Data access abnormality identification method, electronic device and computer-readable medium
By adding an abnormal access identification system between the data packet aggregator and the data acquisition system and updating statistical records to identify and locate data packet access anomalies, the problem of difficult location of access anomalies in the existing technology is solved, and rapid fault repair and system performance improvement are achieved.
Patent Information
- Application Number
- PCT/CN2025/082149
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-28
- Filing Date
- 2025-03-12
- Publication Date
- 2025-10-02
AI Technical Summary
In the existing technology, access anomalies that occur during data packet transmission are difficult to accurately locate, resulting in inaccurate data analysis results and increased network resource consumption. Existing troubleshooting methods are inefficient and not intelligent enough.
By adding an abnormal access identification system between the data packet aggregator and the data acquisition system, the statistical information in the first statistical record is updated, the target statistical record is generated, the abnormal type and source are identified, and the timeliness of fault location is ensured.
It achieves accurate identification of data packet access anomalies and rapid fault repair, improving the accuracy of data analysis and system performance.
Smart Images

Figure CN2025082149_02102025_PF_FP_ABST
Abstract
Description
Data access anomaly identification method, electronic device and computer-readable medium
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application claims priority to Chinese patent application CN 202410381202.9, entitled “Method for identifying data access anomalies, electronic device and computer-readable medium” filed on March 28, 2024, the entire contents of which are incorporated herein by reference. Technical Field
[0003] The present disclosure relates to the field of communication technology, and in particular to a method for identifying data access anomalies, an electronic device, and a computer-readable medium. Background Art
[0004] In the communications field, data collection and analysis of packets transmitted between network elements is used to identify user activity and network transmission quality. This technology has been widely used around the world. For example, data collection systems in the IP (Internet Protocol) communications field.
[0005] However, in actual applications, data packet transmission failures often occur due to incorrect network layout or configuration of data acquisition equipment. In order to analyze the cause of the failure, how to accurately locate the data access anomaly of the network element device that transmits the data packet is an urgent problem that needs to be solved. Summary of the Invention
[0006] In response to the above-mentioned shortcomings, the present disclosure provides a method for identifying data access anomalies, an electronic device, and a computer-readable medium.
[0007] An embodiment of the present disclosure provides a method for identifying data access anomalies, including: updating statistical information in a first statistical record based on a first address pair corresponding to a received data packet to obtain a target statistical record, wherein the first address pair is information that can identify the source network element and the destination network element of the data packet; and identifying whether there is an anomaly in the statistical information in the target statistical record.
[0008] An embodiment of the present disclosure provides an electronic device, comprising: one or more processors; and a memory on which one or more programs are stored. When the one or more programs are executed by the one or more processors, the one or more processors implement a method for identifying data access anomalies according to an embodiment of the present disclosure.
[0009] An embodiment of the present disclosure provides a computer-readable medium having a computer program stored thereon. When the program is executed by a processor, the method for identifying data access anomalies according to the embodiment of the present disclosure is implemented.
[0010] An embodiment of the present disclosure provides a computer program product, including a computer program or computer instructions, wherein the computer program or the computer instructions are stored in a computer-readable storage medium, a processor of a computer device reads the computer program or the computer instructions from the computer-readable storage medium, and the processor executes the computer program or the computer instructions, so that the computer device performs the method for identifying data access anomalies according to an embodiment of the present disclosure.
[0011] The disclosed embodiments provide a method for identifying data access anomalies, an electronic device, a computer-readable medium, and a computer program product. In the disclosed embodiments, by updating the statistical information of a first address pair in a first statistical record to obtain a target statistical record, it is possible to accurately identify, based on the statistical information in the target statistical record, whether an anomaly occurs during the access of a data packet between a mobile communication network to a data acquisition device. In the event of an anomaly, the anomaly type can be accurately determined by analyzing the statistical information of the anomaly. The network element device corresponding to the address pair where the anomaly occurs can also be determined based on the anomaly type, thereby ensuring the timely discovery of the source of the fault. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] FIG1 is a schematic diagram of an application scenario of a method for identifying abnormal data access provided by an embodiment of the present disclosure;
[0013] FIG2 is a flow chart of a method for identifying data access anomalies provided by an embodiment of the present disclosure;
[0014] FIG3 is a flowchart of a specific implementation of step S1 in the method for identifying abnormal data access provided by an embodiment of the present disclosure;
[0015] FIG4 is a flowchart of a specific implementation of step S4 in the method for identifying abnormal data access provided by an embodiment of the present disclosure;
[0016] FIG5 is a schematic structural diagram of an electronic device provided by an embodiment of the present disclosure;
[0017] FIG6 is a schematic diagram of the structure of a computer-readable medium provided in an embodiment of the present disclosure;
[0018] FIG7 is a schematic diagram of the structure of an exemplary abnormal access identification system provided by an embodiment of the present disclosure;
[0019] FIG8 is a schematic diagram of a processing flow of a data packet parser in an exemplary abnormal access identification system provided by an embodiment of the present disclosure;
[0020] FIG9 is a schematic diagram of a processing flow of a data packet counter in an exemplary abnormal access identification system provided by an embodiment of the present disclosure. DETAILED DESCRIPTION
[0021] To enable those skilled in the art to better understand the technical solution of the present disclosure, the data access anomaly identification method, electronic device, and computer-readable medium provided by the present disclosure are described in detail below with reference to the accompanying drawings.
[0022] Example embodiments will be described more fully hereinafter with reference to the accompanying drawings, but the example embodiments may be embodied in different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the scope of this disclosure to those skilled in the art.
[0023] In the absence of conflict, the various embodiments of the present disclosure and the various features therein may be combined with each other.
[0024] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.
[0025] The terms used herein are used only to describe specific embodiments and are not intended to limit the present disclosure. As used herein, the singular forms "a," "an," and "the" are also intended to include the plural forms, unless the context clearly indicates otherwise. It will also be understood that when the terms "comprising" and / or "made of" are used in this specification, the presence of the features, wholes, steps, operations, elements, and / or components is specified, but the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or groups thereof is not excluded.
[0026] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and the present disclosure, and will not be interpreted as having an idealized or overly formal meaning unless expressly defined as such herein.
[0027] FIG1 is a schematic diagram of an application scenario of a method for identifying abnormal data access provided by an embodiment of the present disclosure.
[0028] 1 , in an IP communication system, a routing device interacts with multiple communication clients (e.g., a first communication client, a second communication client) and multiple communication servers (e.g., a first communication server, a second communication server). A data packet aggregator aggregates data packets from multiple sources (i.e., communication clients and communication servers) in the IP communication system through an optical splitter on the communication client and an optical splitter on the communication server. In some related technologies, all data packets aggregated by the data packet aggregator are input into a data acquisition system to achieve IP packet data acquisition. However, some abnormal conditions often occur, such as a communication data packet between an IP address pair not being accessed, a communication data packet only having unilateral data access, or a communication data packet being illegally accessed. The causes of these abnormal conditions are often complex and difficult to locate. For example, abnormal conditions may occur due to changes in the network structure of the IP communication system, upgrades, changes, or abnormalities in the data packet aggregator, abnormalities in the communication client or communication server, upgrades, changes, or abnormalities in the data acquisition system, and the like. These abnormal conditions can directly or indirectly lead to other problems. For example, if data packets from an IP address pair are missing or only accessed, the data analysis system will obtain inaccurate results. If data packets from an illegal IP address pair are accessed, the data collection system will be overloaded, thus affecting its collection performance. Therefore, a solution is urgently needed to accurately locate data access anomalies in network element devices that transmit data packets.
[0029] In a related technology, if the data acquisition and analysis systems detect an anomaly in data packet transmission, they use a reverse engineering approach to check each front-end device (i.e., the communication client and communication server) for anomalies. If an anomaly is found, the access policy is readjusted to ensure accurate data access. However, this method of troubleshooting and preventing abnormal access is relatively passive, inefficient, and lacks intelligence. In practical applications, it can negatively impact product quality and user experience.
[0030] In another related technology, a data collection system filters illegally accessed data packets based on IP addresses, allowing legitimate IP addresses to access corresponding data packets and prohibiting illegitimate IP addresses from accessing corresponding data packets. However, since it is impossible to accurately locate and resolve the source of the problem of illegally accessed data packets, even if the illegally accessed data packets are filtered, the problem of illegally accessed data packets and network resource consumption still persists.
