A method and device for monitoring abnormal users of broadband services of an access network
Patent Information
- Application Number
- CN202610663585.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-14
- Publication Date
- 2026-09-22
AI Technical Summary
[0005]本发明提供了一种面向接入网宽带业务异常用户监管监控的方法和装置,该方法能够解决现有技术误伤高、投诉多、拥塞难治的问题
[0023]第五方面,提供了一种计算机程序产品,所述计算机程序产品存储有指令,所述指令在由计算机执行时使得所述计算机实施第一方面或第二方面所述的方法。
Smart Images

Figure CN122802400A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and in particular to a method and apparatus for monitoring and supervising abnormal users of broadband services in access networks. Background Technology
[0002] Currently, home broadband users access the metropolitan area network (MAN) through optical modems, splitters, and OLTs. Normal internet browsing, such as web browsing, video calls, and online gaming, typically does not generate abnormally high bandwidth usage. However, some users deploy PCDN hardware or software to distribute commercial traffic using their home broadband, leading to significant consumption of OLT uplink bandwidth and causing lag and disconnections for other users on the same network. Simultaneously, P2P traffic is highly volatile, easily causing localized congestion and diverting traffic to cross-regional or cross-carrier networks, increasing inter-network settlement costs.
[0003] Existing technologies for PCDN users often employ a simple approach of directly shutting down or limiting their speed. The typical process involves monitoring traffic thresholds and shutting down or limiting the speed of users exceeding those thresholds. This method relies solely on traffic thresholds, failing to distinguish between PCDN users and normal high-traffic users, resulting in a high false alarm rate. Furthermore, it lacks early warning communication, with users only noticing the outage after it has occurred, leading to frequent complaints. Moreover, violating users can easily change accounts or devices to circumvent the restrictions, failing to fundamentally resolve congestion. Additionally, the process relies on manual intervention and is difficult to automate.
[0004] Therefore, there is an urgent need for a refined method for monitoring and supervising abnormal users to solve the problems of high false positives, numerous complaints, and difficulty in managing congestion caused by existing technologies. Summary of the Invention
[0005] This invention provides a method and apparatus for monitoring and supervising abnormal users in broadband services of access networks. This method can solve the problems of high false positives, numerous complaints, and difficulty in resolving congestion in existing technologies.
[0006] Firstly, a method for monitoring and supervising abnormal users in broadband access network services is provided, including: Construct an abnormal user analysis model, which is used to analyze the correlation between network node traffic and abnormal user traffic; Collect data from at least one data source system in the network node, and extract the network location information, business attributes and traffic behavior data of users in the network node from the collected data based on the abnormal user analysis model to obtain a clustered user information table; Spatial clustering is performed on the clustered user information table according to different physical device dimensions to obtain a clustering candidate set; By combining traffic time period characteristics and flow direction characteristics, and based on the correlation degree output by the model, it is determined whether the cluster candidate set is a suspected abnormal user cluster; Based on abnormal monitoring rules for installation behavior, abnormal user clusters in network nodes are filtered out from suspected abnormal user clusters.
[0007] In this way, by constructing an abnormal user analysis model and integrating spatial clustering, traffic feature analysis, and installation behavior rules, accurate identification and clustered positioning of abnormal users such as PCDN are achieved. Furthermore, it effectively reduces the false judgment rate of traditional threshold control, avoids unintended harm to normal high-traffic users, and eliminates false user groups under the same physical node in one go through cluster governance, thereby releasing OLT uplink bandwidth and alleviating network congestion. It also reduces the inter-network settlement costs caused by cross-province and cross-carrier traffic and avoids blind expansion.
[0008] In one possible implementation, the user information table is spatially clustered according to different physical device dimensions to obtain a clustering candidate set, including: The users in the clustered user information table are grouped according to their respective uplink broadband remote access servers to generate a first-level clustering candidate set; The users in the clustered user information table are grouped according to their respective optical line terminals to generate a second-level clustering candidate set; The users in the clustering user information table are grouped according to their respective first-level spectrometers to generate a third-level clustering candidate set; At least one of the first-level clustering candidate sets, the second-level clustering candidate sets, and the third-level clustering candidate sets shall be used as the clustering candidate sets.
[0009] In this way, spatial clustering can be performed at three different physical dimensions with different granularities: the core network (BRAS), the access network (OLT), and the user side (optical splitter), enabling hierarchical localization of abnormal user groups. The first-level clustering can detect widespread abnormal traffic aggregation across OLTs; the second-level clustering can accurately pinpoint localized congestion caused by PCDN within a single OLT; and the third-level clustering can identify batches of fraudulently installed users within the coverage area of the same optical splitter. This multi-scale clustering approach can select the most appropriate clustering granularity for analysis based on the scale and impact of abnormal behavior, avoiding missed detections or over-aggregation caused by a single dimension, thereby improving the accuracy and efficiency of identifying and handling abnormal user clusters.
[0010] In one possible implementation, the clustering candidate set is determined by combining traffic time-period characteristics and flow direction characteristics, and based on the correlation degree output by the model, whether the cluster is a suspected abnormal user cluster, including: For each user in the cluster candidate set, extract their uplink traffic distribution within a preset time period to calculate the traffic time period entropy value and peak-to-valley ratio, and extract the cross-regional uplink traffic ratio and cross-carrier uplink traffic ratio. When at least one of the following conditions is met: the entropy value of the traffic period is lower than the entropy value threshold, the peak-to-valley ratio is lower than the peak-to-valley ratio threshold, the proportion of cross-regional uplink traffic is higher than the first proportion threshold, and / or the proportion of cross-operator uplink traffic is higher than the second proportion threshold, and the correlation degree output by the abnormal user analysis model is greater than the preset correlation degree threshold, the user is marked as a candidate abnormal user. The number of candidate abnormal users in the cluster candidate set is counted. When the number of candidate abnormal users exceeds the threshold of abnormal users, the cluster candidate set is determined to be a cluster of suspected abnormal users.
[0011] In this way, by extracting the time-period and flow characteristics of user traffic and integrating the correlation results from the abnormal user analysis model, the behavioral patterns of PCDN users can be accurately identified, effectively distinguishing between normal household users and non-compliant users. Based on this, by statistically analyzing the number or proportion of candidate abnormal users within the candidate cluster, the judgment is elevated from individual anomalies to group anomalies, avoiding misjudgments caused by occasional traffic fluctuations of single users and improving the robustness and accuracy of abnormal cluster identification. The final output of suspected abnormal user clusters provides a clear and reliable target range for subsequent on-site verification and tiered handling, reducing the cost of manual verification.
