WO2020140419A1 - 网络流量增量统计、分析方法及系统 - Google Patents
网络流量增量统计、分析方法及系统 Download PDFInfo
- Publication number
- WO2020140419A1 WO2020140419A1 PCT/CN2019/096637 CN2019096637W WO2020140419A1 WO 2020140419 A1 WO2020140419 A1 WO 2020140419A1 CN 2019096637 W CN2019096637 W CN 2019096637W WO 2020140419 A1 WO2020140419 A1 WO 2020140419A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- network traffic
- real
- virtual network
- time
- core data
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
Definitions
- the present invention relates to the field of communication technology, and in particular to network traffic incremental statistics and analysis methods and systems.
- Network function virtualization technology refers to the virtualization of assembled hardware resources, and the creation of a series of virtual machine VMs (Virtual Machine) by constructing three types of virtual resource pools: computing, storage, and network.
- VMs Virtual Machine
- Computing virtualization technology includes two types of full virtualization and paravirtualization, in which full virtualization technology Full Virtualization completely realizes the cooperation of the guest operating system and server hardware through the created virtual machine: the protected computer instructions pass the virtual machine management program Hypervisor captures and processes, and the operating system shares and shares the underlying server hardware through Hypervisor.
- Para-virtualization technology Para-Virtualization uses the hypervisor Hypervisor to share access to the underlying hardware, but its guest operating system integrates software code for virtualization. There is no need to recompile or trigger traps. Virtual processes are very well coordinated and cooperative. Based on these two virtualization technologies, virtual machines can be dynamically generated or withdrawn based on network expansion and contraction requirements.
- the virtual network function VNF (Virtualized Network) is a software package that runs on the virtual machine VM and interacts with MANO (Manager and Orchestration) to achieve network flow control and forwarding.
- the MANO platform implements the description of virtual network functions, virtual deployment units, virtual connections, and network connection points based on the TOSCA (Topology and Orchestration Specification for Cloud Application) template, and builds a network service NS (Network Service) based on the multidirectional forwarding graph FG (Forwarding Graph) ).
- Multi-directional forwarding diagram covers VNF, PNF (Physical Network Function), VL (Virtual Link), CP (Connection Point), supports the description of the virtual network function forwarding path, supports the description of the virtual network function forwarding point, and realizes the virtual network function
- the mapping of nodes to TOSCA template nodes and the decomposition to virtual deployment units realize the mapping of VDU (Virtual Deployment Unit) to VM.
- the orchestrated network service is verified and handed over to the virtual network function manager for analysis, and it is handed over to the VIM to allocate resources according to the description of resources and capabilities in the description file.
- Incremental processing technology formalizes and represents network traffic according to the time dimension, divides the data into a series of data fragments to better study the context of the virtual network traffic data fragments, and analyzes the data in the time dimension with the help of a series of models Changes in technology.
- For the newly added virtual network traffic data it analyzes the relationship between the incremental data and the historical data by projecting it onto the historical traffic data, and uses the incremental data for feature projection on each dimension of the high-dimensional space for modeling. Because the virtual network traffic data has a strong Markov property and the current incremental network traffic data is weakly correlated with historical data, it can directly infer on the incremental data and provide services for network function virtualization applications.
- the virtual network function is an important part of the new generation network.
- the real-time collection and analysis of the network traffic in the virtual network function can help to achieve more intelligent deployment, coordination and scheduling.
- the dynamic change characteristics of network traffic in the time dimension there is currently no effective method for analysis.
- real-time collection and incremental storage of network traffic in a network function virtualization environment can be realized.
- the statistics and analysis of network traffic in the network can make the deployment, coordination and scheduling of virtual network functions more intelligent.
- the object of the present invention is to provide network traffic incremental statistics and analysis methods and systems, which can realize the real-time collection and incremental storage of network traffic in a network function virtualization environment to construct a high-dimensional space and Transfer the spatial model, and make statistics or analysis through the incremental method.
- an embodiment of the present invention provides a network traffic incremental statistics method, which includes the following steps:
- the data packets are provided with multiple feature items, and the feature items include time;
- the real-time core data set is saved in real time along the time dimension in the high-dimensional space to obtain a high-quality core data set.
- the network model is a TCP/IP four-layer reference model, and the data packets are collected from an application layer, a transport layer, a network layer, and a network interface layer.
- the data packet collected from the application layer includes structured data, semi-structured data, and unstructured data.
- the characteristic items further include: source MAC address, target MAC address, source IP address, destination IP address, source port, target port, virtual network function identifier, and virtual network traffic data content.
- VNF Virtualized Network Function
- VM Virtual Machine
- HOSVD High-Order Singular Value Decomposition
- an embodiment of the present invention also provides a network traffic incremental analysis method based on the statistical method described in the first aspect. After obtaining a high-quality core data aggregate, the method further includes:
- the virtual network traffic state of each real-time core data set in the high-quality core data set Based on the virtual network traffic state of each real-time core data set in the high-quality core data set, the virtual network traffic state and probability of the real-time core data set at the next moment are analyzed.
- an embodiment of the present invention also provides an analysis method based on the second aspect, which is characterized in that:
- NFVC is the set of virtual network traffic states of the real-time core data set at the current moment
- NFVP is the set of virtual network traffic states of the real-time core data set at the previous moment
- NFVN is the set of virtual network traffic states of the real-time core data set at the next moment
- the corresponding P of each ANx is the value of the points representing the ACx, APx and each ANx in the three-dimensional transfer space, and expressed in the three-dimensional transfer space, Get the three-dimensional predicted transition space.
- the virtual network traffic state is at least one interval of the high-dimensional space.
- the virtual network traffic state is a value/option interval of more than one characteristic item of the real-time core data set.
- the feature item further includes a hardware usage parameter
- the hardware usage parameter includes CPU utilization rate, memory usage percentage
- the virtual network traffic state represented by the real-time core data set is the current hardware location status.
- the CPU usage rate of 10% or less is defined as State 1
- the CPU usage rate of 11% to 20% is defined as State 2
- the CPU usage rate of 91% or more is defined as 10 so that the CPU usage state space is ⁇ 1,2,3,4,5,6,7,8,9,10 ⁇ .
- the available memory data can be segmented.
- the available memory below 10G is defined as state 1
- the available memory from 11G to 20G is defined as state 2, and so on.
- the state space is also limited. Assuming that the state corresponding to the upper limit of available memory in the data center is N, the state space set is ⁇ 1,2,3,4,5,6,... ,N ⁇ .
- the three-dimensional prediction transition space is used as a three-dimensional transition space, and further probabilities of all possible virtual network traffic states after the subsequent addition of the real-time core data set are predicted, and expressed in the network transition space, obtained Three-dimensional prediction transition probability space.
- an embodiment of the present invention also provides a network traffic incremental statistics system, which includes:
- the collection module is used to obtain and save data packets at various levels of the virtualized network model in real time, and the data packets are provided with multiple feature items, and the feature items include time;
- a calculation module configured to store the data packet in a high-dimensional space in a way that one feature item corresponds to one dimension, and expand along a preset module to obtain a high-order matrix
- An extraction module used to remove duplicate and erroneous data in the high-order matrix, and restore to a high-dimensional space to obtain a real-time core data set;
- the storage module is used to store the real-time core data collection in real time along the time dimension in the high-dimensional space in chronological order to obtain a high-quality core data aggregate.
