Traffic detection for network device

WO2026200411A1PCT designated stage Publication Date: 2026-10-01CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2026/080606
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-28
Filing Date
2026-02-28
Publication Date
2026-10-01

Smart Images

  • Figure CN2026080606_01102026_PF_FP_ABST
    Figure CN2026080606_01102026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a traffic detection method for a network device, a device, a system, a product, and a storage medium. The method comprises: acquiring an original traffic difference of a network device at a target time point, the original traffic difference being determined on the basis of a difference between a sum of total incoming traffic and self-generated traffic of the network device and total outgoing traffic of the network device; correcting the original traffic difference at the target time point on the basis of an original traffic difference at a time point adjacent to the target time point, so as to obtain a corrected traffic difference at the target time point; acquiring corrected traffic difference data distribution of time points within a target time window where the target time point is located, and determining, on the basis of the corrected traffic difference data distribution, whether the corrected traffic difference is a candidate abnormal value; and when the corrected traffic difference is determined as the candidate abnormal value, comparing the corrected traffic difference with historical traffic difference statistical information of a historical time window to determine whether a traffic anomaly exists in the network device.
Need to check novelty before this filing date? Find Prior Art

Description

Traffic detection of network devices Technical Field

[0001] This disclosure relates to the field of traffic detection technology, and in particular to traffic detection of network devices. Background Technology

[0002] Network devices such as routers and switches play a crucial role in network change detection, risk identification, and discovery. Network traffic doesn't appear or disappear out of thin air; therefore, detecting and analyzing network device traffic helps identify anomalies. Consequently, accurately detecting network device traffic is a pressing technical challenge. Summary of the Invention

[0003] To overcome the problems existing in related technologies, this disclosure provides a method, device, system, product and storage medium for detecting network device traffic.

[0004] According to a first aspect of the present disclosure, a traffic detection method for a network device is provided. The method includes: obtaining an original traffic difference of the network device at a target time point, the original traffic difference being determined based on the difference between the sum of the total inflow traffic of the network device and the traffic generated by the network device itself, and the total outflow traffic of the network device; correcting the original traffic difference of the target time point based on the original traffic differences of adjacent time points to obtain a corrected traffic difference of the target time point; obtaining the data distribution of the corrected traffic difference of time points within a target time window where the target time point is located, and determining whether the corrected traffic difference is a candidate outlier based on the data distribution of the corrected traffic difference; if it is determined to be a candidate outlier, comparing the corrected traffic difference with the historical traffic difference statistics of a historical time window to determine whether to output a traffic alarm message for the network device.

[0005] According to a second aspect of the present disclosure, a network device traffic detection system is provided, the detection system including a detection device and a network device, the detection device being used to perform the steps of the method described in the first aspect.

[0006] According to a third aspect of the present disclosure, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method embodiments described in the first aspect above.

[0007] According to a fourth aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored, wherein the computer program, when executed by a processor, implements the steps of the method embodiments described in the first aspect above.

[0008] According to a fifth aspect of the present disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the method embodiments described in the first aspect.

[0009] The technical solutions provided by the embodiments of this disclosure can include the following beneficial effects: In the embodiments of this disclosure, the original traffic difference of the network device at the target time point is determined based on the difference between the sum of the total inflow traffic of the network device and the traffic generated by the network device itself, and the total outflow traffic of the network device. Therefore, it can avoid the deviation in difference calculation caused by ignoring the traffic generated by the device itself. Furthermore, this embodiment corrects the original traffic difference at the target time point based on the original traffic difference at adjacent time points. Therefore, short-term noise can be smoothed over a short period of time to obtain an accurate corrected traffic difference after noise reduction. Further, this embodiment determines candidate outliers based on the data distribution of the corrected traffic difference within the target time window, thereby enabling dynamic candidate outlier judgment based on the current time. Statistical information from historical time windows is used to further verify the current candidate outliers to accurately confirm whether the network device has experienced traffic anomalies. Therefore, this embodiment, through the processing flow of correction, data distribution analysis, and historical verification, can achieve accurate detection of network device traffic.

[0010] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0011] Figure 1A is a flowchart illustrating a traffic detection method for a network device according to an exemplary embodiment of this disclosure.

[0012] Figure 1B is a schematic diagram of a traffic detection system for a network device according to an exemplary embodiment of the present disclosure.

[0013] Figure 2A is a traffic diagram of a network device according to an exemplary embodiment of this disclosure.

[0014] Figure 2B is a schematic diagram of alarm information of a network device according to an exemplary embodiment of the present disclosure.

[0015] Figure 2C is a schematic diagram of traffic data of a network device according to an exemplary embodiment of the present disclosure.

[0016] Figure 3 is a hardware structure diagram of a computer device containing a network device traffic detection device according to an exemplary embodiment of the present disclosure.

[0017] Figure 4 is a block diagram of a traffic detection device for a network device according to an exemplary embodiment of the present disclosure. Detailed Implementation

[0018] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.

[0019] The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the disclosure. The singular forms “a,” “the,” and “the” as used in this disclosure and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.

[0020] It should be understood that although the terms first, second, third, etc., may be used in this disclosure to describe various information, such information should not be limited to these terms. These terms are used only to distinguish information of the same type from one another. For example, without departing from the scope of this disclosure, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."

[0021] The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data shall comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points shall be provided for users to choose to authorize or refuse.

[0022] Network devices such as routers and switches play a crucial role in network change detection, risk identification, and discovery. Since traffic doesn't appear or disappear out of thin air within a network topology, monitoring and analysis based on traffic characteristics helps detect anomalies in network devices.

[0023] Network traffic does not appear or disappear out of thin air under normal circumstances. Therefore, a detection scheme can be designed based on the principle of traffic conservation. The principle of traffic conservation states that the total inflow traffic Sin to a network device is equal to the sum of the traffic consumed by the device and the total outflow traffic Sout.

[0024] The methods for measuring network device traffic can include the following.

[0025] 1) Differentiated Services Code Point (DSCP) coloring: This scheme can accurately calculate non-conservative traffic / packet loss, with advantages of accuracy and strong noise reduction capabilities. However, its disadvantages include high requirements for equipment and its hardware and software, typically smaller coverage, and the need for precise design based on the topology path to provide sufficient coverage.

[0026] 2) Collect data from the device counter, including internal traffic, inflow and outflow traffic, protocol-related traffic, and traffic generated by proactive packet sending from the Central Processing Unit (CPU), and calculate whether the traffic is conserved within the error range. The advantage is clear meaning, but it presents significant challenges in terms of data collection complexity, scale, and cost.