[0012] In one possible implementation, based on abnormal monitoring rules for installation behavior, abnormal user clusters in network nodes are filtered out from suspected abnormal user clusters, including: Obtain broadband completion work order information for users in the suspected abnormal user cluster. The work order information should include at least the installation address, completion time, and engineer identifier. When the number of completed broadband installations in the same building within a preset time window exceeds the first threshold, or when the number of completed broadband installations at the same installation address by the same engineer within a preset time window exceeds the second threshold, the corresponding user will be marked as a candidate for abnormal installation. On-site verification is conducted for candidate users with installation abnormalities. Users who pass the verification are retained as the final confirmed abnormal user cluster, while users who are found to be fraudulent are removed.
[0013] In this way, by analyzing the installation address, completion time, and engineer identification in broadband completion work orders, abnormal behavior patterns such as batch completions in the same building or repeated installations at the same address by the same engineer within a short period of time can be identified, accurately pinpointing potential fraudulent users or PCDN cluster installations. Based on this, a second confirmation is conducted through on-site verification, effectively eliminating fraudulent users and avoiding misjudgments of legitimate users. Simultaneously, it releases occupied access network resources such as PON ports and splitter ports, reducing port hoarding and resource waste. This rule complements the aforementioned traffic characteristic analysis, further purifying the user base from the source of installations and improving the accuracy and reliability of abnormal user cluster screening.
[0014] In one possible implementation, data is collected from at least one data source system in the network node. Based on the abnormal user analysis model, network location information, service attributes, and traffic behavior data of users in the network node are extracted from the collected data to obtain a clustered user information table, including: The system collects the user's service number, installation address, completion time, affiliated optical line terminal management IP, uplink optical line terminal port, primary splitter code and port, and optical modem device code and port as network location information. Collect users' broadband account, package type, account opening time, service status, development channel, and development engineer identifier from the customer business support system as business attributes; The system collects real-time uplink traffic, passive optical network port traffic, user broadband interaction counts, and broadband account information from the network management system. The user authentication system collects the user's public IP address, network address translation port range, online / offline time, uplink and downlink bandwidth and traffic, broadband remote access server device IP and location as traffic behavior data. Using broadband account as the primary key, the collected data is correlated, cleaned, and aggregated to generate a clustered user information table with broadband account as the row and network location information, service attributes, and traffic behavior data as the column.
[0015] In this way, by collecting data from four core systems—line number, customer service support, network management, and user authentication—and using broadband accounts as the primary key for association, cleaning, and aggregation, a full-dimensional fusion of user network location, service subscription, and traffic behavior is achieved, generating a structured clustered user information table. This table provides a unified, complete, and associative basic data view for subsequent spatial clustering, traffic feature analysis, and anomaly detection, avoiding feature loss or association errors caused by data silos. This improves the comprehensiveness and accuracy of abnormal user identification and supports automated modeling and closed-loop management across systems.
[0016] One possible implementation also includes: Traffic tiering will be implemented for users in the finally confirmed abnormal user clusters; Traffic tiering measures include: setting tiered traffic limits based on user package type, historical traffic habits, and network capacity; monitoring user traffic at preset intervals; sending reminder SMS messages when user traffic exceeds the first-level limit; implementing uplink bandwidth throttling when traffic exceeds the second-level limit; and directly blocking network access for users confirmed as fraudulent through on-site investigation.
[0017] In this way, by setting tiered traffic limits based on user plan type, historical traffic habits, and network capacity, differentiated hierarchical management is achieved, avoiding the use of a uniform threshold for all users and significantly reducing the false positive rate for normal high-traffic users. Monitoring at preset intervals and sequentially executing tiered responses such as SMS alerts, uplink speed limits, and network disconnection for fraudulent users provides compliant users with sufficient buffer time for rectification, effectively reducing complaints caused by sudden network outages; on the other hand, verified fraudulent users are directly blocked from access, promptly releasing occupied access network resources. This tiered response mechanism balances user experience and network resource fairness, curbing the impact of PCDN and other violations on other users under the same OLT while maintaining the operator's humanized and compliant service.
[0018] In one possible implementation, an abnormal user analysis model is constructed to analyze the correlation between network node traffic and abnormal user traffic, including: Based on historical user traffic data, clustering, trend, dispersion, and frequency analysis are used to identify candidate abnormal users; By analyzing the time-series correlation between historical user traffic data and network node congestion indicators, the correlation between network node traffic and candidate abnormal user traffic can be determined.
[0019] In this way, by fusing multiple algorithms such as clustering, trend analysis, dispersion analysis, and frequency analysis, candidate abnormal users are identified from the perspective of traffic behavior, avoiding misjudgments caused by simply relying on fixed thresholds. Furthermore, the temporal correlation between user traffic and network node congestion indicators is analyzed, causally binding individual behavior to node load to ensure that the identified abnormal users are directly related to actual network congestion. This two-layer modeling approach of behavior recognition and correlation verification significantly improves the accuracy and interpretability of abnormal user identification, avoids mistakenly classifying normal high-traffic users as violators, and provides a reliable quantitative basis for subsequent cluster judgment and tiered handling.
[0020] Secondly, a device for monitoring and supervising abnormal users in broadband services on access networks is provided, comprising: The first processing module is used to build an abnormal user analysis model, which is used to analyze the correlation between network node traffic and abnormal user traffic. The second processing module is used to collect data from at least one data source system in the network node, and extract the network location information, business attributes and traffic behavior data of users in the network node from the collected data based on the abnormal user analysis model, so as to obtain a clustered user information table. The third processing module is used to perform spatial clustering on the clustered user information table according to different physical device dimensions to obtain cluster candidate sets; combining traffic time period characteristics and flow direction characteristics, and based on the correlation degree output by the model, it determines whether the cluster candidate sets are suspected abnormal user clusters. The fourth processing module is used to filter out abnormal user clusters in network nodes from suspected abnormal user clusters based on abnormal monitoring rules of installation behavior.
[0021] Thirdly, an electronic device is provided, comprising: one or more processors; one or more memories; and one or more programs, wherein the one or more programs are stored in the one or more memories, and the one or more programs include instructions that, when executed by the one or more processors, cause the configured device to perform the method as described in the first aspect.
[0022] Fourthly, a computer storage medium is provided, the computer storage medium storing instructions that, when executed by a computer, cause the computer to perform the method described in the first aspect or the second aspect.