[0031] According to an embodiment of the present disclosure, by adding an abnormal access identification system between the data packet aggregator and the data acquisition system, the abnormal access identification system can execute the data access anomaly identification method according to the embodiment of the present disclosure, so as to accurately identify whether an abnormality occurs in the process of data packets between mobile communication networks accessing the data acquisition device based on the statistical information in the target statistical record. In the event of an abnormality, the type and source of the abnormality can be accurately determined through further analysis of the statistical information of the abnormality, thereby ensuring the timeliness of discovering the source of the fault, thereby helping to quickly repair access fault problems that occur in the IP communication system and its data acquisition system. In some embodiments, the process of data packets between mobile communication networks accessing the data acquisition device is through methods such as optical splitting and copying, and the present disclosure is not limited to this.
[0032] FIG2 is a flowchart of a method for identifying data access anomalies provided by an embodiment of the present disclosure.
[0033] 2 , an embodiment of the present disclosure provides a method for identifying data access anomalies, including the following steps S1 to S2 .
[0034] In step S1, statistical information in a first statistical record is updated according to a first address pair corresponding to a received data packet to obtain a target statistical record, wherein the first address pair is information capable of identifying a source network element and a destination network element of the data packet.
[0035] In step S2, it is identified whether the statistical information in the target statistical record is abnormal.
[0036] According to an embodiment of the present disclosure, by updating the statistical information in the first statistical record, a target statistical record is obtained, thereby accurately identifying whether an abnormality occurs in the process of data packets between mobile communication networks being accessed by the data acquisition device based on the statistical information in the target statistical record. In the event that an abnormality occurs in the statistical information in the target statistical record, the abnormal statistical information can be further analyzed to accurately determine the type of abnormality and the network element device that caused the abnormality (i.e., the source of the abnormality). In addition, since the statistical information records the transmission of data packets by the first address within a cumulative range, the identification of abnormalities in the statistical information in the target statistical record can effectively ensure the timeliness of discovering the source of the fault.
[0037] The first statistical record is the most recently updated statistical record. It is updated sequentially based on the most recent statistical record (i.e., the first statistical record) according to the first address pair corresponding to the received data packet, thereby ensuring real-time identification of data access anomalies. The disclosed embodiments do not impose any specific restrictions on the format of the statistical record; it can be a table, a database storing statistical information, or other storage format that can effectively store statistical information.
[0038] In some embodiments, before S1, the method further includes: creating the first statistical record according to the target address pair in the preset working parameter table.
[0039] The target address pair in the pre-set working parameter table can also be referred to as working parameter information in the working parameter table. The first statistical record created based on the working parameter information is the initial statistical record before being updated. The fields of the first statistical record, the target statistical record, and the initial statistical record are all the same. That is, the first statistical record can be updated based on the initial statistical record, and the target statistical record is a statistical record obtained by updating the first statistical record. The fields of the statistical record include at least the first address pair, so that when updating the first statistical record, the record item to be updated can be determined based on the first address pair.
[0040] Abnormal statistical information refers to one or more record items in the target statistical record that have been identified and are in an abnormal state. Each record item in an abnormal state corresponds to a first address pair. Analysis of the abnormal statistical information and its corresponding first address pair can determine the source and type of the abnormality. The source of the abnormality refers to the network element that caused the abnormal state. Specifically, it can be the source network element corresponding to the first address pair, the destination network element, or both the source network element and the destination network element. The abnormality type refers to the classification of the abnormal state. By determining the source and type of the abnormality, the source of the fault can be quickly discovered, helping to quickly repair access faults.
[0041] In some embodiments, the first address pair includes a source Internet Protocol IP address corresponding to the source network element and a destination IP address corresponding to the destination network element; or, the first address pair includes a source signaling point address number corresponding to the source network element and a destination signaling point address number corresponding to the destination network element.
[0042] In this embodiment, the first address pair is information that can identify the source network element and destination network element of a data packet. The source network element of a data packet refers to the message sender of the data packet, and the destination network element of a data packet refers to the message receiver of the data packet. In different network architectures, the information used to identify the source network element and the destination network element can be the same or different. In a network architecture based on the Internet Protocol (IP), an IP address uniquely identifies a network element device. That is, the source IP address uniquely identifies the source network element, and the destination IP address uniquely identifies the destination network element. In a network architecture based on protocols related to signaling control, a signaling point code (SPC) is an address number set to identify each signaling point (including signaling transfer points) in a signaling network. Each signaling point has a unique address number used for routing signaling messages within the signaling network. Since signaling point codes are independent, a network element device can be uniquely identified by its signaling point address number. That is, the source signaling point address number uniquely identifies the source network element, and the destination signaling point address number uniquely identifies the destination network element.
[0043] The embodiments of the present disclosure do not impose special restrictions on the network architecture. For network architectures corresponding to protocols other than Internet Protocol (IP) and non-signaling control-related protocols, information that can uniquely identify the source network element and the destination network element can be used as an address pair.
[0044] In some embodiments, the statistical information includes at least one of the following: a valid flag, used to identify the legitimacy of transmitting data packets through the first address pair; the number of data packets, used to identify the total number of times the first address pair transmits data packets in the corresponding transmission direction; the latest time, used to identify the time point when the first address pair last transmitted a data packet; and the initial time, used to identify the time point when the first address pair first transmitted a data packet.
[0045] In this embodiment, the fields of the statistical record include at least one address pair and its statistical information, wherein the address pair is a necessary field in the statistical record, and the statistical information records the statistical situation of data packets transmitting data at the address pair. In other words, each address pair in the field of the statistical record is fixed and unchanged. In some embodiments, address pairs can be managed by adding, subtracting, deleting, and modifying, but their changes do not change with the statistical situation of the data packets. The statistics corresponding to the address pair will change with the statistical situation of the data packets. For example, the number of data packets corresponding to the address pair "10.0.1.1" and "10.0.1.2" will increase by 1 when the data packet corresponding to the address pair is received. It should be noted that the necessary fields in the statistical record may also include the transmission direction corresponding to the address pair, the interface name corresponding to the address pair, etc., but this disclosure is not limited to this. The address pair includes information about at least two addresses corresponding to the source network element and the destination network element. The transmission direction corresponding to the address pair refers to the path or flow direction of the data packet transmitted in the address pair.
[0046] The valid mark in the statistical information is used to identify the legality of the data packet transmitted through the address pair, so that it can be determined whether the data packet corresponding to the first address pair is an illegally accessed data packet based on the validity or invalidity of the valid mark. The number of data packets is used to identify the total number of data packets transmitted by the first address pair in the corresponding transmission direction, so that it can be determined whether the address pair has data access in the corresponding transmission direction based on the number of data packets. It can also be determined whether there are abnormal conditions such as unilateral non-access anomalies, bilateral non-access anomalies, or message disproportion based on the number of data packets for the same first address pair in different transmission directions. The transmission time includes the latest time and the initial time, wherein the latest time and the initial time are used to identify the time point of the first address pair's most recent data packet transmission and the time point of the first data packet transmission, respectively. The latest time and the initial time can be used to assist in determining whether there are abnormal conditions such as unilateral non-access anomalies, bilateral non-access anomalies, or message disproportion.
[0047] In some embodiments, before S1, the process further includes: performing protocol layer parsing processing on the data packet to obtain a first address pair corresponding to the data packet.
[0048] In embodiments of the present disclosure, a data packet is typically encapsulated and transmitted across multiple protocol layers. Protocol layer parsing of the data packet refers to parsing the data packet layer by layer, extracting information from each protocol layer as needed, and thereby obtaining a first address pair. In some embodiments, protocol layer parsing may include decapsulation, field parsing, and protocol header parsing of the data packet, but the present disclosure is not limited thereto.
[0049] As an example, the first data packet obtained by aggregation is subjected to protocol layer parsing. The protocol corresponding to the protocol layer of the first data packet is the Internet Protocol IP. Therefore, the first data packet is subjected to protocol layer parsing. The Source Address field corresponding to the IP protocol layer of the first data packet is used as the source IP. The source IP can identify the source network element of the first data packet. The Destination Address field corresponding to the IP protocol layer of the first data packet is used as the destination IP. The destination IP can identify the destination network element of the first data packet, thereby determining that the first address pair corresponding to the first data packet is the source IP and the destination IP.
