A PCDN service identification method, device and equipment and a computer readable storage medium
By filtering and analyzing the uplink traffic data of terminal devices, a feature candidate table is generated to identify and count the frequency of destination addresses. This solves the problem of misjudgment in P2P CDN user identification in existing technologies, achieving higher accuracy and lower maintenance costs.
Patent Information
- Application Number
- CN202610472566.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-10
- Publication Date
- 2026-08-04
AI Technical Summary
Existing technologies struggle to accurately identify P2P CDN users, resulting in a high false positive rate. Furthermore, the feature database is costly to maintain and cannot effectively identify emerging or unknown PCDN services.
By filtering target terminal devices that meet certain characteristics based on uplink traffic data from terminal devices, a candidate table of service and scheduling message characteristics is generated, the frequency of destination addresses is statistically analyzed, and PCDN services are identified by combining uplink rate, number of connections, and duration.
This improved the accuracy of PCDN user identification, reduced false positives, lowered the workload of feature database construction and maintenance, and avoided impacting broadband services.
Smart Images

Figure CN122513299A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and in particular to a PCDN service identification method, apparatus, device, and computer-readable storage medium. Background Technology
[0002] With the explosive growth of internet video streaming, large file distribution, and live streaming services, bandwidth costs for content delivery networks (CDNs) have become a major burden for internet service providers (ISPs) and content providers. Furthermore, a large number of non-compliant home PCDN (P2P CDN, Peer-to-Peer Content Delivery Network) users occupy upstream bandwidth resources, leading to network congestion and degraded network quality.
[0003] Existing technologies rely on traffic statistics or traditional DPI (Data Point Injection) techniques to identify PCDN users. Traffic statistics involve monitoring user upload traffic, connection count, and duration, setting thresholds for coarse-grained filtering. This method has a very high false positive rate, easily misclassifying legitimate users using Network Attached Storage (NAS), uploading large files, or using BitTorrent / Private Tracking (BT / PT) as PCDN users, leading to user dissatisfaction. Traditional DPI techniques analyze packet load and match specific protocol characteristics or server addresses of known PCDN applications. However, PCDN applications frequently and rapidly change and iterate their protocols and node addresses to evade detection, requiring intensive manual maintenance of the signature database. This results in poor timeliness, high construction and maintenance costs, and an inability to effectively identify emerging or unknown PCDN services. In short, existing technologies cannot accurately count PCDN service traffic, leading to some users of BT, PT, NAS, live streaming, and cloud storage being misclassified as PCDN users. Furthermore, the continuous emergence of new PCDN applications results in a large workload for signature database construction and maintenance.
[0004] Therefore, improving the accuracy of PCDN user identification and avoiding misjudgments is a pressing technical problem that needs to be solved. Summary of the Invention
[0005] The main objective of this invention is to provide a PCDN service identification method, apparatus, device, and computer-readable storage medium. On the one hand, it improves the accuracy of PCDN user identification, avoids misjudgment, and improves the accuracy of PCDN service traffic statistics. On the other hand, it reduces the workload of building and maintaining the PCDN identification feature database and can exclude PCDN users with low traffic and no significant impact on broadband services.
[0006] Firstly, this application provides a PCDN service identification method, wherein the method includes the following steps: Based on the uplink traffic data of terminal devices, target terminal devices that meet the first feature are identified and filtered out. The first feature includes: uplink rate, number of connections and duration. The destination addresses of uplink messages of the target terminal device are counted to generate a candidate table of service message features, and the destination addresses of uplink messages of non-service traffic of the target terminal device are counted to generate a candidate table of scheduling message features. Select target destination addresses whose frequency of occurrence meets the threshold from the service message feature candidate table, and count the frequency of occurrence of the target destination addresses in the scheduling message feature candidate table, so as to use the destination addresses whose frequency of occurrence meets the threshold as the second feature; PCDN services are identified based on the first and second features.