[0023] Fifthly, a computer program product is provided, the computer program product storing instructions that, when executed by a computer, cause the computer to perform the method described in the first aspect or the second aspect.
[0024] The beneficial effects of the second to fifth aspects can be referred to the introduction of the beneficial effects of the first aspect above, and will not be repeated here. Attached Figure Description
[0025] Figure 1 This is a flowchart illustrating a method for monitoring and supervising abnormal users in broadband services on an access network, as provided in an embodiment of the present invention. Figure 2 A flowchart illustrating a method for monitoring and supervising abnormal users in broadband services of an access network, provided by an embodiment of the present invention; Figure 3 This is a schematic diagram of an apparatus for monitoring and supervising abnormal users in broadband services of an access network, which can be used to implement the method of the present invention. Figure 4 This is a schematic diagram of an electronic device provided by the present invention. Detailed Implementation
[0026] The solutions provided by the embodiments of the present invention will now be described with reference to the accompanying drawings. In the embodiments of the present invention, "multiple" refers to two or more objects, and "various kinds" refers to two or more types. Terms such as "first," "second," etc., are only used to distinguish similar objects and are not necessarily used to describe a specific order or number of objects.
[0027] First, the relevant technical terms involved in the technical solution provided by this invention will be introduced.
[0028] PCDN, or Peer-to-Peer Content Delivery Network, is a network architecture that optimizes content distribution using P2P (peer-to-peer) technology. Its core idea is to combine the centralized servers of a traditional CDN with decentralized nodes in a P2P network, utilizing the idle resources (such as bandwidth and storage space) of a large number of user terminal devices to share the content distribution task.
[0029] PCDN users refer to individuals or organizations that have deployed PCDN-related hardware or software in their personal broadband networks.
[0030] Currently, most broadband users access the metropolitan area network (MAN) through optical modems, splitters, and OLTs. Normal network services, such as web browsing, video calls, online games, and online video streaming, typically do not generate large traffic spikes or abnormal uplink traffic, as bandwidth is customized according to the network contract agreement.
[0031] However, if individual or home broadband users utilize P2P technology for content distribution, employing specialized hardware or modifying network configurations to exceed the original design purpose of home broadband for personal internet access and instead use it for commercial or quasi-commercial traffic distribution, they become PDCN users. PDCN users consume significant amounts of uplink bandwidth from the Optical Line Terminal (OLT), impacting the normal network quality and speed for other users on the same OLT, causing service interruptions. Furthermore, P2P traffic is sudden and unpredictable, potentially leading to localized network congestion and a decline in user experience. PCDN users on the same uplink can cause other users to experience frequent disconnections, buffering, and inability to access the internet normally. PCDN users redirect large amounts of home broadband traffic, which should be localized, to networks outside the region or even other operators, triggering new billing mechanisms and exacerbating network congestion.
[0032] In existing technologies, the management methods for abnormal traffic users, especially PCDN users, mostly adopt simple measures such as direct shutdown or rate limiting. While this approach can suppress abnormal traffic in the short term, it easily leads to numerous user complaints. Specifically, the operation process of existing solutions is as follows: First, the system defines the usage location and device identification of customer devices; second, it obtains the operating information of IoT devices; when an agent uses the same local area network to build a dedicated content delivery network (PCDN), forming a small cluster network and causing traffic overflow, the system uses the client as a content distribution aggregation point to receive content requests; then it determines whether the requested content already exists in the PCDN network; if not, it temporarily aggregates content fragments among multiple IoT devices; finally, it sends the aggregated content fragments to the target IoT device. This process causes uplink and downlink traffic overload. The system monitors traffic and performs shutdown or rate limiting operations on users exceeding a set threshold.
[0033] The existing solution suffers from the following technical flaws: First, its handling methods are simplistic and lack fine-grained differentiation capabilities, relying solely on traffic thresholds for judgment. This fails to effectively distinguish genuine PCDN violators from normal high-traffic users (such as those using NAS for data backup, frequent video conferencing, or cloud synchronization), leading to a high false positive rate. Second, the control process lacks warning, appeal, or user communication mechanisms. Users typically only perceive the results after service interruption or speed degradation, resulting in a poor user experience and numerous complaints. Third, the solution fails to address the root cause of network congestion. Violators can evade monitoring by changing accounts, devices, or network access points, trapping operators in a passive cycle of "discovery-blocking-rediscovery." Fourth, the solution's device information acquisition and content existence verification require complex system integration and manual intervention, making large-scale automation difficult in actual deployment. Consequently, most operators ultimately revert to simple traffic threshold monitoring. In conclusion, the existing technology lacks fine-grained control capabilities, falsely penalizes legitimate users, fails to effectively alleviate network congestion, and easily triggers service disputes and complaints.
[0034] To address the problems of existing technologies, such as limited control methods, easy mistreatment of normal users, and inability to effectively resolve network congestion, this invention provides a method for monitoring and supervising abnormal users in broadband access networks. By establishing a refined system for identifying and controlling abnormal users, this method can reasonably control network resource usage, reduce inter-network settlement costs, and avoid network congestion and resource waste while ensuring the network experience of ordinary household broadband users.
[0035] The following is in conjunction with the appendix Figure 1 The specific implementation steps of the present invention will be described in detail below.
[0036] Figure 1This is a flowchart illustrating a method for monitoring and supervising abnormal users in broadband services on an access network, as shown in an embodiment of the present invention. Figure 1 As shown, it includes the following steps: In step 110, a broadband anomaly user analysis model is constructed.
[0037] First, key fields such as broadband account, configured bandwidth, uplink and downlink traffic, number of days exceeding data limit, affiliated OLT and product package are extracted from the operator's system. The data is then cleaned, normalized, and summarized according to OLT, splitter, time period and other dimensions to form a basic data table.
[0038] Based on this, four algorithms are integrated for analysis. The first is cluster analysis, which groups users according to uplink / downlink ratio, peak traffic percentage, concurrent connections, and 24 / 7 constancy, labeling clusters with high uplink traffic, asymmetric traffic, and 24 / 7 operation as candidate anomaly clusters. The second is trend analysis: time series analysis of daily user traffic sequences is performed to identify trend labels such as stable, step-like increases, or sudden peaks, and to locate abrupt change points. The third is dispersion analysis, which calculates the variance, kurtosis, and single-user traffic information entropy of user traffic under the same OLT or splitter, identifying concentrated traffic distribution and flat curve characteristics. The fourth is frequency analysis, which defines abnormal days, statistically analyzes the percentage of abnormal days and event intervals, and determines the persistence of behavior.
