Method for extracting traffic characteristics, method for quality of service scheduling, electronic device and computer-readable storage medium

By extracting and analyzing IP data stream characteristics, the method addresses the lack of QoS mechanisms in access networks, improving network intelligence and user experience through effective QoS scheduling.

JP7793044B2Active Publication Date: 2025-12-26ZTE CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024512112
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-08-23
Filing Date
2022-08-19
Publication Date
2025-12-26
Estimated Expiration
2042-08-19

Smart Images

  • Figure 0007793044000008
    Figure 0007793044000008
  • Figure 0007793044000009
    Figure 0007793044000009
  • Figure 0007793044000010
    Figure 0007793044000010
Patent Text Reader

Abstract

The present application provides a method for extracting traffic characteristics, the method including: extracting a traffic characteristic field of an Internet Interconnection Protocol (IP) data stream; and identifying traffic characteristics of the IP data stream based on the traffic characteristic field, the traffic characteristics characterizing a Quality of Service (QoS) requirement of the IP data stream. The present application further provides a quality of service scheduling method, an electronic device, and a computer-readable storage medium.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] [CROSS-REFERENCE TO RELATED APPLICATIONS] This application claims priority from Chinese Patent Application No. 202110968463.7, filed on August 23, 2021, the entire contents of which are incorporated herein by reference. [Technical field] The present application relates to the field of communications technology, and in particular to a method for extracting traffic characteristics, a quality of service scheduling method, an electronic device, and a computer-readable storage medium. [Background technology]

[0002] Identifying the traffic characteristics of an access network and scheduling Quality of Service (QoS) based on the traffic characteristics is of great significance for ensuring the quality of network traffic and improving user experience.

[0003] However, due to limitations in network architecture, some access networks lack mechanisms for identifying traffic characteristics and ensuring accurate traffic quality, which may not meet the needs of the advancement of network intelligence. Summary of the Invention

[0004] In a first aspect, embodiments of the present invention include extracting traffic characteristic fields from an Internet Interconnection Protocol (IP) data stream; and identifying traffic characteristics of the IP data stream based on the traffic characteristic field, the traffic characteristics characterizing a quality of service (QoS) requirement of the IP data stream.

[0005] In a second aspect, the present embodiment comprises: A Quality of Service (QoS) scheduling method is provided, which performs QoS scheduling based on traffic characteristics of a data stream, the traffic characteristics being extracted using a traffic characteristic extraction method according to an embodiment of the present application described in the first aspect.

[0006] In a third aspect, the present embodiment comprises: at least one processor; a memory storing at least one computer program, the at least one computer program being configured to cause the at least one processor to implement at least one of a traffic feature extraction method according to an embodiment of the present application as set forth in the first aspect or a QoS scheduling method according to an embodiment of the present application as set forth in the second aspect; and at least one I / O interface connected between the processor and the memory and configured to enable information interaction between the processor and the memory.

[0007] In a fourth aspect, the present embodiment provides a computer-readable storage medium having a computer program stored thereon, the computer program, when executed by a processor, realizing at least one of the traffic feature extraction method according to the present embodiment described in the first aspect or the QoS scheduling method according to the present embodiment described in the second aspect. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 1 is a flowchart of a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 2] FIG. 2 is a flowchart showing some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 3] FIG. 3 is a flowchart showing some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 4]FIG. 4 is a flowchart of some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 5] FIG. 5 is a flowchart of some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 6] FIG. 6 is a flowchart showing some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 7] FIG. 7 is a flowchart showing some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 8] FIG. 8 is a flowchart showing some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 9] FIG. 9 is a flowchart showing some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 10] FIG. 10 is a flowchart of some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 11] FIG. 11 is a flowchart showing some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 12] FIG. 12 is a flowchart showing some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 13] FIG. 13 is a flowchart showing some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 14] FIG. 14 is a flowchart of some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 15] FIG. 15 is a flowchart showing some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 16] FIG. 16 is a flowchart showing some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 17]FIG. 17 is a flowchart showing some steps in a method for extracting traffic characteristics in an embodiment of the present invention. [Figure 18] FIG. 18 is a flowchart of a quality of service scheduling method in an embodiment of the present invention. [Figure 19] FIG. 19 is a block diagram of the electronic device according to the embodiment of the present invention. [Figure 20] FIG. 20 is a block diagram of a computer-readable storage medium according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0009] In order to make the technical solutions of the present application more understandable to those skilled in the art, the traffic feature extraction method, service quality scheduling method, electronic device, and computer-readable storage medium provided in the present application are described in detail below in combination with the accompanying drawings.

[0010]

[0023] Exemplary embodiments will now be described more fully with reference to the drawings, although the described exemplary embodiments may be embodied in different forms and the present application should not be construed as being limited to the embodiments set forth herein. The purpose of providing these examples is to make the present application more thorough and complete, and to fully convey the scope of the present application to those skilled in the art.

[0011] Where not inconsistent, the embodiments and features of the embodiments of the present application may be combined with each other.

[0012] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.

[0013] The terms used herein are used only to describe particular embodiments and are not intended to limit the present application. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly dictates otherwise. When used herein, the terms "comprising" and / or "consisting of" will be understood to refer to the presence of certain features, wholes, steps, operations, parts, and / or components, but not to exclude the presence or possible addition of one or more other features, wholes, steps, operations, parts, components, and / or groups thereof.

[0014] Unless otherwise specified, the meanings of all terms (including technical and scientific terms) used herein are the same as those commonly understood by those skilled in the art. It will also be understood that terms defined in common dictionaries, unless expressly so limited herein, will be interpreted as having a meaning consistent with their meaning in the context of the relevant art and this application, and will not be interpreted as having an ideal or excessively formal meaning.

[0015] In a first aspect, referring to FIG. 1, the present embodiment provides a method for extracting traffic characteristics, including steps S100 and S200.

[0016] S100 is a step of extracting traffic characteristic fields of an Internet Protocol (IP) data stream.

[0017] S200 is a step of identifying traffic characteristics of the IP data stream based on the traffic characteristic field, the traffic characteristics characterizing a quality of service (QoS) requirement of the IP data stream.

[0018] In the traffic feature extraction method provided by the embodiments of the present application, the IP data stream may be an IP data stream of periodic data traffic or an IP data stream of aperiodic data traffic, although the present application does not particularly limit this. The data traffic may be any of video traffic, large-bandwidth traffic, large-bandwidth low-latency traffic, low-latency high-reliability traffic, etc., although the present application does not particularly limit this.

[0019] In the traffic feature extraction method provided in the present embodiment, the traffic features of the IP data stream identified in step S200 can be used to characterize the traffic features of the data traffic corresponding to the IP data stream, and the QoS requirements required for the data traffic can be characterized. Therefore, QoS scheduling can be performed based on the traffic features of the IP data stream identified in step S200, and the quality of the data traffic can be guaranteed.

[0020] In the traffic feature extraction method provided by the embodiment of the present application, the traffic feature field is identified based on the traffic feature. The traffic feature field may be a field attached to the IP data stream itself, or may be calculated based on a field attached to the IP data stream. The present application does not particularly limit this.

[0021] In the traffic feature extraction method provided by the embodiments of the present application, the traffic feature field corresponding to cyclic data traffic and the traffic feature field corresponding to aperiodic data traffic may be the same or different, and the present application does not particularly limit this. In some embodiments, cyclic data traffic and aperiodic data traffic may be distinguished from each other, and then the corresponding traffic feature field may be extracted based on the distinguishing result in step S100.