[0007] In conjunction with the first aspect mentioned above, as an optional implementation method, based on the service packet feature candidate table of each terminal device, the number of times each destination address appears in the service packet feature candidate table is counted in order to filter target destination addresses whose frequency of occurrence meets the threshold. The frequency of the target destination address appearing in the scheduling message feature candidate table of the corresponding terminal device is statistically analyzed. The destination address whose frequency meets the threshold is recorded as the PCDN scheduling server IP, and the PCDN scheduling server IP is used as the second feature.
[0008] In conjunction with the first aspect mentioned above, as an optional implementation method, for the selected target terminal devices, the destination addresses of uplink packets are counted within a first time unit during the first continuous period. The destination addresses are aggregated to generate a candidate list of business traffic characteristics. The candidate list of business traffic characteristics includes the peer IPs of the PCDN node service and the user and CDN content server cluster.
[0009] In conjunction with the first aspect mentioned above, as an optional implementation method, for the selected target terminal devices, within the second time unit, the peer IPs communicating with the target terminal devices, excluding the already counted uplink message destination addresses, are counted. The statistical peer IPs are summarized to generate a scheduling message feature candidate table, which includes: PCDN scheduling cluster IPs and peer IPs of periodic heartbeat messages of terminal devices.
[0010] In conjunction with the first aspect mentioned above, as an optional implementation method, if the destination address of the other end is obtained through the domain name resolved by the DNS service, then the destination address of the other end is replaced with the corresponding resolved domain name and recorded.
[0011] In conjunction with the first aspect mentioned above, as an optional implementation method, the uplink traffic of the terminal device on the locally open service port is counted; Target terminal devices are selected based on the results of determining whether the uplink traffic rate, the number of connections, and the duration exceed the set thresholds.
[0012] In conjunction with the first aspect mentioned above, as an optional implementation method, terminal devices that simultaneously match the first and second characteristics are identified as PCDN terminal devices, and the corresponding traffic is counted as PCDN application traffic in order to identify PCDN services.
[0013] Secondly, this application provides a PCDN service identification device, which includes: The identification module is used to identify and filter target terminal devices that meet the first feature based on the uplink traffic data of the terminal devices. The first feature includes: uplink rate, number of connections and duration. The generation module is used to count the destination addresses of uplink messages of the target terminal device to generate a candidate list of service message features, and to count the destination addresses of uplink messages of non-service traffic of the target terminal device to generate a candidate list of scheduling message features. The statistics module is used to filter target destination addresses whose frequency of occurrence meets the threshold from the service message feature candidate table, and to count the frequency of occurrence of the target destination addresses in the scheduling message feature candidate table, so as to use the destination addresses whose frequency of occurrence meets the threshold as the second feature. The processing module is used to identify PCDN services based on the first feature and the second feature.
[0014] Thirdly, embodiments of this application provide a PCDN service identification device, characterized in that the PCDN service identification device includes a processor, a memory, and a PCDN service identification program stored in the memory and executable by the processor, wherein when the PCDN service identification program is executed by the processor, it implements the steps of the PCDN service identification method as described in any one of claims 1 to 7.
[0015] Fourthly, embodiments of this application provide a computer-readable storage medium, characterized in that the computer-readable storage medium stores a PCDN service identification program, wherein when the PCDN service identification program is executed by a processor, it implements the steps of the PCDN service identification method as described in any one of claims 1 to 7.
[0016] This application provides a PCDN service identification method, apparatus, device, and computer-readable storage medium. The method includes the following steps: based on uplink traffic data of terminal devices, identifying and filtering target terminal devices that meet first characteristics, the first characteristics including: uplink rate, number of connections, and duration; statistically analyzing the destination addresses of uplink packets of the target terminal devices to generate a service packet characteristic candidate table, and statistically analyzing the destination addresses of non-service traffic uplink packets of the target terminal devices to generate a scheduling packet characteristic candidate table; filtering target destination addresses whose frequency of occurrence meets a threshold from the service packet characteristic candidate table, and statistically analyzing the frequency of occurrence of the target destination addresses in the scheduling packet characteristic candidate table, using the destination addresses whose frequency of occurrence meets the threshold as a second characteristic; and identifying PCDN services based on the first and second characteristics. This application improves the accuracy of PCDN user identification and avoids misjudgments.