[0039] Subsequently, a correlation analysis was performed to calculate the ratio of the total uplink traffic of each OLT port to the sum of its downlink abnormal user traffic. The lead-lag relationship between abnormal user traffic changes and OLT uplink packet loss rate and latency was analyzed to determine the degree of contribution of user traffic to node congestion.
[0040] Finally, the model predicts the development trend of violations, forecasting whether user uplink traffic will exceed limits in the next seven days at the individual level, and predicting when the total traffic of abnormal users within the same cluster will exceed the remaining bandwidth of the OLT, issuing early warnings for capacity expansion or control. The model outputs a list of abnormal users, a network node risk heatmap, and a trend report including the number of newly added abnormal users, the expected congestion time, and recommended measures.
[0041] In step 120, multi-source system data association is performed.
[0042] In this embodiment of the application, the systems that need to be connected are the line system, CBSS system, network management system and AsiaInfo system.
[0043] The line system is primarily responsible for resource and work order management on the user access side. The data it collects includes service number, order code, access method, service type, service center code and name, access unit name, OLT management IP, OLT access room name, uplink OLT port, primary splitter code and port, ONT device code and port, ONT master number, registration SN, and SVLAN information. This data is mainly used to determine the user's physical network location, installation path, and the associated optical line terminal and splitter resources.
[0044] The CBSS system is a customer and business support system for telecom operators. It collects user identifiers, user numbers, broadband accounts, customer names, customer types, account opening dates, package identifiers and names, service status, channel types, channel codes and names, developer codes and names, and billing amounts. This data is primarily used to identify the user's basic identity, package attributes, and development channels, helping to differentiate between residential and enterprise users.
[0045] The network management system is responsible for monitoring the real-time operating status of network devices, collecting data such as real-time uplink traffic in the data center, PON port traffic, number of user broadband interactions, and broadband account information. This data directly reflects the load status of network nodes and the activity level of users.
[0046] User authentication systems typically handle AAA authentication and address allocation, collecting data such as broadband account information, public IP address, IPv6 address, private IP address, NAT start and end ports, user online / offline times, uplink and downlink bandwidth and traffic, BRAS device IP address, and BRAS location. This data is used to track user online behavior, address translation, and traffic consumption details.
[0047] The data from the four systems are linked using broadband accounts as the primary key. Due to potential data delays, format differences, or missing data from each system, data cleaning and alignment are performed.
[0048] In step 130, multi-platform data integration and abnormal user identification are performed.
[0049] In this embodiment of the application, the broadband account is used as the primary key to integrate the effective data from the four platforms of the line system, CBSS system, network management system and user authentication system to generate a unified clustered user information table.
[0050] First, using the broadband account as the unique identifier, all fields related to that account across the four systems are horizontally concatenated. For cases where the same broadband account has multiple records in a single system (e.g., a record is generated for each online / offline session in the user authentication system), aggregation is required in chronological order to extract statistical features such as the first online time, last offline time, cumulative uplink traffic, cumulative downlink traffic, and average concurrent connections for the day. For issues like missing fields or inconsistent formats, the middleware system needs to establish mapping rules, such as matching the OLT management IP in the line system with the OLT device identifier in the network management system, ensuring that the names of the same physical device correspond across different systems. After data cleaning and aggregation, a clustered user information table is generated, with broadband accounts as rows and key fields from each system as columns. This table includes not only user business attributes but also network attributes and traffic behavior attributes.
[0051] Next, we will analyze the clustered user information table. First, we will analyze whether users belong to the same uplink BRAS device. If multiple abnormal users' broadband accounts are all bound to the same BRAS device, it indicates that the abnormal traffic of these users may collectively affect the uplink of that BRAS, leading to outbound congestion. Second, we will determine whether multiple users belong to the same OLT. When some users generate continuous high traffic due to services such as PCDN, it will directly affect the network experience of other users under that OLT. Third, we will determine whether the users are connected to the same optical splitter device. An optical splitter is a passive optical distribution device between the OLT and the user's optical modem. One optical splitter typically covers multiple households in the same building or unit. If multiple abnormal users are connected to the same optical splitter, it indicates that the users' physical locations are highly concentrated, and it is highly likely that multiple broadband lines installed at the same address by the same agent or operator are used to build a PCDN cluster.
[0052] Subsequently, the regularity data of the optical modem's traffic during different time periods is read. Specifically, the uplink traffic distribution of each user's optical modem is collected through the network management system or optical modem probes over a 24-hour period, forming a traffic curve with hourly granularity. For normal home broadband users, the traffic curve usually shows a bimodal or multi-peak characteristic, with peak periods from 7 PM to 11 PM and extremely low traffic from early morning to dawn. For PCDN users, due to the equipment operating 24 / 7, their traffic curve often shows a "flat" characteristic, meaning that there are no obvious troughs in traffic throughout the day, and it may even remain at a relatively high level in the early morning.
[0053] By calculating the traffic entropy or peak-to-valley ratio for each user over a given period, the regularity of their traffic patterns can be quantified. User authentication systems or routing devices can record the geographic region of the destination IP address accessed by a user, thus distinguishing whether the user's traffic flows to their local or external region, and to their own or another operator. The traffic of normal residential users is mainly concentrated in the content delivery network nodes within their local region or in their own operator's resource pool, while the traffic of PCDN users, due to their participation in nationwide or even cross-network content distribution, often has a high proportion of out-of-region and cross-operator traffic. The proportion of out-of-region uplink traffic and cross-operator traffic for each user is extracted as key characteristics.
[0054] Based on the above clustered user information table, traffic time period patterns, and traffic characteristics inside and outside the region, we proceed to the final judgment stage.
[0055] The core logic of the judgment is as follows: Under the same OLT, the same splitter, or the same BRAS device, if multiple users simultaneously meet the following conditions, these users are marked as abnormal users under the same cluster device: First, their uplink traffic is significantly higher than the average of normal users under the same network node, for example, more than three times the average; Second, the traffic pattern shows a flat curve with low entropy and a high proportion of nighttime traffic; Third, the proportion of uplink traffic from outside the region or across operators exceeds 50%; Fourth, the installation time among users is highly concentrated, such as multiple households in the same building being completed on a single day, or multiple households being installed by the same engineer within one hour. The system uses a weighted scoring model to assign weights to the above conditions and calculate the abnormal score for each user. When the number of users with abnormal scores under the same cluster reaches a threshold and the abnormal scores of these users are all higher than a preset threshold, the system determines that the cluster is an abnormal user cluster and outputs a list of all broadband accounts in the cluster, as well as information on the OLT or BRAS devices affected by the cluster.