[0050] In some embodiments, after performing protocol layer parsing on the data packet and obtaining the first address pair corresponding to the data packet, it also includes: searching for target industrial parameter information of the first address pair corresponding to the data packet in a pre-set industrial parameter table; when the target industrial parameter information is found, forwarding the data packet to the data acquisition system, and / or recording the valid mark of the target statistical information of the first address pair corresponding to the data packet as valid; or, when the target industrial parameter information is not found, recording the valid mark of the target statistical information of the first address pair corresponding to the data packet as invalid.
[0051] In an embodiment of the present disclosure, a pre-set working parameter table is generated based on working parameter information (i.e., target address pairs). Working parameter information is the equipment layout information of a real communication network, which is deterministic and unique, and is conducive to ensuring the accuracy of illegal access judgment. The embodiment of the present disclosure does not impose any special restrictions on the method of obtaining working parameter information. It can be directly obtained and imported from the operating manufacturer, or it can be obtained by configuration. The necessary information items in the working parameter information include at least one target address pair, and the target address pairs are all legal address pairs. In some embodiments, the working parameter information may also include the name of the source network element corresponding to the target address pair, the name of the destination network element, and the interface name, etc., and the present disclosure is not limited to this. The name of the source network element corresponding to the target address pair, the name of the destination network element corresponding to the target address pair, and the interface name, etc. are all optional information items in the working parameter information.
[0052] The pre-set working parameter table records the information of the target address pairs corresponding to legally accessed data packets. Since the working parameter table is generated based on the working parameter information, and the necessary information items in the working parameter information include at least one target address pair, in some embodiments, the target address pairs in the working parameter information can be used as the legally accessed address pairs to generate the working parameter table. Each address pair in the working parameter table corresponds one-to-one to a target address pair in the working parameter information.
[0053] Since the pre-set industrial parameter table records the information of the target address pair corresponding to the legally accessed data packet, after parsing the first address pair of the data packet, by searching the industrial parameter table for target industrial parameter information consistent with the first address pair (i.e., the address pair corresponding to the legally accessed data packet), it is possible to determine whether the data packet corresponding to the first address pair is legally accessed. In the case that the target industrial parameter information consistent with the first address pair (i.e., the target address pair) can be found, the data packet is determined to be a legally accessed data packet, the data packet corresponding to the first address pair can be collected, and the data packet is forwarded to the data acquisition system. In some embodiments, in the case that the target industrial parameter information is not found, the data packet corresponding to the first address pair is discarded, and the valid mark of the target statistical information of the first address pair corresponding to the data packet is recorded as invalid. That is, in the case that the target industrial parameter information is not found, the data packet is determined to be an illegally accessed data packet, and the data packet corresponding to the first address pair is discarded, thereby filtering the illegally accessed data packet, avoiding the continued collection and analysis of the illegally accessed data packet, and improving the system performance and the accuracy of data analysis.
[0054] It should be noted that the initial statistical record is also created based on the engineering parameter information of the target address pair. The fields in the initial statistical record include the fields in the engineering parameter information. For example, if the fields in the engineering parameter information include the target address pair (source IP address and destination IP address), transmission direction, and interface name, then the fields in the initial statistical record also include the target address pair (source IP address and destination IP address), transmission direction, and interface name. And because the necessary information items in the engineering parameter information include at least one target address pair, the address pair is also a necessary information item in the fields of the initial statistical record. In addition, the fields in the initial statistical record can also include statistical information corresponding to the address pair, such as the above-mentioned valid mark, number of data packets, latest time, initial time, etc.
[0055] The following describes an initial creation rule for creating an initial statistical record (ie, a first statistical record that has not been updated) based on the work parameter information including at least one target address pair.
[0056] The fields in the initial statistical record include the target address pair. If the engineering parameter information also includes optional information items (such as the name of the source network element corresponding to the target address pair, the name of the destination network element corresponding to the target address pair, and the interface name), corresponding fields can also be generated based on these optional information items. The fields related to statistical information in the initial statistical record can be set according to actual needs.
[0057] Import the target address pair in the working parameter information as the address pair in the initial statistical record to obtain the target address pair and its corresponding transmission direction of the initial statistical record; import the optional information items in the working parameter information as the optional information items in the initial statistical record; set the valid information in the statistical information corresponding to the imported address pair to valid (e.g., set to TRUE), set the number of data packets in the statistical information corresponding to the imported address pair to the initial value (e.g., set the initial value to 0), set the latest time in the statistical information corresponding to the imported address pair to an invalid value (e.g., set the initial value to 0), and set the initial time in the statistical information corresponding to the imported address pair to an invalid value (e.g., set the initial value to 0).
[0058] It should be noted that the address pairs in the initial statistical record correspond one-to-one to the target address pairs in the work parameter information, but after the initial statistical record is updated, the statistical record may also include the address pairs and statistical information corresponding to the illegally accessed data packets.
[0059] As an example, the process of determining the transmission direction corresponding to the address pair of the initial statistical record based on the target address pair in the imported working parameter information is: the data packet transmitted from the user side to the network side is regarded as having an upstream transmission direction (i.e., the source IP address is the IP address of the user side, and the destination IP address is the IP address of the network side), and the data packet transmitted from the network side to the user side is regarded as having a downstream transmission direction (i.e., the source IP address is the IP address of the network side, and the destination IP address is the IP address of the user side).
[0060] As another example, the work parameter information is obtained by directly obtaining and importing it from the operating manufacturer.
[0061] As shown in Table 1:
[0062] Table 1
[0063] The user-side IP address and the network-side IP address are required information items in the engineering parameter information, while the user-side network element name, the network-side network element name, and the interface name are optional information items in the engineering parameter information.
[0064] Generate a pre-set working parameter table based on the working parameter information in Table 1.
[0065] As shown in Table 2:
[0066] Table 2
[0067] The first pair of addresses in the industrial parameter table is: the user side IP address is 10.0.1.1, and the network side IP address is 10.0.1.2; the second pair of addresses is: the user side IP address is 10.0.2.2, and the network side IP address is 10.0.2.1. There is a one-to-one correspondence between the address pairs in the industrial parameter table and the target address pairs in the industrial parameter information in Table 1.
[0068] The initial statistical information is created based on the work parameter information in Table 1.
[0069] As shown in Table 3:
[0070] Table 3
[0071] The source IP address is the address information of the source network element, and the destination IP address is the address information of the destination network element. The source IP address and destination IP address form an address pair. Each address pair corresponds to one statistical information item. Data packets transmitted from the user side to the network side are considered to be transmitted in the uplink direction, while data packets transmitted from the network side to the user side are considered to be transmitted in the downlink direction. The interface name corresponding to the destination address pair in the initial statistical information is consistent with the interface name in the engineering parameter information. The valid information corresponding to the destination address pair in the initial statistical information is uniformly set to the initial value "valid". Data packets transmitted by these address pairs with valid information are all legally received data packets. The packet count corresponding to the destination address pair in the initial statistical information indicates the total number of data packets received in this transmission direction for this destination address pair. Since data packet aggregation has not yet been performed when the initial statistical information is created, the packet count is set to the initial value of 0. The initial time corresponding to the destination address pair in the initial statistical information indicates the time when the first data packet was received in this transmission direction for this destination address pair. Since data packet aggregation has not yet been performed when the initial statistical information is created, the initial time is set to the initial value of 0. The latest time corresponding to the destination address pair in the initial statistical information is used to identify the time point of the last data packet received by the destination address pair and the transmission direction. Since data packet aggregation has not been performed when the initial statistical information is created, the latest time is set to the initial value 0.
[0072] When the second data packet is collected, protocol layer parsing is performed on the second data packet, and the first address pair corresponding to the second data packet is found to be the source IP address 10.0.2.2 and the destination IP address 10.0.2.1. By searching the first address pair corresponding to the second data packet in Table 2 (i.e., the industrial parameter table), the destination address pair corresponding to the second data packet can be found. Therefore, the second data packet is a legally accessed data packet and can be collected.
