Traffic control method, apparatus, device, medium, and program product
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA UNITED NETWORK COMM GRP CO LTD
- Filing Date
- 2026-05-08
- Publication Date
- 2026-08-07
AI Technical Summary
[0004]如此,在执行上述方案的过程中,由于分布式网络攻击可通过分散请求至多个网络节点,从而绕过单个网络节点上的限流方案,因此,会导致无法对分布式网络攻击进行有效防御,进而对网络安全造成威胁
[0064]上述第二方面至第六方面的有益效果参考第一方面的对应描述,不再赘述。
Smart Images

Figure CN122533798A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of artificial intelligence technology, and in particular to a flow control method, apparatus, device, medium, and program product. Background Technology
[0002] With the widespread adoption of cloud computing and IoT technologies, cyberattacks are exhibiting a trend towards being distributed, dynamic, and precise. Malicious attacks such as DDoS attacks, brute-force attacks, and CC attacks, which consume system resources through massive requests, can easily cause slow service responses, business interruptions, or system paralysis, becoming a core security risk threatening business continuity and system stability. Business rate limiting, as a key technology for defending against such attacks, aims to prevent system overload and crashes by limiting request traffic, thus ensuring normal access to legitimate business operations.
[0003] Currently, the industry's rate limiting technology for network attack defense mainly relies on dynamic rate limiting schemes for single nodes. These schemes dynamically adjust the rate limiting threshold by analyzing the real-time traffic characteristics of a single network node or interface.
[0004] Thus, in the process of implementing the above scheme, since distributed network attacks can bypass the rate limiting scheme on a single network node by distributing requests to multiple network nodes, it will be impossible to effectively defend against distributed network attacks, thereby threatening network security. Summary of the Invention
[0005] This application provides a flow control method for improving network security.
[0006] In a first aspect, embodiments of this application provide a flow control method, the method comprising:
[0007] Obtain the node traffic parameters on the first network node;
[0008] Obtain the regional traffic parameters of the network area where the first network node is located;
[0009] Input the above-mentioned regional flow parameters and the above-mentioned node flow parameters into the first flow control model, and output the first flow threshold.
[0010] The first traffic threshold is used to control the traffic on the first network node, and the first model parameter of the first traffic control model is determined based on the historical node traffic parameters on one or more network nodes in the target network topology.
[0011] The node traffic parameters mentioned above include at least one of the following: the attack intent label of the network attack that occurred on the first network node, the load factor of the first network node, and the service traffic distribution factor on the first network node. The load factor is determined based on at least one of the resource utilization rate of the first device and the request processing latency of the first device.
[0012] The aforementioned regional traffic parameters include at least one of the geographical traffic characteristic coefficient and the temporal traffic characteristic coefficient of the aforementioned network region;
[0013] The aforementioned first flow control model is the flow control model on the first device, the aforementioned first device is the device corresponding to the first network node, and the aforementioned first network node is any network node in the aforementioned target network topology.
[0014] The technical solution provided in this application brings at least the following beneficial effects: By adopting the above solution, the device deployed on any network node in the target network topology can determine the model parameters of the flow control model on the device based on the historical node traffic parameters of one or more network nodes in the target network topology. Then, the flow control model outputs the flow threshold for flow control of the network node based on the node traffic parameters on the network node and the regional traffic parameters of the network area where the network node is located. This avoids the problem that distributed network attacks can bypass the rate limiting scheme on a single network node by distributing requests to multiple network nodes. Even in the face of distributed network attacks, the flow of each network node in the target network topology can be accurately controlled, thereby effectively defending against distributed network attacks and improving network security.
[0015] One possible implementation method, where the aforementioned regional traffic parameters include the aforementioned regional traffic characteristic coefficients, involves obtaining the regional traffic parameters of the network area where the first device is located, including:
[0016] Based on the maximum traffic that the above network area can carry and the average traffic that the above network area can carry, the regional carrying capacity coefficient of the above network area is determined. The average traffic that the above network area can carry is the average of the maximum traffic that all network nodes in the above network area can carry.
[0017] Based on the current regional traffic and the historical peak traffic of the aforementioned network regions, the regional traffic density of the aforementioned network regions is determined.
[0018] Based on the aforementioned regional carrying capacity coefficient and the aforementioned regional flow density, the aforementioned regional flow characteristic coefficients are determined.
[0019] Another possible implementation method, where the aforementioned regional traffic parameters include the aforementioned time-based traffic characteristic coefficients, involves obtaining the regional traffic parameters of the network area where the first device is located, including:
[0020] Based on the average regional traffic and peak regional traffic of the aforementioned network area in the first time period, the traffic pressure coefficient of the aforementioned network area in the first time period is determined; the first time period is the time period in which the current moment occurs.
[0021] Based on the flow pressure coefficient and the time period weight coefficient corresponding to the first time period, the above-mentioned time flow characteristic coefficient is determined.
[0022] Another possible implementation method, which involves inputting the aforementioned regional flow parameters and node flow parameters into the aforementioned first flow control model and outputting a first flow threshold, includes:
[0023] The third traffic threshold is determined based on the second traffic threshold corresponding to the first service, the attack intent weight parameter of the aforementioned network attack, the service priority coefficient of the aforementioned first service, and the aforementioned regional traffic parameter.
[0024] Using the first traffic control model described above, based on the regional traffic parameters and the node traffic parameters described above, at least one action and the confidence level of each action are determined; wherein, the at least one action includes a traffic threshold adjustment action and a service priority adjustment action.
[0025] The first traffic threshold is generated based on the action parameters of the first action with the highest confidence among at least one of the above actions and the first parameters corresponding to the first action.
[0026] The first parameter mentioned above can be any one of the following: the third traffic threshold mentioned above, or the service priority coefficient mentioned above;
[0027] The aforementioned first service is the service carried by the aforementioned first network node.
[0028] Another possible implementation method, before obtaining the regional traffic parameters of the network area where the first network node is located, further includes:
[0029] Obtain the training dataset of the first flow control model, wherein the training dataset includes at least one of the following: at least one historical service data on the first network node, the historical geographical data, the historical time data, the historical traffic data, and the historical system status data;
[0030] Using the above training dataset, the initial model parameters of the first flow control model are adjusted to obtain the second model parameters of the first flow control model.
[0031] The first model parameters are generated based on the second model parameters and at least one third model parameter.
[0032] Wherein, the above-mentioned at least one third model parameter is at least one model parameter corresponding to at least one second flow control model, each second flow control model is a flow control model on a device other than the above-mentioned first device in the target network topology, a device is a device corresponding to a network node in the above-mentioned target network topology, and each third model parameter is determined based on the historical node flow parameters on the corresponding network node.
[0033] Secondly, embodiments of this application provide a flow control device, including:
[0034] The acquisition module is specifically used to acquire node traffic parameters on the first network node;
[0035] The aforementioned acquisition module is also used to acquire the regional traffic parameters of the network area where the first network node is located.
[0036] The output module is used to input the above-mentioned regional flow parameters and the above-mentioned node flow parameters into the first flow control model and output the first flow threshold.
[0037] The first traffic threshold is used to control the traffic on the first network node, and the first model parameter of the first traffic control model is determined based on the historical node traffic parameters on one or more network nodes in the target network topology.
[0038] The node traffic parameters mentioned above include at least one of the following: the attack intent label of the network attack that occurred on the first network node, the load factor of the first network node, and the service traffic distribution factor on the first network node. The load factor is determined based on at least one of the resource utilization rate of the first device and the request processing latency of the first device.
[0039] The aforementioned regional traffic parameters include at least one of the geographical traffic characteristic coefficient and the temporal traffic characteristic coefficient of the aforementioned network region;
[0040] The first flow control model mentioned above is the flow control model on the first device mentioned above, the first device mentioned above is the device corresponding to the first network node mentioned above, and the first network node mentioned above is any network node in the target network topology.
[0041] One possible implementation is that the aforementioned acquisition module is specifically used for:
[0042] Based on the maximum traffic that the above network area can carry and the average traffic that the above network area can carry, the regional carrying capacity coefficient of the above network area is determined. The average traffic that the above network area can carry is the average of the maximum traffic that all network nodes in the above network area can carry.
[0043] Based on the current regional traffic and the historical peak traffic of the aforementioned network regions, the regional traffic density of the aforementioned network regions is determined.
[0044] Based on the aforementioned regional carrying capacity coefficient and the aforementioned regional flow density, the aforementioned regional flow characteristic coefficients are determined.
[0045] Another possible implementation, the aforementioned acquisition module, is also used for:
[0046] Based on the average regional traffic and peak regional traffic of the aforementioned network area in the first time period, the traffic pressure coefficient of the aforementioned network area in the first time period is determined; the first time period is the time period in which the current moment occurs.
[0047] Based on the flow pressure coefficient and the time period weight coefficient corresponding to the first time period, the above-mentioned time flow characteristic coefficient is determined.
[0048] Another possible implementation, the above output module, is specifically used for:
[0049] The third traffic threshold is determined based on the second traffic threshold corresponding to the first service, the attack intent weight parameter of the aforementioned network attack, the service priority coefficient of the aforementioned first service, and the aforementioned regional traffic parameter.
[0050] Using the first traffic control model described above, based on the regional traffic parameters and the node traffic parameters described above, at least one action and the confidence level of each action are determined; wherein, the at least one action includes a traffic threshold adjustment action and a service priority adjustment action.
[0051] The first traffic threshold is generated based on the action parameters of the first action with the highest confidence among at least one of the above actions and the first parameters corresponding to the first action.
[0052] The first parameter mentioned above can be any one of the following: the third traffic threshold mentioned above, or the service priority coefficient mentioned above;
[0053] The aforementioned first service is the service carried by the aforementioned first network node.
[0054] In another possible implementation, the aforementioned acquisition module is also used for:
[0055] Obtain the training dataset of the first flow control model, wherein the training dataset includes at least one of the following: at least one historical service data on the first network node, the historical geographical data, the historical time data, the historical traffic data, and the historical system status data;
[0056] The above-mentioned device also includes:
[0057] The adjustment module is used to adjust the initial model parameters of the first flow control model using the training dataset mentioned above, so as to obtain the second model parameters of the first flow control model.