- the network model is a TCP/IP four-layer reference model, and the data packets are collected from an application layer, a transport layer, a network layer, and a network interface layer.
- the data packet collected from the application layer includes structured data, semi-structured data, and unstructured data.
- the characteristic items further include: source MAC address, target MAC address, source IP address, destination IP address, source port, target port, virtual network function identifier, and virtual network traffic data content.
- VNF Virtualized Network Function
- VM Virtual Machine
- HOSVD High-Order Singular Values Decomposition, high-order singular value decomposition
- an embodiment of the present invention further provides a network traffic incremental analysis system based on the statistical system according to the fourth aspect, which includes:
- Corresponding module used to set the correspondence between feature items and virtual network traffic status
- the sampling module is used to obtain the virtual network traffic status of the real-time core data collection at the current time and the previous time;
- the analysis module is configured to analyze the virtual network traffic state and probability of the real-time core data set at the next moment according to the virtual network traffic state of each real-time core data set in the high-quality core data set.
- an embodiment of the present invention further provides an analysis system based on the fifth aspect, which is characterized in that:
- NFVC represents the virtual network traffic state of the real-time core data set at the current moment
- NFVP represents the virtual network traffic state of the real-time core data set at the previous moment
- NFVN represents the virtual network traffic status of the real-time core data collection at the next moment
- the setting module is used to set the virtual network traffic state of the real-time core data set at the current moment to A Cx , the virtual network traffic state of the real-time core data set at the previous moment to A Px , and the virtual network of the real-time core data set at the next moment
- the flow state is A Nx ;
- the statistics module is used to count the probability P of the virtual network traffic state changing from A Px to ACx and finally to various A Nx in the three-dimensional transfer space;
- the prediction module is used to use the A Cx , A Px and each A Nx as the coordinate value of the three-dimensional transfer space, and the corresponding P of each A Nx is A Cx , A Px and each A Nx represent points in the three-dimensional transfer space Value and expressed in the three-dimensional transition space to obtain a three-dimensional predicted transition space.
- the virtual network traffic state is at least one interval of the high-dimensional space.
- the virtual network traffic state is a value/option interval of more than one characteristic item of the real-time core data set.
- the feature item further includes a hardware usage parameter
- the hardware usage parameter includes CPU utilization rate, memory usage percentage
- the virtual network traffic state represented by the real-time core data set is the current hardware location status.
- the three-dimensional predicted transition space is characterized by using the three-dimensional predicted transition space as a three-dimensional transition space, and further predicting the probability of all possible virtual network traffic states after the subsequent addition of real-time core data sets, and indicating the transition in the network Within the space, a three-dimensional predicted transition probability space is obtained.
- the network traffic incremental statistical method and system of the present invention first obtain data packets at various levels of the network model of the current virtualized network. Since the network model may have multiple architectures, the levels are also different. If only Setting a specific number of levels for setting may result in incomplete data or redundant data, resulting in statistics and analysis no longer accurate. Further, after obtaining the data package of each score of the network model of the current virtualized network, multiple feature items are set for the data package, and stored in a high-dimensional space according to a feature item corresponding to one dimension, which is relatively lacking in implementation The conversion of real sense data information to the spatial volume with actual dimension. After the conversion is completed, the space is further expanded to obtain matrix-mode data.
- the present invention saves the data packets in chronological order. Since the present invention focuses on the statistics and analysis of network traffic, it is mainly aimed at the increase of network traffic, that is, the change in network traffic over time. Therefore, the entire collection of high-quality core data that saves data in chronological order is expanded in chronological order, which facilitates subsequent sorting and analysis according to time parameters.
- the method and system for incremental analysis of network traffic of the present invention first classifies the feature items of the data packets, that is, sets the correspondence between the feature items and the virtual network traffic status, such as setting a certain network port flow rate 0-10M/s as " Low speed state, 10-20M/s is the “medium speed” state, 20-100M/s is the "high speed” state.
- the current state is used for analysis, and there will be no different analysis schemes for data that has not changed substantially. For example, 1.01M/s and 1.02M/s are processed according to the low-speed state.
- the classification can be more detailed until the requirements are met, while saving computing resources.
- Figure 1 is a flow chart of steps of an embodiment
- FIG. 2 is a schematic structural diagram of data collection in the embodiment
- FIG. 3 is a schematic diagram of converting network data into high-dimensional spatial data according to an embodiment
- FIG. 4 is a schematic diagram of an embodiment to save the real-time core data set in real time along the time dimension in a high-dimensional space to obtain a high-quality core data total set;
- FIG. 7 is a schematic diagram of establishing a three-dimensional transfer space in an embodiment
- Embodiments of the present invention provide a network traffic incremental statistics and analysis method and system, which can realize real-time network traffic collection and incremental storage in a network function virtualization environment, construct a high-dimensional space and transition space model, and Quantitative methods for analysis.
- an embodiment of the present invention provides a network traffic incremental statistics method, which includes:
- S1 Real-time acquisition and storage of data packets at various levels of the virtualized network model.
- the data packets are provided with multiple feature items, and the feature items include time.
- the present invention first takes the network model of the virtualized network as the extraction object.
- the transmission of the network is inseparable from its network model.
- the computer network refers to a collection of many autonomously working computers connected by communication lines, and each What kind of rules are used to communicate between components is the problem of network model research.
- the network model generally refers to the OSI seven-layer reference model and the TCP/IP four-layer reference model. The establishment and changes of network traffic are inseparable from the network model, so collecting data packets according to the hierarchy of the network model in the virtualized network is very comprehensive and not lost.
- the network traffic model contains three elements: One is the node that characterizes the system components. The second is the arrow line (sometimes the edge) that reflects the relationship between the constituent elements. The third is the flow of traffic in the network. On the one hand, it reflects the quantitative relationship between the elements, and it also determines the goal and direction of the network model optimization. When performing statistical analysis on the network traffic increment in the present invention, these three elements in the network model are also indispensable. Therefore, collecting data packets for the network model can obtain more comprehensive types of data.
- the virtualized network model is the traditional TCP/IP four-layer reference model, and the data packets are collected from the application layer, transport layer, network layer, and network interface layer.
- the data packets collected from the application layer include structured data, semi-structured data, and unstructured data.
- the structured data is stored in a cloud platform or distributed computing environment, and stored in a database or file according to actual application requirements.
- For semi-structured data and unstructured data It is expressed in the form of a file in a cloud platform or distributed computing environment, and the key retrieval information is extracted and analyzed for subsequent rapid and flexible retrieval.
- the invention provides an incremental analyzer, which distributes the incrementally collected network traffic data packets to each corresponding storage space, merges with historical network data packets, and simultaneously updates various types of data retrieval and key data.
- VNF Virtualized Network
- VM Virtual Machine
- VNF Virtualized Network
- MANO Manager and Orchestration
- the MANO platform implements the description of virtual network functions, virtual deployment units, virtual connections, and network connection points based on the TOSCA (Topology and Orchestration Specification for Cloud Application) template, and builds a network service NS (Network Service) based on the multidirectional forwarding graph FG (Forwarding Graph) ).