[0073] When the third data packet is aggregated, protocol layer parsing is performed on the third data packet, and the first address pair corresponding to the third data packet is found to be the source IP address 10.0.2.5 and the destination IP address 10.0.2.6. By searching for the first address pair corresponding to the third data packet in Table 2 (i.e., the industrial parameter table), no destination address pair corresponding to the third data packet is found. Therefore, the third data packet is an illegally accessed data packet and is discarded to prevent further collection and analysis of the illegally accessed third data packet.
[0074] FIG3 is a flowchart of a specific implementation of step S1 in the method for identifying abnormal data access provided by an embodiment of the present disclosure.
[0075] 3 , in some embodiments, step S1 includes the following steps S11 to S122 .
[0076] In step S11 , a target address pair is searched in the first statistical record, wherein the target address pair is consistent with the first address pair corresponding to the data packet.
[0077] In step S121, when the target address pair is found, the statistical information corresponding to the target address pair in the first statistical record is updated according to the first address pair to obtain a target statistical record.
[0078] In step S122, if the target address pair is not found, the first address pair is added to the first statistical record and statistical information of the first address pair is configured according to the first address pair to obtain a target statistical record.
[0079] In an embodiment of the present disclosure, statistics are collected for all the data packets that are aggregated. That is, regardless of whether the corresponding target working parameter information of the data packet can be found in the working parameter table, the data packet needs to be updated in the first statistical record. A target address pair that is consistent with the first address pair is searched in the first statistical record. If the target address pair is found, it is determined that the first address pair has been counted before. The updated target statistical record can be obtained by directly updating the statistical information based on the found target address pair. If the target address pair is not found, it means that the first address pair has not been counted before. It is necessary to create a new record item for the first address pair in the first statistical record, that is, add the first address pair and configure the statistical information of the first address pair to obtain the target statistical record.
[0080] It should be noted that in some embodiments, since the address pairs corresponding to legal access in the statistical information are imported through the work parameter information when the initial statistical information is created, if the target address pair is not found from the first statistical record, it can be determined that the first address pair is illegal, that is, the data packet corresponding to the first address pair is illegally accessed.
[0081] In some embodiments, updating the statistical information corresponding to the target address pair in the first statistical record (ie, step S121 ) includes: updating the number of data packets and / or transmission time corresponding to the target address pair in the first statistical record.
[0082] In this embodiment, the transmission time includes the initial time of the first transmission of the data packet corresponding to the target address pair and the latest time of the most recent transmission of the data packet.
[0083] As an example, updating the statistical information corresponding to the target address pair in the first statistical record (i.e., step S121) includes at least one of the following: adding 1 to the number of data packets corresponding to the target address pair in the first statistical record; updating the latest time corresponding to the target address pair in the first statistical record to the current time point; updating the initial time and the latest time corresponding to the target address pair in the first statistical record to the current time point.
[0084] In this embodiment, a target address pair that is consistent with the first address pair is found, and it is determined that the corresponding statistical information existed before for the first address pair. In the case where the statistical information includes the number of data packets, it is necessary to add 1 to the number of data packets in the statistical information to indicate that the total number of times the address pair corresponding to the statistical information transmits data packets in the corresponding transmission direction is added by 1. In the case where the statistical information includes the latest time, the latest time is updated to the current time point to indicate that the current time point is the moment when the address pair most recently transmitted a data packet in the corresponding transmission direction. In the case where the statistical information includes the initial time, and the data packet transmitted this time is the first time that the target address pair transmits a data packet, both the initial time and the latest time are updated to the current time point to indicate that the current time point is the moment when the address pair first and most recently transmitted a data packet in the corresponding transmission direction.
[0085] In some embodiments, adding the first address pair in the first statistical record and configuring the statistical information of the first address pair (i.e., step S122) includes: adding at least one of the number of data packets, valid mark, and transmission time corresponding to the first address pair in the first statistical record; the added valid mark indicates that the first address pair is illegal.
[0086] In this embodiment, if the target address pair is not found, it means that the first address pair is an illegal address pair, and the data packet transmitted through the illegal first address pair is invalid. Therefore, when configuring the statistical information of the first address pair, the valid mark of the first address pair is determined to be invalid.
[0087] As an example, configuring the statistical information of the first address pair (i.e., step S122) includes at least one of the following: setting the number of data packets corresponding to the first address pair to 1; setting the valid mark corresponding to the first address pair to invalid; setting the initial time corresponding to the first address pair to the current time point; setting the latest time corresponding to the first address pair to the current time point.
[0088] In this embodiment, if the target address pair consistent with the first address pair is not found, it is determined that the first address pair does not have corresponding statistical information before, that is, it is not recorded by the first statistical record. In the case where the statistical information includes the number of data packets, the number of data packets in the statistical information needs to be set to 1 to indicate that the total number of times the first address pair corresponding to the statistical information transmits data packets in the corresponding transmission direction is 1. In the case where the statistical information includes a valid mark, the valid mark is set to invalid to indicate that the transmission of data packets by the first address pair in the corresponding transmission direction is an illegal access. In the case where the statistical information includes an initial time, the initial time is set to the current time point to indicate that the current time point is the moment when the first address pair first transmits a data packet in the corresponding transmission direction. In the case where the statistical information includes the latest time, the latest time is set to the current time point to indicate that the current time point is the moment when the first address pair last transmitted a data packet in the corresponding transmission direction.
[0089] In some embodiments, step S2 includes: determining that there is an abnormality in the statistical information when the first address pair of the statistical information is illegal; determining that there is an abnormality in the statistical information when the number of data packets in the statistical information is abnormal; and determining that there is an abnormality in the statistical information when the transmission time of the statistical information is abnormal.
[0090] As an example, when the first address pair of the statistical information is illegal, determining that the statistical information is abnormal includes: when the valid mark of the statistical information is invalid, determining that the statistical information is abnormal.
[0091] As another example, when an abnormality occurs in the number of data packets in the statistical information, determining that an abnormality exists in the statistical information includes: determining that an abnormality exists in the statistical information when the number of data packets corresponding to the first transmission direction of the statistical information is less than a first preset number and the number of data packets corresponding to the second transmission direction is greater than or equal to a second preset number; determining that an abnormality exists in the statistical information when the number of data packets corresponding to the first transmission direction of the statistical information is less than a third preset number and the number of data packets corresponding to the second transmission direction is less than a fourth preset number; determining that an abnormality exists in the statistical information when the difference between the number of data packets corresponding to the first transmission direction and the number of data packets corresponding to the second transmission direction of the statistical information is greater than or equal to a fifth preset number.
[0092] As another example, when the transmission time of the statistical information is abnormal, determining that the statistical information is abnormal includes: when the number of data packets in the statistical information changes and the latest time does not change, determining that the statistical information is abnormal.
[0093] In some embodiments, when there is anomaly in the statistical information in the target statistical record, the method further includes step S3.
[0094] In step S3, the abnormality type corresponding to the abnormal statistical information is determined, wherein the abnormality type includes at least one of illegal access, unilateral non-access abnormality, bilateral non-access abnormality, message disproportion, and midway non-access abnormality.
[0095] In the embodiment of the present disclosure, since the valid information is used to identify the legitimacy of transmitting a data packet through an address pair, when the valid mark of the abnormal statistical information is invalid, the abnormal type corresponding to the abnormal statistical information is illegal access.
[0096] Since the number of data packets is used to identify the total number of data packets transmitted by the address pair in the corresponding transmission direction, at least three types of exceptions may occur: unilateral non-access exception, bilateral non-access exception, or message disproportion.
[0097] A unilateral non-access exception refers to a situation where the number of data packets corresponding to the first transmission direction of the exception statistical information is less than the first preset number and the number of data packets corresponding to the second transmission direction is greater than or equal to the second preset number. In this case, a non-access exception occurs in the first transmission direction corresponding to the address pair, but the data packet can be accessed normally in the second transmission direction corresponding to the address pair. This is equivalent to a non-access exception in one of the two different transmission directions of the same address pair (i.e., the first transmission direction).