[0017] It should be understood that the above general description and the following detailed description are merely exemplary and do not limit the invention. Attached Figure Description
[0018] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0019] Figure 1 This is a flowchart of a PCDN service identification method provided in the embodiments of this application; Figure 2 This is a schematic diagram of a PCDN service identification device provided in the embodiments of this application; Figure 3 This is a schematic diagram of the architecture of one embodiment provided in this application. Figure 4 This is a schematic diagram illustrating the generation of the second feature provided in the embodiments of this application; Figure 5 This is a schematic diagram of the hardware structure of a PCDN service identification device involved in the embodiments of this application. Detailed Implementation
[0020] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the invention as detailed in the appended claims.
[0021] Furthermore, the accompanying drawings are merely illustrative of this disclosure and are not necessarily drawn to scale. Some of the block diagrams shown in the drawings represent functional entities and do not necessarily correspond to physically or logically independent entities.
[0022] The embodiments of this application will be further described in detail below with reference to the accompanying drawings.
[0023] Reference Figure 1 , Figure 1 The diagram shown is a flowchart of a PCDN service identification method provided by the present invention. Figure 1 As shown, the method includes the following steps: Step S101: Based on the uplink traffic data of the terminal device, identify and filter target terminal devices that meet the first feature, the first feature including: uplink rate, number of connections and duration.
[0024] Specifically, the system counts the uplink traffic of terminal devices on their locally open service ports; and selects target terminal devices based on the results of whether the uplink traffic rate, the number of connections, and the duration exceed the set thresholds.
[0025] For ease of understanding, the Internet traffic analysis module counts the uplink traffic of the locally open service ports on the user side (terminal device), and defines the rate R1, the number of connections C1, and the duration T1 threshold (F1>5Mbps, C1>100, T1>12 hours) as the first feature.
[0026] For example, if user A's uplink traffic exceeds 5Mbps for 12 consecutive hours and the number of connections reaches 200, it meets the first feature, that is, the terminal device that meets the conditions is the target terminal device.
[0027] Step S102: Calculate the destination address of uplink messages of the target terminal device to generate a candidate table of service message features, and calculate the destination address of uplink messages of non-service traffic of the target terminal device to generate a candidate table of scheduling message features.
[0028] Specifically, for the selected target terminal devices, the destination addresses of uplink packets are counted within a first time unit during the first duration period. These destination addresses are then aggregated to generate a candidate list of service traffic characteristics. This candidate list includes the peer IPs of the PCDN node service communicating with the user and the CDN content server cluster. The candidate list contains temporary data used to calculate the first and second characteristics. The statistics and calculations are only repeated when a new terminal needs PCDN identification or when a characteristic fails to correctly identify the PCDN.
[0029] For the selected target terminal devices, within the second time unit, count the peer IPs communicating with the target terminal devices, excluding the already counted uplink message destination addresses; summarize the counted peer IPs to generate a scheduling message feature candidate table, which includes: PCDN scheduling cluster IPs and peer IPs of the terminal devices' periodic heartbeat messages.
[0030] Understandably, for packets that match the first characteristic, the destination IPs of their uplink packets are counted in time unit P1 (P1=10 minutes) and summarized into IP group 1 (service packet characteristic candidate table). In time unit P2 (P2=10 minutes), the peer IPs that the collection node (the collection node can be understood as the terminal device that has not yet been judged as a PCND user) communicates with, excluding IP group 1, are recorded. The IPs that are accessed at the same time unit are counted into IP group 2 (scheduling packet characteristic candidate table).