- Multi-directional forwarding diagram covers VNF, PNF (Physical Network Function), VL (Virtual Link), CP (Connection Point), supports the description of the virtual network function forwarding path, supports the description of the virtual network function forwarding point, and realizes the virtual network function
- VNF Physical Network Function
- VL Virtual Link
- CP Connection Point
- the mapping of nodes to TOSCA template nodes and the decomposition to virtual deployment units realize the mapping of VDU (Virtual Deployment Unit) to VM. Therefore, VNF can collect and upload data packets very well.
- an acquisition manager used to issue collection instructions and parameters.
- the VNF collects data in real time according to the parameters. Its storage system stores the virtual network traffic data uploaded by the VNF, and the incremental analyzer synthesizes and stores the new and historical data.
- the data packet is stored in a high-dimensional space according to a feature item corresponding to a dimension, and expanded along a preset modulus to obtain a high-order matrix.
- data packets with feature items tend to be abstract data, and direct analysis only processes the data through some algorithms. This processing is abstract and may lack actual basis.
- the present invention models the data, that is, the data package is stored in a high-dimensional space according to a feature item corresponding to a dimension, so that the data package is no longer just a series of stacked data, but each coordinate in the high-dimensional space , Interval. After completing the modeling of the transformation of the data packet into the high-dimensional space, in order to be able to process it further, the high-dimensional space is expanded through a preset module to obtain a high-order matrix.
- a data packet with N feature items is represented in a high-dimensional space in ASCII form.
- the defined N-dimensional space model is Where I 1 , I 2 , I 3 , ..., IN represent the first to N-th order of the N-dimensional space.
- the N-dimensional space is expanded along the Pth order, and the resulting P-module matrix is defined as The number of rows of the P-modular matrix is I P and the number of columns is (IP+1IP+2...I1I2...IP-1) .
- the module expansion matrix obtained by expanding the high-dimensional space along a specific module can be used in the network traffic subsequent processing algorithm, such as classification, trend prediction, clustering algorithm, etc.
- a 9-dimensional space is defined as
- the 9 orders of the 9-dimensional space are represented as I TIM , I SM , I DM , I SI , I DI , I SP , I DP , I VI , I CN represent time Time, source MAC address SrcMAC, destination MAC address DstMAC, Source IP address SrcIP, destination IP address DstIP, source port SrcPort, destination port DstPort, virtual network function identifier VNFID, virtual network traffic content Cnt.
- the number of rows of the modulo 3 expansion matrix obtained by expanding this 9-dimensional space along the third order is I 3 , and the number of columns is I 4 I 5 I 6 I 7 I 8 I 9 I 1 I 2 .
- step 2 of Figure 3 during the sampling process, duplicate and erroneous data are unavoidable, so there are inconsistent, duplicate, and redundant data in the current high-order matrix, which may adversely affect the analysis work It may even lead to analysis errors. Therefore, it is necessary to remove the duplicates and erroneous data in the high-order matrix before it can be restored to the high-dimensional space to obtain the real-time core data set. Further data analysis and mining on the core collection in the high-dimensional space is more accurate than processing and analyzing directly on the original data set.
- the repeated inconsistent data of the high-order matrix can be removed through various technical solutions known to those skilled in the art.
- HOSVD High-Order Singular Value Decomposition
- the high-order singularity Value decomposition technology can remove duplicate, redundant, and inconsistent low-quality data to obtain high-quality core data sets.
- Kalman filtering and regression methods can eliminate noisy data and uncertain data, and realize spatio-temporal data cleaning. Based on probability statistical methods, deleting abnormal data or redundant data with a certain degree of confidence can ensure that the effectiveness of the processing results will not be affected. Fuzzy matching technology calculates the approximate degree of data by designing similarity function, so as to realize the cleaning of repeated redundant data.
- the real-time core data set is saved in real time along the time dimension in the high-dimensional space to obtain a high-quality core data total set.
- the real-time core data sets need to be stored one by one for analysis and used as a whole.
- the virtual network traffic data has a strong Markov property, that is, the connection in the time dimension is large. Therefore, the real-time core data set is saved in the high-dimensional space corresponding to the time dimension, and a high-quality core data set is obtained.
- the total set of high-quality core data saved in this way can continuously update the left singular vector space by expanding the optimal basis vector of the matrix and incrementally using the newly added virtual network traffic data, projecting the newly added non-zero elements to each truncation In the unit orthogonal basis space, to achieve incremental network traffic quality data extraction and analysis.
- an embodiment of the present invention provides a network traffic incremental analysis method, which is based on the network traffic statistics method of the embodiment. After completing the statistics method of Embodiment 1, the following steps are performed:
- A1 Set the correspondence between feature items and virtual network traffic status.
- the characteristic items of the data packet can be multiple options or a series of continuous values, and the option values in the network traffic of the virtual network may have many options. If the unique data of each single characteristic item is analyzed , Will require huge amounts of computing resources. However, the actual analysis may not require such high accuracy, which in turn causes a waste of resources and an increase in costs.
- the virtual network traffic state is at least one interval of the high-dimensional space. That is, certain intervals of some feature items in the high-dimensional space are combined to form a virtual network traffic state, and other intervals of the same partial feature items are combined to form another virtual network traffic state, and finally divided into multiple virtual network traffic states. Some feature items.
- the setting feature item of the present invention corresponds to the virtual network traffic state, setting a certain network port traffic 0-10M/s as “low speed” state, 10-20M/s as “medium speed” state, 20-100M/s as “high speed” "status.
- the data of 5.01M/s and 5.02M/s are all low-speed states for subsequent analysis, and only three state quantities need to be processed during analysis, which is very convenient and fast. 5.01M/s and 5.02M/s are calculated as different data in detail, which does not have much impact on the fuzzy analysis. If the above status classification does not meet the requirements, further detailed classification can be performed until the analysis requirements are met. This correspondence improves the efficiency of analysis and the cost of calculation.
- the above example corresponds to the state of a single feature item. If the state distinction of multiple feature items in a high-dimensional space is involved, the traditional detailed analysis of all data may be difficult to achieve, and the present invention can be further subdivided Other characteristic item states, such as the flow characteristic item and the port characteristic item, the corresponding state can be: the flow of port A and port B is 0-10M/s, which is the "low speed” state, and 10-20M/s is the “medium speed” "State, 20-100M/s is the "high speed” state, A port traffic is 0-10M/s, B port traffic is 10-20M/s is "low and medium speed” state, and so on. In this way, the state correspondence ensures a more intuitive connection between different feature items.
- the change of state means the change of multiple feature items.
- the analysis of the state actually achieves the analysis of multiple feature items.
- multiple feature items are counted as a state and are linked together.
- the analysis result can represent the actual representation of the current virtual network traffic status.
- each hardware in the virtual network is expressed as a feature item and corresponds to different
- the hardware load and calculation loss of the virtual network represented by each state can be roughly changed to understand the hardware status of the virtual network, which is more efficient, low cost, and very intuitive.
- it can also be network traffic, interface switching, error reporting, etc. virtual network data.
- the virtual network traffic status is the value/option interval of more than one characteristic item of the real-time core data set.
- feature items may also be options, such as ports A, B, C, etc., as long as they are characterized by one dimension in a high-dimensional space.
- A2 Obtain the virtual network traffic status of the real-time core data collection at the current time and the previous time.
- Analysis of the total set of real-time core data that is, to summarize the changes in the virtual network before and after, there is a time sequence, so it is necessary to distinguish the line of real-time core data centers.