[0022] The traffic feature extraction method provided in the embodiments of the present application analyzes an IP data stream, extracts traffic feature fields, and then identifies traffic features based on the traffic feature fields. The traffic features can characterize the characteristics of the data traffic corresponding to the IP data stream and the service quality requirements of the data traffic, which can provide basis and support for network QoS scheduling and effectively improve the user's QoS experience, thereby realizing intelligent wireless networks centered on user equipment and traffic.

[0023] In some embodiments, for aperiodic data traffic, a data block characteristic is extracted as a traffic characteristic of the IP data stream of the aperiodic data traffic, where the data block consists of consecutive non-zero messages or packets.

[0024] Correspondingly, in some embodiments, referring to FIG. 2, step S200 includes steps S210 and S220.

[0025] S210 is a step of identifying a data block characteristic of at least one data block in the IP data stream based on the traffic characteristic field.

[0026] S220 is a step of calculating a data block feature statistic based on the data block feature of each of the data blocks, and taking the data block feature statistic as the traffic feature of the IP data stream.

[0027] The present embodiment does not particularly limit the data block characteristics of a data block. For example, for aperiodic traffic such as video traffic, large-bandwidth traffic, large-bandwidth low-latency traffic, and low-latency high-reliability traffic, the arrival delay and / or data block size of the data block are used as the data block characteristics. In the traffic characteristic extraction method provided by the present embodiment, each data block corresponds to one request (GET) message, the arrival delay of the data block is the delay between the arrival time of the first packet (start packet) of the data block and the arrival time of the GET message, and the block size is the sum of the sizes of all packets in the data block.

[0028] In the traffic feature extraction method provided by the embodiments of the present application, in some embodiments, a content-length field is attached to the IP data stream, and the value of the content-length field indicates the size of the data block, and the size of the data block can be determined by extracting the content-length field attached to the IP data stream; in some embodiments, no content-length field is attached to the IP data stream, and the size of the data block can be determined by extracting the size information of each packet of the data block.

[0029] Correspondingly, in some embodiments, referring to FIG. 3, the data block characteristics include a data block size and an arrival delay of the data block, and step S100 includes steps S110 to S130.

[0030] S110 is a step of extracting the timestamp of the request (GET) message and the timestamp of the start packet of the data block.

[0031] S120 is a step of extracting a content length field if the data block includes an HTTP / 1.1 field or an HTTP / 1.0 field, where the content length field characterizes a data block size of the data block.

[0032] S130 extracts size information of all packets of the data block when the data block does not include an HTTP / 1.1 field and an HTTP / 1.0 field.

[0033] In step S110, the timestamp of the GET message and the timestamp of the start packet of the data block are identified, and the arrival delay of the data block can be obtained by subtracting the two timestamps.

[0034] In addition, in an IP data stream, the content length field corresponds to the HTTP / 1.1 field or HTTP / 1.0 field; that is, if an HTTP / 1.1 field or HTTP / 1.0 field is attached to an IP data stream, the content length field is also attached. On the other hand, the format of the HTTP / 1.1 field or HTTP / 1.0 field is fixed, and it is located at the beginning of the payload of the Transmission Control Protocol (TCP), making it easier to identify than the content length field. In step S120, the data block size can be determined by extracting the content length field, and in step S130, the size information of all packets in the data block is extracted and accumulated to obtain the data block size.

[0035] In some embodiments, it is first necessary to identify the GET message and the starting packet of the data block. In some embodiments, the GET message is identified by the GET field. The data block corresponding to the GET message follows the GET message, and then the starting packet of the data block is identified.

[0036] The present application does not particularly limit how the start packet of the data block is identified after identifying the GET message. In some embodiments, the start packet of the data block is identified based on the correspondence between the SEQ field value and LEN field value in the GET message and the ACK field value in the packet.

[0037] In some embodiments, referring to FIG. 4, before extracting the timestamp of the request (GET) message and the timestamp of the starting packet of the data block (ie, step S110), step S100 further includes steps S141 to S143.

[0038] S141 is a step of identifying the GET message based on the GET field. S142 is a step of extracting the SEQ field value and LEN field value from the GET message.

[0039] S143 is a step of identifying the first packet after the GET message, whose ACK field value is equal to the sum of the SEQ field value and the LEN field value, as the start packet.

[0040] Note that all packets whose ACK field value after a GET message is equal to the sum of the SEQ field value and the LEN field value are packets of the data block corresponding to that GET message. Therefore, after obtaining the sum of the SEQ field value and the LEN field value, all packets of the data block can be identified by the ACK field, and the size of each packet can be obtained by accumulating them.

[0041] In some embodiments, the start and end packets (last packets) of a data block are identified based on packet length.

[0042] Correspondingly, in some embodiments, referring to FIG. 5, step S100 further includes steps S151 and S152 before extracting the timestamp of the request (GET) message and the timestamp of the starting packet of the data block (i.e., step S110).

[0043] S151 is a step of identifying the GET message based on the GET field. S152 is a step of identifying the first packet after the GET message whose length is greater than a preset length as the start packet.

[0044] In some embodiments, the end packet of the data block may be further identified, for example, by identifying a packet whose length is less than a second preset length and greater than a third preset length as the end packet. The sizes of all packets between the start packet and the end packet are accumulated to obtain the data block size.

[0045] In some embodiments, referring to FIG. 6, the data block feature statistics include data block size statistics and arrival delay statistics, and step S220 includes steps S221 and S222.

[0046] S221 is a step of generating at least one traffic feature table based on the data block size and arrival delay of the at least one data block, wherein each of the data blocks corresponds to one traffic feature table entry in the traffic feature table.

[0047] S222 is a step in which, when a predetermined statistical condition is met, the average value of the data block size in the traffic characteristics table is calculated to obtain the data block size statistical value, and the average value of the arrival delay in the traffic characteristics table is calculated to obtain the arrival delay statistical value.

[0048] In some embodiments, referring to FIG. 7, step S220 further includes step S223.

[0049] S223 is a step of determining the number of traffic feature table entries in the traffic feature table, and indicating that the predetermined statistical condition is met when the number of traffic feature table entries in the traffic feature table reaches a predetermined quantity threshold.

[0050] In some embodiments, the preset quantity threshold is the capacity of the traffic feature table. The present application does not particularly limit the preset quantity threshold. For example, the preset quantity threshold is 10,000.

[0051] In some embodiments, referring to FIG. 8, step S220 further includes step S224.

[0052] S224 is a step of starting a timer, and indicating that the preset statistical condition is met when the timer reaches a preset time threshold.

[0053] The traffic feature extraction method provided in the present embodiment can also be used to extract traffic features of IP data streams with periodic traffic.

[0054] Correspondingly, in some embodiments, referring to FIG. 9, step S200 includes steps S230 to S250.

[0055] S230 is a step of identifying the traffic type of the IP data stream based on the traffic characteristic field.

[0056] S240 is a step of calculating data block statistical characteristics of data blocks in the IP data stream based on the traffic type of the IP data stream.

[0057] S250 is a step of identifying traffic characteristics of the IP data stream based on the data block statistical characteristics.

[0058] In some embodiments, referring to FIG. 10, step S230 includes steps S231 and S232.