[0098] A bilateral non-access anomaly occurs when the number of packets corresponding to the first transmission direction in the anomaly statistics information is less than a third preset number and the number of packets corresponding to the second transmission direction is less than a fourth preset number. A non-access anomaly occurs in both the first and second transmission directions corresponding to the address pair, and the source of the anomaly is the network element identified by the address pair corresponding to the first and second transmission directions. In some embodiments, the third and fourth preset numbers are set to 0.
[0099] Message disproportionality means that, when the difference between the number of packets corresponding to the first transmission direction and the number of packets corresponding to the second transmission direction in the abnormal statistical information is greater than or equal to a fifth preset number, the number of packets transmitted in the first transmission direction is disproportionate to the number of packets transmitted in the second transmission direction. It should be noted that message disproportionality can indicate either an abnormal state or a normal state of the network element, depending on the specific service.
[0100] Since the latest time is used to identify the time point when the address pair last transmitted a data packet, if the number of data packets in the abnormal statistical information changes within a cumulative time range and the latest time does not change, it means that the address pair has not transmitted any data packets after the latest time. That is, the abnormality type corresponding to the abnormal statistical information is a mid-connection abnormality.
[0101] It should be noted that the first preset number, the second preset number, the third preset number, the fourth preset number and the fifth preset number may be the same number or different numbers, and the present disclosure is not limited thereto.
[0102] In some embodiments, the target statistical records are displayed in the form of a visual interface so that users can intuitively understand the address pairs where abnormal conditions occur and their statistical information, so that they can accurately locate the network element devices (source network elements and / or destination network elements) that cause the abnormal conditions, the abnormality type, the time when the abnormality occurs, the time when the abnormality is eliminated, etc., to provide guidance for troubleshooting and provide a visual basis for tracking the progress of troubleshooting.
[0103] In some embodiments, when there is an abnormality in the statistical information in the target statistical record, the method further includes at least one of the following: when the first address pair of the statistical information is illegal, determining the source network element identified by the first address pair as the abnormal source of the statistical information; when the number of data packets corresponding to the first transmission direction of the statistical information is less than a first preset number and the number of data packets corresponding to the second transmission direction is greater than or equal to a second preset number, determining the source network element identified by the first address pair as the abnormal source of the statistical information; when the number of data packets corresponding to the first transmission direction of the statistical information is less than a third preset number and the number of data packets corresponding to the second transmission direction is less than a fourth preset number, determining the source network element and the destination network element identified by the first address pair as the abnormal sources of the statistical information; when the difference between the number of data packets corresponding to the first transmission direction and the number of data packets corresponding to the second transmission direction of the statistical information is greater than or equal to a fifth preset number, determining the source network element and the destination network element identified by the first address pair as the abnormal sources of the statistical information; when the number of data packets in the statistical information changes and the latest time does not change, determining the destination network element identified by the first address pair as the abnormal source of the statistical information.
[0104] In the embodiment of the present disclosure, the abnormal source refers to the network device that causes the statistical information of the abnormal type to appear.
[0105] The illegality of the first address pair in the statistical information specifically means that the first address pair is inconsistent with the address pair specified in the work parameter information. Therefore, the source of the abnormality is the source network element identified in the address pair. That is to say, the source network element generates an illegally accessed data packet, resulting in an illegal access problem when the data packet is transmitted through the address pair.
[0106] In the case of a unilateral non-access exception, that is, the number of data packets corresponding to the first transmission direction of the statistical information is less than the first preset number and the number of data packets corresponding to the second transmission direction is greater than or equal to the second preset number, the data packets have a non-access exception in the first transmission direction corresponding to the first address pair, and can be accessed normally in the second transmission direction corresponding to the first address pair, which is equivalent to a non-access exception in one of the two different transmission directions of the same address pair (that is, the first transmission direction), so the source of the exception is the source network element identified by the address pair corresponding to the first transmission direction.
[0107] In the case of bilateral non-access anomaly, that is, the number of data packets corresponding to the first transmission direction of the statistical information is less than the third preset number and the number of data packets corresponding to the second transmission direction is less than the fourth preset number, the data packets have non-access anomalies in both the first transmission direction and the second transmission direction corresponding to the address pair. Therefore, the source of the anomaly is the network element identified by the address pair corresponding to the first transmission direction and the second transmission direction, that is, anomalies have occurred in both the source network element and the destination network element.
[0108] In the case of disproportionate messages, that is, the difference between the number of data packets corresponding to the first transmission direction and the number of data packets corresponding to the second transmission direction of the statistical information is greater than or equal to the fifth preset number, the number of data packets transmitted in the first transmission direction is disproportionate to the number of data packets transmitted in the second transmission direction, and therefore the source of the abnormality is the source network element and the destination network element identified by the address pair.
[0109] In the case of no access exception in the middle, that is, when the number of data packets in the abnormal statistical information changes within a cumulative time range and the latest time does not change, it means that the address pair has not transmitted any data packets after the latest time, so the source of the exception is the destination network element identified by the address pair corresponding to the abnormal statistical information.
[0110] The present disclosure does not specifically limit the analysis process of the target statistical records. In some embodiments, abnormal statistical information and its corresponding abnormal source and / or abnormal type can also be identified from the target statistical records through manual analysis.
[0111] As an example, data packet access starts at 00:00 on 2024-01-01. Table 4 below shows the second statistical information corresponding to 06:00 on 2024-01-01.
[0112] Table 4
[0113] As shown in Table 4, the source IP address 10.0.1.1 and the destination IP address 10.0.1.2 are an address pair with an upstream transmission direction, while the source IP address 10.0.1.2 and the destination IP address 10.0.1.1 are an address pair with a downstream transmission direction. From 00:00 on January 1, 2024, to 06:00 on January 1, 2024, the validity flag is valid, indicating that the data packets corresponding to this address pair have legal access. The number of data packets transmitted in the upstream direction for this address pair is 6,000,000, while the number of data packets transmitted in the downstream direction for this address pair is 0. The first preset number and the second preset number are both 0. Abnormal statistical information has occurred in the downstream transmission direction. The abnormality type is a unilateral non-access abnormality. The source of the abnormality is the network element with the source IP address 10.0.1.2 in the downstream transmission direction. Access in the upstream transmission direction is normal.
[0114] The source IP address 10.0.2.1 and the destination IP address 10.0.2.2 are an address pair with an upstream transmission direction. The source IP address 10.0.2.2 and the destination IP address 10.0.2.1 are an address pair with a downstream transmission direction. From 00:00 on January 1, 2024, to 06:00 on January 1, 2024, the validity flag is valid, indicating that the data packets corresponding to this address pair have legal access. The number of data packets transmitted in both the upstream and downstream directions for this address pair is 0, and the fourth preset number is 0. Abnormal statistical information occurs in both the upstream and downstream transmission directions. The abnormality type is a bilateral non-access abnormality. The sources of the abnormality are the network element with the address 10.0.2.1 and the network element with the address 10.0.2.2.
[0115] The source IP address 10.0.3.1 and the destination IP address 10.0.3.2 are an address pair with an upstream transmission direction. The source IP address 10.0.3.2 and the destination IP address 10.0.3.1 are an address pair with a downstream transmission direction. From 00:00 on January 1, 2024 to 06:00 on January 1, 2024, the valid mark is valid, indicating that the data packets corresponding to this address pair are legally accessed. The number of data packets transmitted in both the upstream and downstream directions for this address pair is 1,000,000. Combined with the latest time, it can be seen that the address pair last transmitted a data packet in both the upstream and downstream directions at 01:00 on 2024-01-01. Analysis shows that the address pair has experienced an anomaly type of mid-way bilateral access failure since 01:00 on 2024-01-01. The sources of the anomaly are the network elements with addresses 10.0.3.1 and 10.0.3.2.
[0116] The address pair with source IP address 20.0.0.1 and destination IP address 20.0.0.2 had the first access time at 00:00 on 2024-01-01 and the most recent access time at 06:00 on 2024-01-01 between 00:00 and 06:00 on 2024-01-01. The number of packets was 6,000,000 and the valid flag was invalid, indicating that the packets corresponding to this address pair were illegally accessed.
[0117] The address pair with source IP address 20.0.0.2 and destination IP address 20.0.0.1 had the first access time at 00:00 on 2024-01-01 and the most recent access time at 06:00 on 2024-01-01 between 00:00 and 06:00 on 2024-01-01. The number of packets was 6,000,000 and the valid flag was invalid, indicating that the packets corresponding to this address pair were illegally accessed.