[0027] 3) Collect the inbound and outbound traffic of the network device's ports, and treat other data as other variables. The advantage is its simplicity, but the disadvantage is that the inbound and outbound traffic of the ports cannot be collected at the same time, thus failing to align the time base points. This can lead to discrepancies between the collected data, resulting in errors in the detection results.

[0028] Based on this, the embodiments described herein provide a traffic detection scheme for network devices, which can obtain accurate detection results. The embodiments of this disclosure will now be described in detail.

[0029] As shown in Figure 1A, which is a flowchart of a traffic detection method for a network device according to an exemplary embodiment of the present disclosure, the method includes the following steps.

[0030] In step 102, obtain the original traffic difference of the network device at the target time point.

[0031] The original traffic difference refers to the difference between the sum of the total inflow traffic of the network device and the traffic generated by the network device itself, and the total outflow traffic of the network device.

[0032] In step 104, based on the original flow difference between adjacent time points of the target time point, the original flow difference of the target time point is corrected to obtain the corrected flow difference of the target time point.

[0033] In step 106, obtain the distribution of traffic difference data for time points within the target time window where the target time point is located, and determine whether the corrected traffic difference is a candidate outlier based on the distribution of traffic difference data.

[0034] In step 108, if a candidate outlier is identified, the corrected traffic difference is compared with the historical traffic difference statistics of the historical time window to determine whether the network device has experienced traffic anomalies.

[0035] As an example, a network device may include any device responsible for communication over the network, including but not limited to routers, switches, repeaters, load balancers, or gateways. As an example, a network device may have one or more ports, and other devices can be connected to these ports using cables. In this embodiment, other devices connected to the ports of the network device are referred to as neighboring devices.

[0036] As an example, the method of this embodiment is applied to a detection terminal, which can be a program deployed on a computer device. The computer device on which the detection terminal is deployed in this embodiment can be arbitrary; for example, the computer device can be configured to deploy the detection terminal. This computer device can be another device independent of the network device, and the computer device can obtain the network device's traffic data through wired or wireless connections. Alternatively, the detection terminal can also be deployed on a user device, and this embodiment does not limit this.

[0037] As an example, the traffic detection method of this embodiment can perform one or more detections on a network device. For instance, this embodiment can run continuously in a loop to continuously detect the network device. Optionally, the detection method of this embodiment can be applied to the traffic detection of multiple network devices, as long as the traffic information of each detected network device can be obtained.

[0038] Figure 1B is a schematic diagram of a network device traffic detection system according to an exemplary embodiment of this disclosure. The traffic detection system may include detection devices and network devices. The detection devices are used to execute a network device traffic detection method embodiment. The number of detection devices and network devices in the system can be arbitrary, and this embodiment does not limit this.

[0039] As an example, a traffic data collection program can run in a network device. This program can collect traffic information of the network device, including but not limited to: inbound traffic to each port of the network device, outbound traffic to each port, traffic generated by the network device itself, and non-forwarded traffic consumed by the network device itself.

[0040] Figure 2A illustrates the traffic flow of a network device according to an exemplary embodiment of this disclosure; wherein, the neighboring devices of device A include device B1, device B2, etc. The principle of traffic conservation can be expressed by the following formula (eq1): Sin + xin = Sout + xout;

[0041] Sin represents the total inflow traffic from each neighboring device to device A, collected from each port of device A; Sout represents the total outflow traffic from device A to each neighboring device, collected from each port of device A; xin represents the outflow traffic generated by device A itself, which can be obtained by collecting the traffic generated within the CPU of device A; xout represents the non-forwarded traffic consumed by device A itself.

[0042] xout is usually a very small proportion of the traffic between devices. If we ignore it and assume it is 0, then the above formula eq1 can be simplified to the following formula (eq2): Sin + xin = Sout.

[0043] In this embodiment, Sin and Sout are calculated by the difference between two consecutive data collections; in other words, the program collects the inflow traffic of each port to obtain Sin, and then collects the outflow traffic of each port to obtain Sout. Therefore, Sin and Sout cannot be collected at the same time, and there will be a time difference between them. Considering the traffic deviation e caused by the deviation in the collection time of Sin and Sout, the formula eq2 can be slightly adjusted to the following formula eq3: Sin + xin = Sout + e.

[0044] Therefore, the original flow difference in step 102 can be e here, i.e., "Sin + xin - Sout"; of course, it is also optional to use formula eq1 and consider xout to determine the original flow difference, i.e., e can also be "Sin + xin - Sout - xout", and this embodiment does not limit this.

[0045] Network devices normally adhere to the principle of traffic conservation. However, malfunctions can lead to non-conservation of traffic. Examples include traffic congestion (where traffic exceeding bandwidth is dropped during forwarding) and black hole phenomena (where traffic is dropped without being forwarded). Therefore, when traffic non-conservation occurs, a traffic difference can be calculated. However, as mentioned in the previous embodiments, the calculated traffic difference is subject to deviations due to differences in the collection times of outflow and inflow traffic. Consequently, the original traffic difference contains noise. This embodiment performs noise reduction processing on the original traffic difference in step 104.

[0046] In step 104, the original flow difference at the target time point can be corrected based on the original flow difference between adjacent time points to obtain the corrected flow difference at the target time point. Adjacent time points can be one or more, and can be time points before or after the target time point; this embodiment does not limit this. That is, this embodiment aims to minimize the noise in the original flow difference at the target time point through temporal context correlation. Similarly, the original flow difference between adjacent time points can be obtained, and the continuity of the flow difference in the time dimension can be used to correct the original flow difference at the target time point. In this embodiment, the corrected flow difference at the target time point is referred to as the corrected flow difference.

[0047] Optionally, the correction method can be configured according to actual needs. For example, the average of the original flow difference between the target time point and adjacent time points can be calculated to correct the original flow difference at the target time point, or the correction can be based on the average of the original flow differences at multiple adjacent time points. In specific correction, the average can be directly used as the corrected flow difference at the target time point, or the original flow difference at the target time point can be adjusted based on the difference or ratio between the average and the original flow difference at the target time point.

[0048] After obtaining the noise-reduced corrected traffic difference at the target time point, in step 106, this embodiment uses data distribution to achieve dynamic anomaly detection. Traditional traffic anomaly detection typically uses a static threshold method (such as setting an alarm when the traffic difference exceeds a certain absolute value). However, network traffic has periodic fluctuations and sudden business growth, and a fixed threshold cannot adapt to dynamic changes. Moreover, anomalies may be hidden in the long tail region of the data distribution. Therefore, this embodiment designs a method based on the traffic difference data distribution within the target time window to achieve dynamic identification.