[0059] S231 is a step of calculating message statistical characteristics of the message based on the traffic characteristic field.

[0060] S232 is a step of identifying a traffic type of the IP data stream based on the message statistical characteristics.

[0061] In some embodiments, referring to FIG. 11, the traffic characteristics field includes message information of messages in the IP data stream, step S231 includes step S2311 and step S2312, and step S232 includes step S2321.

[0062] S2311 is a step of generating a message information table based on message information of at least one message.

[0063] S2312 is a step of calculating an expected value of the message size in the message information table based on the message size information of each message in the message information table, and obtaining the message statistical characteristics.

[0064] S2321 is a step of comparing the message statistical characteristic with a message size threshold, and if the message statistical characteristic exceeds the message size threshold, determining that the traffic type of the IP data stream is one of a first type of traffic, a second type of traffic, and a first aperiodic traffic, and if the message statistical characteristic does not exceed the message size threshold, determining that the traffic type of the IP data stream is one of a third type of traffic, a fourth type of traffic, and a second aperiodic traffic.

[0065] In addition, in the traffic characteristic extraction method provided in the embodiment of the present application, the first type of traffic is large-bandwidth traffic and has characteristics of multiple block sizes; the second type of traffic is large-bandwidth low-latency traffic and has characteristics of multiple data block intervals; the third type of traffic is upstream low-latency high-reliability traffic and has characteristics of messages with low periodicity; the fourth type of traffic is downstream low-latency high-reliability traffic and has characteristics of messages with low periodicity; and the first and second aperiodic traffic have no obvious characteristics.

[0066] In some embodiments, referring to FIG. 12 , the traffic characteristics field further includes data block information of data blocks in the IP data stream, and if the traffic type of the IP data stream is one of the third traffic, the fourth traffic, and the second non-periodic traffic, step S240 includes steps S241 and S242, and step S250 includes steps S251 to S253.

[0067] S241 is a step of generating a data block information table based on the data block information of a plurality of data blocks.

[0068] S242 is a step of calculating a standard difference of data block intervals in the data block information table based on the data block interval information of a plurality of data blocks in the data block information table, to obtain the data block statistical characteristics.

[0069] S251 is a step of comparing the standard difference between data block intervals with a standard difference threshold for data block intervals.

[0070] S252 is a step of determining that the traffic type of the IP data stream is second aperiodic traffic if the standard difference between data block intervals exceeds the standard difference threshold between data block intervals, calculating bandwidth characteristics and maximum packet size characteristics of the IP data stream whose traffic type is second aperiodic traffic, and obtaining the traffic characteristics.

[0071] S253 is a step of determining that the traffic type of the IP data stream is third type traffic or fourth type traffic if the data block interval standard difference does not exceed the data block interval standard difference threshold, and calculating periodicity characteristics, data block size characteristics, bandwidth characteristics, and maximum packet size characteristics of the IP data stream whose traffic type is third type traffic or fourth type traffic to obtain the traffic characteristics.

[0072] In some embodiments, referring to FIG. 13, the traffic characteristics field further includes data block information of data blocks in the IP data stream, and if the traffic type of the IP data stream is one of a first type of traffic, a second type of traffic, and a first non-periodic traffic, step S240 includes steps S243 and S244, and step S250 includes steps S254 to S256.

[0073] S243 is a step of generating a data block information table based on the data block information of a plurality of data blocks.

[0074] S244 is a step of calculating the standard difference of the data blocks in the data block information table based on the data block size information of the plurality of data blocks in the data block information table to obtain the data block statistical characteristics.

[0075] S254 is a step of identifying a traffic type of the IP data stream based on the data block size standard difference.

[0076] S255 is a step of calculating a bandwidth characteristic and a maximum packet size characteristic of the IP data stream whose traffic type is the first aperiodic traffic to obtain the traffic characteristic if the traffic type of the IP data stream is the first aperiodic traffic.

[0077] S256 is a step of identifying the traffic characteristics by clustering based on the traffic type of the IP data stream if the traffic type of the IP data stream is the first type of traffic or the second type of traffic.

[0078] In some embodiments, referring to FIG. 14, step S254 includes step S2541. S2541 is the step of comparing the data block size standard difference with a first data block size standard difference threshold and a second data block size standard difference threshold, and determining that the traffic type of the IP data stream is first non-periodic traffic if the data block size standard difference exceeds the second data block size standard difference threshold; determining that the traffic type of the IP data stream is first type of traffic if the data block size standard difference does not exceed the second data block size standard difference threshold and exceeds the first data block size standard difference threshold; and determining that the traffic type of the IP data stream is second type of traffic if the data block size standard difference does not exceed both the first data block size standard difference threshold and the second data block size standard difference threshold.

[0079] In some embodiments, referring to FIG. 15, if the traffic type of the IP data stream is a first type of traffic, step S256 includes steps S2561 and S2562.

[0080] S2561 is a step of clustering the data block information of the plurality of data blocks in the data block information table according to the data block size information to obtain a first clustering result.

[0081] S2562 is a step of identifying the traffic characteristics based on the first clustering result.

[0082] In some embodiments, referring to FIG. 16, if the traffic type of the IP data stream is a second type of traffic, step S256 includes steps S2563 and S2564.

[0083] S2563 is a step of clustering the data block information of the plurality of data blocks in the data block information table according to the data block interval information to obtain a second clustering result.

[0084] S2564 is a step of identifying the traffic characteristics based on the second clustering result.

[0085] In some embodiments, referring to FIG. 17, step S230 includes step S233. S233 is a step of identifying the traffic type of the IP data stream based on the traffic type field in the traffic characteristic field.

[0086] In a second aspect, referring to FIG. 18, the present embodiment provides a Quality of Service (QoS) scheduling method, including step S300.

[0087] S300 is a step of performing QoS scheduling based on traffic characteristics of a data stream, the traffic characteristics being extracted by the traffic characteristic extraction method according to the embodiment of the present invention described in the first aspect.

[0088] The service quality scheduling method provided in the present embodiment can perform network QoS scheduling based on the traffic characteristics extracted by the extraction method provided in the first aspect of the present embodiment, thereby effectively improving the user's QoS experience and realizing intelligent wireless networks centered on user equipment and traffic.

[0089] In a third aspect, referring to FIG. 19, the present embodiment includes: At least one processor 101 (only one shown in FIG. 19); a memory 102 storing at least one computer program, the at least one computer program being configured to cause the at least one processor 101 to implement at least one of a traffic feature extraction method according to an embodiment of the present application as set forth in the first aspect or a QoS scheduling method according to an embodiment of the present application as set forth in the second aspect, when executed by the at least one processor 101; and at least one I / O interface 103 connected between the processor 101 and the memory 102 and configured to realize information interaction between the processor 101 and the memory 102.

[0090] The processor 101 is a device capable of processing data, and includes, but is not limited to, a central processing unit (CPU). The memory 102 is a device capable of storing data, and includes, but is not limited to, random access memory (RAM, more specifically, SDRAM, DDR, etc.), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory (FLASH), etc. The I / O interface (read / write interface) 103 is connected between the processor 101 and the memory 102 and enables information interaction between the processor 101 and the memory 102, and includes, but is not limited to, a data bus.

[0091] In some embodiments, the processor 101, memory 102, and I / O interface 103 are connected to each other and to other components of the computing device via a bus 104.