[0118] FIG4 is a flowchart of a specific implementation of step S4 in the method for identifying abnormal data access provided by an embodiment of the present disclosure.
[0119] 4 , in some embodiments, after S3 , step S4 is further included.
[0120] In step S4, when there is an abnormality in the statistical information in the target statistical record, the abnormality elimination situation corresponding to the abnormal statistical information is determined.
[0121] In the embodiments of the present disclosure, based on the analysis of the target statistical record, it is possible to quickly locate whether an abnormality occurs in the network element corresponding to the address pair corresponding to the statistical information, and to quickly and accurately locate the abnormality type and / or abnormality source. Analyzing the abnormality type and abnormality source can guide rapid and thorough troubleshooting. By analyzing the changes in the target statistical record of the statistical information with abnormalities, it is possible to effectively determine the abnormality elimination situation corresponding to the abnormal statistical information, that is, to determine whether the abnormal source of the abnormal statistical information has been processed, so that data packets can be transmitted normally through the address pair, and continuous tracking of data packets corresponding to the address pair of the abnormal statistical information is achieved, thereby deriving the progress of troubleshooting. The present disclosure does not make special restrictions on the abnormality elimination situation, and may include the abnormality resolution situation (for example, whether the abnormality is partially resolved or completely resolved), the abnormality resolution time, etc.
[0122] It should be noted that the timing of the occurrence of the abnormal statistical information can be further determined based on the abnormal statistical information and its dynamic changes. The timing of the occurrence of the abnormal statistical information here can be an access exception when the program is started, or an access exception during the operation of the program. This disclosure is not limited to this.
[0123] In some embodiments, when the abnormality type of the statistical information is a unilateral non-access abnormality, a bilateral non-access abnormality, or a midway non-access abnormality in the first transmission direction, determining the abnormality exclusion situation corresponding to the abnormal statistical information (i.e., step S4) includes: when the change corresponding to the statistical information is that the number of data packets corresponding to the first transmission direction and the second transmission direction is greater than or equal to a sixth preset number, and the latest time changes synchronously with the number of data packets, determining that the abnormality exclusion situation corresponding to the abnormal statistical information is that the abnormality has been repaired.
[0124] In this embodiment, if the abnormality type of the abnormal statistical information in the target statistical record is a unilateral non-access abnormality in the first transmission direction, a bilateral non-access abnormality in the first transmission direction and the second transmission direction, or a midway non-access abnormality, but after analyzing the changes in the abnormal statistical information, it is determined that the number of data packets in the abnormal statistical information has returned to normal counting, and the latest time is synchronized with the change in the number of data packets, then it means that the address pair has restored access to data packets, and therefore the abnormal exclusion situation corresponding to the abnormal statistical information is that the abnormality has been repaired.
[0125] In some embodiments, when the abnormality type of the statistical information is illegal access, determining the abnormality exclusion situation corresponding to the abnormal statistical information (i.e., step S4) includes: when the valid mark corresponding to the abnormal statistical information is invalid within a preset time period and the number of data packets and the latest time have not changed, determining that the abnormality exclusion situation corresponding to the statistical information is that the abnormality has been repaired.
[0126] In this embodiment, if the abnormality type of the statistical information in the target statistical record is illegal access, but after analyzing the changes in the statistical information, it is determined that the number of data packets and the latest time of the statistical information no longer change, then it means that no new illegal access data packets are generated, indicating that the access failure caused by the illegal access address has been eliminated, and the time of eliminating the failure is the time point corresponding to the latest time field, so the abnormality elimination situation corresponding to the statistical information is that the abnormality has been repaired.
[0127] As another example, data packets are accessed starting at 00:00 on January 1, 2024. After identifying the statistical information in Table 4 at 06:00 on January 1, 2024, the following abnormal statistical information is determined:
[0128] 1) The source IP address is 10.0.1.2, and the destination IP address is 10.0.1.1. The corresponding statistical information for the address pair with the transmission direction being downlink is the statistical information of unilateral non-access exception.
[0129] 2) The statistical information corresponding to the address pair with the source IP address 10.0.2.1 and the destination IP address 10.0.2.2 (transmission direction is upstream) and the address pair with the source IP address 10.0.2.2 and the destination IP address 10.0.2.1 (transmission direction is downstream) is the statistical information of bilateral non-access anomalies;
[0130] 3) The source IP address 10.0.3.1 and the destination IP address 10.0.3.2 are the address pairs with the transmission direction being upstream. The source IP address 10.0.3.2 and the destination IP address 10.0.3.1 are the address pairs with the transmission direction being downstream. The corresponding statistical information is the statistical information of the mid-way bilateral non-access anomaly.
[0131] 4) The statistical information corresponding to the address pair with the source IP address 20.0.0.1 and the destination IP address 20.0.0.2 is the statistical information of illegal access;
[0132] 5) The statistical information corresponding to the address pair with the source IP address of 20.0.0.2 and the destination IP address of 20.0.0.1 is the statistical information of illegal access.
[0133] The fault is corrected between 06:00 on January 1, 2024 and 08:00 on January 1, 2024. Based on Table 4, data aggregation statistics are continued. The resulting Table 5 is the third statistical information corresponding to 08:00 on January 1, 2024.
[0134] Table 5
[0135] By analyzing the statistical information of the anomalies (1) to (5) and their changes in Tables 4 and 5, it can be seen that during the period from 06:00 on 2024-01-01 to 08:00 on 2024-01-01:
[0136] 1) The source IP address is 10.0.1.2, and the destination IP address is 10.0.1.1. The transmission direction is downlink. The corresponding exception type is unilateral access failure. The anomaly troubleshooting status is that the anomaly has been fixed. Referring to the initial time, it can be seen that the fault was fixed at 07:00 on 2024-01-01.
[0137] 2) For the address pairs with source IP address 10.0.2.1 and destination IP address 10.0.2.2 (transmission direction is uplink), and for the address pairs with source IP address 10.0.2.2 and destination IP address 10.0.2.1 (transmission direction is downlink), the exception type corresponding to the bilateral access failure statistics is resolved. The initial time indicates that the fault was resolved at 07:00 on January 1, 2024.
[0138] 3) The source IP address 10.0.3.1 and the destination IP address 10.0.3.2 are address pairs with an upstream transmission direction. The source IP address 10.0.3.2 and the destination IP address 10.0.3.1 are address pairs with a downstream transmission direction. The corresponding exception type is a mid-way bilateral non-access exception. The exception exclusion situation of the statistical information is that the exception of the upstream address pair has been fixed, but the abnormal state of the downstream address pair still exists. Therefore, the exception type of the downstream address pair is changed to a unilateral non-access exception.
[0139] 4) The abnormality elimination status of the statistical information corresponding to the abnormality type of illegal access for the address pair with the source IP address of 20.0.0.1 and the destination IP address of 20.0.0.2 is that the abnormality has been fixed. According to the latest time, the fault was eliminated at 06:00 on 2024-01-01;
[0140] 5) The abnormality elimination status of the statistical information of the illegal access corresponding to the address pair with the source IP address of 20.0.0.2 and the destination IP address of 20.0.0.1 is that the abnormality has been fixed. Referring to the latest time, it can be seen that the fault was eliminated at 06:00 on 2024-01-01.
[0141] According to the above-mentioned embodiment of the present disclosure, by updating the statistical information of the first address pair in the first statistical record, the target statistical record is obtained, so that whether an abnormality occurs in the process of data packets between mobile communication networks accessing the data acquisition device can be accurately identified based on the statistical information in the target statistical record. In the event of an abnormality, the type of abnormality can be accurately determined by analyzing the statistical information of the abnormality. The network element device corresponding to the address pair where the abnormality occurs can also be determined based on the type of abnormality, thereby ensuring the timeliness of discovering the source of the fault.
[0142] Furthermore, on the basis of quickly locating the type and source of anomalies, it is also possible to track the results of fault repairs through continuous tracking of statistical information to completely eliminate abnormal access problems, reduce the workload of the data collection process, improve system performance, and enhance the network quality of data packet analysis and the accuracy of user behavior.