[0049] As an example, the target time window can be a time range encompassing the target time point. The length of the target time window can be configured according to actual needs, and the frequency of time points used within a time window can also be configured according to actual needs; this embodiment does not impose any limitations on this. The target time window can include time points before the target time point, and may or may not include time points after the target time point. In the case where the target time window includes m (m≥1) time points after the target time point, it can be understood that this embodiment can detect the network device's traffic at the target time point using a delayed m time point approach.

[0050] As an example, data distribution refers to the arrangement and frequency of data points within a specific interval, describing the central tendency, dispersion, shape, and overall characteristics of a dataset. In this embodiment, a dataset consisting of corrected flow difference values ​​at various time points within a target time window can be obtained to obtain the corrected flow difference data distribution. As an example, the corrected flow difference data distribution in this embodiment can be described by parameters such as mean, median, mode, and variance or standard deviation. These statistics provide a measure of the central location and dispersion of the data distribution. Alternatively, the shape of the data distribution can be obtained, such as normal, symmetrical, skewed, or kurtosis, etc.

[0051] As an example, the distribution of the corrected flow difference data can be used to determine whether a corrected flow difference is a candidate outlier. For instance, a normal range can be determined based on the distribution of the corrected flow difference data; if the corrected flow difference is within the normal range, it is considered not a candidate outlier; otherwise, it is considered a candidate outlier. The normal range can be determined based on some statistical information of the corrected flow difference data distribution, such as one or more of the mean, median, mode, standard deviation, or variance. For example, the normal range can be determined based on the mean of the dataset, or based on the median, or by combining multiple statistical information such as the mean and median. Alternatively, the normal range can be determined by combining the mean and standard deviation. In practical applications, other methods such as the interquartile range method or the 3σ principle can also be used; this embodiment does not limit this approach.

[0052] If the corrected traffic difference is not a candidate anomaly, the network device's traffic at the target time point can be considered normal; if the corrected traffic difference is a candidate anomaly, step 108 can be further executed. In this embodiment, candidate anomalies are further filtered using historical statistical information to reduce the false alarm rate. The design concept of this embodiment is that "anomalies are not absolute, but rather deviations from historical norms." Therefore, this embodiment introduces historical traffic difference statistics from historical time windows to achieve accurate alarm decisions.

[0053] The number of historical time windows can be one or more, and this embodiment does not limit this. Historical traffic difference statistics can be set according to actual needs, including but not limited to mean, median, mode, variance, or standard deviation. Therefore, based on the historical traffic difference statistics between the corrected traffic difference and the historical time window, it can be determined whether to output a traffic alarm message for the network device. For example, it can be determined whether to output a traffic alarm message based on the difference between the corrected traffic difference and the historical traffic difference statistics. For example, if the difference between the corrected traffic difference and the historical traffic difference statistics is large, it is determined that a traffic alarm message needs to be output; if the difference is small, it is determined that a traffic alarm message does not need to be output. The difference between the corrected traffic difference and the historical traffic difference statistics can be implemented in various ways. For example, it can be the difference with any of the aforementioned historical traffic difference statistics; the specific difference can be the difference value, the absolute value of the difference, or a ratio. Alternatively, it can be the comprehensive difference between the corrected traffic difference and multiple historical traffic difference statistics; this comprehensive difference can be obtained based on the difference between the corrected traffic difference and each of the historical traffic difference statistics.

[0054] As can be seen from the above embodiments, the original traffic difference of the network device at the target time point in this embodiment is determined based on the difference between the sum of the total inflow traffic of the network device and the traffic generated by the network device itself, and the total outflow traffic of the network device. Therefore, it can avoid the deviation in difference calculation caused by ignoring the traffic generated by the device itself. Furthermore, this embodiment corrects the original traffic difference at the target time point based on the original traffic difference at adjacent time points. Therefore, short-term noise can be smoothed out over a short period of time to obtain an accurate corrected traffic difference after noise reduction. Further, this embodiment determines candidate outliers based on the data distribution of the corrected traffic difference within the target time window, thereby enabling dynamic candidate outlier judgment based on the current time. Statistical information from historical time windows is used to further verify the current candidate outliers to accurately confirm whether to issue an alarm. Therefore, this embodiment, through the processing flow of correction, data distribution analysis, and historical verification, can achieve accurate detection of network devices and improve alarm accuracy.

[0055] In some examples, to improve noise reduction accuracy, the original flow difference at the target time point is corrected based on the original flow difference between adjacent time points to obtain the corrected flow difference at the target time point. This may include: obtaining a first absolute value of the average of the original flow difference between the target time point and the previous time point, and a second absolute value of the average of the original flow difference between the target time point and the next time point; determining the corrected flow difference based on the smaller of the first absolute value and the second absolute value; or, calculating the average of the original flow differences corresponding to the k time points before the target time point, the target time point, and the k time points after the target time point, and determining the corrected flow difference based on the calculated average; wherein, k is an integer greater than or equal to 1.

[0056] The above content provides two noise reduction implementation methods, and one of them can be selected according to actual needs in practical applications. One of the implementation methods is based on the idea of ​​local smoothing, that is, based on the flow difference between adjacent time points before and after the target time point, it corrects for possible sudden fluctuations at the target time point, thereby avoiding single-point noise interference.

[0057] Specifically, the first absolute value can be obtained by averaging the original flow differences between the target time point and the previous time point. Similarly, the second absolute value can be obtained by averaging the original flow differences between the target time point and the next time point. The smaller of the first and second absolute values ​​can be used as the corrected flow difference. This calculation process can be referenced in the following formula (eq4):

[0058] Where Dt is the original flow difference at the target time point, Dt-1 is the original flow difference at the time point before the target time point, and Dt+1 is the original flow difference at the time point after the target time point; min indicates taking the smaller one. To correct the flow difference.

[0059] Thus, this embodiment can refer to the original traffic difference between two time points before and after the target time point and correct the original traffic difference at the target time point to a corrected traffic difference. In this way, this embodiment only needs to delay by one time point to enable timely detection of network devices. At the same time, since it compares the absolute value of the traffic difference at the target time point with the sum of the traffic differences at the adjacent time points before and after it, the combination with the least fluctuation is selected for averaging, thereby reducing the sudden changes in single-point traffic difference caused by instantaneous noise.

[0060] In another embodiment, this can be understood as averaging the flow difference within a certain time window to suppress random fluctuations. This time window includes time points before and after the target time point, with the target time point in between. Specifically, the number of time points before and after the target time point is the same. Specifically, the original flow difference values ​​corresponding to the k time points before the target time point, the target time point, and the k time points after the target time point can be obtained, where k can be an integer greater than or equal to 1. This calculation process can be referenced in the following formula (eq5):

[0061] Thus, this embodiment can reduce the noise of the original flow difference at the target time point by using the average of the k time points before the target time point to the k time points after the target time point within a certain time window. This can accurately suppress possible random fluctuations in the corrected flow difference at the target time point.