[0056] Through the above multi-dimensional data integration and correlation analysis, it is possible to accurately distinguish abnormal user groups under the same physical location or the same network node, avoiding misjudging ordinary high-traffic users scattered under different OLTs as non-compliant users. At the same time, it effectively locates commercial operators who centrally deploy PCDN equipment through clustering. This judgment provides accurate input for subsequent on-site verification, traffic control, and compliance labeling.
[0057] In step 140, anomaly monitoring rules and on-site verification are set.
[0058] Establish anomaly monitoring rules based on access network physical resources, and verify the authenticity of abnormal users identified by the system through on-site investigation, thereby eliminating fake users and ensuring the authenticity of broadband users.
[0059] First, the anomaly monitoring rules are based on PON port data. A PON port is the physical port connecting to the optical splitter under the OLT. Each PON port connects to multiple users' optical modems through one or more splitters. The PON port information, splitter code, splitter port, and installation address corresponding to each broadband account are obtained through the numbering system. Based on this data, the authenticity of the user address can be verified, i.e., it can be determined whether there is batch installation activity at the same physical location. Specifically, for scenarios involving concentrated installation of optical splitters, two monitoring thresholds are defined; meeting either condition determines the user as an abnormal broadband user.
[0060] For example, the first threshold is a single-day broadband installation count of 5 or more households in the same building. Here, "same building" refers to users with the same building number in their installation address, such as Building 12 in a residential complex. The system extracts the installation addresses of newly installed broadband users daily from the network system and groups them by building. If a building has 5 or more newly installed broadband households in a single day, the system marks all users in that building who installed broadband that day as abnormal broadband users. This rule is primarily used to identify agents or operators who centrally subscribe to multiple broadband lines in the same residential building to build a PCDN cluster. The probability of a normal household user subscribing to more than 5 broadband lines in the same building in a single day is extremely low; therefore, this threshold has high specificity for identification.
[0061] For example, the second threshold is when the same engineer completes broadband installations for more than two households at the same address within one hour. Each engineer has a unique code in the system, and their work order records include the completion time and installation address. The system counts each engineer's work orders hourly. If an engineer completes broadband installations for more than two households at the same installation address within one hour, these broadband accounts are marked as abnormal broadband users. This rule is used to identify the behavior of engineers assisting agents or users in activating multiple broadband lines in a short period of time, such as installing multiple broadband lines in the same room simultaneously for PCDN equipment aggregation. Under normal circumstances, it is highly unlikely that the same household user would install more than two broadband lines in the same hour, so this threshold can effectively identify abnormal installation patterns.
[0062] The two threshold rules mentioned above are configured as scheduled tasks in the local middleware management system, which automatically scan newly completed broadband work orders daily. For broadband accounts that meet either condition, the system automatically adds them to the abnormal broadband user candidate list and records the reason for the abnormality.
[0063] Next, on-site investigations are conducted simultaneously on the captured abnormal user data. After the on-site investigations are completed, the validity of the abnormal user information table is determined based on the investigation results. Through the above closed-loop verification process, fraudulent users can be eliminated.
[0064] In step 150, abnormal traffic is monitored and handled in a tiered manner.
[0065] After completing the identification of abnormal users, on-site verification, and cleanup of fake users, the abnormal traffic behavior of real users is monitored in real time. Based on the degree of abnormality and user type, graded handling measures are taken to reasonably control the use of network resources while ensuring the network experience of ordinary home users and avoid group network lag under the same OLT device due to the illegal high traffic behavior of individual users.
[0066] Once abnormal traffic is detected, deep packet inspection is used to analyze the user's traffic, including protocol type, destination IP address, and number of connections, to further confirm whether the anomaly is caused by PCDN services. Simultaneously, the system checks whether the user has already been flagged as a clustered fraudulent user or a user with abnormal batch installations in step 140, thus distinguishing between an ordinary user's accidental over-limit behavior and the illegal actions of a professional operator.
[0067] For users confirmed to have abnormal traffic or be fraudulent users, a combination of SMS alerts and compliance control procedures will be implemented. For fraudulent users identified in the cluster, direct disconnection will be enforced. The disconnection operation forcibly terminates the user's session via the BRAS device, preventing their optical modem from dialing up to the internet and prohibiting them from redialing for a period of time. Simultaneously, the user's broadband account will be blacklisted, and the line system will be notified to reclaim the PON port resources and splitter ports they occupy, preventing the address or engineer from opening new broadband accounts. Disconnection is a relatively strong control measure and is only applicable to fraudulent users confirmed through on-site inspection to avoid inadvertently affecting legitimate home users.
[0068] In step 160, protection is provided for compliant high-traffic users.
[0069] To avoid inadvertently affecting users with legitimate high-traffic needs, such as businesses backing up data, families downloading HD movies, or remotely transferring large files, a dedicated protection mechanism has been designed. First, compliant high-traffic users are specially tagged based on user-reported activity or automatic service type identification. This tag is mutually exclusive with the labeling of non-compliant users. Then, the system monitors these users' internet activity in real time, including their uplink bandwidth usage, number of connections, and the congestion level of their optical line terminal (OLT), such as uplink port utilization, packet loss rate, and latency. If the OLT is found to be persistently congested, and this congestion is clearly time-dependent on the traffic changes of compliant users, the system automatically generates a capacity expansion work order, checks for available ports on upstream equipment, and then directly increases bandwidth via software or combines multiple ports together for speed boost. If hardware adjustments are involved, a construction order is dispatched to engineers for on-site handling. After the expansion is completed, the high-traffic needs of compliant users are met, and other users under the same OLT no longer experience lag. Once the traffic of compliant users decreases, the bandwidth can be automatically reduced back to avoid waste. This mechanism protects legitimate users while avoiding the costs associated with blindly expanding capacity.
[0070] In step 170, the entire process is managed in a closed loop.
[0071] All records generated during the process from anomaly identification, on-site verification, traffic handling to compliance assurance are synchronized to the middleware system and archived in a unified format to form a complete file for each user. In this way, the entire process, from the initial anomaly detection to the final archiving and backtracking, forms a closed loop, with each step being traceable. This avoids misjudgment and abuse, and allows the system to continuously adapt to new PCDN behaviors, ensuring network fairness and user experience in the long term.