[0058] The generation module is used to generate the first model parameters based on the second model parameters and at least one third model parameter.
[0059] Wherein, the above-mentioned at least one third model parameter is at least one model parameter corresponding to at least one second flow control model, each second flow control model is a flow control model on a device other than the above-mentioned first device in the target network topology, a device is a device corresponding to a network node in the above-mentioned target network topology, and each third model parameter is determined based on the historical node flow parameters on the corresponding network node.
[0060] Thirdly, this application provides an electronic device comprising: a processor and a memory; the memory stores a program or instructions executable on the processor, wherein the program or instructions, when executed by the processor, implement the method of the first aspect described above.
[0061] Fourthly, this application provides a readable storage medium on which a program or instructions are stored, which, when executed by a computer, implement the method of the first aspect described above.
[0062] Fifthly, this application provides a computer program product stored in a storage medium, which, when executed by a computer, implements the method described in the first aspect.
[0063] In a sixth aspect, embodiments of this application provide a chip including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect.
[0064] The beneficial effects of the second to sixth aspects mentioned above are described in the corresponding description of the first aspect and will not be repeated here. Attached Figure Description
[0065] Figure 1 A schematic diagram of a network architecture for the application of a flow control method provided in this application embodiment;
[0066] Figure 2 A flowchart illustrating a flow control method provided in an embodiment of this application;
[0067] Figure 3 A flowchart illustrating a flow control method provided in an embodiment of this application;
[0068] Figure 4 A flowchart illustrating a flow control method provided in an embodiment of this application;
[0069] Figure 5 A flowchart illustrating a flow control method provided in an embodiment of this application;
[0070] Figure 6 A flowchart illustrating a flow control method provided in an embodiment of this application;
[0071] Figure 7 A schematic diagram of a flow control system provided in an embodiment of this application;
[0072] Figure 8 A schematic diagram of a flow control system provided in an embodiment of this application;
[0073] Figure 9 A flowchart illustrating a flow control method provided in an embodiment of this application;
[0074] Figure 10 A flowchart illustrating a flow control method provided in an embodiment of this application;
[0075] Figure 11 A flowchart illustrating a flow control method provided in an embodiment of this application;
[0076] Figure 12 A flowchart illustrating a flow control method provided in an embodiment of this application;
[0077] Figure 13 This is a schematic diagram of the structure of a flow control device provided in an embodiment of this application;
[0078] Figure 14 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0079] The flow control method, apparatus, equipment, medium, and program products provided in this application will now be described in detail with reference to the accompanying drawings.
[0080] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.
[0081] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.
[0082] The terms "at least one," "at least one of," etc., used in the specification and claims of this application refer to any one, any two, or a combination of two or more of the included items. For example, at least one of a, b, and c can mean: "a," "b," "c," "a and b," "a and c," "b and c," and "a, b, and c," where a, b, and c can be single or multiple. Similarly, "at least two" refers to two or more items, and its meaning is similar to that of "at least one."
[0083] In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0084] The present application provides a flow control method, apparatus, device, medium, and program product that can be applied to flow control scenarios for defending against network attacks, such as flow control scenarios for defending against network attacks in multiple fields such as cloud computing, Internet of Things, and Internet services.
[0085] In the field of cloud computing, with the popularization of cloud computing technology, cloud service providers need to provide various services such as virtual machines, containers, cloud storage, and cloud databases to a large number of users. Their infrastructure adopts a distributed multi-node deployment mode, making it a high-frequency target for DDoS and CC attacks. In such scenarios, attackers often use botnets to distribute malicious requests to multiple nodes of the cloud platform, attacking the network and causing slow cloud service response or even node paralysis, affecting the business of all users who rely on the cloud service.
[0086] In the Internet of Things (IoT) field, a massive number of terminal devices (such as smart home devices, industrial sensors, connected vehicle devices, and medical IoT devices) connect to the network through multi-node gateways, forming a distributed network architecture. Many IoT devices are vulnerable to intrusion and control, making them important vectors for attackers to launch distributed attacks. Attackers can control a large number of IoT devices to send malicious requests (such as brute-forcing gateway login passwords or launching DDoS attacks) to multiple access nodes of the IoT platform, attacking the network. This can lead to gateway congestion, platform overload, and an inability to properly receive and process legitimate data from terminal devices, affecting the normal operation of the IoT system and even causing serious consequences such as industrial production disruptions and smart home malfunctions.
[0087] In the field of internet services, various internet services (such as e-commerce platforms, social platforms, online payment, game services, video platforms, etc.) adopt distributed multi-node deployment to cope with high concurrency access demands, but their core business interfaces and service nodes are vulnerable to distributed network attacks.
[0088] Currently, the industry's rate limiting technology for network attack defense mainly relies on dynamic rate limiting schemes for single nodes. These schemes dynamically adjust the rate limiting threshold by analyzing the real-time traffic characteristics of a single network node or interface.
[0089] Thus, in the process of implementing the above scheme, since distributed network attacks can bypass the rate limiting scheme on a single network node by distributing requests to multiple network nodes, it will be impossible to effectively defend against distributed network attacks, thereby threatening network security.
[0090] To address the aforementioned technical problems, embodiments of this application provide a traffic control method, apparatus, device, medium, and program product, which acquires node traffic parameters on a first network node; acquires regional traffic parameters of the network area where the first network node is located; inputs the regional traffic parameters and the node traffic parameters into a first traffic control model, and outputs a first traffic threshold; wherein, the first traffic threshold is used to control the traffic on the first network node, and the first model parameters of the first traffic control model are determined based on historical node traffic parameters on one or more network nodes in the target network topology; the node traffic parameters include at least one of the following: an attack intent label of a network attack occurring on the first network node, the load coefficient of the first network node, and the service traffic distribution coefficient of the first network node, wherein the load coefficient is determined based on at least one of the resource utilization rate of the first device and the request processing latency of the first device; the regional traffic parameters include at least one of the geographical traffic characteristic coefficient and the temporal traffic characteristic coefficient of the network area; the first device is a device deployed on the first network node, and the first network node is any network node in the target network topology. In this way, a device deployed on any network node in the target network topology can determine the model parameters of the flow control model on that device based on the historical node traffic parameters of all network nodes in the target network topology. Then, based on the node traffic parameters of that network node and the regional traffic parameters of the network area where the network node is located, the flow control model outputs the flow threshold for flow control of that network node. This prevents distributed network attacks from bypassing the rate limiting scheme on a single network node by distributing requests to multiple network nodes. Even in the face of distributed network attacks, the flow of each network node in the target network topology can be accurately controlled, thereby effectively defending against distributed network attacks and improving network security.
[0091] The flow control method, apparatus, device, medium, and program products provided in the embodiments of this application will be described in detail below with reference to the accompanying drawings.
[0092] Figure 1 This illustration shows a network architecture for an application of a flow control method provided in an embodiment of this application. For example... Figure 1 As shown, the network architecture includes a flow control device 101 and a terminal device 102. The flow control device 101 and the terminal device 102 are interconnected.
[0093] In some embodiments, the flow control device 101 may be a server, a computer, or a processor or processing unit within a server or computer. The server may be a single server or a server cluster consisting of multiple servers. It should be noted that the embodiments of this application do not limit the specific device form of the flow control device 101. Figure 1 The example shown is a single server using the flow control device 101.
[0094] In some embodiments, the terminal device 102 may be a mobile phone, tablet computer, laptop computer, handheld computer, in-vehicle electronic device, mobile internet device (MID), augmented reality (AR) / virtual reality (VR) device, robot, wearable device, personal computer (PC), ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc., and the embodiments of this application do not specifically limit it. Figure 1 The example shown is a mobile phone, with terminal device 102 as an example.
[0095] In some embodiments, the flow control device 101 acquires node flow parameters on a first network node; acquires regional flow parameters of the network area where the first network node is located; inputs the regional flow parameters and the node flow parameters into the first flow control model and outputs a first flow threshold; the flow control device 101 sends the first flow threshold to the terminal device 102; the terminal device 102 uses the first flow threshold to control the flow of the first network node, and the terminal device 102 can be a device deployed on the first network node.
[0096] It should be noted that the network architecture described in the embodiments of this application is for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and does not constitute a limitation on the technical solutions provided in the embodiments of this application. As network architectures evolve, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0097] See Figure 2 This is a flowchart illustrating a flow control method provided in an embodiment of this application. Figure 2 As shown, the flow control method provided in this application embodiment can be implemented by the above-mentioned flow control device, specifically by the following steps 201 to 203.
[0098] Step 201: The flow control device acquires the node flow parameters on the first network node.
[0099] In some embodiments, the first network node is any network node in the target network topology.
[0100] In some embodiments, the target network topology described above can be the network topology of a local area network, such as the network topology of a city or region's local area network.
[0101] In some embodiments, the node traffic parameters include at least one of the following: an attack intent label of a network attack occurring on the first network node, a load factor of the first network node, and a service traffic distribution factor on the first network node, wherein the load factor is determined based on at least one of the resource utilization rate of the first device and the request processing latency of the first device.
[0102] In some embodiments, the aforementioned network attacks can be distributed network attacks, malicious code network attacks, and network deception network attacks, etc. The specific type can be determined according to actual needs, and this embodiment does not impose specific limitations here.
[0103] In some embodiments, the attack intent label is used to indicate the attack intent of the network attack, such as DDoS network attack intent, brute-force network attack intent, CC network attack intent, etc. The specific intent can be determined according to actual needs, and no specific limitation is made here in this embodiment.
[0104] In some embodiments, the above-mentioned service traffic distribution coefficient is used to indicate the service traffic distribution on the first network node.
[0105] In some embodiments, the aforementioned request processing latency may be the average processing latency of the central processing unit of the first device for at least one service processing request.
[0106] In some embodiments, the resource utilization rate may include at least one of central processing unit utilization, memory utilization, and bandwidth utilization.