[0031] It should be noted that if any IP address in IP group 2 is obtained through a domain name resolved via DNS service, the corresponding IP address can be replaced with the domain name. This allows for a more intuitive identification of which PCDN application the second characteristic belongs to, facilitating manual labeling. IP group 2 may contain some well-known domain names or IP addresses. For example, routers or home networking devices may periodically communicate with specific servers; these server IPs will be recorded in IP group 2. This situation can be excluded using a pre-defined whitelist.
[0032] Step S103: Select target destination addresses whose frequency of occurrence meets the threshold from the service message feature candidate table, and count the frequency of occurrence of the target destination addresses in the scheduling message feature candidate table, so as to use the destination addresses whose frequency of occurrence meets the threshold as the second feature.
[0033] Specifically, based on the service packet feature candidate table for each terminal device, the frequency of each destination address appearing in the service packet feature candidate table is counted to filter target destination addresses whose frequency meets the threshold; the frequency of the target destination address appearing in the corresponding terminal device's scheduling packet feature candidate table is also counted; destination addresses whose frequency meets the threshold are recorded as PCDN scheduling server IPs, and the PCDN scheduling server IPs are used as the second feature. In other words, based on IP group 1 for each collection node, the frequency of each IP appearing in IP group 1 is counted. For IPs with a frequency greater than N1 (N1=5), the frequency of each IP in the corresponding collection node's IP group 2 is counted, and IPs with a frequency greater than N2 (N2=5) are recorded as PCDN scheduling server IPs, and used as the second feature (see details). Figure 4 describe).
[0034] Step S104: Identify PCDN services based on the first feature and the second feature.
[0035] Specifically, terminal devices that simultaneously match the first and second characteristics are identified as PCDN terminal devices, and the corresponding traffic is counted as PCDN application traffic in order to identify PCDN services.
[0036] To illustrate this, the network administrator sends the second characteristic to the internet traffic analysis module. When internet users on the network have traffic that meets both the first and second characteristics, they are marked as PCDN users, and this traffic is counted as PCDN service traffic.
[0037] It is understood that this application counts the uplink traffic of the service ports opened locally on the user side, and defines the rate R1, the number of connections C1, and the duration T1 threshold (F1>5Mbps, C1>100, T1>12 hours) as the first feature.
[0038] For packets matching the first characteristic, the destination IPs of their uplink packets are counted in time unit P1 (P1=10 minutes), and summarized into IP group 1 (service packet characteristic candidate table). In time unit P2 (P2=10 minutes), the peer IPs that the collection node communicates with, excluding IP group 1, are recorded. The IPs that are accessed consistently in each time unit are counted into IP group 2 (scheduling packet characteristic candidate table). IP group 1 and IP group 2 are then reported to the network management system.
[0039] On the network management system, based on IP group 1 of each collection node, the number of times each IP appears in IP group 1 is counted. For IPs with a count greater than N1 (N1=5), the number of times each IP appears in IP group 2 of the corresponding collection node is counted. IPs with a count greater than N2 (N2=5) are recorded as PCDN scheduling server IPs and recorded as the second feature.
[0040] The network management system sends the second characteristic to the Internet traffic analysis module. When there is traffic from a network user that meets the first and second characteristics, it is marked as a PCDN user, and this traffic is counted as PCDN service traffic.
[0041] Reference Figure 2 , Figure 2 The diagram shown is a schematic of a PCDN service identification device provided by the present invention. Figure 2 As shown, the device includes: Identification module 201: It is used to identify and filter target terminal devices that meet the first characteristics based on the uplink traffic data of the terminal devices, the first characteristics including: uplink rate, number of connections and duration.
[0042] Generation module 202: It is used to count the destination address of uplink messages of the target terminal device to generate a candidate table of service message features, and to count the destination address of uplink messages of non-service traffic of the target terminal device to generate a candidate table of scheduling message features.
[0043] Statistics module 203: It is used to filter target destination addresses whose frequency of occurrence meets the threshold from the service message feature candidate table, and to count the frequency of occurrence of the target destination addresses in the scheduling message feature candidate table, so as to use the destination addresses whose frequency of occurrence meets the threshold as the second feature.