[0072] Figure 2 This is a flowchart illustrating a method for monitoring and supervising abnormal users in broadband services on an access network, as shown in an embodiment of the present invention. Figure 2 As shown, it includes the following steps: 210: Construct an abnormal user analysis model, which is used to analyze the correlation between network node traffic and abnormal user traffic.
[0073] 220: Collect data from at least one data source system in the network node, and extract the network location information, business attributes and traffic behavior data of users in the network node from the collected data based on the abnormal user analysis model to obtain a clustered user information table; 230: Spatial clustering is performed on the clustered user information table according to different physical device dimensions to obtain a clustering candidate set; 240: Combining traffic time period characteristics and flow direction characteristics, and based on the correlation degree output by the model, determine whether the cluster candidate set is a suspected abnormal user cluster; 250: Based on abnormal monitoring rules for installation behavior, filter out abnormal user clusters in network nodes from suspected abnormal user clusters.
[0074] Step 230 includes: The users in the clustered user information table are grouped according to their respective uplink broadband remote access servers to generate a first-level clustering candidate set; The users in the clustered user information table are grouped according to their respective optical line terminals to generate a second-level clustering candidate set; The users in the clustered user information table are grouped according to their respective first-level spectrometers to generate a third-level clustering candidate set; At least one of the first-level clustering candidate set, the second-level clustering candidate set, and the third-level clustering candidate set is used as the clustering candidate set.
[0075] Step 240 includes: For each user in the clustered candidate set, extract their uplink traffic distribution within a preset time period to calculate the traffic time period entropy value and peak-to-valley ratio, and extract the cross-regional uplink traffic ratio and cross-carrier uplink traffic ratio. When the traffic period entropy value is lower than the first threshold, the peak-to-valley ratio is lower than the second threshold, the cross-regional uplink traffic proportion is higher than the third threshold, and the cross-carrier uplink traffic proportion is higher than the fourth threshold, the user is marked as a candidate abnormal user based on the correlation degree output by the abnormal user analysis model. The number or proportion of candidate abnormal users in the cluster candidate set is counted. When the number or proportion exceeds the fifth threshold, the cluster candidate set is determined to be a suspected abnormal user cluster.
[0076] Step 250 includes: Obtain broadband completion work order information of users in the suspected abnormal user cluster. The work order information includes at least the installation address, completion time, and engineer identifier. When the number of completed broadband installations in the same building within a preset time window exceeds the first threshold, or when the number of completed broadband installations at the same installation address by the same engineer within a preset time window exceeds the second threshold, the corresponding user will be marked as a candidate for abnormal installation. The candidate users with installation abnormalities are verified on-site. Users who pass the verification are retained as the final confirmed abnormal user cluster, while users who are found to be fraudulent are removed.
[0077] Step 220 includes: The network location information is obtained by collecting the user's service number, installation address, completion time, home optical line terminal management IP, uplink optical line terminal port, primary splitter code and port, and optical modem device code and port from the line system. The user's broadband account, package type, account opening time, service status, development channel, and development engineer identifier are collected from the customer business support system as the business attributes. The network management system collects real-time uplink traffic in the computer room, passive optical network port traffic, number of broadband interactions and broadband accounts of users. The user authentication system collects users' public IP address, network address translation port range, online and offline time, uplink and downlink bandwidth and traffic, broadband remote access server device IP and location as the traffic behavior data. Using broadband accounts as the primary key, the data collected from the aforementioned systems are correlated, cleaned, and aggregated to generate a clustered user information table with broadband accounts as rows and the aforementioned network location information, service attributes, and traffic behavior data as columns.
[0078] It also includes step 260, which includes: Traffic tiering measures will be implemented for users in the finally confirmed abnormal user cluster; The traffic tiered handling includes: setting tiered traffic limits based on user package type, historical traffic habits, and network capacity; monitoring user traffic at preset intervals; sending reminder SMS messages when user traffic exceeds the first-level limit; implementing uplink bandwidth limiting when traffic exceeds the second-level limit; and directly blocking the network for users confirmed as fraudulent through on-site investigation.
[0079] Step 210 includes: Based on historical user traffic data, clustering, trend, dispersion, and frequency analysis are used to identify candidate abnormal users; By analyzing the time-series correlation between historical user traffic data and network node congestion indicators, the correlation between network node traffic and the candidate abnormal user traffic is determined.
[0080] Next, based on the methods in the above embodiments, an apparatus for monitoring and supervising abnormal users of broadband services in access networks provided by the present invention will be introduced.
[0081] Figure 3 This is a schematic diagram of an apparatus 310 for monitoring and supervising abnormal users in broadband services of an access network, which can be used to implement the method of the present invention. (See attached diagram) Figure 3 As shown, the device 310 for monitoring and supervising abnormal users of broadband services in the access network includes: The first processing module is used to construct an abnormal user analysis model, which is used to analyze the correlation between network node traffic and abnormal user traffic. The second processing module is used to collect data from at least one data source system in the network node, and extract the network location information, business attributes and traffic behavior data of the users in the network node from the collected data according to the abnormal user analysis model, so as to obtain a clustered user information table. The third processing module is used to perform spatial clustering on the clustered user information table according to different physical device dimensions to obtain a clustering candidate set; combining the traffic time period characteristics and flow direction characteristics, and based on the correlation degree output by the model, it determines whether the clustering candidate set is a suspected abnormal user cluster. The fourth processing module is used to filter out abnormal user clusters in the network nodes from the suspected abnormal user clusters based on abnormal monitoring rules of installation behavior.
[0082] In one possible implementation, the third processing module is used to group the users in the clustered user information table according to their respective uplink broadband remote access servers to generate a first-level clustering candidate set. The users in the clustered user information table are grouped according to their respective optical line terminals to generate a second-level clustering candidate set; The users in the clustered user information table are grouped according to their respective first-level spectrometers to generate a third-level clustering candidate set; At least one of the first-level clustering candidate set, the second-level clustering candidate set, and the third-level clustering candidate set is used as the clustering candidate set.
[0083] In one possible implementation, the third processing module is used to extract the uplink traffic distribution of each user in the clustering candidate set within a preset time period to calculate the traffic time period entropy value and peak-to-valley ratio, and to extract the cross-regional uplink traffic ratio and the cross-carrier uplink traffic ratio. When the traffic period entropy value is lower than the first threshold, the peak-to-valley ratio is lower than the second threshold, the cross-regional uplink traffic proportion is higher than the third threshold, and the cross-carrier uplink traffic proportion is higher than the fourth threshold, the user is marked as a candidate abnormal user based on the correlation degree output by the abnormal user analysis model. The number or proportion of candidate abnormal users in the cluster candidate set is counted. When the number or proportion exceeds the fifth threshold, the cluster candidate set is determined to be a suspected abnormal user cluster.