[0107] In some embodiments, the bandwidth utilization rate can be the bandwidth utilization rate of the device port of the first device, and the device port can be at least one of the input port and output port of the first device.
[0108] In some embodiments, when the device port is the input port of the first device, the bandwidth utilization can be calculated using the following formula:
[0109] BAND1=BANDinput / BANDtotal; (1)
[0110] Wherein, BAND1 represents the bandwidth utilization rate mentioned above, BANDinput represents the bandwidth used by the input port, and BANDtotal represents the total bandwidth used by the input port and output of the first device mentioned above.
[0111] In some embodiments, when the device port is the output port of the first device, the bandwidth utilization rate can be calculated using the following formula:
[0112] BAND2=BANDoutput / BANDtotal; (2)
[0113] Wherein, BAND2 represents the bandwidth utilization rate mentioned above, and BANDoutput represents the bandwidth used by the output port.
[0114] In some embodiments, the flow control device may first normalize the aforementioned resource utilization and request processing latency, and then use the following formula to determine the aforementioned load factor:
[0115] L = 0.3×CPU+0.2×MEM+0.3×BAND+0.2×LATENCY; (3)
[0116] Where L represents the load factor, CPU represents the normalized central processing unit utilization, MEM represents the normalized memory utilization, BAND represents the normalized bandwidth utilization, and LATENCY represents the normalized request processing latency.
[0117] Step 202: The flow control device obtains the regional flow parameters of the network area where the first network node is located.
[0118] In some embodiments, the aforementioned regional traffic parameters may include at least one of the geographical traffic characteristic coefficients and the temporal traffic characteristic coefficients of the network region.
[0119] It should be noted that the execution order of steps 201 and 202 described above is not limited in this embodiment. For example, step 201 can be executed first, followed by step 202; or step 202 can be executed first, followed by step 201; or steps 201 and 202 can be executed simultaneously. Figure 2 This example illustrates the process of executing step 201 first, followed by step 202.
[0120] In some embodiments, combined with Figure 2 ,like Figure 3 As shown, when the above-mentioned regional flow parameters include the above-mentioned regional flow characteristic coefficients, the above-mentioned step 202 can be specifically implemented through the following steps 202a1 to 202a3.
[0121] Step 202a1: The flow control device determines the regional carrying capacity coefficient of the network area based on the maximum flow that the network area can carry and the average flow that the network area can carry.
[0122] In some embodiments, the average carrying capacity is the average of the maximum carrying capacity of all network nodes within the network area.
[0123] In some embodiments, the flow control device may use the following formula to determine the carrying capacity coefficient of the aforementioned area:
[0124] (4)
[0125] in, The above-mentioned area carrying capacity coefficient is represented by A, which represents the maximum traffic that the above-mentioned network area can carry, and B represents the average carrying traffic.
[0126] Step 202a2: The flow control device determines the regional traffic density of the network area based on the current regional traffic and the historical peak traffic of the network area.
[0127] In some embodiments, the flow control device may use the following formula to determine the flow density of the aforementioned area:
[0128] (5)
[0129] in, C represents the traffic density of the above-mentioned area, D represents the current traffic of the above-mentioned network area, and D represents the historical peak traffic of the above-mentioned network area.
[0130] Step 202a3: The flow control device determines the regional flow characteristic coefficient based on the regional carrying capacity coefficient and the regional flow density.
[0131] In some embodiments, the flow control device may use the following formula to determine the above-mentioned regional flow characteristic coefficients:
[0132] Karea=0.6×Carea+0.4×(1−Darea); (6)
[0133] Wherein, Karea represents the aforementioned regional flow characteristic coefficient.
[0134] Thus, the flow control device determines the regional flow characteristic coefficient based on the regional carrying capacity coefficient and the regional flow density, enabling the flow control device to determine the regional flow parameters through the regional flow characteristic coefficient. In turn, the flow control device can accurately determine the first flow threshold used to control the flow on the first network node through the regional flow parameters.
[0135] In some embodiments, combined with Figure 2 ,like Figure 4 As shown, when the above-mentioned regional flow parameters include the above-mentioned time flow characteristic coefficients, the above-mentioned step 202 can be specifically implemented through the following steps 202b1 and 202b2.
[0136] Step 202b1: The flow control device determines the flow pressure coefficient of the network area in the first time period based on the average flow rate of the network area in the first time period and the peak flow rate of the network area in the first time period.
[0137] In some embodiments, the first time period is the time period in which the current moment occurs.
[0138] In some embodiments, the aforementioned regional average traffic can be the average traffic within the aforementioned network area as statistically analyzed by the traffic control device during the aforementioned first time period.
[0139] In some embodiments, the peak traffic in the aforementioned area can be the peak traffic in the aforementioned network area as counted by the traffic control device during the aforementioned first time period.
[0140] In some embodiments, the flow control device may pre-divide the system time into different time periods, determine which time period in the system time the current time is in the first time period, and then obtain the regional average flow and regional peak flow of the network area in that time period.
[0141] For example, a flow control device can divide the system time into 8 time periods, each lasting 3 hours. That is, 00:00-3:00 is one time period, 3:00-6:00 is another time period, ... 18:00-21:00 is another time period, and 21:00-0:00 is yet another time period. Assuming the current time is 20:45, the flow control device can determine that the first time period is 18:00-21:00, and then obtain the average and peak traffic of the network area during the 8:00-21:00 time period.
[0142] In some embodiments, the flow control device determines the flow pressure coefficient of the aforementioned network area in the first time period using the following formula:
[0143] (7)
[0144] Where Ptime represents the traffic pressure coefficient of the network area in the first time period, E represents the average traffic of the network area in the first time period, and F represents the peak traffic of the network area in the first time period.
[0145] Step 202b2: The flow control device determines the time flow characteristic coefficient based on the flow pressure coefficient and the time period weight coefficient corresponding to the first time period.
[0146] In some embodiments, the flow control device can classify time periods to obtain different types of time periods, and then set different time period weight coefficients for different types of time periods. In other words, one type of time period corresponds to one time period weight coefficient.
[0147] In some embodiments, the flow control device can determine the time period weight coefficient corresponding to the time period type of the first time period as the time period weight coefficient corresponding to the first time period.
[0148] For example, a flow control device can classify the periods 9:00-12:00 and 18:00-21:00 as peak hours, with a weighting coefficient of 1.0. The period 0:00-6:00 AM can be classified as off-peak, with a weighting coefficient of 0.3. The remaining periods can then be classified as off-peak, with a weighting coefficient of 0.7. Assuming the first period is 9:00-12:00, then this first period is a peak hour, and its weighting coefficient is 1.0.
[0149] In some embodiments, the flow control device determines the above-mentioned time-flow characteristic coefficient using the following formula:
[0150] Ktime=0.7×Wtype+0.3×(1−Ptime); (8)
[0151] Wherein, Ktime represents the aforementioned time-flow characteristic coefficient, and Wtype represents the aforementioned time-period weight coefficient.
[0152] Step 203: The flow control device inputs the regional flow parameters and node flow parameters into the first flow control model and outputs the first flow threshold.
[0153] In some embodiments, the first traffic threshold is used to control the traffic on the first network node, and the first model parameter of the first traffic control model is determined based on the historical node traffic parameters on one or more network nodes in the target network topology.
[0154] In some embodiments, the first flow control model can be a flow control model on a first device, and the first device is a device deployed on the first network node.
[0155] In some embodiments, the first flow control model described above may be a model used by an agent on a first device.
[0156] In some embodiments, the model structure of the first flow control model described above can be a value network.
[0157] Thus, the flow control device determines the time flow characteristic coefficient based on the flow pressure coefficient and the time period weight coefficient corresponding to the first time period, so that the flow control device can determine the time flow parameter through the time flow characteristic coefficient, and then the flow control device can accurately determine the first flow threshold used to control the flow on the first network node through the time flow parameter.
[0158] In some embodiments, combined with Figure 2 ,like Figure 5 As shown, step 203 above can be implemented through steps 203a1 to 203a3.
[0159] Step 203a1: The flow control device determines the third flow threshold based on the second flow threshold corresponding to the first service, the attack intent weight parameter of the network attack, the service priority coefficient of the first service, and the regional flow parameter.
[0160] In some embodiments, the first service is the service carried by the first network node.
[0161] In some embodiments, the flow control device sets different flow thresholds for different service priorities, with one flow threshold corresponding to one service priority.
[0162] In some embodiments, the flow control device may determine the third flow threshold using the following formula:
[0163] T=T0×[P×(1−Wattack×L)+(1−P)×(1−Wattack)]×Karea×Ktime; (9)
[0164] Where T represents the third traffic threshold, T0 represents the second traffic threshold, Wattack represents the attack intent weight, and P represents the service priority coefficient.
[0165] For example, the weight of DDoS network attack intent can be 0.8, the weight of brute-force network attack intent can be 0.6, the weight of CC network attack intent can be 0.4, and the weight of network attack intent corresponding to normal traffic services is 0.1.
[0166] It should be noted that the above-mentioned service priority coefficient is positively correlated with the service priority of the first service mentioned above; that is, the higher the service priority of the first service, the larger the above-mentioned service priority coefficient. When encountering a high-intensity attack, with Wattack > 0.6 and a surge in load, to prevent a precipitous drop in the threshold, a damping coefficient D (D = 0.7 + 0.3 × (1.5 - L)) is introduced. This damping coefficient is then used as a coefficient for Wattack to recalculate the third traffic threshold. The specific formula can be found in the following formula:
[0167] T=T0×[P×(1−D×Wattack×L)+(1−P)×(1−D×Wattack)]×Karea×Ktime; (10)
[0168] D=0.7 + 0.3×(1.5-L); (11)
[0169] Where D represents the damping coefficient mentioned above.
[0170] Step 203a2: The flow control device determines at least one action and the confidence level of each action based on the regional flow parameters and the node flow parameters using the first flow control model.
[0171] In some embodiments, the above-mentioned at least one action includes a traffic threshold adjustment action and a service priority adjustment action.