- the time interval can be 1s, 3min, 6h It can also be a time specified by other people, and only need to be specifically limited according to the change time interval to be analyzed.
- A3 According to the virtual network traffic state of each real-time core data set in the high-quality core data set, analyze the virtual network traffic state and probability of the real-time core data set at the next moment.
- the virtual network traffic status of the real-time core data collection at the current time and the previous time that is, know the initial conditions of the virtual network traffic status, and then need to perform an overall analysis based on each real-time core data collection in the entire high-quality core data collection to obtain
- the law of state change can be used to determine the state of network traffic at the next moment.
- the initial condition is that the hardware usage rate in the network traffic of the virtual network is "high”, “medium” and "low”.
- the initial condition is to directly change from the "high” state to the "low” state.
- the current network traffic is between 9M/s and 26M/s.
- the probability of a ternary sequence starting with 10 in the entire state sequence is 2/9, which means that the probability of the ternary sequence (10, x, x) is 2/9.
- the value of x is 17, 23; the probability of the occurrence of the ternary sequence with 17 as the first in the entire state sequence is 3/9, that is to say the probability of the occurrence of the ternary sequence of (17, x, x) is 3/9, x
- the values are 10 and 23; the probability of a ternary sequence with 23 as the first in the entire state sequence is 4/9, which means that the probability of (23, x, x) ternary sequence is 4/9, x is taken The values are 10 and 17.
- This embodiment intercepts the middle segment of this sequence as (10,17,23,10,17,17,10,10,17,23,10,17,23,17,10,23,10,23,10,23,10,23,10,23,23), the above contains 21 element sequences, (10,x,x) there are 8 such ternary sequences, namely (10,17,23), (10,17,17), (10,10 ,17), (10,17,23), (10,17,23), (10,23,10), (10,23,10), (10,23,23).
- the first value 10 in the eight ternary sequences indicates that the state at the previous time is 10
- the second value indicates the state at the current time
- the third value indicates the state at the next time.
- the second value is 10 only the third sequence (10,10,17), which indicates the probability that the state at the previous time is 10, the state at the current time is 10, and the state at the next time is 17.
- the second value is 17 with four sequences, namely (10,17,23), (10,17,17), (10,17,23), (10,17 , 23), indicating that the state at the previous time is 10, the state at the current time is 17, and the probability that the state at the next time is 17 is 1/4. For the same reason, the probability that the state at the previous moment is 10, the current moment is 17, and the next moment is 23 is 3/4.
- the state at the previous time is 10, the state at the current time is 23, and the probability of the state at the next time is 23 is 1/3.
- the statistics of the entire virtual network traffic status sequence can be used to obtain the transition probability.
- this embodiment assumes that the transition probability is shown in Table 1.
- the top row of Table 1 shows the three states at the last moment, where 10(2/9) means that the probability of state 10 at the last moment is 2/9, and 17(3/9) means that the probability of state 17 at the last moment is 3/9, 23 (4/9) means that the probability of state 23 appearing at the last moment is 4/9.
- the sum of the probability values of the three states is 1.
- Table 1 has 12 columns. The first column, the fifth column, and the ninth column indicate the current status. Table 1 has 5 rows, and the second row indicates the next state.
- Table 1 row 3, columns 2, 3, and 4, row 4, columns 2, 3, and 4, row 5, columns 2, 3, and 4 have a total of 9 state transition probabilities, indicating that the state at the previous time was 10 , The transition probability of each state value between the current time and the next time.
- the value in the third row and third column of Table 1 is 1, indicating that the state at the previous time is 10, the current state is 10, and the probability at the next time state is 17 is 1.
- the value of the column is 3/4, indicating that the state at the previous time is 10, the state at the current time is 17, and the probability that the state at the next time is 23 is 3/4.
- Table 1 row 3, columns 6, 7, and 8, row 4, columns 6, 7, and 8, row 5, columns 6, 7, and 8 have a total of 9 state transition probabilities, indicating that the state at the previous time was 17 o'clock , The transition probability of each state value between the current time and the next time.
- the transition probability value Multiply the probability corresponding to the state value at the previous time in the first row of Table 1 by the transition probability value below to calculate the transition probability value in three dimensions, as shown in Table 2.
- Table 2 the sum of the transition probabilities in the third, fourth, and fifth rows is 1.
- the transition probability of the third row is 2/9, 1/3, 4/9, and the addition is 1.
- the traffic state of the virtual network can be predicted: if the network traffic state at the previous moment is 23, and the network traffic state at the current moment is 17, according to Table 4, row 4, columns 10, 11, and 12, you can It is learned that the probability of the network traffic state at the next moment is 17 is 5/36, and the probability of 23 is 15/36. Because the probability is high, the possibility is high, so the next time the network traffic state value is most likely to be 23, that is, the network traffic is between 21M/s and 26M/s. After calculating the network traffic status at the next moment, you can then calculate the network traffic status at the next moment.
- the network traffic at the next moment is most likely to be 10, that is, the network traffic is at Between 9M/s and 14M/s. Further, the necessary measures should be taken for the possible traffic state at the next moment, and disaster prevention.
- an embodiment of the present invention provides a network traffic analysis method, which is based on the foregoing network traffic analysis method and includes the following steps:
- NFVC represents the virtual network traffic status of the real-time core data collection at the current moment
- NFVP represents the virtual network traffic status of the real-time core data collection at the previous moment
- NFVN represents The virtual network traffic status of the real-time core data collection at the next moment.
- NFVC represents the virtual network traffic state of the real-time core data collection at the current moment
- NFVP represents the virtual network traffic state of the real-time core data collection at the previous moment
- NFVN represents the next moment Virtual network traffic status of real-time core data collection.
- the high-dimensional space is still too abstract for people, and if the change of the virtual network traffic state can be expressed in a three-dimensional space, it will be more intuitive, and the low-dimensional data will be easier to analyze.
- the analysis of the three time-related parameters can more reflect the changes of the real-time core data set with time.
- the characteristic items further include hardware usage parameters, which include CPU utilization rate and memory occupancy percentage, and the virtual network traffic status represented by the real-time core data set is the current hardware status.
- B2 Set the virtual network traffic state of the real-time core data collection at the current time to A Cx , the virtual network traffic state of the real-time core data collection at the previous time to A Px , and the virtual network traffic state of the real time core data collection at the next time to A Nx ;
- the virtual network traffic state of the real-time core data set at the current moment is A Cx
- the virtual network traffic state of the real-time core data set at the previous moment is A Px
- the virtual network traffic state of the real-time core data set at the next moment may be represented by A Nx .
- B3 Calculate the probability P of the virtual network traffic state changing from A Px to A Cx and finally to various A Nx in the three-dimensional transfer space.
- the virtual network traffic state of all real-time core data sets of the high-quality core data set is represented in it, including the virtual network traffic state A Px and the virtual network traffic state A Cx , which can be counted at this time.
- a Cx , A Px and each A Nx are used as the coordinate values of the three-dimensional transfer space, and the corresponding P of each A Nx is the value of A Cx , A Px and each A Nx representing points in the three-dimensional transfer space, and It is expressed in the three-dimensional transition space to obtain a three-dimensional predicted transition space.