[0143] 5 , an embodiment of the present disclosure provides an electronic device, comprising: one or more processors 501; and a memory 502 on which one or more programs are stored. When the one or more programs are executed by one or more processors, the one or more processors implement a method for identifying data access anomalies according to various embodiments of the present disclosure.
[0144] As shown in FIG. 5 , the electronic device may further include one or more I / O interfaces 503 connected between the processor 501 and the memory 502 and configured to implement information interaction between the processor 501 and the memory 502 .
[0145] The processor 501 is a device with data processing capabilities, including but not limited to a central processing unit (CPU); the memory 502 is a device with data storage capabilities, including but not limited to random access memory (RAM, more specifically SDRAM, DDR, etc.), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), and flash memory (FLASH); the I / O interface (read-write interface) 503 is connected between the processor 501 and the memory 502, and can realize information exchange between the processor 501 and the memory 502, including but not limited to a data bus (Bus), etc.
[0146] 6 , an embodiment of the present disclosure provides a computer-readable medium having a computer program stored thereon. When the program is executed by a processor, the method for identifying data access anomalies according to various embodiments of the present disclosure is implemented.
[0147] An embodiment of the present disclosure provides a computer program product, which stores program instructions. When the program instructions are executed on a computer, the computer implements the method for identifying data access anomalies according to various embodiments of the present disclosure.
[0148] In a specific embodiment, the above-mentioned computer program product can be used to implement each step of the method for identifying data access anomalies according to various embodiments of the present disclosure.
[0149] In order to enable those skilled in the art to more clearly understand the technical solutions provided by the embodiments of the present disclosure, the technical solutions provided by the embodiments of the present disclosure are described in detail below through specific examples.
[0150] Example 1
[0151] FIG7 is a schematic diagram of the structure of an exemplary abnormal access identification system provided by an embodiment of the present disclosure.
[0152] Referring to Figures 1 and 7 , according to an embodiment of the present disclosure, an abnormal access identification system is added between the data packet aggregator and the data acquisition system to implement the data access anomaly identification method according to various embodiments of the present disclosure. The statistical record format in this embodiment is a table. The abnormal access identification system includes a configurator, a data packet receiver, a data packet transmitter, a data packet parser, a data packet counter, and a data packet access display.
[0153] The configurator is used to configure the abnormal access identification system. For example, the configurator controls whether the abnormal access identification system, located between the data packet aggregator and the data acquisition system, enables the data access anomaly identification function. Another example is the configurator importing industrial parameter information to generate an industrial parameter table and create an initial statistical table (i.e., a first, unupdated statistical table).
[0154] The data packet receiver is used to establish and maintain a communication link between the abnormal access identification system and the data packet aggregator, and is also used to forward all data packets received by the data packet aggregator to the data packet parser.
[0155] The packet parser is used to perform protocol layer parsing on all packets forwarded by the packet receiver to obtain key information (i.e., the first address pair), construct a statistics request message based on the key information, and send the statistics request message to the packet counter. The packet parser is also used to filter all packets forwarded by the packet receiver, that is, to compare the key information of the packet (i.e., the first address pair) with the address pairs in the working parameter table pre-set by the configurator. If an address pair that matches the key information can be found in the working parameter table, it indicates that the packet has been legally accessed and the packet is sent to the packet transmitter. Otherwise, the packet is illegally accessed and is discarded.
[0156] The data packet transmitter is used to establish and maintain a communication link between the abnormal access identification system and the data acquisition system, and is also used to forward the data packets transmitted after filtering by the data packet parser to the data acquisition system.
[0157] The packet counter receives statistics request messages from the packet analyzer and updates the statistics table based on the statistics request messages. The statistics table stores the statistics of all address pairs corresponding to the packets, so that it can be provided to the packet access display for visualization.
[0158] The data packet access displayer is used to display the statistical table maintained by the data packet counter in the form of a visual interface, so that users can intuitively understand the address pairs of abnormal access data packets and their statistical information, and can accurately locate the abnormal source (network element device), abnormal type, abnormal occurrence time, and abnormal elimination time of the data packet that causes abnormal access, provide guidance for troubleshooting, and provide a visual basis for tracking the progress of troubleshooting.
[0159] The following describes the process of implementing the data access anomaly identification method in each module of the abnormal access identification system.
[0160] In step 701, the configurator imports the engineering parameter information into the abnormal access identification system to generate an engineering parameter table and create an initial statistical table. The engineering parameter information includes: address pairs (a set of user-side IP addresses and network-side IP addresses), user-side network element names, network-side network element names, and interface names. The statistical table fields include: address pairs (a set of source IP addresses and destination IP addresses), valid flag, number of packets, and transmission time (initial time and latest time).
[0161] In step 702, the packet parser performs protocol layer parsing on all packets received by the packet receiver from the packet aggregator to obtain a first address pair (i.e., key information) corresponding to each packet. Based on the parsed first address pair, the parsed packet parser constructs a statistics request message and sends the statistics request message to the packet counter for access packet statistics. The first address pair includes a source IP address and a destination IP address.
[0162] In step 703, the data packet parser searches the industrial parameter table based on the parsed first address pair. If an address pair consistent with the first address pair is successfully found in the industrial parameter table, the data packet is forwarded to the data packet transmitter so that the data packet transmitter sends the data packet to the data acquisition system. Otherwise, the data packet is discarded.
[0163] Step 704: The data packet counter updates the statistical table according to the first address in the received statistical request message, and sends the statistical information in the updated statistical table to the data packet access display for visual interface display.
[0164] In Example 1 of the present disclosure, by analyzing the updated statistical table, the statistical information corresponding to various types of exceptions (unilateral non-access exceptions, bilateral non-access exceptions, midway non-access exceptions, illegal access, etc. in the first transmission direction) can be quickly and accurately located, and displayed through a visual interface through a data packet access display, allowing users to more intuitively understand the cause of the abnormal state (the source of the abnormality) and quickly and accurately troubleshoot the problem.
[0165] Example 2
[0166] FIG8 is a schematic diagram of a processing flow of a data packet parser in an exemplary abnormal access identification system provided by an embodiment of the present disclosure.
[0167] 1 , 7 and 8 , the processing procedure of the data packet parser is described.
[0168] Step 801: A data packet parser receives a data packet from a data packet transmitter, wherein the data packet transmitter forwards all data packets received by a data packet aggregator to the data packet parser.
[0169] In step 802 , the data packet analyzer determines whether the abnormal access automatic identification function of the abnormal access identification system is enabled. If enabled, step 803 is executed; otherwise, step 808 is executed.
[0170] Step 803: The data packet analyzer performs protocol layer analysis on the data packet to obtain key information of the data packet (ie, the first address pair). The key information includes the source IP address and the destination IP address.
[0171] Step 804: The data packet parser constructs a statistics request message according to the key information of the data packet, and sends the statistics request message to the data packet counter.
[0172] In step 805, the data packet analyzer searches the preset working parameter table based on the key information (source IP address and destination IP address).
[0173] In step 806, the data packet analyzer determines whether an address pair that matches the key information can be found in the pre-set work parameter table. If so, step 808 is executed; otherwise, step 807 is executed.
[0174] Step 807: If no address pair consistent with the key information can be found in the work parameter table, it indicates that the data packet is an illegally accessed data packet (ie, the key information corresponding to the data packet is invalid), and the data packet parser discards the data packet.
[0175] In step 808, if an address pair that matches the key information can be found in the work parameter table, the packet is considered a legitimate access packet (i.e., the key information corresponding to the packet is valid), and the packet parser forwards the packet to the packet transmitter. Alternatively, if the abnormal access automatic identification function of the abnormal access identification system is not enabled, it is impossible to determine whether the packet is legitimate, and the packet parser forwards the packet to the packet transmitter.
[0176] In Example 2 of the present disclosure, the received data packet is parsed by a data packet parser to obtain key information of the source network element and the destination network element of the data packet. The key information can be used to determine whether the data packet is legally accessed. The key information can uniquely determine the source network element and the destination network element, which is conducive to accurately judging illegally accessed data packets.
[0177] Example 3
[0178] FIG9 is a schematic diagram of a processing flow of a data packet counter in an exemplary abnormal access identification system provided by an embodiment of the present disclosure.