[0172] In some embodiments, the confidence level of an action can be used to characterize the credibility of that action.
[0173] In some embodiments, the flow control device may input the aforementioned regional flow parameters and node flow parameters into the aforementioned value network, and output the aforementioned at least one action and the confidence level of each of the aforementioned at least one action.
[0174] Step 203a3: The flow control device generates a first flow threshold based on the action parameters of the first action with the highest confidence among at least one action and the first parameter corresponding to the first action.
[0175] In some embodiments, the first parameter may be at least one of the following: the third traffic threshold and the service priority coefficient.
[0176] In some embodiments, when the first action is the flow threshold adjustment action, the action parameter can be the flow threshold adjustment step size.
[0177] In some embodiments, when the first action is the service priority adjustment action, the action parameter can be the service priority parameter adjustment step size.
[0178] In some embodiments, when the first action is the flow threshold adjustment action, the first parameter is the third flow threshold.
[0179] In some embodiments, when the first action is the service priority adjustment action, the first parameter is the service priority coefficient.
[0180] In some embodiments, when the first action is the flow threshold adjustment action, the flow control device may determine the first flow threshold using the following formula:
[0181] T1 = T×(1 +ΔT); (12)
[0182] Where T1 represents the first flow threshold mentioned above, and ΔT represents the adjustment step size of the flow threshold mentioned above.
[0183] In some embodiments, when the first action is the service priority adjustment action, the flow control device may use the following formula to determine the first flow threshold:
[0184] T1=T0×[(P+ΔW)×(1−Wattack×L)+(1−(P+ΔW))×(1−Wattack)]×Karea×Ktime; (13)
[0185] Wherein, ΔW represents the adjustment step size of the above business priority parameter.
[0186] In this way, the flow control device inputs the regional flow parameters and node flow parameters into the first flow control model and outputs the first flow threshold, thereby enabling the flow control device to regulate the flow of each node according to the first flow threshold.
[0187] In the flow control method provided in this application, a device deployed on any network node in the target network topology can determine the model parameters of the flow control model on the device based on the historical node flow parameters of all network nodes in the target network topology. Then, the flow control model outputs the flow threshold for flow control of the network node based on the node flow parameters on the network node and the regional flow parameters of the network area where the network node is located. This avoids the problem that distributed network attacks can bypass the rate limiting scheme on a single network node by distributing requests to multiple network nodes. Even in the face of distributed network attacks, the flow of each network node in the target network topology can be accurately controlled, thereby effectively defending against distributed network attacks and improving network security.
[0188] In some embodiments, combined with Figure 2 ,like Figure 6As shown, prior to step 201 above, the flow control method provided in this application embodiment may further include steps 204 to 206.
[0189] Step 204: The flow control device acquires the training dataset of the first flow control model.
[0190] In some embodiments, the training dataset may be at least one historical service data, historical geographical data, historical time data, historical traffic data, or historical system status data from the first network node.
[0191] Step 205: The flow control device uses the training dataset to adjust the initial model parameters of the first flow control model to obtain the second model parameters of the first flow control model.
[0192] In some embodiments, the flow control device may use the training dataset to train the first flow control model to adjust the initial model parameters and obtain the second model parameters of the first flow control model.
[0193] In some embodiments, the flow control device can set the initial model parameter θ0 of the first flow control model. The flow control device adjusts θ0 using the aforementioned training dataset to obtain the second model parameter θ of the first flow control model, θ=[w1, w2, w3, w4, k1, k2], where w1 is the attack intent weight coefficient, w2 is the service priority weight coefficient, w3 is the system load weight coefficient, and w4 is the regional time weight coefficient. Each coefficient is a 32-bit floating-point type, supporting dynamic fine-tuning, with a fine-tuning step size set to 0.001 to avoid parameter oscillation; k1-k2 are the initial calibration parameters of the regional-time feature coefficients, where k1 corresponds to the regional feature with a value range of [0.1, 0.9], and k2 corresponds to the time feature with a value range of [0.2, 0.8]. They are generated using feature encoding and normalization. After converting the regional and time features into quantized values, the initial values of k1 and k2 are obtained through linear mapping.
[0194] Step 206: The flow control device generates the first model parameters based on the second model parameters and at least one third model parameter.
[0195] In some embodiments, the at least one third model parameter is at least one model parameter corresponding to the at least one second flow control model, each second flow control model is a flow control model on a device other than the first device in the target network topology, and a device is a device deployed on a network node in the target network topology. Each third model parameter is determined based on the historical node flow parameters on the corresponding network node.
[0196] In some embodiments, the flow control device can use the historical node flow parameters on a network node as the training dataset for its corresponding flow control model to train the flow control model and obtain the third model parameters of the flow control model.
[0197] In some embodiments, the electronic device may determine the first model parameters using the following formula:
[0198] θ1=(Σnᵢ×Wareai×Wtimeiθᵢ) / Σnᵢ×Wareai×Wtimei; (14)
[0199] Where θ1 represents the first model parameter mentioned above, i∈[1,n], n represents the total number of network nodes in the target network topology, i represents the i-th network node in the target network topology, ni represents the number of training samples corresponding to the i-th network node, and when the i-th network node is the first network node mentioned above, θᵢ represents the second model parameter mentioned above, or when the i-th network node is any network node other than the first network node mentioned above, θi represents the third model parameter corresponding to the i-th network node, Wareai represents the regional dynamic weight corresponding to the i-th network node, and Wtimei represents the time dynamic weight corresponding to the i-th network node.
[0200] Thus, the flow control device can continuously iterate and optimize the first flow control model based on the first model parameters. As a result, the flow control device can use the optimized first flow control model to accurately output the flow threshold for controlling the flow of network nodes in the target network topology. In turn, the flow control device can use the flow threshold to control the flow of network nodes in the target network topology.
[0201] The flow control method provided in this application will be described below with reference to specific implementation methods.
[0202] For example, the system proposed in this embodiment constructs a dynamic service rate limiting system of "multi-agent collaboration - service perception - intent recognition - closed-loop optimization". Through distributed agent collaborative decision-making, dynamic adaptation of service priorities, and accurate identification of attack intent, it achieves efficient defense against network attacks and accurate protection of legitimate services.
[0203] For example, this embodiment provides a flow control system, the overall architecture of which is as follows: Figure 7 As shown, a layered distributed architecture is adopted, consisting of a perception layer 701, an intelligent decision-making layer 702, a rate-limiting execution layer 703, and a feedback optimization layer 704. The terminal control module 705 is responsible for global scheduling and status monitoring. Each layer realizes data interaction through standardized interfaces.
[0204] For example, this embodiment provides a flow control system, the detailed design diagram of each module is as follows: Figure 8 As shown.
[0205] Overall Architecture
[0206] For example, the perception layer 701 serves as the data input terminal for the flow control system 700, responsible for comprehensive data acquisition and preprocessing. It is mainly divided into a business data acquisition module, an attack traffic acquisition module, a system status acquisition module, and a region-time data acquisition module. The region-time data acquisition module is deployed at various edge or core nodes. Based on the provincial network element characteristics of the communication network, it collects regional characteristic data, such as the province / city to which the network element belongs, the region's carrying capacity, historical traffic peaks, and the number of network elements deployed, as well as time characteristic data, such as the current timestamp, time period, and historical traffic fluctuation patterns within that time period. This data is then categorized and stored by region and time period, providing quantitative data for dimensional adaptation.
[0207] For example, the intelligent decision layer 702 is the brain of the flow control system 700. Based on multi-agent collaboration and intelligent algorithms, it integrates multiple factors such as attack intent, business priority, region, time and system load to generate flow limiting strategies and achieve accurate flow limiting decisions. This is the core innovation of the present invention.
[0208] (1) Distributed deployment of edge intelligent agents (innovative highlights): The distributed architecture is deployed on each business edge node to realize the preliminary analysis and decision-making of local multi-dimensional data by region. It integrates lightweight local traffic feature analysis and dynamic matching of business priorities, can independently generate basic rate limiting policies, achieve millisecond-level response, and effectively reduce cross-node transmission latency.
[0209] (2) Core Intelligent Agent (Innovation Highlight): Deployed in the regional business center, it is used to receive model parameters (non-raw data) uploaded by the aggregated edge intelligent agents, and dynamically optimize the flow limiting strategy parameters by combining regional traffic characteristics and global business priorities, thereby enhancing regional collaborative decision-making capabilities and global scheduling efficiency.
[0210] (3) Global Coordination Agent (Innovation Highlight): The built-in federated learning collaboration module serves as the core unit for distributed collaboration among agents. Adaptive federated averaging algorithm is adopted to dynamically allocate aggregation weights based on the computing power, data quality, and training contribution of each agent. Iterative optimization of model parameters for each edge agent and core agent is performed to generate the globally optimal model and distribute it to each agent, achieving collaborative optimization of the global model without compromising data privacy.
[0211] (4) Attack Intent Recognition Module (Innovation Highlight): Based on the CNN-LSTM spatiotemporal fusion model, an adaptive intent discrimination model is constructed for the feature sequences of business traffic and attack traffic. Through spatiotemporal joint learning of multi-dimensional traffic features, the classification and recognition of traffic-type DDoS, frequency-type brute-force attacks, and session-type CC attacks are realized, and the recognition results are transmitted to the rate limiting scheduling unit in real time, providing a reliable decision basis for differentiated rate limiting.
[0212] (5) Business Priority Assessment Module (Innovation Highlight): Construct a multi-dimensional business priority assessment model, with business type, user level and business timeliness requirements as independent assessment dimensions, and preset differentiated weight coefficients. The weights are dynamically adjusted according to the actual network load, and a dynamic business priority coefficient in the range of 0-1 is generated through weighted scoring (the higher the value, the higher the priority).