[0062] In some cases, since traffic has both periodicity (such as a certain correlation at the same time every day) and randomness (also with certain business fluctuations), the algorithm should try to take into account the different data distributions that may occur in actual applications. This embodiment designs a data distribution adaptation process so that it can dynamically adapt to the actual data distribution under different data distributions to accurately identify candidate outliers.

[0063] The step of determining whether the corrected flow difference is a candidate outlier based on the data distribution of the corrected flow difference includes: checking whether the data distribution of the corrected flow difference conforms to a normal distribution; if it is determined to conform to a normal distribution, then determining whether the corrected flow difference is within the three standard deviations of the data mean in the target time window; if not, then determining that the corrected flow difference is a candidate outlier, otherwise, determining that the corrected flow difference is not a candidate outlier; if it is determined not to conform to a normal distribution, then obtaining the standard score of the corrected flow difference; if the standard score is not within a set range, then determining that the corrected flow difference is a candidate outlier, otherwise, determining that the corrected flow difference is not a candidate outlier; wherein, the set range is determined based on the data mean and standard deviation of the target time window.

[0064] In this embodiment, a data distribution test method can be used to test whether the distribution of the flow difference data conforms to a normal distribution. The test method can include the Kolmogorov-Smirnov Test (KS test). Alternatively, the Shapiro-Wilk Test (SW test) is also optional.

[0065] Assuming a normal distribution is followed, the 3σ principle can be used to determine whether the corrected flow difference is a candidate outlier. The 3σ principle states that if a variable follows a normal distribution with mean u and standard deviation σ, then 99% of the data will fall within u ± 3σ, meaning the probability of the data being distributed within the range (u - 3σ, u + 3σ) is 99%. Therefore, it can be determined whether the corrected flow difference falls within the interval (u - 3σ, u + 3σ). If it does, it is not a candidate outlier; otherwise, it is. This can be achieved by using the corrected flow differences at each time point within the target time window as the dataset, and calculating the mean and standard deviation of this dataset.

[0066] Assuming a normal distribution is followed, the Z-score of the adjusted flow difference can be used to determine whether it is a candidate outlier. The Z-score method is typically used to identify points that are too far from the mean, i.e., observations that fall in the tail of the normal distribution. Generally, if a data point's Z-score exceeds a certain threshold (usually 3 or -3), it can be considered an outlier. This is because, in a standard normal distribution, approximately 99.7% of data points fall within the range of the mean plus or minus 3 standard deviations. For example, if a data point has a Z-score of 4, it means that this point is 4 standard deviations above the mean, which is a very rare event in a normal distribution, therefore this data point is likely an outlier. The Z-score can be calculated using the following formula (eq6): Z=(X-μ) / σ

[0067] Where Z is the Z-score of data point X. X is the corrected flow difference at the target time point. μ is the mean of the dataset. σ is the standard deviation of the dataset.

[0068] Based on this, in this embodiment, if the absolute value of the Z-score of the corrected flow difference is greater than 3, the corrected flow difference can be considered as a candidate outlier; otherwise, it can be considered as not a candidate outlier.

[0069] As can be seen, this embodiment can dynamically select anomaly judgment rules based on data distribution. For the target time point, by dynamically identifying the data distribution pattern, the 3σ principle is selected for normal distribution, and the Z-score method is selected for non-normal distribution, thus enabling accurate judgment of candidate outliers.

[0070] In some examples, the historical time window includes: historical time windows of different lengths; the historical traffic difference statistics include: the historical mean and historical median of the corrected traffic difference at each time point within the historical time window; the step of comparing the corrected traffic difference with the historical traffic difference statistics of the historical time window to determine whether the network device has experienced traffic anomalies includes: for each historical time window, obtaining the degree of deviation of the corrected traffic difference relative to the historical traffic difference of that historical time window based on the differences between the corrected traffic difference and the historical mean and historical median of that historical time window; and determining whether the network device has experienced traffic anomalies based on the degree of deviation of the corrected traffic difference relative to the historical traffic difference of that historical time window.

[0071] As an example, there can be two or more historical time windows, and the specific number can be configured according to actual needs. Different historical time windows have different durations, so this embodiment can achieve accurate anomaly detection by comparing the historical traffic difference characteristics of multiple time windows. For example, short-period historical time windows can capture transient anomalies, while long-period historical time windows can filter periodic noise. If a certain corrected traffic difference is relatively large, but there are also large traffic differences in multiple historical time windows, then the corrected traffic difference that is identified as a candidate anomaly value is not a real anomaly, and no traffic alarm message needs to be output to the network device; conversely, if a certain corrected traffic difference is relatively small, but multiple historical time windows are almost all 0, then the corrected traffic difference is indeed an anomaly, and an alarm needs to be issued.

[0072] Based on this, to achieve the aforementioned effects, this embodiment designs multiple historical time windows and includes historical traffic difference statistics, including the historical mean and median of the corrected traffic difference at each time point within the historical time window. The historical mean and median of each historical time window can be understood as the historical baseline of the corrected traffic difference for that window. The mean is easily affected by extreme values, while the median, being an intermediate value, is not sensitive to outliers. Using these two statistical information within the historical time window is complementary, considering both overall trends and central tendency, and avoiding interference from outliers.

[0073] As an example, multiple historical time windows of different lengths can be used, including short-term, medium-term, or long-term historical time windows, to capture historical traffic patterns of network devices at different time scales and comprehensively assess whether the current traffic is abnormal. For example, historical windows of different lengths, such as 1 hour, 24 hours, or 7 days, can be set as needed in practical applications; this embodiment does not limit this.

[0074] Furthermore, it is possible to determine the degree of deviation of the corrected traffic difference at the target time point relative to the historical average and historical median of each historical time window, so as to determine whether the corrected traffic difference at the target time point is consistent with the history, and thus accurately determine whether an alarm needs to be issued.

[0075] The difference between the corrected flow difference and the historical mean of the historical time window can be a difference, an absolute value of the difference, or a ratio, etc. Similarly, the difference between the corrected flow difference and the historical median of the historical time window can be a difference, an absolute value of the difference, or a ratio, etc. In this embodiment, for each historical time window, the deviation of the corrected flow difference relative to the historical flow difference of that historical time window can be obtained by combining the difference between the corrected flow difference and the historical mean and the difference between the corrected flow difference and the historical median. For example, the two differences can be averaged or weighted averaged, etc., and this embodiment does not limit this.