[0092] In a fourth aspect, referring to FIG. 20, an embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, the computer program, when executed by a processor, realizing at least one of the traffic feature extraction method according to the embodiment of the present application described in the first aspect or the QoS scheduling method according to the embodiment of the present application described in the second aspect.

[0093] In order to make the technical solutions provided by the embodiments of the present application more clearly understandable to those skilled in the art, the technical solutions provided by the embodiments of the present application will be described in detail below using specific examples.

[0094] Example 1 This example provides a method for extracting features of aperiodic data traffic, including identifying and extracting feature fields in a data stream, calculating traffic features of the data stream based on the identification and extraction results, and outputting statistical results.

[0095] The extracting and identifying characteristic fields in the data stream includes identifying and extracting an IP 5-tuple (i.e., source IP address, source port, destination IP address, destination port, transport layer protocol), a GET field, an HTTP / 1.1 field or an HTTP / 1.0 field, a Content-Length field, a data block start message, a data block end message, and the arrival time of the message corresponding to each characteristic field in the data stream.

[0096] Calculating the traffic characteristics of the data stream based on the extracted and identified feature fields includes identifying a GET message based on the GET field, calculating the arrival time of the data block based further on the GET message arrival time and the data block start message arrival time, directly extracting the size of the data block based on the HTTP / 1.1 field or HTTP / 1.0 field and a Content-Length field in the message, obtaining the data block size by cumulative addition based on the data block start message and the data block end message, and calculating the duration of the data block based on the difference between the data block start message arrival time and the data block end message arrival time.

[0097] The outputting of the statistical results includes using a statistical method to classify and summarize all received packets according to the IP 5-tuple to generate a traffic characteristic table, which includes multiple records of current traffic streams, each record including a data block arrival delay and a data block size.

[0098] In some embodiments, when the traffic feature table is filled, average values ​​are calculated for the data block arrival delays and data block sizes in the traffic feature table to obtain statistical results, i.e., the traffic features of the current IP data stream.

[0099] In some embodiments, when the timer times out, an average value is calculated for the existing data block arrival delays and data block sizes in the traffic characteristics table to obtain a statistical result, i.e., the traffic characteristics of the current IP data stream.

[0100] Example 2 This example provides a method for extracting features of periodic data traffic, including extracting IP data messages, calculating message statistical features and comparing them with corresponding message statistical feature thresholds, calculating data block statistical features based on traffic types, comparing the data block statistical features with corresponding data block statistical feature thresholds, distinguishing traffic types to calculate data block statistical features, and outputting traffic features of data streams; alternatively, selecting an appropriate clustering method to perform clustering, performing statistics based on the clustering results, and outputting statistical results.

[0101] Extracting the IP data message includes writing the IP data message information into a message information table, which includes information such as a message serial number, a message arrival time, a message size, and a message direction.

[0102] The step of calculating the message statistical feature and comparing it with the corresponding message statistical feature threshold includes extracting and calculating the statistical value of the message in the message information table, and comparing it with the message size threshold to initially distinguish the traffic type: if the message size threshold is exceeded, it is the first type of traffic, the second type of traffic, or the first aperiodic traffic; if the message size threshold is not exceeded, it is the third type of traffic, the fourth type of traffic, or the second aperiodic traffic.

[0103] The first type of traffic is high bandwidth traffic and has multiple block size characteristics.

[0104] The second type of traffic is high bandwidth low latency traffic, characterized by multiple data block intervals.

[0105] The third type of traffic is upstream low-delay, high-reliability traffic, characterized by messages with low periodicity.

[0106] The fourth type of traffic is downstream low-delay, highly reliable traffic, characterized by messages with low periodicity.

[0107] The first and second aperiodic traffics have no obvious characteristics. The calculating of the data block statistical characteristics based on the traffic type includes: If the traffic type is the first type, the second type, or the first aperiodic traffic, generating a corresponding data block information table, extracting data block size information, and calculating data block size statistics, including but not limited to, a data block size expectation value and a data block size standard difference; if the traffic type is the third type, the fourth type, or the second aperiodic traffic, generating a corresponding data block information table, extracting data block interval information, and calculating data block interval statistics, including but not limited to, a data block interval expectation value and a data block interval standard difference.

[0108] The step of comparing the data block statistical features with corresponding data block statistical feature thresholds, distinguishing traffic types, calculating data block statistical features, and outputting traffic features of the data stream includes: The method includes comparing the standard difference of the data block intervals with a standard difference threshold of the data block intervals, and if the standard difference threshold of the data block intervals is not exceeded, determining that the traffic is a third type or a fourth type, calculating the expected values ​​of the data block sizes, bandwidths, and maximum packet sizes of the third type traffic and the fourth type traffic, respectively, extracting the expected values ​​of the data block intervals, and outputting them as traffic characteristics of the data stream; and if the standard difference threshold of the data block intervals is exceeded, determining that the traffic is a second non-periodic traffic, setting the data block size and data block interval to 0, calculating the bandwidth and maximum packet size, and outputting them as traffic characteristics of the data stream.

[0109] The above-mentioned comparing the data block statistical features with the corresponding data block statistical feature threshold, distinguishing traffic types, calculating data block statistical features, and outputting traffic features of the data stream, or selecting an appropriate clustering method for clustering, may include: The method further includes comparing the standard difference in data block size with a second standard difference threshold for data block size, and determining that the traffic is of the first type or the second type if the standard difference does not exceed the second standard difference threshold for data block size; comparing the standard difference in data block size with a first standard difference threshold for data block size, and determining that the traffic is of the second type, generating a data block information table for the second type of traffic and clustering according to data block intervals; if the standard difference in data block size exceeds the first standard difference threshold for data block size, the traffic is of the first type, generating a data block information table for the first type of traffic and clustering according to data block size; if the standard difference in data block size exceeds the second standard difference threshold for data block size, the traffic is of the first non-periodic traffic, marking the data block size and the data block interval as 0, calculating the bandwidth and the maximum packet size, and outputting them as traffic characteristics of the data stream.

[0110] The performing of statistics based on the clustering results and outputting the statistical results includes, in the case of a first type of traffic, calculating an expected value of the data block size and data block interval of each clustered data based on the data block size clustering result, calculating a bandwidth and a maximum packet size, and outputting the results as traffic characteristics of the data stream; in the case of a second type of traffic, calculating an expected value of the data block size and data block interval of each clustered data based on the data block interval clustering result, calculating a bandwidth and a maximum packet size, and outputting the results as traffic characteristics of the data stream; and in the case of aperiodic traffic, setting the data block size and data block interval to 0, calculating a bandwidth and a maximum packet size, and outputting the results as traffic characteristics of the data stream.

[0111] Example 3 This example provides an aperiodic traffic feature identification device, which includes an online analysis module, an offline module, and a prediction module.

[0112] In this example, the input is an initial IP data stream. The input IP data stream is copied to obtain two IP data streams, one of which is input to the online analysis module and the other to the offline module. The output is the traffic characteristics of the IP data stream, including data block size and data arrival delay.

[0113] The online analysis module is configured to complete real-time packet analysis, identify message GET fields, identify message HTTP / 1.1 fields, extract packet size information, and simultaneously read the predicted arrival time from the offline module.

[0114] The offline module is configured to identify message GET fields, identify message HTTP / 1.1 fields, identify data block start packets and data block end packets, extract or calculate data block size information, calculate the time interval between the GET message and the data start packet, and build and maintain a traffic feature library.