[0213] (6) Geographic-Time Dimension Adaptation Module (Innovative Highlight): In response to the characteristics of communication networks where network elements are deployed in different provinces and traffic varies significantly in different regions and time periods, this module is deployed at each edge / core node to collect geographic feature data (province / city to which the network element belongs, regional carrying capacity, regional historical traffic peak, number of network elements deployed) and time feature data (current timestamp, traffic type of time period, historical traffic fluctuation pattern of time period). The data is stored according to region / time period. Based on the combined geographic and time features, the module dynamically adjusts the service scheduling strategy for different regions, providing data support for the subsequent refined adaptation and balanced utilization of network resources in different provinces and time periods.
[0214] For example, the rate limiting execution layer 703 is the execution unit of the flow control strategy of the flow control system 700. Through three levels of rate limiting—network layer, application layer, and business layer—it transforms abstract strategies into concrete execution actions. Among them, the business layer rate limiting module implements fine-grained and differentiated rate limiting based on regional-time coefficients, business priority coefficients, and attack intent tags. It strictly limits the rate of low-priority services, dynamically relaxes the threshold for high-priority services, and queues requests for suspected attack traffic instead of directly blocking them.
[0215] For example, the feedback optimization layer 704 is the self-optimization engine of the flow control system 700, responsible for collecting execution results and iterating strategies. The core innovation of this unit lies in the reinforcement learning optimization module, which incorporates regional-temporal features into the optimization state dimension and achieves strategy self-optimization through reinforcement learning.
[0216] For example, the flow control system 700 uses the current state of the system as its state space, such as attack intent, system load, business traffic distribution, and geographic-temporal characteristics, and uses the flow limiting strategy adjustment actions as its action space, such as flow limiting threshold adjustment, priority weight adjustment, and flow limiting dimension switching. It uses maximizing the interception rate, minimizing the false blocking rate, and ensuring the response speed of high-priority businesses as its reward function, and uses the DQN algorithm to optimize the parameters of the intelligent agent decision model.
[0217] Core Algorithm
[0218] 1. Multi-agent federated collaborative decision-making algorithm
[0219] For example, this algorithm adopts a three-layer intelligent agent federated learning architecture, integrating regional temporal features and dynamic periodic aggregation to achieve collaborative decision-making and privacy-preserving optimization of distributed intelligent agents. Specifically, it combines... Figure 9 As shown, the process is as follows:
[0220] (1) Initialization: Each edge agent and core agent loads and initializes the model parameters θ0, and the global agent sets the dynamic aggregation period.
[0221] ① The local model parameters of the edge agent are θ=[w1, w2, w3, w4, k1, k2], where w1-w4 are the initial weight coefficients in the five-factor current limiting threshold algorithm. Each coefficient is a 32-bit floating-point number that supports dynamic fine-tuning. The fine-tuning step size is set to 0.001 to avoid parameter oscillation. k1-k2 are the initial calibration parameters of the regional-temporal feature coefficients. k1 corresponds to the regional feature and has a value range of [0.1, 0.9]. k2 corresponds to the temporal feature and has a value range of [0.2, 0.8]. They are generated by feature encoding and normalization. After converting the regional and temporal features into quantized values, the initial values of k1 and k2 are obtained through linear mapping.
[0222] ② The core intelligent agent regional model parameter θ = [θ edge set, w5, w6], where θ edge set is the aggregated value of parameters of each edge intelligent agent in the jurisdiction, and w5-w6 are the regional business priority correction weights. w5 corresponds to the core business priority, such as payment and package change, and w6 corresponds to the non-core business priority. Both are 32-bit floating point type with a value range of [0.3, 1.0]. The initial weights are calculated by the analytic hierarchy process and support dynamic updates.
[0223] ③ The global model parameter θ = [θ core set, w7, w8], where the θ core set is the aggregated parameter value of all core agents nationwide, w7-w8 are the network-wide attack intent adaptation weights, w7 corresponds to the adaptation coefficient for known attack types, and w8 corresponds to the early warning adaptation coefficient for unknown attack types, all of which are 32-bit floating-point numbers. The initial value is obtained through offline training using historical business data, based on the provincial and time-based traffic data and attack defense records of the past 12 months. It can be dynamically adjusted in conjunction with real-time attack detection results. For every 105 increase in the attack occurrence rate, w7 is finely adjusted by 0.05.
[0224] (2) Local training: Each edge agent trains a local model based on locally collected business data, regional data, time data, traffic data, and system status data. The core agent aggregates the parameters to obtain the model parameters θᵢ (i is the agent number), θ core aggregation = (Σn i ×θ edge i ) / Σn i (n) i (where is the local training sample size for the i-th edge agent), and the original data remains locally.
[0225] (3) Parameter upload: Each agent encrypts and uploads the model parameters θᵢ to the global coordinating agent.
[0226] ① Parameter encryption: The encryption method adopts an asymmetric encryption algorithm (RSA-2048). Each edge agent pre-generates a pair of public and private keys. The public key is uploaded to the core agent, and the private key is stored locally at the edge.
[0227] ② Transmission Channel: The encrypted transmission protocol HTTS+TLS1.3 is used to establish a dedicated federated collaborative transmission channel to avoid the security risks brought about by public network transmission.
[0228] (4) Regional Time-Weighted Global Aggregation (Innovative Highlight): The global coordinating agent adopts a federated averaging algorithm to calculate the global model parameters θ_global=(ΣnᵢW i θᵢ) / ΣnᵢW i Where nᵢ is the number of local training samples for the i-th agent, and W i W is the dynamic weight of the i-th agent in terms of region and time, with a value range of [0.1, 1.0]. It is obtained by the weighted product of the region weight and the time weight. i =Warea×Wtime.
[0229] ① Determining the regional weight Warea: Based on the business importance and network quality of the region where the agent is located, the business importance coefficient of each region is first configured offline (e.g., the coefficient for important cities and provincial capitals is 0.8-1.0, for ordinary cities it is 0.4-0.7, and for remote areas it is 0.1-0.3). Then, the network quality coefficient is calculated by real-time collected regional network quality data (latency, packet loss rate) (1-packet loss rate-latency / 1000, mapped to [0.5,1.0]). Finally, Warea = business importance coefficient × network quality coefficient, which is updated once per hour.
[0230] ② Determination of time weight Wtime: Based on the business peak coefficient and time period risk coefficient of the current time, the time period is divided into types (peak period: 9:00-12:00, 18:00-21:00, coefficient 1.0; off-peak period: other working hours, coefficient 0.7; low-peak period: 0:00-6:00 in the morning, coefficient 0.3), and then combined with the attack risk level of the current time period (based on real-time attack detection results, high risk coefficient 1.0, medium risk 0.8, low risk 0.6), the final Wtime = time period coefficient × risk coefficient, which is updated every 30 minutes.
[0231] ③W i Dynamic adjustment: The global coordinating agent deploys a weight update module to collect data on the regional network quality, time-of-day traffic volume, and attack risk of each agent in real time, and recalculates W every 30 minutes. i Simultaneously, set weight thresholds to avoid single agent W i Too high (maximum not exceeding 1.0) or too low (minimum not less than 0.1) to prevent the aggregation result from being dominated by a single agent.
[0232] ④ Sample size statistics: After the global agent receives the parameters uploaded by each agent, it synchronously receives the local training sample size of each agent and calculates the total sample size of all agents as Σnᵢ.
[0233] ⑤ Weighted calculation: θ_global=(ΣnᵢW i θᵢ) / ΣnᵢW i Matrix operations are used to improve efficiency; at the same time, each element in the parameter vector is individually weighted and normalized to ensure accuracy.
[0234] (5) Model distribution: The global coordinating agent distributes θ_ globally to each agent, and updates the local model parameters hierarchically.
[0235] (6) Dynamic periodic iterative execution: After each round of aggregation, the global agent evaluates indicators such as system load and network latency, and repeats steps (2)-(5) continuously to achieve continuous iterative optimization of the model. The iteration period is set to 60 minutes. If the indicators meet the threshold for three consecutive rounds of optimization, the iteration period is extended to 90 minutes.
[0236] This algorithm resolves the conflict between distributed decision-making and data privacy protection, ensuring the accuracy of global decisions while avoiding the risk of leakage of core business data during cross-node transmission.
[0237] 2. Location-Time Dual-Dimensional Dynamic Adaptation Algorithm
[0238] For example, the algorithm constructs a region-time two-dimensional coupled quantization model to achieve fine-grained dynamic adaptation of the flow limiting threshold in the region and time dimensions. The process is as follows: Figure 10 As shown, the output is the standardized regional characteristic coefficient Kara and the time characteristic coefficient Ktime (0.5~1.5, the larger the value, the stronger the system's carrying capacity under this dimension, and the flow limit threshold can be relaxed accordingly).
[0239] (1) Multidimensional input factors:
[0240] ①Regional factors: Regional carrying capacity coefficient Carea (the ratio of the actual carrying capacity of the region to the average carrying capacity of the entire network, with an initial value of 0.5~2.0) and regional traffic density Darea (the ratio of the current regional traffic to the historical peak traffic of the region, normalized to 0~1).
[0241] ② Time Factors: Period Flow Pressure Coefficient Ptime (the ratio of current period flow to historical peak flow for that period, 0~1), Period Type Weight Wtype (Peak = 1.2, Off-Peak = 1.0, Off-Peak = 0.6, Holidays = 1.5). The period division rules are as follows: Peak: 9:00-12:00, 18:00-21:00; Off-Peak: 7:00-9:00, 12:00-18:00, 21:00-23:00; Off-Peak: 23:00-7:00 the next day; Holidays: All day on national statutory holidays.
[0242] ③ After all input factors are collected, they are uniformly stored as 32-bit floating-point numbers. A dual storage strategy of Redis caching and local file backup is adopted. The Redis cache is used for real-time access, and the cache validity period is 30 minutes. It is automatically refreshed when it expires. The local file format is CSV for data traceability.
[0243] (2) Factor normalization: Standardize all input factors to [0,1] to eliminate dimensional differences.
[0244] ①Carea normalization: Since the initial value is in the range of 0.5 to 2.0, the normalization formula is Carea = (Carea - 0.5) / (2.0 - 0.5), which maps to [0,1].