[0076] Through the above processing, since there are multiple historical time windows, the degree of deviation of the corrected traffic difference relative to the historical traffic difference of each historical time window can be obtained. Therefore, this embodiment further integrates the degree of deviation of the corrected traffic difference relative to the historical traffic difference of each historical time window to determine whether to output a traffic alarm message for the network device. The larger the deviation, the lower the consistency between the corrected traffic difference at the target time point and the historical data. This can be implemented in various ways. For example, the deviations can be averaged or weighted, and then the value obtained is used to determine whether to output a traffic alarm message. Alternatively, a threshold can be set according to the actual application scenario, and the relationship between the obtained value and the set threshold can be used to determine whether to output a traffic alarm message.

[0077] Based on this, this embodiment employs multiple historical time windows of different lengths and designs historical traffic difference statistics, including historical mean and historical median. Thus, this embodiment can combine the difference between the corrected traffic difference and the historical mean, as well as the difference between the corrected traffic difference and the historical median, to comprehensively obtain the degree of deviation of the corrected traffic difference relative to the historical traffic difference of the historical time window. Furthermore, it can comprehensively obtain the degree of deviation of the corrected traffic difference relative to the historical traffic difference of each historical time window. Therefore, it can accurately assess the consistency between the corrected traffic difference at the target time point and the historical data, so as to accurately determine whether a traffic alarm message for the network device needs to be output.

[0078] In some examples, to improve the accuracy of the deviation of the corrected flow difference relative to the flow difference of a historical time window, the step of obtaining the deviation of the corrected flow difference relative to the historical flow difference of the historical time window based on the differences between the corrected flow difference and the historical mean and historical median of the historical time window includes: obtaining a first sum of the corrected flow difference and a preset smoothing factor, a second sum of the historical mean and the preset smoothing factor of the historical time window, and a third sum of the historical median and the preset smoothing factor of the historical time window; determining a first difference between the corrected flow difference and the historical mean based on the ratio of the first sum to the second sum; determining a second difference between the corrected flow difference and the historical median based on the ratio of the first sum to the third sum; and determining the deviation of the corrected flow difference relative to the historical flow difference of the historical time window based on the average of the first difference and the second difference.

[0079] In practical applications, there may be scenarios where the flow difference is small (e.g., close to 0). Directly calculating the absolute difference ratio of the corrected flow difference relative to the historical mean / median may lead to numerical instability where the denominator approaches 0. For example, when the historical mean or median is close to 0, the ratio calculation may produce a maximum value or infinity. Alternatively, it may lead to misjudgment in low-flow scenarios: normal low flow fluctuations of the device (e.g., corrected flow difference = 1, historical mean = 0.5) may be amplified into a significant deviation (1 / 0.5 = 2), resulting in a misjudgment as abnormal.

[0080] Based on this, in this embodiment, a preset smoothing factor α is introduced in the process of determining the degree of deviation of the corrected flow difference relative to the historical flow difference of the historical time window. This preset smoothing factor α can solve the problems of numerical instability and misjudgment when the flow rate is small or the historical statistics are close to zero, through denominator smoothing and numerator compensation, while maintaining sensitivity to large flow scenarios. In practical applications, the preset smoothing factor can be determined by manually adjusting parameters to obtain a suitable value; this embodiment does not limit its specific value.

[0081] Therefore, in this embodiment, when determining the difference between the corrected flow difference and the historical average, it is possible to first obtain the first sum of the corrected flow difference and the preset smoothing factor, and then obtain the second sum of the historical average of the historical time window and the preset smoothing factor, and finally obtain the result based on the ratio of the first sum to the second sum.

[0082] Similarly, when determining the difference between the corrected flow rate difference and the historical median, the third sum of the historical median of the historical time window and the preset smoothing factor can be obtained, and then the result can be obtained based on the ratio of the first sum to the third sum.

[0083] As an example, taking three historical time windows as an example, the three historical time windows have different durations, which can be short-term, medium-term, and long-term windows. The duration of each window can be set as needed, such as 1 hour, 1 day, or 7 days, etc. This embodiment does not limit this. The above calculation process can refer to the following formulas: O1=0.5*(D_abs+α) / (D_med_1+α)+0.5*(D_abs+α) / (D_avg_1+α) O2=0.5*(D_abs+α) / (D_med_2+α)+0.5*(D_abs+α) / (D_avg_2+α) O3=0.5*(D_abs+α) / (D_med_3+α)+0.5*(D_abs+α) / (D_avg_3+α)

[0084] Where O1 represents the degree of deviation of the corrected flow difference relative to the historical flow difference in historical time window 1; D_abs is the absolute value of the corrected flow difference; D_med_1 is the historical median of historical time window 1; and D_avg_1 is the historical mean of historical time window 1. That is, the first difference is (D_abs+α) / (D_med_1+α); the second difference is (D_abs+α) / (D_avg_1+α). O1 is the mean between the first and second differences, i.e., the degree of deviation.

[0085] O2 represents the degree of deviation of the corrected flow difference relative to the historical flow difference in historical time window 2; D_abs represents the absolute value of the corrected flow difference; D_med_2 represents the historical median in historical time window 2; and D_avg_2 represents the historical mean in historical time window 2.

[0086] O3 represents the degree of deviation of the corrected flow difference relative to the historical flow difference in historical time window 3; D_abs represents the absolute value of the corrected flow difference; D_med_3 represents the historical median in historical time window 3; and D_avg_3 represents the historical mean in historical time window 3.

[0087] The above calculation of the offset degree uses the average value method. In practical applications, other methods such as weighted average are also optional. This embodiment does not limit this method.

[0088] Therefore, O1, O2, and O3 respectively characterize the degree of deviation of the corrected flow difference relative to the historical flow difference of the corresponding historical time window.

[0089] Optionally, the above example uses three historical time windows, and can also be expressed by the following formula: Oi=0.5*(D_abs+α) / (D_med_i+α)+0.5*(D_abs+α) / (D_avg_i+α)

[0090] Where i is the i-th historical time window among multiple historical time windows.

[0091] Therefore, by introducing a preset smoothing factor, this embodiment can avoid the misjudgment of outliers caused by excessively large calculated offsets under low flow conditions.

[0092] In some examples, determining whether the network device has experienced traffic anomalies based on the degree of deviation of the corrected traffic difference relative to the historical traffic differences of each of the historical time windows includes: calculating a weighted average of the degree of deviation of the corrected traffic difference relative to the historical traffic differences of each of the historical time windows based on preset weights corresponding to each of the historical time windows; if the weighted average is greater than or equal to a preset threshold, determining that the network device has experienced traffic anomalies; if the weighted average is less than the preset threshold, determining that the network device has not experienced traffic anomalies.