[0115] The prediction module is configured to output the data block size (obtained by parsing a special field or by calculation) and the delay between the request (GET) message and the first packet (obtained by calculation).

[0116] The traffic feature library consists of multiple traffic feature tables, and the general structure of a traffic feature table is shown in Table 1.

[0117] [Table 1]

[0118] The traffic characteristics table includes the following: ●Combination of server IP address + server port number + protocol number (App IP + App port + protocol): Server IP address + server port number + protocol number analyzed from the message's IP 5-tuple. The server IP address + server port number + protocol number (App IP + App port + protocol) in the same traffic feature table are the same, and the capacity of each table is expressed as the traffic feature table capacity (tableLength), with the default value being 10,000, indicating that the traffic feature table can record 10,000 analysis records for the same traffic stream. If the number of traffic feature tables is expressed as the number of tables (tableNum), the capacity of the entire feature library is the number of tables (tableqiNum) x the table capacity per table (tableLength).

[0119] ● Data block size: The data block size corresponding to the current GET request message.

[0120] Delay: The delay between the current request (GET) message and the first packet of the corresponding data block.

[0121] ● Application Identification (APP tag): Used to identify the video application (APP) to which the traffic stream belongs.

[0122] Traffic feature table update: Adopting a first-in, first-out method, newly received data is written to the end of the traffic feature table, dynamically maintaining up to 10,000 records.

[0123] Message GET field: The GET keyword is in the first three bytes of the HTTP message. Its ASCII encoding is 47,4554 (hexadecimal). The HTTP message is packaged into a TCP message after adding a TCP header, and the TCP message is packaged into an IP message after adding an IP header. The IPv6 message header length is 40 bytes, the IPv4 message header length is 20 bytes, and the TCP message header length is 20 bytes.

[0124] When identifying the GET field, for an IPv6 message, it can detect whether bytes 61 to 63 of the IPv6 message are 47 45 54 (hexadecimal), and for an IPv4 message, it can detect whether bytes 41 to 43 of the IPv4 message are 47 45 54 (hexadecimal).

[0125] Message HTTP / 1.1 field: Traverse the analysis packet from the message following the GET message. If the packet payload contains an 'HTTP / 1.1' field, it indicates that the packet contains data block size information. Extract the value of the Content-Length field in the payload, and the value of this field corresponds to the data block size of the GET request message.

[0126] The ASCII encoding for HTTP / 1.1 is 48 54 54 50 2f 31 2e 31 (hexadecimal), which is found in the first eight bytes of the TCP payload. Similar to the GET field identification scheme, for IPv6 messages, it can be detected if bytes 61-68 of an IPv6 message are 48 54 54 50 2f 31 2e 31. For IPv4 messages, it can be detected if bytes 61-68 of an IPv4 message are 48 54 54 50 2f 31 2e 31.

[0127] The first packet of a data block can be identified using two methods: Method 1: Traverse the analysis packets from the message following the GET message. If the packet length exceeds 1400 bytes, determine that the current message is the first packet of the data block.

[0128] Method 2: Step 1: Extract the Seq and Len field values ​​in the GET message, and sum the two field values. The Seq field is the serial number of the TCP message field, and the Len field is the total length field of the IP message, including the length of the header and data; and Step 2: Traverse the analysis packets from the message following the GET message, and if it is detected that the Ack field value in the message is equal to the sum of the Seq field value and Len field value of the GET message in step 1, it is determined that the current message is the first packet of the data block.

[0129] Two methods are used to identify the end-of-data-block packet: Method 1: Traverse the analysis packet from the message following the GET data. If the packet length is more than 150 bytes but less than 1000 bytes, it is determined to be the end packet of the current data block.

[0130] Method 2: Step 1: Extract the Seq and Len field values ​​in the GET message, and sum the two field values. The Seq field is the serial number of the TCP message field, and the Len field is the total length field of the IP message, including the length of the header and data; and Step 2: Traverse the analysis packets from the message following the GET message. If it is found that the Ack field value in the message is equal to the sum of the Seq field value and Len field value of the GET message in step 1, mark all packets that satisfy the above condition, and the last packet is a data block end packet.

[0131] Block size: Corresponding to the packet size (data size) field in Table 1, there are two calculation methods:

[0132] Method 1 (the message payload contains the 'HTTP / 1.1' field) The Content-Length field value in the packet payload is directly read, and this value corresponds to the data block size of this GET request message.

[0133] Method 2 (the message payload does not contain the 'HTTP / 1.1' field) All packets between the first packet of the current data block and the end packet of the data block are cumulatively added, and the value corresponds to the data block size of the current GET request message.

[0134] Data arrival delay: Corresponding to the data arrival delay field in Table 1, obtain the timestamp of each GET message in the current IP data stream and the first packet of the data block corresponding to that GET message, and subtract the two timestamps to obtain the data block delay.

[0135] Data block size and expected delay: When Table 1 is created, a timer is started (tableUPDateTimer) (default: 60 s), and when the timer times out, the following process is completed.

[0136] Clear the timer (tabelUPDateTimer) and then restart it. Calculate the average value of all packet sizes (data size) in the current Table 1 and update the current data block size statistic (avg_size).

[0137] The average value of all data arrival delays (delay) in the current Table 1 is calculated and the current data delay statistic value (avg_delay) is updated.

[0138] Example 4 In this example, A method for extracting periodic traffic features includes extracting IP data messages, calculating message statistical features and comparing them with corresponding message statistical feature thresholds, calculating data block statistical features based on traffic types, comparing the data block statistical features with corresponding data block statistical feature thresholds, further distinguishing traffic types, calculating data block statistical features and outputting traffic features of the data stream; or selecting an appropriate clustering method to perform clustering, performing statistics based on the clustering results, and outputting the statistical results.

[0139] The extracting of the IP data message includes writing the IP data message information into a message information table. The message information table is used to record the captured initial message information, including a message arrival number (pktNo), a message arrival time (pktTstp), a message size (pktSize), a message direction (pktDir), etc. The message direction (pktDir) refers to the message transmission direction, where uplink is UL and downlink is DL.

[0140] The message information table consists of 10 data slices (sections), and the capacity of each slice (section capacity) is set to 1000 by default. The statistics table is filled by capturing one data slice message from the IP data stream each time, capturing a total of 10 data slices. After the statistics table is filled, when a new data slice is captured, the data slice with the smallest number in the statistics table (section 1 slice) is discarded and the new data slice is added to the end of the statistics table. The general structure of the message information table is shown in Table 2.

[0141] [Table 2]

[0142] Calculating the message statistical feature and comparing it with the corresponding message statistical feature threshold value, and calculating based on the message information in the message information table when the message information table is filled. In some embodiments, if the message information table is not filled when the timer times out, calculating based on the existing message information in the message information table, and the calculation method is as follows:

[0143] The non-zero value of the message size (pktSize) field in the message information table is extracted, the expected value (pktSizeNAvg) of the extracted non-zero message is calculated, and compared with the message size threshold (pktSizeThr) (default: 200 bytes) to roughly distinguish the traffic type. If the expected value (pktSizeNAvg) of the non-zero message exceeds the message size threshold (pktSizeThr), it is the first type of traffic, the second type of traffic, or the first non-periodic traffic. If it does not exceed the message size threshold, it is the third type of traffic, the fourth type of traffic, or the second non-periodic traffic.