[0044] Processing module 204: It is used to identify PCDN services based on the first feature and the second feature.
[0045] Furthermore, in one possible implementation, the statistics module is also used to count the number of times each destination address appears in the service packet feature candidate table based on the service packet feature candidate table of each terminal device, so as to filter the target destination address whose frequency of occurrence meets the threshold. The frequency of the target destination address appearing in the scheduling message feature candidate table of the corresponding terminal device is statistically analyzed. The destination address whose frequency meets the threshold is recorded as the PCDN scheduling server IP, and the PCDN scheduling server IP is used as the second feature.
[0046] Furthermore, in one possible implementation, the generation module is also used to count the destination addresses of uplink messages within a first time unit for the selected target terminal devices during a first duration period. The destination addresses are aggregated to generate a candidate list of business traffic characteristics. The candidate list of business traffic characteristics includes the peer IPs of the PCDN node service and the user and CDN content server cluster.
[0047] Furthermore, in one possible implementation, the generation module is also used to count, within a second time unit, the peer IPs communicating with the selected target terminal devices, excluding the already counted uplink message destination addresses. The statistical peer IPs are summarized to generate a scheduling message feature candidate table, which includes: PCDN scheduling cluster IPs and peer IPs of periodic heartbeat messages of terminal devices.
[0048] Furthermore, in one possible implementation, the generation module is also configured to replace the destination address of the peer with the corresponding resolved domain name and record it if the destination address of the peer is obtained through the domain name resolved by the DNS service.
[0049] Furthermore, in one possible implementation, the identification module is also used to count the uplink traffic of the terminal device on the locally open service port; Target terminal devices are selected based on the results of determining whether the uplink traffic rate, the number of connections, and the duration exceed the set thresholds.
[0050] Furthermore, in one possible implementation, the processing module is also used to determine the terminal device that simultaneously hits the first feature and the second feature as a PCDN terminal device, and to count the corresponding traffic as PCDN application traffic, so as to identify PCDN services.
[0051] Reference Figure 3 , Figure 3 The diagram shown is an architectural schematic of an embodiment provided by the present invention. Figure 3 As shown: For a PCDN node to distribute traffic to other users, it needs to cache traffic data. The scheduling server tells it where to download the cached traffic data, and this process involves scheduling message exchange between the node and the scheduling server cluster. The characteristics of the traffic distributed to other users, i.e., the business traffic characteristics, are relatively obvious: large uplink traffic and a large number of connections. However, judging PCDN applications solely based on business traffic characteristics is prone to misidentification; for example, users who are live streaming or using BitTorrent downloads may also be identified as PCDN users.
[0052] Therefore, pre-defined service traffic characteristics are established. IPs matching these characteristics are grouped into IP group 1. External interaction IPs or domains during the period matching these characteristics are then grouped into IP group 2 and reported to the network management system. The network management system receives data reported from multiple data collection nodes (Internet traffic analysis modules). For IP groups 1 that overlap, the overlapping IP group 3 of IP group 2 is calculated. IP group 3 represents the scheduling message characteristics. The network management system distributes these scheduling message characteristics to each Internet traffic analysis module, combining them with the traffic message characteristics to identify PCDN applications.
[0053] Reference Figure 4 , Figure 4 The diagram shown is a schematic diagram of generating the second feature provided by the present invention. Figure 4 As shown: For ease of understanding, let's illustrate with an example. Suppose there are three broadband data acquisition nodes in a metropolitan area network: Node 1, Node 2, and Node 3. They report the following data to the network management system: Node 1 reports: IP group 1 (candidate IPs for service message characteristics): {203.0.113.10, 203.0.113.20, 198.51.100.30}. IP group 2 (candidate IPs for scheduling message characteristics): {192.0.2.100, 192.0.2.200}.
[0054] Node 2 reports: IP group 1: {203.0.113.10, 198.51.100.30, 198.51.100.40}. IP group 2: {192.0.2.100, 192.0.2.300}.