[0245] ②Darea and Ptime normalization: Since they have been naturally normalized to 0~1, no additional processing is required, and the original values can be used directly;
[0246] ③Wtype normalization: Based on the preset weight value range (0.6~1.5), the normalization formula Wtype=(Wtype-0.6) / (1.5 -0.6) is mapped to [0,1].
[0247] ④ Deploy a normalization processing module locally on the edge agent and use Python's NumPy library to implement vectorized calculations. After processing, verify the normalization results to ensure that all factors are in the [0,1] interval. If values exceed the interval, automatically prune them to the interval boundary to avoid affecting subsequent coefficient calculations.
[0248] ⑤ The normalized factor results (Carea, Darea, Ptime, Wtype) are cached in Redis, corresponding one-to-one with the original factors. The cache validity period is the same as that of the original factors, which facilitates quick retrieval during subsequent coefficient calculations. At the same time, the original factor data is retained for anomaly investigation and tracing.
[0249] (3) Coefficient calculation: Karea = 0.6 × Carea + 0.4 × (1 − Darea)
[0250] Ktime = 0.7 × Wtype + 0.3 × (1 − Ptime). The weight coefficients (0.6, 0.4, 0.7, 0.3) in the formula are configured in the system configuration file. Dynamic adjustment is supported to adapt to the needs of different regions and different business scenarios. After adjustment, the system automatically synchronizes to all edge agents to ensure the consistency of the computing logic across the entire network.
[0251] (4) Output: Map Kara and Ktime to 0.5~1.5 and output to the dynamic rate limiting threshold algorithm. A RESTful interface is set up here to output the mapped result to the dynamic rate limiting threshold algorithm module in real time in JSON form (HTTPS encrypted transmission). The interface call frequency and the coefficient calculation frequency are kept consistent.
[0252] 3. Business priority-aware dynamic rate limiting threshold algorithm
[0253] For example, this algorithm is designed for distributed, multi-type business security defense scenarios. It dynamically calculates rate limiting thresholds based on attack intent, region, time, business priority, and system load, generating differentiated rate limiting thresholds. Specifically, it combines... Figure 11 As shown, the process is as follows:
[0254] (1) Input factors:
[0255] ① The basic threshold T0 represents the maximum number of requests that the business can normally handle (no attacks, low load, and normal geographical and time conditions). The initial value is determined by stress testing and regression analysis based on the business's historical traffic, interface success rate, and system resource usage data over the past 12 months. The edge agent is automatically calibrated every 24 hours, with a calibration range of ±10%, to avoid benchmark deviations caused by business iterations. The data is stored in the edge node in a JSON configuration file and supports remote batch updates.
[0256] ②Attack Intent Weight Wattack, a discrete fixed weight coefficient, DDoS=0.8, brute force attack=0.6, CC attack=0.4, normal traffic=0.1.
[0257] ③ Business priority coefficient P, a continuous floating-point coefficient, takes the value [0,1]. The higher the value, the higher the business priority. For core businesses (payment, authentication), the value range is [0.8,1.0], for important businesses it is [0.5,0.8), for ordinary businesses it is [0.2,0.5), and for low-priority businesses it is [0,0.2].
[0258] ④ The system load factor L is a floating-point number with a normalized value of [0,1]. It collects data such as CPU utilization, memory usage, bandwidth utilization, and request processing latency every second and performs a fusion calculation on them. L = 0.3×CPU+0.2×MEM+0.3×BAND+0.2×LATENCY.
[0259] ⑤ The regional feature coefficient Kara and the time feature coefficient Ktime are output in real time by the regional-time dual-dimensional dynamic adaptation algorithm, with a value range of [0.5, 1.5], and are read directly in the form of shared memory.
[0260] (2) Factor normalization: Standardize all input factors to the [0,1] interval to ensure calculation consistency.
[0261] (3) Threshold calculation: T=T0×[P×(1−Wattack×L)+(1−P)×(1−Wattack)]×Karea×Ktime
[0262] Formula explanation: When the system load is low (L is small), the threshold of high priority services (P close to 1) is close to T0; when encountering high-intensity attacks, Wattack>0.6 and the load surges, in order to avoid the threshold dropping sharply, a damping coefficient D is introduced (D=0.7 +0.3×(1.5-L)).
[0263] (4) Output: The dynamic threshold T is sent to the rate limiting module (network layer / application layer / service layer) of the corresponding region or time period to realize multi-level collaborative rate limiting. The rate limiting module reports the threshold effective status in real time, and any abnormality will automatically roll back to the stable value of the previous cycle.
[0264] The algorithm achieves multi-dimensional dynamic adaptation of "attack intensity, business priority, system load, region, and time", which not only ensures the effectiveness of attack defense but also maximizes the availability of core business.
[0265] 4. Attack Intent-Driven Reinforcement Learning Closed-Loop Optimization Algorithm
[0266] For example, this algorithm is designed for distributed multi-layer rate limiting scenarios. It uses DQN to achieve adaptive iterative optimization of the rate limiting strategy. All parameters are stored in 32-bit floating-point format, and the calculation precision retains four decimal places. Specifically, it combines... Figure 12 As shown, the process is as follows:
[0267] (1) State initialization: Define the system state S=(I, L, D, Kara, Ktime), where I is the attack intent label, L is the system load coefficient, D is the service traffic distribution (proportion of high-priority services), Kara is the regional characteristic coefficient, and Ktime is the time characteristic coefficient. The specific implementation is as follows:
[0268] ① Attack Intent Label I: Represented using one-hot encoding, with four dimensions (DDoS, brute force, CC attack, and normal traffic scenarios). For example, DDoS attack corresponds to [1,0,0,0], and normal traffic corresponds to [0,0,0,1], facilitating input recognition by the DQN network. The attack intent label is output in real-time by the attack detection engine built into the edge agent, matching traffic characteristics with an attack feature library. It is updated every 100ms, with no delay in label updates when attack types switch, ensuring real-time state awareness. A monitoring and alarm mechanism is also set up to promptly alert in case of anomalies.
[0269] ② System load coefficient L: The system load coefficient acquisition logic is continued, and it is directly read through shared memory. The value range is normalized to [0,1]. The acquisition frequency is 1 time / second. The 5-window moving average method is used to smooth the instantaneous fluctuations and ensure the stability of the load state representation. When the system load coefficient L changes abruptly, such as when a single fluctuation exceeds ±0.1, state resampling is automatically triggered to speed up the policy adjustment of reinforcement learning and adapt to the scenario of load change.
[0270] ③ Business traffic distribution D: The value range is [0,1]. Its value is obtained by dividing the current number of high-priority business requests by the current total number of business requests.
[0271] The edge agent deploys a traffic statistics module to count the number of requests for each priority service in real time. It calculates the D value every 50ms and uses linear normalization to ensure that it is in the range of [0,1]. The D value is cached in real time to the Redis cache.
[0272] ④ Geographic feature coefficient Kara and temporal feature coefficient Ktime: The results of the geographic-temporal dual-dimensional dynamic adaptation algorithm are directly adopted and read through shared memory. The values are [0.5, 1.5] and the reading latency is ≤1ms to ensure the consistency of state input. When Kara and Ktime change, the reconstruction of system state S is automatically triggered to ensure that the state reflects the changes in geographic and temporal dimensions in real time and improves the targeting of strategy optimization.
[0273] (2) Action space definition: A = {threshold coefficient adjustment ΔT (-0.2~+0.2), service priority weight adjustment ΔW (-0.1~+0.1), switching rate limiting level (network layer / application layer / service layer)}.
[0274] ① The threshold coefficient adjustment ΔT adopts discretization processing with a step size of 0.01 to adjust the dynamic rate limiting threshold T. The adjustment formula is T_new = T_old×(1 +ΔT). Before execution, a validity check is required to ensure that the adjusted T_new is in the range [T0×0.2, T0×1.8]. If it exceeds the range, it will be automatically clipped to the range boundary to avoid service interruption or overload caused by abnormal threshold.
[0275] ② Business priority weight adjustment ΔW: The value range is [-0.1, +0.1], the step size is 0.005, and there are 41 optional actions in total. It is used to fine-tune the priority coefficient P of each business. The adjustment formula is P_new = P_old +ΔW to ensure the smoothness of priority adjustment. The adjusted P_new must be in the range of [0,1], and the P_new of core business (original P≥0.8) must not be lower than 0.7, and the P_new of low priority business (original P≤0.2) must not be higher than 0.3 to avoid excessive priority adjustment leading to business protection imbalance. After the ΔW action is executed, it is automatically synchronized to the business priority configuration table and the dynamic rate limiting threshold algorithm that is aware of business priority to ensure that the priority parameters of the two algorithms are consistent.
[0276] ③ Switching Rate Limiting Levels: There are three selectable actions: switching to network layer rate limiting, application layer rate limiting, and service layer rate limiting. Each action corresponds to a unique level identifier (network layer = 0, application layer = 1, service layer = 2) to facilitate DQN network output identification. The level switching module is deployed by an edge agent. Upon receiving a switching action, it immediately interrupts the current level's rate limiting policy and loads the target level's rate limiting rules. The switching latency is ≤50ms to ensure rapid adaptation of the rate limiting level to the attack scenario. Simultaneously, the switching interval within the same level must not be less than 1 second to avoid frequent switching causing system instability. After switching, the switching action and the current attack intent are automatically recorded for subsequent reward function calculation and strategy optimization.
[0277] (3) Reward function design: R = α × R_intercept - β × R_false - γ × R_delay, where R_intercept is the attack interception rate (0-1); R_false is the false blocking rate of legitimate requests (0-1); R_delay is the response delay of high-priority services (normalized to 0-1); α, β, and γ are adaptive weight coefficients that are dynamically adjusted according to the attack type. The key points of implementation are as follows:
[0278] ① The weight values are all in the range of [0.1, 0.8] and satisfy α+β+γ=1.0 to ensure the balance of the reward function.