[0093] In this embodiment, as in the previous embodiment, after obtaining the deviation of the corrected traffic difference relative to the historical traffic difference of each historical time window, this embodiment can calculate the weighted average of the deviation of the corrected traffic difference relative to the historical traffic difference of each historical time window using preset weights corresponding to each historical time window. Thus, by weighted fusion of multiple historical time windows, the deviations of multiple historical time windows can be dynamically aggregated, thereby improving the accuracy of alarm decisions.

[0094] As an example, a preset weight ui can be assigned to the offset degree Oi of each historical time window, and the weighted average ω = ∑ui * Oi can be calculated. Whether to trigger an alarm is determined based on a comparison of ω and a preset threshold. Thus, this embodiment can set corresponding preset weights for each historical time window according to the actual application scenario, thereby adjusting the preset weight of each historical time window according to the actual application scenario. For example, in some scenarios, short-term historical time windows are emphasized, such as in scenarios where network devices have recently undergone changes, the weight of this window can be greater than the weight of other windows; in other scenarios, such as log services, long-term windows can be emphasized, and the weight of long-term historical time windows can be greater than that of other windows. Therefore, the solution of this embodiment can be flexibly adapted to different application scenarios.

[0095] As an example, still using three historical time windows, the following formula can be referenced: ω=u1*O1+u2*O2+u3*O3

[0096] Wherein, ω is the weighted average of the deviation of the corrected flow difference relative to the historical flow difference of each of the historical time windows; u1, u2, and u3 are the preset weights corresponding to the three historical time windows respectively. Optionally, u1+u2+u3=1 can be set, but the specific value can be set according to the specific scenario.

[0097] Therefore, whether to output a traffic alarm message to the network device can be determined based on whether ω is greater than a preset threshold. The preset threshold can be set according to specific scenarios and dynamically adjusted based on network conditions (such as peak / off-peak periods). For example, the threshold can be appropriately increased during peak periods to avoid triggering alarms due to normal traffic fluctuations; during off-peak periods, the threshold can be decreased to enhance the detection of small-scale abnormal traffic and improve detection sensitivity.

[0098] As an example, the preset threshold can be 1+θ. If ω>1+θ, where θ is similar to a smoothing factor, it can be adjusted according to actual needs. When ω>1+θ, the corrected traffic difference, as a candidate outlier, can be confirmed as an anomaly and a traffic alarm message can be output. This corrected traffic difference can also be stored for subsequent analysis. If ω≤1+θ, the corrected traffic difference can be considered not an anomaly, and no traffic alarm message needs to be output. It can be seen that through the above processing, if a certain outlier is large, but multiple historical time windows, such as 1 hour, 1 day, and 1 week, show large traffic differences, then it will be smoothed out. Conversely, if a certain traffic difference is small, but historically it has almost always been 0, then it will be amplified and trigger an alarm.

[0099] As can be seen from the above embodiments, this embodiment can aggregate the offset of multiple historical time windows through weighted fusion of multiple time windows, thereby accurately determining whether network devices have abnormal traffic.

[0100] Optionally, alarm decisions can also be made based on the detection results. For example, if it is determined that the network device has abnormal traffic, a traffic alarm message for the network device can be output to notify the user. Therefore, this embodiment can also improve the accuracy of alarm decisions.

[0101] In practical applications, the output network device traffic alarm message can contain any information related to this detection, including but not limited to the target time point, network device information (such as device name or IP address), traffic information, etc. This embodiment does not limit this.

[0102] As an example, when the solution in this embodiment is running on a user device, the network device traffic alarm message can be directly output on the user device. If the solution in this embodiment is running on a server, the output of the network device traffic alarm message can be achieved by the server sending the traffic alarm message to the user device.

[0103] Figure 2B is a schematic diagram of alarm information for a network device according to an exemplary embodiment of this disclosure. The diagram shows relevant alarm information for the network device, such as device name, alarm time, alarm type, and IP address. Based on this alarm information, the network device's traffic data is retrieved for verification. Figure 2C is a schematic diagram of traffic data for a network device according to an exemplary embodiment of this disclosure. It can be seen that the device did indeed experience a sudden increase in traffic at this time, causing a brief period of non-conservation.

[0104] As can be seen from the above embodiments, this embodiment solves the problem of inconsistent time base points that are commonly encountered in network traffic collection through data noise reduction. Based on the collected traffic data, by modeling the characteristics of the traffic, risks and anomalies of network devices under conditions of non-conservative traffic can be detected relatively quickly. At the same time, this solution avoids the limitations of DSCP collection and can be applied to multiple areas of network traffic. This embodiment can dynamically generate traffic alarms through real-time data, historical data, and different business scenarios, avoiding the problems of single thresholds and traffic noise in different scenarios. In addition, in network changes, the correlation of the changes can be combined to better reduce noise and detect anomalies in the changes from a more general perspective.

[0105] Corresponding to the embodiments of the aforementioned network device traffic detection method, this disclosure also provides embodiments of a network device traffic detection apparatus and the computer equipment on which it is applied.

[0106] The embodiments of the traffic detection device of this disclosed network device can be applied to computer devices, such as servers or terminal devices. The device embodiments can be implemented through software, hardware, or a combination of both. Taking software implementation as an example, as a logical device, it is formed by its processor reading the corresponding computer program instructions from non-volatile memory into memory and executing them. From a hardware perspective, as shown in Figure 3, which is a hardware structure diagram of the computer device where the traffic detection device of this disclosed network device is located, in addition to the processor 310, network interface 320, memory 330, and non-volatile memory 340 shown in Figure 3, the computer device where the traffic detection device of the network device in the embodiment is located may also include other hardware depending on the actual function of the computer device, which will not be elaborated further.

[0107] As shown in Figure 4, which is a block diagram of a network device traffic detection apparatus according to an exemplary embodiment of the present disclosure, the apparatus includes: an acquisition module 41, configured to: acquire the original traffic difference of the network device at a target time point, the original traffic difference being determined based on the difference between the sum of the total inflow traffic of the network device and the traffic generated by the network device itself, and the total outflow traffic of the network device; a correction module 42, configured to: correct the original traffic difference of the target time point based on the original traffic difference of adjacent time points, to obtain the corrected traffic difference of the target time point; an anomaly determination module 43, configured to: acquire the data distribution of the corrected traffic difference of time points within the target time window, and determine whether the corrected traffic difference is a candidate anomaly based on the data distribution of the corrected traffic difference; and an alarm determination module 44, configured to: if determined to be a candidate anomaly, compare the corrected traffic difference with the historical traffic difference statistics of the historical time window to determine whether the network device has experienced a traffic anomaly.

[0108] In some examples, the correction module is further configured to: obtain a first absolute value of the average of the corrected flow difference between the target time point and the previous time point, and a second absolute value of the average of the original flow difference between the target time point and the next time point; determine the corrected flow difference based on the smaller of the first absolute value and the second absolute value; or, calculate the average of the original flow differences corresponding to the k time points before the target time point, the target time point, and the k time points after the target time point, and determine the corrected flow difference based on the calculated average; wherein, k is an integer greater than or equal to 1.