[0055] Node 3 reports: IP group 1: {203.0.113.10, 203.0.113.20, 198.51.100.50}. IP group 2: {192.0.2.100, 192.0.2.200}.
[0056] 1. Find high-frequency candidate IPs in IP group 1, that is, the network administrator merges all nodes' IP groups 1 and counts the number of nodes where each IP appears (not the total number of times): 203.0.113.10 appears in nodes 1, 2, and 3 → number of co-occurring nodes = 3.
[0057] 203.0.113.20 appears in nodes 1 and 3 → number of co-occurring nodes = 2.
[0058] 198.51.100.30 appears in node 1 and node 2 → number of co-occurring nodes = 2.
[0059] 198.51.100.40 appears in node 2 → number of co-occurring nodes = 1.
[0060] 198.51.100.50 appears in node 3 → number of co-occurring nodes = 1.
[0061] Assuming the threshold N1 = 2 (for simplicity, the original N1 = 5 is lowered here), then the high-frequency candidate IPs are: 203.0.113.10 (Number of nodes 3 > 2); 203.0.113.20 (Number of nodes: 2=2); 198.51.100.30 (Number of nodes: 2=2).
[0062] 2. For each high-frequency candidate IP, search for higher-frequency IPs in IP group 2 of its associated nodes. That is, the network administrator no longer looks at all nodes, but instead looks at the IP group 2 corresponding to the nodes that reported the candidate IP.
[0063] For candidate IP 203.0.113.10: It appears in IP group 1 of nodes 1, 2, and 3. Therefore, we only need to consider IP group 2 of these three nodes: Node 1's IP group 2: {192.0.2.100, 192.0.2.200}; Node 2's IP group 2: {192.0.2.100, 192.0.2.300}; IP group 2 of node 3: {192.0.2.100, 192.0.2.200}.
[0064] Count the number of times each IP address appears in these three groups: 192.0.2.100 appears in 1, 2, 3 → Number of occurrences = 3; 192.0.2.200 appears in 1 and 3 → Number of occurrences = 2; 192.0.2.300 appears in 2 → Number of occurrences = 1.
[0065] Assuming the threshold N² = 2, then the IPs strongly associated with candidate IP 203.0.113.10 are 192.0.2.100 (times 3 > 2) and 192.0.2.200 (times 2 = 2).
[0066] For candidate IP 203.0.113.20: It appears in IP group 1 of nodes 1 and 3. Examine IP group 2 of nodes 1 and 3 and perform the following analysis: 192.0.2.100 appears in 1 and 3 (number of occurrences = 2); 192.0.2.200 appears in 1 and 3 (number of occurrences = 2). The number of occurrences of these two IPs is ≥ N2(2). Therefore, 192.0.2.100 and 192.0.2.200 are also strongly associated with this candidate IP.
[0067] For candidate IP 198.51.100.30: It appears in IP group 1 of nodes 1 and 2. Examine IP group 2 of nodes 1 and 2 and perform the following analysis: 192.0.2.100 appears in 1 and 2 → number of times = 2; 192.0.2.200 appears 1 time; 192.0.2.300 appears 2 times = 1. Only 192.0.2.100 appears ≥ N2(2) times.
[0068] 3. Summarize the results of all candidate IP association analyses to see which IPs are frequently mentioned in multiple analyses: 192.0.2.100: When analyzing 203.0.113.10, 203.0.113.20, and 198.51.100.30, the number of occurrences were 3, 2, and 2 respectively, all satisfying ≥N². This indicates that it commonly and stably appears in node IP group 2 behind numerous service IPs.
[0069] 192.0.2.200: Appears twice in the analysis of 203.0.113.10 and 203.0.113.20, but only once in the analysis of 198.51.100.30. Its correlation is slightly weaker, but it may also be one of the scheduling servers.