[0279] ② Dynamic Adjustment Mechanism: The weighting coefficients are dynamically adjusted according to the attack intent tag I. The higher the attack intensity, the greater the α weight; the greater the impact of false blocking, the greater the β weight; the higher the proportion of high-priority services, the greater the γ weight. The adjustment rules are as follows:
[0280] DDoS attack (I=[1,0,0,0]): α=0.8, β=0.1, γ=0.1 (prioritize blocking attacks to reduce the risk of business interruption);
[0281] Brute-force attack (I=[0,1,0,0]): α=0.6, β=0.2, γ=0.2 (balancing interception and false blocking to ensure normal access to core services);
[0282] CC attack (I=[0,0,1,0]): α=0.5, β=0.3, γ=0.2 (to reduce false positives and avoid affecting normal user requests);
[0283] Normal traffic (I=[0,0,0,1]): α=0.1, β=0.6, γ=0.3 (prioritize the passage of legitimate requests and low latency for high-priority services).
[0284] ③ Adjustment Implementation: Establish a dynamic weight adjustment module to read the attack intent tag I in real time, automatically match the corresponding weight coefficient, and adjust the latency ≤10ms to ensure that the reward function can quickly adapt to changes in attack type and drive the targeted optimization of the strategy.
[0285] ④ Engineering the reward function calculation: Vectorized operation is used to calculate the reward value. The calculation time for a single set of reward values is ≤5ms. After the calculation is completed, the reward value is pruned (to ensure that R∈[-0.5, 0.8]) to avoid extreme reward values causing model training oscillations. At the same time, the reward value is bound to the corresponding state S and action A for subsequent experience playback and network update.
[0286] (4) Reinforcement learning training: Construct an action value network based on the DQN algorithm, take state S as input, output the Q value of each action A, and select the optimal action to execute.
[0287] ① Action Value Network: A 3-layer fully connected neural network (input layer + hidden layer + output layer) is adopted. The input layer is a 7-dimensional system state vector S, the hidden layer has 2 layers (64 neurons in the first layer and 32 neurons in the second layer), and the output layer is the Q value of the action space A (a total of 41+41+3=85 output nodes, corresponding to all selectable actions). The network weight parameters are initialized using Xavier, the bias parameter is initialized to 0.01, the learning rate is set to 0.001, and the discount factor γ (used for future reward decay) is set to 0.9 to ensure training convergence speed and generalization ability. The network model adopts quantization compression technology to quantize the model parameters to 32-bit floating point type, and the model size is controlled within 10MB. It is deployed locally on the edge agent, without relying on GPU, and can achieve real-time training only through CPU. The training time per round is ≤20ms.
[0288] ② Action Selection Strategy: An ε-greedy strategy is adopted to select the optimal action. The initial value of ε is 0.9 (90% probability of selecting the optimal action with the largest current Q value, and 10% probability of randomly selecting an action for exploring new strategies). As the number of training iterations increases, ε decreases linearly (ε decreases by 0.05 every 1000 iterations), eventually stabilizing at 0.1, balancing strategy exploration and utilization. After the DQN network outputs the Q values of all actions, it filters out legal actions and selects the action with the largest Q value for execution; if multiple optimal actions with the same Q value exist, one is randomly selected for execution.
[0289] ③ Training constraint optimization: Each time an action is performed, network training is triggered once, and L2 regularization (regularization coefficient λ=0.0001) is added to the hidden layer. An early stopping strategy is adopted (training is paused when the Q value on the validation set does not improve for 50 consecutive rounds to avoid overfitting).
[0290] A training monitoring module is built to track the network loss value (using mean squared error MSE as the loss function) and Q value change trends in real time. When the loss value continues to rise (exceeding 0.5), the network training is automatically restarted to ensure training stability.
[0291] (5) Experience replay and network update: Store (S, A, R, S') in the experience replay pool, randomly sample samples to update the value network parameters, and improve the model's generalization ability.
[0292] (6) Policy Iteration: After every N rate-limiting actions (default N=100), the optimized action value network parameters are synchronized to the federated collaborative node. The synchronization data is transmitted using AES-256 encryption, and the synchronization channel uses TCP long connection + TLS1.3 encryption. The synchronization latency is ≤100ms, and batch synchronization is supported. After receiving the iterated network parameters or global calibration parameters, the edge agent immediately updates the local DQN network to realize local reinforcement learning and policy update.
[0293] This algorithm is an attack intent-driven algorithm that enables the system to continuously optimize its rate limiting strategy based on attack evolution and business changes, achieving "self-evolution of defense capabilities".
[0294] As can be seen, the above mainly describes the solutions provided by the embodiments of this application from a methodological perspective. To achieve the above functions, the embodiments of this application provide corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, in conjunction with the modules and algorithm steps of the various examples described in the embodiments disclosed herein, the embodiments of this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0295] This application embodiment can divide the flow control device into functional modules according to the above method example. For example, each function can be divided into its own functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. Optionally, the module division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.
[0296] In some embodiments, this application also provides a flow control device. The flow control device may include one or more functional modules for implementing the flow control method of the above method embodiments.
[0297] For example, Figure 13 This is a schematic diagram of a flow control device provided in an embodiment of this application. Figure 13 As shown, the flow control device 1300 includes: an acquisition module 1301 and an output module 1302.
[0298] In some embodiments, the acquisition module 1301 is specifically used for:
[0299] Obtain the node traffic parameters on the first network node;
[0300] The aforementioned acquisition module 1301 is also used for:
[0301] Obtain the regional traffic parameters of the network area where the first network node is located;
[0302] The aforementioned output module 1302 is specifically used for:
[0303] Input the above-mentioned regional flow parameters and the above-mentioned node flow parameters into the first flow control model, and output the first flow threshold.
[0304] The first traffic threshold is used to control the traffic on the first network node, and the first model parameter of the first traffic control model is determined based on the historical node traffic parameters on one or more network nodes in the target network topology.
[0305] The node traffic parameters mentioned above include at least one of the following: the attack intent label of the network attack that occurred on the first network node, the load factor of the first network node, and the service traffic distribution factor on the first network node. The load factor is determined based on at least one of the resource utilization rate of the first device and the request processing latency of the first device.
[0306] The aforementioned regional traffic parameters include at least one of the geographical traffic characteristic coefficient and the temporal traffic characteristic coefficient of the aforementioned network region;
[0307] The aforementioned first flow control model is the flow control model on the first device, the aforementioned first device is the device corresponding to the aforementioned first network node, and the aforementioned first network node is any network node in the target network topology.
[0308] The flow control device 1300 provided in this application acquires node flow parameters on a first network node; acquires regional flow parameters of the network area where the first network node is located; inputs the regional flow parameters and the node flow parameters into a first flow control model, and outputs a first flow threshold; wherein the first flow threshold is used to control the flow on the first network node, and the first model parameters of the first flow control model are determined based on historical node flow parameters on one or more network nodes in the target network topology; the node flow parameters include at least one of the following: attack intent label of a network attack occurring on the first network node, load coefficient of the first network node, and service flow distribution coefficient of the first network node, wherein the load coefficient is determined based on at least one of the resource utilization rate of the first device and the request processing latency of the first device; the regional flow parameters include at least one of the regional flow characteristic coefficient and the time flow characteristic coefficient of the network area; the first flow control model is a flow control model on a first device, the first device is the device corresponding to the first network node, and the first network node is any network node in the target network topology. Thus, by adopting the above scheme, a device deployed on any network node in the target network topology can determine the model parameters of the flow control model on that device based on the historical node traffic parameters of all network nodes in the target network topology. Then, the flow control model outputs the flow threshold for flow control of that network node based on the node traffic parameters on that network node and the regional traffic parameters of the network area where that network node is located. This avoids the problem that distributed network attacks can bypass the rate limiting scheme on a single network node by distributing requests to multiple network nodes. Even in the face of distributed network attacks, the flow of each network node in the target network topology can be accurately controlled, thereby effectively defending against distributed network attacks and improving network security.
[0309] In some embodiments, the acquisition module 1301 is specifically used for:
[0310] Based on the maximum traffic that the above network area can carry and the average traffic that the above network area can carry, the regional carrying capacity coefficient of the above network area is determined. The average traffic that the above network area can carry is the average of the maximum traffic that all network nodes in the above network area can carry.
[0311] Based on the current regional traffic and the historical peak traffic of the aforementioned network regions, the regional traffic density of the aforementioned network regions is determined.
[0312] Based on the aforementioned regional carrying capacity coefficient and the aforementioned regional flow density, the aforementioned regional flow characteristic coefficients are determined.
[0313] In some embodiments, the acquisition module 1301 is further configured to:
[0314] Based on the average regional traffic and peak regional traffic of the aforementioned network area in the first time period, the traffic pressure coefficient of the aforementioned network area in the first time period is determined; the first time period is the time period in which the current moment occurs.
[0315] Based on the flow pressure coefficient and the time period weight coefficient corresponding to the first time period, the above-mentioned time flow characteristic coefficient is determined.
[0316] In some embodiments, the output module 1302 is specifically used for:
[0317] The third traffic threshold is determined based on the second traffic threshold corresponding to the first service, the attack intent weight parameter of the aforementioned network attack, the service priority coefficient of the aforementioned first service, and the aforementioned regional traffic parameter.
[0318] Using the first traffic control model described above, based on the regional traffic parameters and the node traffic parameters described above, at least one action and the confidence level of each action are determined; wherein, the at least one action includes a traffic threshold adjustment action and a service priority adjustment action.
[0319] The first traffic threshold is generated based on the action parameters of the first action with the highest confidence among at least one of the above actions and the first parameters corresponding to the first action.
[0320] The first parameter mentioned above can be any one of the following: the third traffic threshold mentioned above, or the service priority coefficient mentioned above;
[0321] The aforementioned first service is the service carried by the aforementioned first network node.
[0322] In some embodiments, the acquisition module 1301 is further configured to:
[0323] Obtain the training dataset of the first flow control model, wherein the training dataset includes at least one of the following: at least one historical service data on the first network node, the historical geographical data, the historical time data, the historical traffic data, and the historical system status data;
[0324] The aforementioned device 1300 further includes: an adjustment module 1303, specifically used for:
[0325] Using the above training dataset, the initial model parameters of the first flow control model are adjusted to obtain the second model parameters of the first flow control model.