[0144] The first type of traffic is large bandwidth traffic, which has multiple data block size characteristics, such as video surveillance, online live services, etc.

[0145] The second type of traffic is high-bandwidth, low-latency traffic characterized by multiple data block intervals, such as high-definition images taken by production line cameras and uploaded to a server for real-time quality inspection.

[0146] The third type of traffic is upstream low-latency and high-reliability traffic, characterized by messages with low periodicity, such as data collected by sensors on production lines or in factories.

[0147] The fourth type of traffic is downstream low-latency and highly reliable traffic, characterized by messages with low periodicity, such as when a production line issues operational control commands to control the operation of a mechanical arm.

[0148] The first and second aperiodic traffics are traffics that do not have obvious periodicity and do not have periodic characteristics such as noise or interference.

[0149] said calculating data block statistical characteristics based on traffic type includes: For the first type traffic, the second type traffic, or the first aperiodic traffic, generating a data block information table, extracting data block size information, and calculating data block size statistics, including but not limited to a data block size expectation value (dbSizeAvg) and a data block size standard difference (dbSizeStd); and for the third type traffic, the fourth type traffic, or the second aperiodic traffic, generating a corresponding data block information table, extracting data block interval information, and calculating data block interval statistics, including but not limited to a data block interval expectation value (dbItvlAvg) and a data block interval standard difference (dbItvlStd).

[0150] The data block information table is used to record data block information, where the data block consists of consecutive non-zero messages. The data block information includes the data block number (dbNo), start time (dbStart), end time (dbEnd), data block size (dbSize), data block interval (dbItvl), and data block duration (dbDu). dbStart is the message time of the first packet in the data block, and dbEnd is the message time of the end packet in the data block. When constructing the data block information table, the following five types of block information tables (traffic types 0 to 4) are generated according to the traffic type ID (serviceTypeID) label.

[0151] serviceTypeID=0, non-periodic traffic, serviceTypeID=1, the first type of traffic, serviceTypeID=2, second type of traffic, serviceTypeID=3, the third type of traffic, serviceTypeID=4, the fourth type of traffic.

[0152] Table 3 shows a block information table for the first type of traffic (serviceTypeID=1).

[0153] [Table 3]

[0154] The data block start time is the arrival time of the first packet of the data block. The arrival time of the first packet of the data block can be determined by the following method.

[0155] For the first and second types of traffic: If the message length is greater than bPktThr (default: 1468 bytes), it is determined to be the first packet of a data block, and the time of the first packet of the data block, dbStart, is recorded.

[0156] For the third and fourth types of traffic: If the length of three consecutive messages is greater than sPktThr (default: 64 bytes), the first of the three consecutive messages is determined to be the first packet of the data block, and the time of the first packet of the data block, dbStart, is recorded.

[0157] The end time of the data block is the arrival time of the data block end packet, which can be determined in the following manner.

[0158] After identifying the first packet of the data block, traversal is started from the message next to the first packet of the data block.

[0159] For the first and second types of traffic: If the message length is less than bPktThr (default: 1468 bytes), it is determined to be a data block end packet and the data block end packet time dbEnd is recorded.

[0160] For the third and fourth types of traffic: If the message length is not larger than sPktThr (default: 64 bytes), it is determined to be a data block end packet and the data block end packet time dbEnd is recorded.

[0161] The data block size (dbSize) is the cumulative sum of the message sizes of multiple consecutive messages that meet the condition. In this example, the data block size is obtained by cumulatively adding the lengths of all data packets between the first packet of the current data block and the end packet of the current data block.

[0162] The data block interval (dbItvl): The first packet times of two adjacent data blocks are subtracted to obtain the data block interval.

[0163] The data block duration (dbDu): The arrival time of the first packet of the data block is subtracted from the arrival time of the end packet of the same data block.

[0164] said comparing said data block statistical feature with a corresponding data block statistical feature threshold to further distinguish traffic types; It involves comparing the data block interval standard difference (dbItvlStd) with the data block interval standard difference threshold (dbItvlStdthr). If dbItvlStd does not exceed the threshold dbItvlStdthr, it is type 3 or type 4 traffic. Type 3 traffic is upstream traffic, and type 4 traffic is downstream traffic. The feature calculation method for the two types of traffic is the same. The feature calculation method is as follows:

[0165] Periodic feature: The expected value of the data block interval (dbItvlAvg) is extracted and used as the periodic feature of the data stream. The output method is as shown in Table 4.

[0166] [Table 4]

[0167] Data block size feature: The expected value of the data block size (dbSizeAvg) is extracted and used as the block size feature of the data stream. The output method is as shown in Table 5.

[0168] [Table 5]

[0169] Bandwidth characteristics: The amount of data (total number of packets) generated by the corresponding traffic type in 2000 millisecond intervals, i.e., the bandwidth value, is calculated, and the statistical average of the obtained multiple bandwidth values ​​is calculated to obtain the bandwidth characteristics of the data stream. The output method is shown in Table 6.

[0170] [Table 6]

[0171] Maximum packet size feature: Traverse the maximum value of pktSize of the corresponding traffic type message in the packet statistics table to obtain the maximum packet size feature of the data stream. The output method is shown in Table 7.

[0172] [Table 7]

[0173] If dbItvlStd exceeds the threshold dbItvlStdthr, it is the second aperiodic traffic, and its feature calculation method is as follows.

[0174] Periodic characteristics: 0. The output method is as shown in Table 4. Data block size characteristics: 0. The output method is as shown in Table 5.

[0175] Bandwidth characteristics: The amount of data generated by non-periodic traffic, i.e., the bandwidth value, is counted in 2000 millisecond intervals, and the statistical average of the multiple bandwidth values ​​obtained is calculated to obtain the bandwidth characteristics. The output method is shown in Table 6.

[0176] Maximum packet size feature: Traverse the maximum pktSize value corresponding to the message of the non-periodic traffic type in the packet statistics table to obtain the maximum packet size feature of the data stream. The output method is shown in Table 7.

[0177] The step of comparing the data block statistical features with the corresponding data block statistical feature threshold value, further distinguishing traffic types, calculating the data block statistical features, and outputting the traffic features of the data stream includes: The method further includes comparing the standard difference of data block sizes (dbSizeStd) with a second standard difference threshold of data block sizes (dbSizeStdthr2) (default: 2*pktSizeNAvg). If dbSizeStd does not exceed dbSizeStdthr2, it is the first or second type of traffic, which needs to be further determined. If it exceeds dbSizeStdthr2, it is the first non-periodic traffic, and the characteristic calculation method is as follows:

[0178] Periodic characteristics: 0. The output method is as shown in Table 4. Data block size characteristics: 0. The output method is as shown in Table 5.

[0179] Bandwidth characteristics: The amount of data generated by non-periodic traffic, i.e., the bandwidth value, is counted in 2000 millisecond intervals, and the statistical average of the multiple bandwidth values ​​obtained is calculated to obtain the bandwidth characteristics. The output method is shown in Table 6.

[0180] Maximum packet size feature: Traverse the maximum pktSize value corresponding to the message of the aperiodic traffic type in the packet statistics table to obtain the maximum packet size feature of the data stream. The output method is shown in Table 7.