[0109] In some examples, the anomaly determination module is further configured to: check whether the distribution of the corrected flow difference data conforms to a normal distribution; if it is determined to conform to a normal distribution, determine whether the corrected flow difference is within the three standard deviations of the data mean in the target time window; if not, determine that the corrected flow difference is a candidate outlier, otherwise, determine that the corrected flow difference is not a candidate outlier; if it is determined not to conform to a normal distribution, obtain the standard score of the corrected flow difference; if the standard score is greater than a preset threshold, determine that the corrected flow difference is a candidate outlier, otherwise, determine that the corrected flow difference is not a candidate outlier; wherein, the preset threshold is determined based on the data mean and standard deviation of the target time window.

[0110] In some examples, the historical time window includes: historical time windows of different lengths; the historical traffic difference statistics include: the historical mean and historical median of the corrected traffic difference at each time point within the historical time window; the alarm determination module is further configured to: for a historical time window, based on the differences between the corrected traffic difference and the historical mean and historical median of the historical time window, obtain the degree of deviation of the corrected traffic difference relative to the historical traffic difference of the historical time window; and determine whether the network device has experienced traffic anomalies based on the degree of deviation of the corrected traffic difference relative to the historical traffic difference of the historical time window.

[0111] In some examples, the alarm determination module is further configured to: obtain a first sum of the corrected flow difference and a preset smoothing factor, a second sum of the historical mean and the preset smoothing factor for the historical time window, and a third sum of the historical median and the preset smoothing factor for the historical time window; determine a first difference between the corrected flow difference and the historical mean based on the ratio of the first sum to the second sum; determine a second difference between the corrected flow difference and the historical median based on the ratio of the first sum to the third sum; and determine the degree of deviation of the corrected flow difference relative to the historical flow difference for the historical time window based on the average of the first difference and the second difference.

[0112] In some examples, the alarm determination module is further configured to: calculate a weighted average of the degree of deviation of the corrected traffic difference relative to the historical traffic difference of each of the historical time windows based on the preset weights corresponding to each of the historical time windows; if the weighted average is greater than or equal to a preset threshold, determine that the network device has traffic abnormality; if the weighted average is less than the preset threshold, determine that the network device has no traffic abnormality.

[0113] The specific implementation process of the functions and roles of each module in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.

[0114] Accordingly, this disclosure also provides a network device traffic detection system, the detection system including a detection device and a network device, the detection device being used to execute the steps of the aforementioned network device traffic detection method embodiments.

[0115] Accordingly, this disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the aforementioned network device traffic detection method embodiment.

[0116] Accordingly, this disclosure also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the network device traffic detection method embodiment.

[0117] Accordingly, this disclosure also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the network device traffic detection method embodiment.

[0118] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this disclosure according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0119] The above embodiments can be applied to one or more computer devices. The computer device is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions. The hardware of the computer device includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0120] The computer device can be any electronic product that can interact with the user, such as a personal computer, tablet computer, smartphone, personal digital assistant (PDA), game console, interactive network television (IPTV), smart wearable device, etc.

[0121] The computer equipment may also include network equipment and / or user equipment. The network equipment includes, but is not limited to, a single network server, a server group consisting of multiple network servers, or a cloud based on cloud computing consisting of a large number of hosts or network servers.

[0122] The network in which the computer device is located includes, but is not limited to, the Internet, wide area network, metropolitan area network, local area network, and virtual private network (VPN).

[0123] The foregoing has described specific embodiments of this disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired results. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0124] The steps of the various methods described above are only for clarity. In practice, they can be combined into one step or some steps can be split into multiple steps. As long as they include the same logical relationship, they are all within the scope of protection of this patent. Adding insignificant modifications or introducing insignificant designs to the algorithm or process, but without changing the core design of the algorithm and process, are also within the scope of protection of this application.

[0125] While this disclosure contains numerous specific implementation details, these should not be construed as limiting the scope of any invention or the scope of the claims, but rather are primarily intended to describe features of specific embodiments of a particular invention. Certain features described in the multiple embodiments of this disclosure may also be implemented in combination in a single embodiment. Conversely, various features described in a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination. Furthermore, while features may function in certain combinations as described above and even initially claimed in this way, one or more features from a claimed combination may be removed from that combination in some cases, and a claimed combination may refer to a sub-combination or a variation thereof.

[0126] The terms "specific example" or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with the embodiments or examples, which are included in at least one embodiment or example of this disclosure. In this disclosure, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0127] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention applied herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not claimed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.

[0128] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

[0129] The above description is merely a preferred embodiment of this disclosure and is not intended to limit this disclosure. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A method for detecting traffic on a network device, the method comprising: Obtain the original traffic difference of the network device at the target time point. The original traffic difference is determined based on the difference between the sum of the total inflow traffic of the network device and the traffic generated by the network device itself, and the total outflow traffic of the network device. Based on the original flow difference between adjacent time points of the target time point, the original flow difference of the target time point is corrected to obtain the corrected flow difference of the target time point. Obtain the distribution of corrected flow difference data for time points within the target time window where the target time point is located, and determine whether the corrected flow difference is a candidate outlier based on the distribution of corrected flow difference data; If a candidate outlier is identified, the corrected traffic difference is compared with the historical traffic difference statistics of the historical time window to determine whether the network device has experienced traffic anomalies.

2. The method according to claim 1, wherein correcting the original flow difference at the target time point based on the original flow difference between adjacent time points to obtain the corrected flow difference at the target time point includes: Obtain the first absolute value of the average of the corrected flow difference between the target time point and the previous time point, and the second absolute value of the average of the original flow difference between the target time point and the subsequent time point; determine the corrected flow difference based on the smaller of the first absolute value and the second absolute value; or, The mean of the original flow difference is calculated for the k time points before the target time point, the target time point, and the k time points after the target time point, and the corrected flow difference is determined based on the calculated mean; wherein, k is an integer greater than or equal to 1.

3. The method according to claim 1, wherein determining whether the corrected flow difference is a candidate outlier based on the distribution of the corrected flow difference data includes: Verify whether the distribution of the corrected flow difference data conforms to a normal distribution; If it is determined that the data conforms to a normal distribution, then determine whether the corrected flow difference is within the three standard deviations of the data mean in the target time window; If not, the corrected flow difference is determined to be a candidate outlier; otherwise, the corrected flow difference is determined not to be a candidate outlier. If it is determined that the corrected flow rate difference does not conform to a normal distribution, then the standard score of the corrected flow rate difference is obtained; If the standard score is greater than a preset threshold, the corrected flow difference is determined to be a candidate outlier; otherwise, the corrected flow difference is determined not to be a candidate outlier. The preset threshold is determined based on the mean and standard deviation of the data in the target time window.