[0326] Module 1304 is generated, specifically for:
[0327] The first model parameters are generated based on the second model parameters and at least one third model parameter.
[0328] Wherein, the above-mentioned at least one third model parameter is at least one model parameter corresponding to at least one second flow control model, each second flow control model is a flow control model on a device other than the first device in the target network topology, a device is a device deployed on a network node in the target network topology, and each third model parameter is determined based on the historical node flow parameters on the corresponding network node.
[0329] It should be noted that the flow control device can implement all the processes implemented in the above method embodiments and achieve the same beneficial effects. To avoid repetition, it will not be described again here.
[0330] In the case where the functions of the integrated modules described above are implemented in hardware, this application provides a possible structural schematic diagram of the electronic device involved in the above embodiments. For example... Figure 14 As shown, the electronic device 140 includes: a processor 142, a communication interface 143, and a bus 144. Optionally, the electronic device 140 may also include a memory 141.
[0331] Processor 142 may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 142 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 142 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0332] Communication interface 143 is used to connect with other devices via a communication network. This communication network can be Ethernet, wireless access network, wireless local area network (WLAN), etc.
[0333] The memory 141 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.
[0334] As one possible implementation, the memory 141 can exist independently of the processor 142. The memory 141 can be connected to the processor 142 via a bus 144 and is used to store instructions or program code. When the processor 142 calls and executes the instructions or program code stored in the memory 141, it can implement the flow control method provided in the embodiments of this application.
[0335] In another possible implementation, the memory 141 can also be integrated with the processor 142.
[0336] Bus 144 can be an Extended Industry Standard Architecture (EISA) bus, etc. Bus 144 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 14 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0337] Through the above description of the implementation methods, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the service calling device can be divided into different functional modules to complete all or part of the functions described above.
[0338] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described flow control method embodiments and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0339] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.
[0340] This application also provides a readable storage medium storing a program or instructions that, when executed by a computer, implement the flow control method provided in the above embodiments. It is understood that all or part of the processes in the above method embodiments can be executed by computer instructions instructing related hardware; the readable storage medium can be any of the foregoing embodiments or memory; the readable storage medium can also be an external storage device of the service invocation device, such as a pluggable hard drive, Smart MediaCard (SMC), Secure Digital (SD) card, flash card, etc., equipped on the service invocation device. Further, the readable storage medium can include both internal storage units of the service invocation device and external storage devices. The readable storage medium is used to store the computer program and other programs and data required by the service invocation device. The readable storage medium can also be used to temporarily store data that has been output or will be output.
[0341] This application also provides a computer program product, which is stored in a storage medium and implements the flow control method provided in the above embodiments when executed by a computer.
[0342] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.
[0343] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0344] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
Claims
1. A flow control method, characterized in that, include: Obtain the node traffic parameters on the first network node; Obtain the regional traffic parameters of the network area where the first network node is located; The regional flow parameters and the node flow parameters are input into the first flow control model, and the first flow threshold is output. Wherein, the first traffic threshold is used to control the traffic on the first network node, and the first model parameter of the first traffic control model is determined based on the historical node traffic parameters on one or more network nodes in the target network topology; The node traffic parameters include at least one of the following: the attack intent label of the network attack that occurred on the first network node, the load coefficient of the first network node, and the service traffic distribution coefficient on the first network node. The load coefficient is determined based on at least one of the resource utilization rate of the first device and the request processing latency of the first device. The regional traffic parameters include at least one of the geographical traffic characteristic coefficient and the temporal traffic characteristic coefficient of the network region. The first flow control model is the flow control model on the first device, the first device is the device corresponding to the first network node, and the first network node is any network node in the target network topology.
2. The flow control method according to claim 1, characterized in that, When the regional traffic parameters include the regional traffic characteristic coefficient, obtaining the regional traffic parameters of the network area where the first device is located includes: Based on the maximum traffic that the network area can carry and the average traffic that the network area can carry, the regional carrying capacity coefficient of the network area is determined, wherein the average traffic is the average of the maximum traffic that all network nodes in the network area can carry; The regional traffic density of the network region is determined based on the current regional traffic and the historical peak traffic of the network region. The regional flow characteristic coefficient is determined based on the regional carrying capacity coefficient and the regional flow density.
3. The flow control method according to claim 1, characterized in that, When the regional traffic parameters include the time-based traffic characteristic coefficient, obtaining the regional traffic parameters of the network area where the first device is located includes: The traffic pressure coefficient of the network region in the first time period is determined based on the average regional traffic and the peak regional traffic of the network region in the first time period; the first time period is the time period in which the current moment occurs. The time-flow characteristic coefficient is determined based on the flow pressure coefficient and the time period weight coefficient corresponding to the first time period.
4. The flow control method according to claim 1, characterized in that, The step of inputting the regional flow parameters and the node flow parameters into the first flow control model and outputting the first flow threshold includes: A third traffic threshold is determined based on the second traffic threshold corresponding to the first service, the attack intent weight parameter of the network attack, the service priority coefficient of the first service, and the regional traffic parameter. Using the first traffic control model, based on the regional traffic parameters and the node traffic parameters, at least one action and the confidence level of each action are determined; wherein, the at least one action includes a traffic threshold adjustment action and a service priority adjustment action; The first traffic threshold is generated based on the action parameters of the first action with the highest confidence among the at least one actions and the first parameters corresponding to the first action. Wherein, the first parameter is any one of the following: the third traffic threshold, the service priority coefficient; The first service is the service carried by the first network node.
5. The flow control method according to claim 1, characterized in that, Before obtaining the regional traffic parameters of the network area where the first network node is located, the traffic control method further includes: Obtain the training dataset of the first flow control model, wherein the training dataset includes at least one of the following: at least one historical service data on the first network node, the historical geographical data, the historical time data, the historical traffic data, and the historical system status data; Using the training dataset, the initial model parameters of the first flow control model are adjusted to obtain the second model parameters of the first flow control model; The first model parameters are generated based on the second model parameters and at least one third model parameter. Wherein, the at least one third model parameter is at least one model parameter corresponding to the at least one second flow control model, each second flow control model is a flow control model on a device other than the first device in the target network topology, a device is a device corresponding to a network node in the target network topology, and each third model parameter is determined based on the historical node flow parameters on the corresponding network node.
6. A flow control device, characterized in that, include: The acquisition module is used to acquire node traffic parameters on the first network node; Obtain the regional traffic parameters of the network area where the first network node is located; The output module is used to input the regional flow parameters and the node flow parameters into the first flow control model and output the first flow threshold. Wherein, the first traffic threshold is used to control the traffic on the first network node, and the first model parameter of the first traffic control model is determined based on the historical node traffic parameters on one or more network nodes in the target network topology; The node traffic parameters include at least one of the following: the attack intent label of the network attack that occurred on the first network node, the load coefficient of the first network node, and the service traffic distribution coefficient on the first network node. The load coefficient is determined based on at least one of the resource utilization rate of the first device and the request processing latency of the first device. The regional traffic parameters include at least one of the geographical traffic characteristic coefficient and the temporal traffic characteristic coefficient of the network region. The first flow control model is the flow control model on the first device, the first device is the device corresponding to the first network node, and the first network node is any network node in the target network topology.
7. The apparatus according to claim 6, characterized in that, The acquisition module is specifically used for: Based on the maximum traffic that the network area can carry and the average traffic that the network area can carry, the regional carrying capacity coefficient of the network area is determined, wherein the average traffic is the average of the maximum traffic that all network nodes in the network area can carry; The regional traffic density of the network region is determined based on the current regional traffic and the historical peak traffic of the network region. The regional flow characteristic coefficient is determined based on the regional carrying capacity coefficient and the regional flow density.
8. The apparatus according to claim 6, characterized in that, The acquisition module is also used for: The traffic pressure coefficient of the network region in the first time period is determined based on the average regional traffic and the peak regional traffic of the network region in the first time period; the first time period is the time period in which the current moment occurs. The time-flow characteristic coefficient is determined based on the flow pressure coefficient and the time period weight coefficient corresponding to the first time period.
9. The apparatus according to claim 6, characterized in that, The output module is specifically used for: A third traffic threshold is determined based on the second traffic threshold corresponding to the first service, the attack intent weight parameter of the network attack, the service priority coefficient of the first service, and the regional traffic parameter. Using the first traffic control model, based on the regional traffic parameters and the node traffic parameters, at least one action and the confidence level of each action are determined; wherein, the at least one action includes a traffic threshold adjustment action and a service priority adjustment action; The first traffic threshold is generated based on the action parameters of the first action with the highest confidence among the at least one actions and the first parameters corresponding to the first action. Wherein, the first parameter is any one of the following: the third traffic threshold, the service priority coefficient; The first service is the service carried by the first network node.
10. The apparatus according to claim 6, characterized in that, The acquisition module is also used for: Obtain the training dataset of the first flow control model, wherein the training dataset includes at least one of the following: at least one historical service data on the first network node, the historical geographical data, the historical time data, the historical traffic data, and the historical system status data; The device further includes: an adjustment module, used to adjust the initial model parameters of the first flow control model using the training dataset to obtain the second model parameters of the first flow control model; A generation module is used to generate the first model parameters based on the second model parameters and at least one third model parameter; Wherein, the at least one third model parameter is at least one model parameter corresponding to the at least one second flow control model, each second flow control model is a flow control model on a device other than the first device in the target network topology, a device is a device corresponding to a network node in the target network topology, and each third model parameter is determined based on the historical node flow parameters on the corresponding network node.
11. An electronic device, characterized in that, It includes a processor and a memory, the memory storing a program or instructions that can run on the processor, the program or instructions being executed by the processor to implement the flow control method as described in any one of claims 1-5.
12. A readable storage medium, characterized in that, The readable storage medium stores a program or instructions that, when executed by a computer, implement the flow control method as described in any one of claims 1-5.
13. A computer program product, characterized in that, The computer program product is stored in a storage medium, and when executed by a computer, the computer program product implements the flow control method as described in any one of claims 1-5.