[0181] The above-mentioned selecting an appropriate clustering method, performing clustering, performing statistics based on the clustering results, and outputting the statistical results are The method includes comparing the standard difference of data block sizes (dbSizeStd) with a first standard difference threshold of data block sizes (dbSizeStdthr 1) (default: 0.5*pktSizeNAvg). If dbSizeStd does not exceed dbSizeStdthr 1, the traffic is of a second type, and a second type traffic block information table is generated and clustering is performed according to the data block interval (dbItvl). If dbSizeStd exceeds dbSizeStdthr 1, the traffic is of a first type, and a first type traffic block information table is generated and clustering is performed according to the data block size (dbSize).

[0182] Clustering is performed using an unsupervised clustering method. For the first type of traffic, clustering is performed according to the data block size (dbSize). In this example, the number of traffic periods for the first type is 2, and a K-means clustering (k-means) algorithm is used to compile statistics on the labels corresponding to each data block size (dbSize) and generate a new statistical table. Each new statistical table records the category to which the current data block size (dbSize) belongs and the statistical data of the cluster center, which is the expected value of dbSize.

[0183] The K-means clustering (k-means) algorithm uses the python sklearn.cluster.KMeans function, with the nclusters parameter set to 2 and the remaining parameters set to default.

[0184] For the second type of traffic, dbItvl is clustered. Because the number of periods is unknown, clustering is performed using the mean shift algorithm, and the aggregated number of categories is the number of periods. The labels corresponding to each data block interval (dbItvl) are counted and a new statistical table is generated. Each new statistical table records the category to which the current data block interval (dbItvl) belongs and the statistical data of the cluster center, which is the expected value of dbItvl.

[0185] The mean_shift algorithm uses the python sklearn.cluster.MeanShift function with default parameters.

[0186] For the first type of traffic, clustering is performed based on the data block size (dbSize). For each clustered data, the expected value (dbItvlAvg) of the data block interval (dbItvl) is calculated as the periodicity feature, and the output format of the periodicity feature is shown in Table 4. For each cluster data, the cluster center is used as the data block size feature, and the output format of the block size feature is shown in Table 5. For each cluster data, the amount of data generated within 2000 milliseconds, i.e., the bandwidth, is calculated as a statistic, and the statistical average of the multiple bandwidth values ​​obtained is calculated to obtain the bandwidth feature. The output format of the bandwidth characteristic is shown in Table 6. For each cluster data, the maximum pktSize value of the corresponding traffic type message in the packet statistics table is traversed to obtain the maximum packet size feature of the data stream. The output format of the maximum packet size feature is shown in Table 7.

[0187] For the second type of traffic, clustering is performed based on the data block interval (dbItvl). For each cluster data, the cluster center is used as the periodic feature, and the output format of the periodic feature is shown in Table 4. For each cluster data, the expected value (dbSizeAvg) of the data block size (dbSize) is calculated and used as the data block size feature, and the output format of the data block size feature is shown in Table 5. For each cluster data, statistics are collected on the amount of data generated within 2000 milliseconds, i.e., the bandwidth value, and the statistical average of the multiple bandwidth values ​​obtained is calculated to obtain the bandwidth feature. The output format of the bandwidth characteristic is shown in Table 6. For each cluster data, the maximum pktSize value of the corresponding traffic type message in the packet statistics table is traversed to obtain the maximum packet size feature of the data stream. The output format of the maximum packet size feature is shown in Table 7.

[0188] For the first aperiodic traffic, the data block interval statistic is set to 0 to determine the periodicity feature, and the output format of the periodicity feature is as shown in Table 4. The data block size statistic is set to 0 to determine the data block size feature, and the output format of the data block size is as shown in Table 5. The amount of data generated within 2000 milliseconds, i.e., the bandwidth value, is counted, and the statistical average of the multiple bandwidth values ​​obtained is calculated to obtain the bandwidth feature. The output format of the bandwidth feature is as shown in Table 6. The maximum pktSize value of the corresponding traffic type message in the packet statistics table is traversed to obtain the maximum packet size feature of the data stream. The output format of the maximum packet size feature is as shown in Table 7.

[0189] Those skilled in the art will understand that all or some of the steps of the methods disclosed above and the functional modules / units within the apparatus can be implemented as software, firmware, hardware, or a suitable combination thereof. In hardware embodiments, the division between the functional modules / units described above does not necessarily correspond to the division of physical components. For example, one physical component may have multiple functions, or one function or step may be performed by multiple physical components working together. Some or all of the physical components may be implemented as software executed by a processor, such as a central processor, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as a dedicated integrated circuit. Such software may be distributed on computer-readable media, which may include computer storage media (or non-transitory media) and communication media (or transitory media). As known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium used to store desired information and which can be accessed by a computer. Additionally, it will be well known to those skilled in the art that communication media typically include computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism and can include any information delivery media.

[0190] Although exemplary embodiments have been disclosed and specific terms have been used herein, they are used and should be construed as being generally illustrative and descriptive only, and not for limiting purposes. It will be apparent to those skilled in the art that, in some instances, features, characteristics, and / or elements described in connection with particular embodiments can be used alone or in combination with features, characteristics, and / or elements described in connection with other embodiments, unless expressly indicated otherwise. Accordingly, those skilled in the art will recognize that various changes in form and detail may be made without departing from the scope of the present application, as defined by the appended claims.

Claims

1. extracting traffic feature fields from an Internet Interconnection Protocol (IP) data stream; identifying traffic characteristics of the IP data stream based on the traffic characteristics field, the traffic characteristics characterizing a quality of service (QoS) requirement of the IP data stream; The step of identifying traffic characteristics of the IP data stream based on the traffic characteristics field comprises: identifying a data block characteristic of at least one data block in the IP data stream based on the traffic characteristic field; calculating a data block feature statistic based on the data block feature of each data block, and determining the data block feature statistic as a traffic feature of the IP data stream; Traffic feature extraction methods.

2. The data block characteristics include a data block size and an arrival delay of the data block, and the step of extracting a traffic characteristic field of an Internet Interconnection Protocol (IP) data stream includes: extracting the timestamp of the request (GET) message and the timestamp of the starting packet of said data block; if the data block includes an HTTP / 1.1 field or an HTTP / 1.0 field, extracting a content length field, the content length field characterizing a data block size of the data block; If the data block does not include an HTTP / 1.1 field and an HTTP / 1.0 field, extracting size information of all packets of the data block. The extraction method according to claim 1.

3. said step of extracting traffic characteristic fields of an Internet Interconnection Protocol (IP) data stream comprising: identifying a request (GET) message based on a GET field before extracting the timestamp of the GET message and the timestamp of the starting packet of the data block; extracting a SEQ field value and a LEN field value in the GET message; identifying a first packet after the GET message whose ACK field value is equal to the sum of the SEQ field value and the LEN field value as the start packet. The extraction method according to claim 2.

4. said step of extracting traffic characteristic fields of an Internet Interconnection Protocol (IP) data stream comprising: identifying a request (GET) message based on a GET field before extracting the timestamp of the GET message and the timestamp of the starting packet of the data block; and identifying a first packet after the GET message whose length is greater than a predetermined length as the start packet. The extraction method according to claim 2.

5. The data block feature statistics include a data block size statistic and an arrival delay statistic, and the step of calculating the data block feature statistics based on the data block features of each of the data blocks includes: generating at least one traffic feature table based on a data block size and an arrival delay of the at least one data block, each of the data blocks corresponding to one traffic feature table entry in the traffic feature table; When a predetermined statistical condition is satisfied, calculating an average value of data block sizes in the traffic feature table to obtain the data block size statistical value, and calculating an average value of arrival delays in the traffic feature table to obtain the arrival delay statistical value. The extraction method according to claim 2.