[0084] In one possible implementation, the fourth processing module is used to obtain broadband completion work order information of users in the suspected abnormal user cluster, and the work order information includes at least the installation address, completion time and engineer identifier. When the number of completed broadband installations in the same building within a preset time window exceeds the first threshold, or when the number of completed broadband installations at the same installation address by the same engineer within a preset time window exceeds the second threshold, the corresponding user will be marked as a candidate for abnormal installation. The candidate users with installation abnormalities are verified on-site. Users who pass the verification are retained as the final confirmed abnormal user cluster, while users who are found to be fraudulent are removed.
[0085] In one possible implementation, the second processing module is used to collect the user's service number, installation address, completion time, home optical line terminal management IP, uplink optical line terminal port, first-level splitter code and port, and optical modem device code and port from the line system as the network location information; The user's broadband account, package type, account opening time, service status, development channel, and development engineer identifier are collected from the customer business support system as the business attributes. The network management system collects real-time uplink traffic in the computer room, passive optical network port traffic, number of broadband interactions and broadband accounts of users. The user authentication system collects users' public IP address, network address translation port range, online and offline time, uplink and downlink bandwidth and traffic, broadband remote access server device IP and location as the traffic behavior data. Using broadband accounts as the primary key, the data collected from the aforementioned systems are correlated, cleaned, and aggregated to generate a clustered user information table with broadband accounts as rows and the aforementioned network location information, service attributes, and traffic behavior data as columns.
[0086] In one possible implementation, the fourth processing module is used to perform traffic tiered handling on users in the finally confirmed abnormal user cluster; The traffic tiered handling includes: setting tiered traffic limits based on user package type, historical traffic habits, and network capacity; monitoring user traffic at preset intervals; sending reminder SMS messages when user traffic exceeds the first-level limit; implementing uplink bandwidth limiting when traffic exceeds the second-level limit; and directly blocking the network for users confirmed as fraudulent through on-site investigation.
[0087] In one possible implementation, the first processing module is used to identify candidate abnormal users based on historical user traffic data, employing clustering, trend, dispersion, and frequency analysis. By analyzing the time-series correlation between historical user traffic data and network node congestion indicators, the correlation between network node traffic and the candidate abnormal user traffic is determined.
[0088] Those skilled in the art will readily recognize that, based on the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein, the present invention can be implemented in hardware or a combination of hardware and computer software. Whether a function is implemented in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of the present invention.
[0089] It should be noted that, Figure 3 The division of modules / units is illustrative and represents only one logical functional division; in actual implementation, other division methods are possible. For example, two or more functions can be integrated into a single data acquisition module. The integrated modules described above can be implemented either in hardware or as software functional modules.
[0090] An electronic device according to an embodiment of the present invention includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements any of the above-mentioned methods for monitoring and supervising abnormal users of broadband services in access networks. That is, an electronic device according to an embodiment of the present invention may include, but is not limited to: a processor and a memory; the memory is used to store the computer program; the processor is used to execute the method for monitoring and supervising abnormal users of broadband services in access networks as shown in any embodiment of the present invention by calling the computer program.
[0091] In one alternative embodiment, an electronic device is provided, such as Figure 4 As shown, Figure 4 The illustrated electronic device 400 includes a processor 401 and a memory 403. The processor 401 and the memory 403 are connected, for example, via a bus 402. Optionally, the electronic device 400 may further include a transceiver 404, which can be used for data interaction between the electronic device and other electronic devices, such as sending and / or receiving data. It should be noted that in practical applications, the transceiver 404 is not limited to one type, and the structure of the electronic device 400 does not constitute a limitation on the embodiments of the present invention.
[0092] Processor 401 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute the various exemplary logic blocks, modules, and circuits described in connection with this disclosure. Processor 401 may also be a combination that implements computational functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0093] Bus 402 may include a path for transmitting information between the aforementioned components. Bus 402 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. Bus 402 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 4 The bus 402 is represented by only one thick line, but this does not mean that there is only one bus or one type of bus.
[0094] The memory 403 may be a ROM (Read Only Memory) or other type of static storage device capable of storing static information and instructions, RAM (Random Access Memory) or other type of dynamic storage device capable of storing information and instructions, or an EEPROM (Electrically Erasable Programmable Read Only Memory), CD-ROM (Compact Disc Read Only Memory) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto.
[0095] The memory 403 stores application code (computer program) for executing the present invention, and its execution is controlled by the processor 401. The processor 401 executes the application code stored in the memory 403 to implement the content shown in the foregoing method embodiments.
[0096] Among them, electronic devices can also be terminal devices, which can be any device that can install applications, including at least one of smartphones, tablets, laptops, desktop computers, smart speakers, smartwatches, smart TVs, and smart in-vehicle devices.
[0097] It should be noted that, Figure 4 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of use of the embodiments of the present invention.
[0098] An embodiment of the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements any of the above-mentioned methods for monitoring and supervising abnormal users of broadband services in access networks.
[0099] Alternatively, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), magnetic tape, a floppy disk, and an optical data storage device, etc.
[0100] In an exemplary embodiment, a computer program product or computer program is also provided, which includes computer instructions stored in a computer-readable storage medium. The processor of an electronic device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the electronic device to perform the aforementioned method for monitoring and supervising abnormal users of broadband services in an access network.
[0101] Computer program code for performing the operations of this invention can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0102] It should be understood that the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of methods and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0103] The computer-readable storage medium provided in this invention can be, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EEPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this invention, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0104] The aforementioned computer-readable storage medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to perform the method for monitoring and supervising abnormal users of broadband services in the access network as described in the above embodiments.
[0105] The above description is merely a preferred embodiment of the present invention and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of disclosure in this invention is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-disclosed concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this invention.
[0106] It should be noted that the terms "first," "second," etc., used in the specification and claims of this invention are used to distinguish similar objects and represent a limitation on a specific order or sequence. Where appropriate, the order of use for similar objects can be interchanged so that the embodiments of the invention described herein can be implemented in an order other than that shown or described.