4. The method according to any one of claims 1 to 3, wherein the historical time window comprises: For historical time windows of different lengths, the historical flow difference statistics include: the historical mean and historical median of the corrected flow difference at each time point within the historical time window; The step of comparing the corrected traffic difference with the historical traffic difference statistics of the historical time window to determine whether the network device is experiencing traffic anomalies includes: For a given historical time window, the degree of deviation of the corrected flow difference relative to the historical flow difference of that historical time window is obtained based on the differences between the corrected flow difference and the historical mean and historical median of that historical time window. Based on the degree of deviation of the corrected traffic difference relative to the historical traffic difference of the historical time window, it is determined whether the network device has experienced traffic anomalies.

5. The method according to claim 4, wherein obtaining the degree of deviation of the corrected flow difference relative to the historical flow difference of the historical time window based on the differences between the corrected flow difference and the historical mean and historical median of the historical time window, comprises: Obtain the first sum of the corrected flow difference and the preset smoothing factor, the second sum of the historical mean of the historical time window and the preset smoothing factor, and the third sum of the historical median of the historical time window and the preset smoothing factor. Based on the ratio of the first sum to the second sum, a first difference between the corrected flow rate difference and the historical average is determined; Based on the ratio of the first sum to the third sum, a second difference between the corrected flow difference and the historical median is determined; The degree of deviation of the corrected flow difference relative to the historical flow difference of the historical time window is determined based on the average between the first difference and the second difference.

6. The method according to claim 4, wherein determining whether the network device has experienced traffic anomalies based on the degree of deviation of the corrected traffic difference relative to the historical traffic differences of each of the historical time windows includes: Based on the preset weights corresponding to each of the historical time windows, a weighted average of the deviation of the corrected flow difference relative to the historical flow difference of each of the historical time windows is calculated. If the weighted average value is greater than or equal to a preset threshold, it is determined that the network device has an abnormal traffic pattern. If the weighted average value is less than a preset threshold, it is determined that the network device has not experienced abnormal traffic.

7. A network device traffic detection system, the traffic detection system comprising a detection device and a network device, the detection device being used to perform the steps of the method according to any one of claims 1 to 6.

8. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein, When the processor executes the computer program, it achieves the following: Obtain the original traffic difference of the network device at the target time point. The original traffic difference is determined based on the difference between the sum of the total inflow traffic of the network device and the traffic generated by the network device itself, and the total outflow traffic of the network device. Based on the original flow difference between adjacent time points of the target time point, the original flow difference of the target time point is corrected to obtain the corrected flow difference of the target time point. Obtain the distribution of corrected flow difference data for time points within the target time window where the target time point is located, and determine whether the corrected flow difference is a candidate outlier based on the distribution of corrected flow difference data; If a candidate outlier is identified, the corrected traffic difference is compared with the historical traffic difference statistics of the historical time window to determine whether the network device has experienced traffic anomalies.

9. The computer device according to claim 8, wherein correcting the original flow difference at the target time point based on the original flow difference between adjacent time points to obtain the corrected flow difference at the target time point comprises: Obtain the first absolute value of the average of the corrected flow difference between the target time point and the previous time point, and the second absolute value of the average of the original flow difference between the target time point and the subsequent time point; determine the corrected flow difference based on the smaller of the first absolute value and the second absolute value; or, The mean of the original flow difference is calculated for the k time points before the target time point, the target time point, and the k time points after the target time point, and the corrected flow difference is determined based on the calculated mean; wherein, k is an integer greater than or equal to 1.

10. The computer device according to claim 8, wherein determining whether the corrected flow difference is a candidate outlier based on the corrected flow difference data distribution comprises: Verify whether the distribution of the corrected flow difference data conforms to a normal distribution; If it is determined that the data conforms to a normal distribution, then determine whether the corrected flow difference is within the three standard deviations of the data mean in the target time window; If not, the corrected flow difference is determined to be a candidate outlier; otherwise, the corrected flow difference is determined not to be a candidate outlier. If it is determined that the corrected flow rate difference does not conform to a normal distribution, then the standard score of the corrected flow rate difference is obtained; If the standard score is greater than a preset threshold, the corrected flow difference is determined to be a candidate outlier; otherwise, the corrected flow difference is determined not to be a candidate outlier. The preset threshold is determined based on the mean and standard deviation of the data in the target time window.

11. The computer device according to any one of claims 8 to 10, wherein the historical time window comprises: For historical time windows of different lengths, the historical flow difference statistics include: the historical mean and historical median of the corrected flow difference at each time point within the historical time window; The step of comparing the corrected traffic difference with the historical traffic difference statistics of the historical time window to determine whether the network device is experiencing traffic anomalies includes: For a given historical time window, the degree of deviation of the corrected flow difference relative to the historical flow difference of that historical time window is obtained based on the differences between the corrected flow difference and the historical mean and historical median of that historical time window. Based on the degree of deviation of the corrected traffic difference relative to the historical traffic difference of the historical time window, it is determined whether the network device has experienced traffic anomalies.

12. The computer device according to claim 11, wherein obtaining the degree of deviation of the corrected flow difference relative to the historical flow difference of the historical time window based on the differences between the corrected flow difference and the historical mean and historical median of the historical time window respectively includes: Obtain the first sum of the corrected flow difference and the preset smoothing factor, the second sum of the historical mean of the historical time window and the preset smoothing factor, and the third sum of the historical median of the historical time window and the preset smoothing factor. Based on the ratio of the first sum to the second sum, a first difference between the corrected flow rate difference and the historical average is determined; Based on the ratio of the first sum to the third sum, a second difference between the corrected flow difference and the historical median is determined; The degree of deviation of the corrected flow difference relative to the historical flow difference of the historical time window is determined based on the average between the first difference and the second difference.

13. The computer device according to claim 11, wherein determining whether the network device has experienced traffic anomalies based on the degree of deviation of the corrected traffic difference relative to the historical traffic differences of each of the historical time windows includes: Based on the preset weights corresponding to each of the historical time windows, a weighted average of the deviation of the corrected flow difference relative to the historical flow difference of each of the historical time windows is calculated. If the weighted average value is greater than or equal to a preset threshold, it is determined that the network device has an abnormal traffic pattern. If the weighted average value is less than a preset threshold, it is determined that the network device has not experienced abnormal traffic.

14. A computer program product comprising a computer program that, when executed by a processor, implements the steps of the method according to any one of claims 1 to 6.

15. A computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method according to any one of claims 1 to 6.