- a Nx After obtaining various A Nx , A Cx , A Px and each A Nx can also be expressed in the three-dimensional transfer space, but the point is not a 100% solid point, but the probability of all points is added as a 100% virtual Point, if the shade of color is used to represent the probability of A Cx , A Px and each A Nx in the three-dimensional transition space, then you can see a block/line/at least two points with different shades, which intuitively reflects A The possible probability of Nx , that is, the trend of the virtual network traffic state of the virtual network at the next moment, and after identifying A Cx , A Px, and each A Nx to the three-dimensional transfer space, the three-dimensional space actually contains the predicted space, It is set as the three-dimensional prediction transition space.
- the probability P of various A Nx is obtained, and the probability P is also taken as the value represented by the midpoint in the high-dimensional space.
- the three-dimensional predicted transition space is used as a three-dimensional transition space to further predict the probability of all possible virtual network traffic states after the subsequent addition of the real-time core data set, and it is expressed in the network transition space to obtain the three-dimensional predicted transition probability space .
- the network transfer space also includes a four-dimensional transfer space and a five-dimensional transfer space.
- the three-dimensional transition space includes a three-dimensional prediction transition space; the data in the three-dimensional transition space is used to predict future traffic trends, and the prediction result is expressed in the three-dimensional space to obtain the three-dimensional prediction transition space.
- the data in the three-dimensional transfer space is used for statistical analysis of historical flow characteristics, and the statistical results are expressed in the three-dimensional space to obtain the three-dimensional statistical transfer space.
- the three-dimensional predicted transition space includes a three-dimensional predicted transition probability space. If the three-dimensional prediction transition space is predicted by a probabilistic analysis method, and the prediction result is expressed in three-dimensional space, it is the three-dimensional prediction transition probability space.
- the three-dimensional prediction transition space can also be predicted by using the logic reasoning method in set theory, and the prediction result is expressed in the three-dimensional space to obtain the three-dimensional prediction transition inference space.
- an embodiment of the present invention provides a network traffic incremental statistics system, which includes an acquisition module 1, a calculation module 2, an extraction module 3, and a storage module 4:
- the collection module 1 is used to obtain and save data packets at various levels of the virtualized network model in real time.
- the data packets are provided with a plurality of feature items, and the feature items include time.
- the collection module 1 takes the network model of the virtualized network as an extraction object.
- the establishment and change of network traffic cannot be separated from the network model. Therefore, collecting data packets according to the hierarchy of the network model in the virtualized network is very comprehensive and not lost.
- the network traffic model contains three elements: one is the node that characterizes the system components. The second is the arrow line (sometimes the edge) that reflects the relationship between the constituent elements. The third is the flow of traffic in the network. On the one hand, it reflects the quantitative relationship between the elements, and it also determines the goal and direction of the network model optimization. Therefore, collecting data packets for the network model can obtain more comprehensive types of data.
- the virtualized network model is the traditional TCP/IP four-layer reference model, and the data packets are collected from the application layer, transport layer, network layer, and network interface layer.
- the data packets collected from the application layer include structured data, semi-structured data, and unstructured data.
- the structured data is stored in a cloud platform or distributed computing environment, and stored in a database or file according to actual application requirements.
- For semi-structured data and unstructured data It is expressed in the form of a file in a cloud platform or distributed computing environment, and the key retrieval information is extracted and analyzed for subsequent rapid and flexible retrieval.
- the invention provides an incremental analyzer, which distributes the incrementally collected virtual network flow data packets to each corresponding storage space, merges with historical network data packets, and simultaneously updates various types of data retrieval and key data.
- the collection module 1 obtains data packets from the virtual network environment through a virtual network function VNF (Virtualized Network Function) running on a virtual machine VM (Virtual Machine).
- Virtual Network Function VNF Virtualized Network
- the MANO platform implements the description of virtual network functions, virtual deployment units, virtual connections, and network connection points based on the TOSCA (Topology and Orchestration Specification for Cloud Application) template, and builds a network service NS (Network Service) based on the multidirectional forwarding graph FG (Forwarding Graph) ).
- Multi-directional forwarding diagram covers VNF, PNF (Physical Network Function), VL (Virtual Link), CP (Connection Point), supports the description of the virtual network function forwarding path, supports the description of the virtual network function forwarding point, and realizes the virtual network function
- VNF Physical Network Function
- VL Virtual Link
- CP Connection Point
- the mapping of nodes to TOSCA template nodes and the decomposition to virtual deployment units realize the mapping of VDU (Virtual Deployment Unit) to VM. Therefore, VNF can collect and upload data packets very well.
- the calculation module 2 is configured to store the data packet in a high-dimensional space according to a feature item corresponding to a dimension, and expand along a preset modulus to obtain a high-order matrix.
- the calculation module 2 models the acquired data, that is, the data package is stored in a high-dimensional space according to a feature item corresponding to a dimension, so that the data package is not just a series of stacked data, but each in the high-dimensional space Coordinates, intervals. After completing the modeling of the transformation of the data packet into the high-dimensional space, in order to be able to process it further, the high-dimensional space is expanded through a preset module to obtain a high-order matrix.
- the N-dimensional space model is defined as Where I 1 , I 2 , I 3 , ..., IN represent the first to N-th order of the N-dimensional space.
- the N-dimensional space is expanded along the Pth order, and the resulting P-module matrix is defined as The number of rows of the P-module matrix is I P , and the number of columns is (I P+1 I P+2 ...I 1 I 2 ...I P-1 ).
- the module expansion matrix obtained by expanding the high-dimensional space along a specific module can be used in the network traffic subsequent processing algorithm, such as classification, trend prediction, clustering algorithm, etc.
- a 9-dimensional space is defined as
- the 9 orders of the 9-dimensional space are represented as I TIM , I SM , I DM , I SI , I DI , I SP , I DP , I VI , I CN represent time Time, source MAC address SrcMAC, destination MAC address DstMAC, Source IP address SrcIP, destination IP address DstIP, source port SrcPort, destination port DstPort, virtual network function identifier VNFID, virtual network traffic content Cnt.
- the modulo 3 expansion matrix obtained by expanding this 9-dimensional space along the third order has I 3 rows and I 4 I 5 I 6 I 7 I 8 I 9 I 1 I 2 .
- the extraction module 3 is used to remove duplicate and erroneous data in the high-order matrix and restore to a high-dimensional space to obtain a real-time core data set.
- the extraction module 3 removes the duplicate and erroneous data in the high-order matrix, and then can restore to the high-dimensional space to obtain the real-time core data set. Further data analysis and mining on the core collection in the high-dimensional space is more accurate than processing and analyzing directly on the original data set.
- the storage module 4 is configured to save the real-time core data set in real time along the time dimension in the high-dimensional space in chronological order to obtain a high-quality core data total set.
- the real-time core data sets need to be stored one by one for analysis and used as a whole.
- the virtual network traffic data has a strong Markov property, that is, the connection in the time dimension is large. Therefore, the storage module 4 will obtain the real-time core data collection in the high-dimensional space and save it in the corresponding time dimension to obtain high-quality core data. Total set.
- the total set of high-quality core data saved in this way can continuously update the left singular vector space by expanding the optimal basis vector of the matrix and incrementally using the newly added virtual network traffic data, projecting the newly added non-zero elements to each truncation In the unit orthogonal basis space, to achieve incremental network traffic quality data extraction and analysis.