6. said step of calculating data block feature statistics based on data block features of each of said data blocks comprises: determining a number of traffic feature table entries in the traffic feature table; and indicating that the predetermined statistical condition is met when the number of traffic feature table entries in the traffic feature table reaches a predetermined quantity threshold. The extraction method according to claim 5.

7. said step of calculating data block feature statistics based on data block features of each of said data blocks comprises: Starting the timer and and indicating that the predetermined statistical condition has been met when the timer reaches a predetermined time threshold. The extraction method according to claim 5.

8. The step of identifying traffic characteristics of the IP data stream based on the traffic characteristics field comprises: identifying a traffic type of the IP data stream based on the traffic characteristic field; calculating data block statistical characteristics of data blocks in the IP data stream based on a traffic type of the IP data stream; determining traffic characteristics of the IP data stream based on the data block statistical characteristics; the traffic characteristics field includes data block information of data blocks in the IP data stream, and the step of calculating the data block statistical characteristics of the data blocks in the IP data stream based on the traffic type of the IP data stream includes: generating a data block information table based on data block information of the plurality of data blocks; calculating a standard difference in data block size or a standard difference in data block interval in the data block information table based on the data block size information in the data block information table or the data block interval information of the plurality of data blocks, to obtain the data block statistical characteristics; The extraction method according to claim 1.

9. said step of identifying a traffic type of said IP data stream based on said traffic characteristic field comprises: calculating message statistical characteristics of the message based on the traffic characteristics field; identifying a traffic type of the IP data stream based on the message statistical characteristics; The traffic characteristic field further includes message information of a message in the IP data stream, and the step of calculating the message statistical characteristic of the message based on the traffic characteristic field includes: generating a message information table based on message information of the at least one message; calculating an expected value of the message size in the message information table based on the message size information of each message in the message information table to obtain the message statistical characteristics; The extraction method according to claim 8.

10. The step of identifying a traffic type of the IP data stream based on the message statistical characteristics comprises: comparing the message statistical characteristics to a message size threshold; If the message statistical characteristic exceeds the message size threshold, the traffic type of the IP data stream is one of a first type of traffic, a second type of traffic, and a first aperiodic traffic; If the message statistical characteristic does not exceed the message size threshold, the traffic type of the IP data stream is one of a third type of traffic, a fourth type of traffic, and a second non-periodic traffic. The extraction method according to claim 9.

11. If the traffic type of the IP data stream is one of a third type of traffic, a fourth type of traffic, and a second non-periodic traffic, calculating the standard difference of data block intervals in the data block information table based on the data block interval information of a plurality of data blocks in the data block information table to obtain the data block statistical characteristics; The step of identifying traffic characteristics of the IP data stream based on the data block statistical characteristics comprises: comparing the standard difference between data blocks with a standard difference threshold for data blocks; If the standard difference between data block intervals exceeds the standard difference threshold between data block intervals, the traffic type of the IP data stream is a second aperiodic traffic, and calculating a bandwidth characteristic and a maximum packet size characteristic of the IP data stream whose traffic type is the second aperiodic traffic to obtain the traffic characteristic; if the data block interval standard difference does not exceed the data block interval standard difference threshold, the traffic type of the IP data stream is a third type of traffic or a fourth type of traffic, and calculating a periodicity characteristic, a data block size characteristic, a bandwidth characteristic, and a maximum packet size characteristic of the IP data stream whose traffic type is the third type of traffic or the fourth type of traffic to obtain the traffic characteristics; The extraction method according to claim 10.

12. If the traffic type of the IP data stream is one of a first type of traffic, a second type of traffic, and a first non-periodic traffic, calculating the standard difference of the data block size in the data block information table based on the data block size information of a plurality of data blocks in the data block information table to obtain the data block statistical characteristics; The step of identifying traffic characteristics of the IP data stream based on the data block statistical characteristics comprises: identifying a traffic type of the IP data stream based on the data block size standard difference; if the traffic type of the IP data stream is a first aperiodic traffic, calculating a bandwidth characteristic and a maximum packet size characteristic of the IP data stream whose traffic type is the first aperiodic traffic to obtain the traffic characteristic; if the traffic type of the IP data stream is a first type of traffic or a second type of traffic, identifying the traffic characteristics by clustering based on the traffic type of the IP data stream; The extraction method according to claim 10.

13. identifying a traffic type of the IP data stream based on the data block size standard difference, comparing the data block size standard difference with a first data block size standard difference threshold and a second data block size standard difference threshold; If the data block size standard difference exceeds the second data block size standard difference threshold, the traffic type of the IP data stream is a first aperiodic traffic; If the data block size standard difference does not exceed the second data block size standard difference threshold and exceeds the first data block size standard difference threshold, the traffic type of the IP data stream is a first type of traffic; determining that the traffic type of the IP data stream is a second type of traffic if the data block size standard difference does not exceed the first data block size standard difference threshold and the second data block size standard difference threshold; The extraction method according to claim 12.

14. If the traffic type of the IP data stream is a first type of traffic, identifying the traffic characteristics by clustering based on the traffic type of the IP data stream includes: clustering the data block information of the plurality of data blocks in the data block information table according to data block size information to obtain a first clustering result; and identifying the traffic characteristics based on the first clustering result. The extraction method according to claim 13.

15. If the traffic type of the IP data stream is a second type of traffic, identifying the traffic characteristics by clustering based on the traffic type of the IP data stream includes: clustering the data block information of the plurality of data blocks in the data block information table according to the data block interval information to obtain a second clustering result; and identifying the traffic characteristics based on the second clustering results. The extraction method according to claim 13.

16. said step of identifying a traffic type of said IP data stream based on said traffic characteristic field comprises: identifying a traffic type of the IP data stream based on a traffic type field in the traffic characteristics field; The extraction method according to claim 8.

17. identifying traffic characteristics of an Internet Interconnection Protocol (IP) data stream, the traffic characteristics characterizing a quality of service QoS requirement of the IP data stream, the traffic characteristics being identified based on a traffic characteristics field of the IP data stream; performing QoS scheduling based on traffic characteristics of the IP data stream; Identifying the traffic characteristics of the IP data stream includes: identifying data block characteristics in the IP data stream based on the traffic characteristics field; calculating a data block feature statistic based on the data block feature of each data block, and determining the data block feature statistic as the traffic feature of the IP data stream; Quality of Service (QoS) scheduling methods.

18. at least one processor; a memory storing at least one computer program, the at least one computer program being configured to cause the at least one processor to implement at least one of the traffic feature extraction method according to any one of claims 1 to 16 or the QoS scheduling method according to claim 17, when the at least one computer program is executed by the at least one processor; and at least one I / O interface connected between the processor and the memory and configured to enable information interaction between the processor and the memory. electronic equipment.

19. a computer program stored therein, the computer program being executed by a processor to implement at least one of the traffic feature extraction method according to any one of claims 1 to 16 or the QoS scheduling method according to claim 17; A computer-readable storage medium.

Citation Information

Patent Citations

  • Response time measurement system

    JP1999346238A

  • Flow classification method, system, and program

    JP2012034262A

  • Communication control system, communication method, and gateway device

    JP2016152453A