[0179] 1 , 7 and 9 , the processing process of the data packet counter is described.
[0180] Step 901: The data packet counter receives a statistics request message sent by the data packet analyzer. The statistics request message carries key information of the data packet, including the source IP address and the destination IP address.
[0181] In step 902, the data packet counter performs a query in the first statistics table using the source IP address and the destination IP address.
[0182] Step 903 , determining whether an address pair consistent with the source IP address and the destination IP address can be found in the first statistical table. If so, executing step 904 ; if not, executing step 905 .
[0183] In step 904, if the packet counter finds a matching source IP address and destination IP address in the first statistical table, this indicates that the source IP address and destination IP address have been previously counted by the first statistical table. The statistical information in the first statistical table is updated. More specifically, the packet number field is incremented by 1, and the latest time field is updated to the current time point.
[0184] In step 905, if the packet counter fails to find an address pair that matches the source IP address and destination IP address in the first statistical table, this indicates that the source IP address and destination IP address have never been counted in the first statistical table before. A new statistical record entry needs to be created in the first statistical table for the source IP address and destination IP address pair, i.e., the first address pair is added and the statistical information for the first address pair is configured. More specifically, the source IP address is set to the source IP address carried in the statistics request message, the destination IP address is set to the destination IP address carried in the statistics request message, the valid flag field is set to invalid, the number of packets field is set to 1, and the latest time field and the initial time field are set to the current time point.
[0185] In Example 3 of the present disclosure, data packets are counted through a data packet counter to count the number of data packets (i.e., the number of data packets) and the data packet access time (e.g., the initial time, the latest time), thereby presenting statistical information about the address pair, so as to facilitate clearer presentation of statistical information when there are abnormalities in the statistical information (e.g., abnormal access IP address pairs, abnormality types, abnormality occurrence time, abnormality sources, etc.).
[0186] It will be appreciated by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware implementations, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As is well known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable, and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those skilled in the art that communication media typically embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.
[0187] Example embodiments have been disclosed herein, and although specific terms are employed, they are used and should be interpreted only in a general illustrative sense and not for purposes of limitation. In some instances, it will be apparent to those skilled in the art that, unless otherwise expressly indicated, features, characteristics, and / or elements described in conjunction with a particular embodiment may be used alone or in combination with features, characteristics, and / or elements described in conjunction with other embodiments. Therefore, it will be understood by those skilled in the art that various changes in form and detail may be made without departing from the scope of the present disclosure as set forth in the appended claims.
Claims
1. A method for identifying data access anomalies, comprising: updating statistical information in the first statistical record according to a first address pair corresponding to the received data packet to obtain a target statistical record, wherein the first address pair is information capable of identifying a source network element and a destination network element of the data packet; Identify whether there is any anomaly in the statistical information of the target statistical record.
2. The method for identifying data access anomalies according to claim 1, wherein: The first address pair includes a source Internet Protocol IP address corresponding to a source network element and a destination IP address corresponding to a destination network element, or The first address pair includes a source signaling point address number corresponding to a source network element and a destination signaling point address number corresponding to a destination network element.
3. The method for identifying data access anomalies according to claim 1, wherein: Updating statistical information in the first statistical record according to the first address pair corresponding to the received data packet to obtain a target statistical record includes: Searching for a destination address pair in the first statistical record, wherein the destination address pair is consistent with the first address pair corresponding to the data packet; When the target address pair is found, the statistical information corresponding to the target address pair in the first statistical record is updated according to the first address pair to obtain the target statistical record; or In the case that the target address pair is not found, the first address pair is added to the first statistical record and statistical information of the first address pair is configured according to the first address pair to obtain the target statistical record.
4. The method for identifying data access anomalies according to claim 3, wherein: Updating statistical information corresponding to the target address pair in the first statistical record includes: The number of data packets and / or transmission time corresponding to the target address pair in the first statistical record is updated.
5. The method for identifying data access anomalies according to claim 3, wherein: Adding the first address pair to the first statistical record and configuring statistical information of the first address pair includes: At least one of the number of data packets, the valid flag, and the transmission time corresponding to the first address pair is added to the first statistical record, wherein the added valid flag indicates that the first address pair is illegal.
6. The method for identifying data access anomalies according to claim 1, wherein: The statistical information includes at least one of the following: A valid flag, used to identify the legitimacy of transmitting a data packet through the first address pair; The number of data packets is used to identify the total number of data packets transmitted by the first address pair in the corresponding transmission direction; Latest time, used to identify the time point when the first address pair last transmitted a data packet; The initial time is used to identify the time point when the first address pair transmits a data packet for the first time.
7. The method for identifying data access anomalies according to claim 6, wherein: Identifying whether the statistical information in the target statistical record is abnormal includes at least one of the following: If the first address pair of the statistical information is illegal, determining that an abnormality exists in the statistical information; In the case where the number of data packets in the statistical information is abnormal, determining that the statistical information is abnormal; When the transmission time of the statistical information is abnormal, it is determined that the statistical information is abnormal.
8. The method for identifying data access anomalies according to claim 1, wherein: When there is an anomaly in the statistical information in the target statistical record, the method further includes: Determine the abnormal type corresponding to the abnormal statistical information, The abnormality type includes at least one of illegal access, unilateral non-access abnormality, bilateral non-access abnormality, message disproportion, and midway non-access abnormality.
9. The method for identifying data access anomalies according to claim 1, wherein: When the statistical information in the target statistical record is abnormal, the method further includes at least one of the following: In a case where the first address pair of the statistical information is illegal, determining the source network element identified by the first address pair as the abnormal source of the statistical information; When the number of data packets corresponding to the first transmission direction of the statistical information is less than a first preset number and the number of data packets corresponding to the second transmission direction is greater than or equal to a second preset number, determining the source network element identified by the first address pair as the abnormal source of the statistical information; When the number of data packets corresponding to the first transmission direction of the statistical information is less than a third preset number and the number of data packets corresponding to the second transmission direction is less than a fourth preset number, determining the source network element and the destination network element identified by the first address pair as the abnormal source of the statistical information; If a difference between the number of data packets corresponding to the first transmission direction and the number of data packets corresponding to the second transmission direction of the statistical information is greater than or equal to a fifth preset number, determining the source network element and the destination network element identified by the first address pair as the abnormal source of the statistical information; In a case where the number of data packets in the statistical information changes and the latest time does not change, the destination network element identified by the first address pair is determined as the abnormal source of the statistical information.
10. The method for identifying data access anomalies according to any one of claims 1 to 9, wherein: Before updating the statistical information in the first statistical record according to the first address pair corresponding to the received data packet to obtain the target statistical record, the method further includes: The first statistical record is created according to the target address pair in the preset working parameter table.
11. The method for identifying data access anomalies according to any one of claims 1 to 9, further comprising: Searching for target working parameter information of the first address pair corresponding to the data packet in a preset working parameter table; When the target work parameter information is found, the data packet is forwarded to a data acquisition system, and / or a valid mark of the target statistical information of the first address pair corresponding to the data packet is recorded as valid; or In the case that the target work parameter information is not found, the validity mark of the target statistical information of the first address pair corresponding to the data packet is recorded as invalid.
12. An electronic device comprising: one or more processors; as well as a memory having one or more programs stored thereon, When the one or more programs are executed by the one or more processors, the one or more processors implement the method for identifying data access anomalies according to any one of claims 1 to 11.
13. A computer-readable medium having a computer program stored thereon, wherein when the program is executed by a processor, the method for identifying data access anomalies according to any one of claims 1 to 11 is implemented.
14. A computer program product, comprising a computer program or computer instructions, wherein the computer program or the computer instructions are stored in a computer-readable storage medium, a processor of a computer device reads the computer program or the computer instructions from the computer-readable storage medium, and the processor executes the computer program or the computer instructions, so that the computer device executes the method for identifying data access anomalies according to any one of claims 1 to 11.
Citation Information
Patent Citations
Abnormal behavior detection method and device, equipment and storage medium
CN117254970A
Abnormal IPv4 address identification method and device, storage medium and electronic equipment
CN117596031A
Fixed-line telephone abnormity identification method and device, and storage medium
CN117768578A
System and method for intercepting and controling source address spoofed abnormal traffic
KR1020090132787A