- an embodiment of the present invention provides a network traffic incremental analysis system based on Embodiment 4, which includes a corresponding module 5, a collection module 6, and an analysis module 7:
- Corresponding module 5 is used to set the correspondence between feature items and virtual network traffic status.
- Corresponding module 5 can further subdivide the status of other feature items, such as port feature items in addition to traffic feature items.
- the state correspondence ensures a more intuitive connection between different feature items, and at the same time, the status changes during analysis It means the change of multiple feature items, the analysis of the state actually achieves the analysis of multiple feature items, and the multiple feature items are statistically linked as a state.
- the results of the analysis can represent the current virtual
- the actual representation of the network traffic status such as expressing each hardware in the virtual network as a feature item and corresponding to different states, after the analysis is completed, that is, the load and calculation loss of the hardware in the virtual network represented by each state generally change , You can understand the hardware status of the virtual network, more efficient, low cost, and very intuitive.
- it can also be network traffic, interface switching, error reporting, etc. virtual network data.
- the virtual network traffic status is the value/option interval of more than one characteristic item of the real-time core data set.
- feature items may also be options, such as ports A, B, C, etc., as long as they are characterized by one dimension in a high-dimensional space.
- the sampling module 6 is used to obtain the virtual network traffic status of the real-time core data set at the current time and the previous time.
- the sampling module 6 first needs to obtain the virtual network traffic state with a large correlation before the predicted time, that is, the virtual network traffic state of the real-time core data set at the current time and the previous time. For use in subsequent steps.
- the analysis of the real-time core data collection that is, the summary of the changes in the virtual network before and after, exists in time, so it is necessary to distinguish the real-time core data center.
- the time interval can be 1s, 3min, 6h It can also be a time specified by other people, and only need to be specifically limited according to the change time interval to be analyzed.
- the analysis module 7 is configured to analyze the virtual network traffic state and its probability of the real-time core data set at the next moment according to the virtual network traffic state of each real-time core data set in the high-quality core data set.
- the analysis module 7 After acquiring the virtual network traffic status of the real-time core data collection at the current time and the previous time, that is, knowing the initial conditions of the virtual network traffic status, the analysis module 7 performs an overall analysis based on each real-time core data collection in the entire high-quality core data collection, Obtaining the change rule of the state and combining the above initial conditions, the state of the network traffic at the next moment can be obtained.
- an embodiment of the present invention provides a network traffic incremental analysis system based on Embodiment 5, which includes a creation module 8, a setting module 9, a statistics module 10, and an analysis module 11:
- NFVC represents the virtual network traffic state of the real-time core data set at the current moment
- NFVP represents the virtual network traffic of the real-time core data set at the previous moment State
- NFVN represents the virtual network traffic state of the real-time core data set at the next moment.
- the creation module 8 uses the virtual network traffic status of the current moment, the previous moment, and the next moment as three dimensions of the three-dimensional space, each of which is related to time and can intuitively represent the virtual network traffic of the virtual network Changes in state. During the analysis, the analysis of the three time-related parameters can better reflect the changes of the real-time core data set with time.
- the characteristic items further include hardware usage parameters, which include CPU utilization rate and memory occupancy percentage, and the virtual network traffic status represented by the real-time core data set is the current hardware status.
- the setting module 9 is used to set the virtual network traffic state of the real-time core data set at the current moment to A Cx , the virtual network traffic state of the real-time core data set at the previous moment to A Px , and the virtual state of the real-time core data set at the next moment
- the network traffic status is A Nx .
- the setting module 9 When predicting the next virtual network traffic state, the setting module 9 needs to obtain the virtual network traffic state of the real-time core data set at the current moment as A Cx , and the virtual network traffic state of the real-time core data set at the previous moment is A Px . There are many changes in network traffic status, and the virtual network traffic status of the real-time core data set at the next moment may be represented by A Nx .
- the statistics module 10 is used to count the probability P of the virtual network traffic state changing from A Px to A Cx and finally to various A Nx in the three-dimensional transfer space.
- the virtual network traffic status of all real-time core data sets of the high-quality core data set is represented in it, which includes the virtual network traffic status A Px and the virtual network traffic status A Cx .
- the statistics module 10 The type and number of changes of A Nx at the next moment can be counted to obtain the probability P of the final change to various A Nx .
- the prediction module 11 is configured to use the A Cx , A Px and each A Nx as the coordinate value of the three-dimensional transfer space, and the corresponding P of each A Nx is A Cx , A Px and each A Nx represent points in the three-dimensional transfer space And expressed in the three-dimensional transition space to obtain a three-dimensional predicted transition space.
- a Nx After obtaining various A Nx , A Cx , A Px and each A Nx can also be expressed in the three-dimensional transfer space, but the point is not a 100% solid point, but the probability of all points is added as a 100% virtual Point, if the shade of color is used to represent the probability of A Cx , A Px and each A Nx in the three-dimensional transition space, then you can see a block/line/at least two points with different shades, which intuitively reflects A The possible probability of Nx , that is, the trend of the virtual network traffic state of the virtual network at the next moment, and after identifying A Cx , A Px, and each A Nx to the three-dimensional transfer space, the three-dimensional space actually contains the predicted space, It is set as the three-dimensional prediction transition space.
- the probability P of various A Nx is obtained, and the probability P is also taken as the value represented by the midpoint in the high-dimensional space.
- the network traffic incremental analysis system further predicts the probability of all possible virtual network traffic states after the subsequent addition of the real-time core data set, and represents it in the network transition space, The three-dimensional predicted transition probability space is obtained.
- the network traffic incremental analysis system After predicting the possible virtual network state and probability at the next moment, the network traffic incremental analysis system further predicts the possible virtual network state and probability at the next moment, which can better analyze the change of network state and provide a virtual network State early warning, the initial virtual network can take reasonable precautions and prepare measures to deal with possible subsequent bad states.