[0070] Based on the final policy (such as requiring the IP to satisfy N2 in the analysis of more than K candidate IPs), the network management system determines 192.0.2.100 (and most likely 192.0.2.200) as the IP of the PCDN scheduling server. Together, they constitute the second feature used for accurate identification.
[0071] Understandably, IPs appearing in the service IP lists (IP group 1) of multiple data collection nodes (e.g., nodes 1, 2, and 3) are potential PCDN service servers. The focus then shifts to analyzing the nodes behind these potential service IPs, observing which fixed IPs they communicate with (IP group 2). If an IP (e.g., 192.0.2.100) frequently and consistently appears in the fixed communication IP lists corresponding to multiple potential service IPs, then this IP is highly likely to be the command center responsible for scheduling and directing these service servers—i.e., the PCDN scheduling server.
[0072] Reference Figure 5 , Figure 5 This is a schematic diagram of the hardware structure of the PCDN service identification device involved in the embodiments of this application. In the embodiments of this application, the PCDN service identification device may include a processor, a memory, a communication interface, and a communication bus.
[0073] The communication bus can be of any type and is used to interconnect the processor, memory, and communication interface.
[0074] The communication interface includes input / output (I / O) interfaces, physical interfaces, and logical interfaces used for interconnecting devices within the PCDN service identification equipment, as well as interfaces used for interconnecting the PCDN service identification equipment with other devices (such as other computing devices or user equipment). Physical interfaces can be Ethernet interfaces, fiber optic interfaces, ATM interfaces, etc.; user equipment can be displays, keyboards, etc.
[0075] Memory can be various types of storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile RAM (NVRAM), flash memory, optical storage, hard disk, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), etc.
[0076] The processor can be a general-purpose processor, which can call the PCDN service identification program stored in the memory and execute the PCDN service identification method provided in the embodiments of this application. For example, the general-purpose processor can be a central processing unit (CPU). The method executed when the PCDN service identification program is called can be referred to in the various embodiments of the PCDN service identification method of this application, and will not be repeated here.
[0077] Those skilled in the art will understand that Figure 5 The hardware structure shown does not constitute a limitation of this application and may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0078] This application also provides a computer-readable storage medium. The computer-readable storage medium stores a PCDN service identification program, which, when executed by a processor, implements the steps of the PCDN service identification method described above.
[0079] The method implemented when the PCDN service identification program is executed can be referred to in various embodiments of the PCDN service identification method of this application, and will not be repeated here.
[0080] It should be noted that the sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0081] The terms "comprising" and "having," and any variations thereof, in the specification, claims, and accompanying drawings of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus. The terms "first," "second," and "third," etc., are used to distinguish different objects, etc., and do not indicate a sequence, nor do they limit "first," "second," and "third" to different types.
[0082] In the description of the embodiments of this application, terms such as "exemplary," "for example," or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplary," "for example," or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of terms such as "exemplary," "for example," or "for instance" is intended to present the relevant concepts in a concrete manner.
[0083] In the description of the embodiments of this application, unless otherwise stated, " / " means "or". For example, A / B can mean A or B. The "and / or" in the text is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of this application, "multiple" means two or more.
[0084] In some processes described in the embodiments of this application, multiple operations or steps are included in a specific order. However, it should be understood that these operations or steps may not be executed in the order they appear in the embodiments of this application, or they may be executed in parallel. The sequence number of the operation is only used to distinguish different operations, and the sequence number itself does not represent any execution order. In addition, these processes may include more or fewer operations, and these operations or steps may be executed sequentially or in parallel, and these operations or steps may be combined.
[0085] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device to execute the methods described in the various embodiments of this application.
[0086] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.
Claims
1. A PCDN service identification method, characterized by, include: Based on the uplink traffic data of terminal devices, target terminal devices that meet the first feature are identified and filtered out. The first feature includes: uplink rate, number of connections and duration. The destination addresses of uplink messages of the target terminal device are counted to generate a candidate table of service message features, and the destination addresses of uplink messages of non-service traffic of the target terminal device are counted to generate a candidate table of scheduling message features. Select target destination addresses whose frequency of occurrence meets the threshold from the service message feature candidate table, and count the frequency of occurrence of the target destination addresses in the scheduling message feature candidate table, so as to use the destination addresses whose frequency of occurrence meets the threshold as the second feature; PCDN services are identified based on the first and second features.
