rate of change of the residual of the communication traffic feature value is greater than the second threshold and the absolute value of the residual of at least the most recent two update cycles is less than the third threshold includes: The residual of the communication traffic feature value in the current update period is added to a second preset sliding window, and based on the residual sequence in the second preset sliding window, the negative rate of change of the residual of the communication traffic feature value is calculated, wherein the negative rate of change is: ; in, This indicates that the communication traffic characteristic value is in the current update cycle. The negative rate of change of the residuals; This indicates the length of the second preset sliding window; This represents the residual in the i-th update cycle of the second preset sliding window; This represents the residual in the (i-1)th update cycle of the second preset sliding window; This represents the negative change in the residual between adjacent update cycles; If the negative rate of change of the residual of the communication traffic feature value is greater than the second threshold, and the absolute value of the residual of the most recent two update cycles is less than the third threshold, then the operation of replacing the state vector in the main filter unit with the state vector currently output by the auxiliary filter unit and restoring the recursive update process of the error covariance matrix in the main filter unit is performed.
7. The method according to claim 1, characterized in that, The method further includes: An initial value is set for the process noise covariance matrix of the main filter unit, and the initial value is controlled to decay exponentially according to a preset attenuation constant.
8. The method according to claim 7, characterized in that, The step of setting an initial value for the process noise covariance matrix of the main filter unit and controlling the initial value to decay exponentially according to a preset attenuation constant includes: An initial value is set for the process noise covariance matrix of the main filter unit, and the initial value is controlled to decay exponentially according to a preset attenuation constant. The process noise covariance matrix of the main filter unit is: ; in, Indicates that the index is updated periodically; Indicates that the main filter unit is in the first... The process noise covariance matrix for each update cycle; This represents the initial value of the process noise covariance matrix; This represents the preset attenuation constant.
9. An electronic device, characterized in that, It includes a processor, a main filtering unit, an auxiliary filtering unit, and a storage unit; the storage unit is used to store executable instructions, which cause the processor to execute the communication traffic detection method as described in any one of claims 1 to 8.
10. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the communication traffic detection method as described in any one of claims 1 to 8.