Landscapes
- Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
本发明公开了网络流量增量统计、分析方法及系统,涉及通信技术领域,该方法包括实时获取并保存虚拟化网络网络模型的各个层级的数据包,所述数据包设有多个特征项,所述特征项包括时间。将所述数据包按照一个特征项对应一个维度的方式保存于高维度空间,并沿预设的模展开得到高阶矩阵。去除所述高阶矩阵中的重复以及错误数据后,还原至高维度空间得到实时核心数据集合。按时间顺序,沿着高维空间中的时间维度实时保存所述实时核心数据集合,得到高质量核心数据总集。本发明能够实现网络功能虚拟化环境下的网络流量实时采集和增量式存储,构建高维度空间和转移空间模型,并通过增量方法进行分析。
Description
本发明涉及通信技术领域,具体涉及网络流量增量统计、分析方法及系统。
网络功能虚拟化技术指对组装成型的硬件资源进行虚拟化,通过构建计算、存储、网络三类虚拟资源池,来创建一系列虚拟机VM(Virtual Machine)。
计算虚拟化技术包括全虚拟化和半虚拟化两类,其中全虚拟化技术Full Virtualization完全通过创建的虚拟机来实现客户机操作系统和服务器硬件的协同:受保护的计算机指令通过虚拟机管理程序Hypervisor捕获并进行处理,操作系统通过Hypervisor分享和共用底层的服务器硬件。半虚拟化技术Para-Virtualization使用虚拟机管理程序Hypervisor分享存取底层的硬件,但是它的客户操作系统集成了虚拟化方面的软件代码.从而并不需重新编译或者触发陷阱,操作系统自身能够与虚拟进程进行非常好地协同与合作。基于这两种虚拟化技术能够根据网络扩容和缩容等需求动态生成或撤消虚拟机。
虚拟网络功能VNF(Virtualized Network Function)是一个软件包,运行于虚拟机VM之上,并与MANO(Manager and Orchestration)交互,实现网络流量控制和转发。MANO平台基于TOSCA(Topology and Orchestration Specification for Cloud Application)模板实现对虚拟网络功能、虚拟部署单元、虚拟连接、网络连接点的描述,基于 多向转发图FG(Forwarding Graph)构建网络服务NS(Network Service)。多向转发图涵盖VNF、PNF(Physical Network Function)、VL(Virtual Link)、CP(Connection Point),支持对虚拟网络功能转发路径的描述,支持对虚拟网络功能转发点的描述,实现虚拟网络功能结点到TOSCA模板结点的映射,以及到虚拟部署单元的分解,实现VDU(Virtual Deployment Unit)到VM的映射。编排后的网络服务通过验证并交给虚拟网络功能管理器进行解析,根据描述文件对资源和能力的描述交给VIM分配资源。
增量处理技术将网络流量按照时间维度进行形式化描述和表示,将数据切分为一系列的数据片段从而更好地研究虚拟网络流量数据片断的前后关系,借助一系列模型分析数据在时间维度上的变化的技术。而对于新增加的虚拟网络流量数据,其通过将其投影到历史流量数据来分析增量数据与历史数据的关系,借助增量数据在高维度空间各维度上的特征投影等进行建模。由于虚拟网络流量数据的马氏性很强且当前增量网络流量数据与历史数据关联很弱,可以直接在增量数据上进行推理并为网络功能虚拟化应用提供服务。另外可以利用增量奇异值分解等方法更新历史网络流量数据从而得到新的核心集合集,并针对核心集合进行快速处理,以提供及时和优质网络功能虚拟化服务。
虚拟网络功能是新一代网络中的重要组成部分,对虚拟网络功能中的网络流量进行实时采集和分析,有助于实现更智能化的部署、协同和调度。但是针对网络流量在时间维度上的动态变化特性,目前缺乏有效的方法进行分析能够首先实现网络功能虚拟化环境下的网络流量实时采集和增量式存储,构建关于这些数据的模型,并对虚拟网络中的网络流量进行统计以及分析,促使虚拟网络功能的部署、协同 以及调度能够更加智能化。
发明内容
针对现有技术中存在的缺陷,本发明的目的在于提供网络流量增量统计、分析方法及系统,能够实现网络功能虚拟化环境下的网络流量实时采集和增量式存储,构建高维度空间和转移空间模型,并通过增量方法进行统计或分析。
为达到以上目的,第一方面,本发明实施例提供一种网络流量增量统计方法,其包括以下步骤:
实时获取并保存虚拟化网络网络模型的各个层级的数据包,所述数据包设有多个特征项,所述特征项包括时间;
将所述数据包按照一个特征项对应一个维度的方式保存于高维度空间,并沿预设的模展开得到高阶矩阵;
去除所述高阶矩阵中的重复以及错误数据后,还原至高维度空间得到实时核心数据集合;
按时间顺序,沿着高维空间中的时间维度实时保存所述实时核心数据集合,得到高质量核心数据总集。
作为一个可选的实施方案,所述网络模型为TCP/IP四层参考模型,所述数据包采集自应用层、传输层、网络层以及网络接口层。
作为一个可选的实施方案,采集自所述应用层的数据包包括结构化数据、半结构化数据、非结构化数据。
作为一个可选的实施方案,所述特征项还包括:源MAC地址、目标MAC地址、源IP地址、目的IP地址、源端口、目标端口、虚拟网络功能标识符和虚拟网络流量数据内容。
作为一个可选的实施方案,其通过运行于虚拟机VM(Virtual Machine)上的虚拟网络功能VNF(Virtualized Network Function)从虚拟网络环境中获取数据包。
作为一个可选的实施方案,通过HOSVD(High-Order Singular Value Decomposition,高阶奇异值分解)去除所述高阶矩阵中的重复以及错误数据。
第二方面,本发明实施例还提供一种基于第一方面所述统计方法的网络流量增量分析方法,在得到高质量核心数据总集后,还包括:
设置特征项与虚拟网络流量状态的对应关系;
获取当前时刻和前一时刻的实时核心数据集合的虚拟网络流量状态;
根据所述高质量核心数据总集中各个实时核心数据集合的虚拟网络流量状态,分析下一时刻的实时核心数据集合的虚拟网络流量状态及其概率。
第三方面,本发明实施例还提供一种基于第二方面所述的分析方法,其特征在于:
以NFVC、NFVP、NFVN为维度建立三维转移空间,其中,NFVC为当前时刻的实时核心数据集合的虚拟网络流量状态的集合,NFVP为前一时刻的实时核心数据集合的虚拟网络流量状态的集合,NFVN为下一时刻的实时核心数据集合的虚拟网络流量状态的集合;
设置当前时刻的实时核心数据集合的虚拟网络流量状态为ACx,前一时刻的实时核心数据集合的虚拟网络流量状态为APx,下一时刻的实时核心数据集合的虚拟网络流量状态为ANx;
统计三维转移空间内,虚拟网络流量状态从APx变化至ACx最后变化至各种ANx的概率P;
将所述ACx、APx和各个ANx作为三维转移空间的坐标值,各个ANx相应的P为ACx、APx和各个ANx在所述三维转移空间表示点的值,并表示于所述三维转移空间内,得到三维预测转移空间。
作为一个可选的实施方案,所述虚拟网络流量状态为所述高维度空间的至少一个区间。
作为一个可选的实施方案,所述虚拟网络流量状态为所述实时核心数据集合一个以上的特征项的数值/选项区间。
作为一个可选的实施方案,所述特征项还包括硬件使用参数,所述硬件使用参数包括CPU利用率、内存占用百分比,所述实时核心数据集合所表示的虚拟网络流量状态为当前硬件所处的状态。
举例来说,在进行预测CPU利用率、可用内存、可用硬盘等资源时,如果想预测CPU利用率,可以采集CPU使用率数据,构建状态空间。例如,将CPU使用率10%以下定义为状态1,CPU使用率11%至20%下定义为状态2,以此类推,CPU使用率91%以上定义为10,这样CPU使用率状态空间为{1,2,3,4,5,6,7,8,9,10}。
或者构建可用内存状态空间时可以对可用内存数据进行分段,例如,将10G以下可用内存定义为状态1,11G至20G可用内存定义为状态2,以此类推。因为数据中心服务器可用内存数量是有上限的,所以状态空间也是有限的,假设数据中心可用内存上限对应的状态为N,则状态空间集合为{1,2,3,4,5,6,…,N}。
作为一个可选的实施方案,将所述三维预测转移空间作为三维转移空间,进一步预测后续添加实时核心数据集合后所有可能达成虚拟网络流量状态的概率,并表示在所述网络转移空间内,得到三维预测转移概率空间。
第四方面,本发明实施例还提供一种网络流量增量统计系统,其 包括:
采集模块,用于实时获取并保存虚拟化网络网络模型的各个层级的数据包,所述数据包设有多个特征项,所述特征项包括时间;
计算模块,用于将所述数据包按照一个特征项对应一个维度的方式保存于高维度空间,并沿预设的模展开得到高阶矩阵;
提取模块,用于去除所述高阶矩阵中的重复以及错误数据后,还原至高维度空间得到实时核心数据集合;
存储模块,用于按时间顺序,沿着高维空间中的时间维度实时保存所述实时核心数据集合,得到高质量核心数据总集。
作为一个可选的实施方案,所述网络模型为TCP/IP四层参考模型,所述数据包采集自应用层、传输层、网络层以及网络接口层。
作为一个可选的实施方案,采集自所述应用层的数据包包括结构化数据、半结构化数据、非结构化数据。
作为一个可选的实施方案,所述特征项还包括:源MAC地址、目标MAC地址、源IP地址、目的IP地址、源端口、目标端口、虚拟网络功能标识符和虚拟网络流量数据内容。
作为一个可选的实施方案,其通过运行于虚拟机VM(Virtual Machine)上的虚拟网络功能VNF(Virtualized Network Function)从虚拟网络环境中获取数据包。
作为一个可选的实施方案,通过HOSVD(High-Order Singular Value Decomposition,高阶奇异值分解)去除所述高阶矩阵中的重复以及错误数据.