[0107] Those skilled in the art will recognize that this invention can be implemented as a system, method, or computer program product. Therefore, this invention can be specifically implemented in the following forms: it can be entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software, generally referred to herein as a "circuit," "module," or "system." Furthermore, in some embodiments, this invention can also be implemented as a computer program product contained in one or more computer-readable media, which includes computer-readable program code.
[0108] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.
Claims
1. A method for monitoring and supervising abnormal users in broadband access network services, characterized in that, include: An abnormal user analysis model is constructed, which is used to analyze the correlation between network node traffic and abnormal user traffic; Collect data from at least one data source system in the network node, and extract the network location information, business attributes and traffic behavior data of users in the network node from the collected data based on the abnormal user analysis model to obtain a clustered user information table; Spatial clustering is performed on the clustered user information table according to different physical device dimensions to obtain a clustering candidate set; By combining traffic time period characteristics and flow direction characteristics, and based on the correlation degree output by the model, it is determined whether the cluster candidate set is a suspected abnormal user cluster; Based on the abnormal monitoring rules of installation behavior, abnormal user clusters in the network nodes are filtered out from the suspected abnormal user clusters.
2. The method according to claim 1, characterized in that, The step of spatially clustering the clustered user information table according to different physical device dimensions to obtain a clustering candidate set includes: The users in the clustered user information table are grouped according to their respective uplink broadband remote access servers to generate a first-level clustering candidate set; The users in the clustered user information table are grouped according to their respective optical line terminals to generate a second-level clustering candidate set; The users in the clustered user information table are grouped according to their respective first-level spectrometers to generate a third-level clustering candidate set; At least one of the first-level clustering candidate set, the second-level clustering candidate set, and the third-level clustering candidate set is used as the clustering candidate set.
3. The method according to claim 1, characterized in that, The step of combining traffic time-period characteristics and flow direction characteristics, and determining whether the cluster candidate set is a suspected abnormal user cluster based on the correlation degree output by the model, includes: For each user in the clustered candidate set, extract their uplink traffic distribution within a preset time period to calculate the traffic time period entropy value and peak-to-valley ratio, and extract the cross-regional uplink traffic ratio and cross-carrier uplink traffic ratio. When at least one of the following conditions is met: the entropy value of the traffic period is lower than the entropy value threshold, the peak-to-valley ratio is lower than the peak-to-valley ratio threshold, the cross-regional uplink traffic ratio is higher than the first ratio threshold, and / or the cross-carrier uplink traffic ratio is higher than the second ratio threshold, and the correlation degree output by the abnormal user analysis model is greater than the preset correlation degree threshold, the user is marked as a candidate abnormal user. The number of candidate abnormal users in the cluster candidate set is counted. When the number of candidate abnormal users exceeds the abnormal user count threshold, the cluster candidate set is determined to be a suspected abnormal user cluster.
4. The method according to claim 1, characterized in that, The abnormal monitoring rules based on installation behavior filter out abnormal user clusters in the network nodes from the suspected abnormal user clusters, including: Obtain broadband completion work order information for users in the suspected abnormal user cluster. The work order information includes at least the installation address, completion time, and engineer identifier. When the number of completed broadband installations in the same building within a preset time window exceeds the first threshold, or when the number of completed broadband installations at the same installation address by the same engineer within a preset time window exceeds the second threshold, the corresponding user will be marked as a candidate for abnormal installation. The candidate users with installation abnormalities are verified on-site. Users who pass the verification are retained as the final confirmed abnormal user cluster, while users who are found to be fraudulent are removed.
5. The method according to claim 1, characterized in that, The data is collected from at least one data source system in the network node. Based on the abnormal user analysis model, the network location information, service attributes, and traffic behavior data of users in the network node are extracted from the collected data to obtain a clustered user information table, including: The network location information is obtained by collecting the user's service number, installation address, completion time, home optical line terminal management IP, uplink optical line terminal port, primary splitter code and port, and optical modem device code and port from the line system. The user's broadband account, package type, account opening time, service status, development channel, and development engineer identifier are collected from the customer business support system as the business attributes. The network management system collects real-time uplink traffic in the computer room, passive optical network port traffic, number of broadband interactions and broadband accounts of users. The user authentication system collects users' public IP address, network address translation port range, online and offline time, uplink and downlink bandwidth and traffic, broadband remote access server device IP and location as the traffic behavior data. Using broadband account as the primary key, the collected data is correlated, cleaned, and aggregated to generate a clustered user information table with broadband account as the row and network location information, service attributes, and traffic behavior data as the column.
6. The method according to claim 1, characterized in that, Also includes: Traffic tiering measures will be implemented for users in the finally confirmed abnormal user cluster; The traffic tiered handling includes: setting tiered traffic limits based on user package type, historical traffic habits, and network capacity; monitoring user traffic at preset intervals; sending reminder SMS messages when user traffic exceeds the first-level limit; implementing uplink bandwidth limiting when traffic exceeds the second-level limit; and directly blocking the network for users confirmed as fraudulent through on-site investigation.
7. The method according to claim 1, characterized in that, The construction of the abnormal user analysis model, which is used to analyze the correlation between network node traffic and abnormal user traffic, includes: Based on historical user traffic data, clustering, trend, dispersion, and frequency analysis are used to identify candidate abnormal users; By analyzing the time-series correlation between historical user traffic data and network node congestion indicators, the correlation between network node traffic and the candidate abnormal user traffic is determined.
8. A device for monitoring and supervising abnormal users in broadband services of an access network, characterized in that, include: The first processing module is used to construct an abnormal user analysis model, which is used to analyze the correlation between network node traffic and abnormal user traffic. The second processing module is used to collect data from at least one data source system in the network node, and extract the network location information, business attributes and traffic behavior data of the users in the network node from the collected data according to the abnormal user analysis model, so as to obtain a clustered user information table. The third processing module is used to perform spatial clustering on the clustered user information table according to different physical device dimensions to obtain a cluster candidate set; and to determine whether the cluster candidate set is a suspected abnormal user cluster by combining traffic time period characteristics and flow direction characteristics and based on the correlation degree output by the model. The fourth processing module is used to filter out abnormal user clusters in the network nodes from the suspected abnormal user clusters based on abnormal monitoring rules of installation behavior.
9. An electronic device, characterized in that, include: processor; Memory used to store the processor's executable instructions; The processor is configured to execute the instructions to implement the method for monitoring and supervising abnormal users of broadband services in access networks as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores at least one computer program, which is loaded and executed by a processor to enable the computer to implement the method for monitoring and supervising abnormal users of broadband services in access networks as described in any one of claims 1 to 7.