2. The method of claim 1, wherein, The step of filtering target destination addresses whose frequency of occurrence meets a threshold from the service message feature candidate table, and counting the frequency of occurrence of the target destination addresses in the scheduling message feature candidate table, to use the destination addresses whose frequency of occurrence meets the threshold as the second feature, includes: Based on the service packet feature candidate table for each terminal device, the number of times each destination address appears in the service packet feature candidate table is counted in order to filter target destination addresses whose frequency of occurrence meets the threshold. The frequency of the target destination address appearing in the scheduling message feature candidate table of the corresponding terminal device is statistically analyzed. The destination address whose frequency meets the threshold is recorded as the PCDN scheduling server IP, and the PCDN scheduling server IP is used as the second feature.
3. The method of claim 1, wherein, The uplink destination address of the target terminal device is used to generate a candidate table of service message characteristics, including: For the selected target terminal devices, the destination addresses of uplink messages are counted within the first time unit during the first continuous period. The destination addresses are aggregated to generate a candidate list of business traffic characteristics. The candidate list of business traffic characteristics includes the peer IPs of the PCDN node service and the user and CDN content server cluster.
4. The method of claim 1, wherein, The process of excluding the destination addresses of the uplink packets, calculating the destination addresses of the remaining uplink packets for the target terminal device, and generating a candidate list of scheduling packet features includes: For the selected target terminal devices, within the second time unit, count the peer IPs communicating with the target terminal devices, excluding the already counted uplink message destination addresses; The statistical peer IPs are summarized to generate a scheduling message feature candidate table, which includes: PCDN scheduling cluster IPs and peer IPs of periodic heartbeat messages of terminal devices.
5. The method of claim 4, wherein, Also includes: If the destination address of the peer is obtained through a domain name resolved by the DNS service, then the destination address of the peer will be replaced with the corresponding resolved domain name and recorded.
6. The method of claim 1, wherein, The process of identifying and filtering target terminal devices that meet the first characteristic based on the uplink traffic data of the terminal devices includes: Statistical analysis of uplink traffic on locally open service ports of terminal devices; Target terminal devices are selected based on the results of determining whether the uplink traffic rate, the number of connections, and the duration exceed the set thresholds.
7. The method of claim 1, wherein, The identification of PCDN services based on the first and second features includes: Terminal devices that simultaneously match the first and second characteristics are identified as PCDN terminal devices, and the corresponding traffic is counted as PCDN application traffic to identify PCDN services.
8. A PCDN service identification apparatus, characterized by, include: The identification module is used to identify and filter target terminal devices that meet the first feature based on the uplink traffic data of the terminal devices. The first feature includes: uplink rate, number of connections and duration. The generation module is used to count the destination addresses of uplink messages of the target terminal device to generate a candidate list of service message features, and to count the destination addresses of uplink messages of non-service traffic of the target terminal device to generate a candidate list of scheduling message features. The statistics module is used to filter target destination addresses whose frequency of occurrence meets the threshold from the service message feature candidate table, and to count the frequency of occurrence of the target destination addresses in the scheduling message feature candidate table, so as to use the destination addresses whose frequency of occurrence meets the threshold as the second feature. The processing module is used to identify PCDN services based on the first feature and the second feature.
9. A PCDN service identification device, characterized in that, The PCDN service identification device includes a processor, a memory, and a PCDN service identification program stored in the memory and executable by the processor, wherein when the PCDN service identification program is executed by the processor, it implements the steps of the PCDN service identification method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a PCDN service identification program, wherein when the PCDN service identification program is executed by a processor, it implements the steps of the PCDN service identification method as described in any one of claims 1 to 7.