第五方面,本发明实施例还提供一种基于第四方面所述统计系统的网络流量增量分析系统其包括:
对应模块,用于设置特征项与虚拟网络流量状态的对应关系;
取样模块,用于获取当前时刻和前一时刻的实时核心数据集合的虚拟网络流量状态;
分析模块,用于根据所述高质量核心数据总集中各个实时核心数据集合的虚拟网络流量状态,分析下一时刻的实时核心数据集合的虚拟网络流量状态及其概率。
第六方面,本发明实施例还提供一种基于第五方面所述的分析系统,其特征在于:
创建模块,用于以NFVC、NFVP、NFVN为维度建立三维转移空间,其中,NFVC代表当前时刻的实时核心数据集合的虚拟网络流量状态,NFVP代表前一时刻的实时核心数据集合的虚拟网络流量状态,NFVN代表下一时刻的实时核心数据集合的虚拟网络流量状态;
设置模块,用于设置当前时刻的实时核心数据集合的虚拟网络流量状态为A
Cx,前一时刻的实时核心数据集合的虚拟网络流量状态为A
Px,下一时刻的实时核心数据集合的虚拟网络流量状态为A
Nx;
统计模块,用于统计三维转移空间内,虚拟网络流量状态从A
Px变化至ACx最后变化至各种A
Nx的概率P;
预测模块,用于将所述A
Cx、A
Px和各个A
Nx作为三维转移空间的坐标值,各个A
Nx相应的P为A
Cx、A
Px和各个A
Nx在所述三维转移空间表示点的值,并表示于所述三维转移空间内,得到三维预测转移空间。
作为一个可选的实施方案,所述虚拟网络流量状态为所述高维度空间的至少一个区间。
作为一个可选的实施方案,所述虚拟网络流量状态为所述实时核心数据集合一个以上的特征项的数值/选项区间。
作为一个可选的实施方案,所述特征项还包括硬件使用参数,所 述硬件使用参数包括CPU利用率、内存占用百分比,所述实时核心数据集合所表示的虚拟网络流量状态为当前硬件所处的状态。
作为一个可选的实施方案,其特征在于:将所述三维预测转移空间作为三维转移空间,进一步预测后续添加实时核心数据集合后所有可能达成虚拟网络流量状态的概率,并表示在所述网络转移空间内,得到三维预测转移概率空间。
与现有技术相比,本发明的优点在于:
(1)本发明网络流量增量统计方法以及系统首先获取的是当前虚拟化网络的网络模型的各个层级中的数据包,由于网络模型可能有多种架构,其层级也各不相同,如果仅仅设定具体数量的层级进行设定,则可能获取的数据不全、或者出现冗余数据,导致统计以及分析不再准确。进一步的,获取得到当前虚拟化网络的网络模型的各个成绩的数据包后,为数据包设置了多个特征项,并按照一个特征项对应一个维度的方式保存到了高维度空间中,实现较为缺乏实感的数据信息到具有实际量纲的空间量的转化。在转化完成后,进一步将空间量展开得到矩阵模式的数据,在矩阵中,能够更加清晰的看出数据中不符合规则、异常的数据,因此能够通过转化为矩阵去除数据包中重复或者错误的数据,使得数据更加优质、准确。在完成数据的“提纯”后,本发明按照时间的顺序对数据包进行保存,由于本发明针对网络流量的统计和分析,主要针对的是网络流量增量,即网络流量在时间上的变化,因此,将数据以时间的顺序进行保存是的整个高质量核心数据总集是按照时间顺序扩展的,方便了后续整理、分析依照时间参数进行。
(2)本发明网络流量增量分析方法及系统首先对数据包的特征项进行分类,即设置特征项与虚拟网络流量状态的对应关系,如设置 某个网络端口流量0-10M/s为“低速”状态,10-20M/s为“中速”状态,20-100M/s为“高速”状态。分析时候通过当前状态来分析,对于实质改变不大的数据不会出现不同的分析方案,如对1.01M/s和1.02M/s,均按照低速状态处理。而当需要进行细节处理时候,分类可以更加细致,直至满足需求,同时节省了计算资源。在知道高质量核心数据总集内的各个实时核心数据所表示的虚拟网络流量状态的已经发生的变化后,即可以分析历史趋势,并分析下一时刻的实时核心数据集合的虚拟网络流量状态及其概率。
图1为实施例的步骤流程图;
图2为实施例中采集数据的结构示意图;
图3为实施例网络数据转化为高维空间数据的示意图;
图4为实施例沿着高维空间中的时间维度实时保存所述实时核心数据集合得到高质量核心数据总集的示意图;
图5为另一实施例的步骤流程图;
图6为另一实施例的步骤流程图;
图7为实施例建立三维转移空间的示意图;
图8为实施例的结构示意图;
图9为另一实施例的结构示意图;
图10为另一实施例的结构示意图;
图中:1-采集模块,2-计算模块,3-提取模块,4-存储模块,5-对应模块,6-取样模块,7-分析模块,8-创建模块,9-设置模块,10-统计模块,11-预测模块。
以下结合附图对本发明的实施例作进一步详细说明。
本发明实施例提供一种网络流量增量统计、分析方法及系统,其能够实现网络功能虚拟化环境下的网络流量实时采集和增量式存储,构建高维度空间和转移空间模型,并通过增量方法进行分析。
为了更好的理解技术方案,下面结合具体实施方式进行详细的说明。
实施例一
如图1所示,本发明实施例提供一种网络流量增量统计方法,其包括:
S1:实时获取并保存虚拟化网络网络模型的各个层级的数据包,所述数据包设有多个特征项,所述特征项包括时间。
需要对虚拟化网络的网络流量分析,那么首先需要对虚拟化网络的各个数据进行采集,如果采集的各个要素不全,那么就相当于遗漏一部分的影响因子,在要素不全的情况下,进行数据分析是不客观且不准确的。因此,本发明首先以虚拟化网络的网络模型作为提取对象,网络的传输是离不开其网络模型的,计算机网络是指由通信线路互相连接的许多自主工作的计算机构成的集合体,而各个部件之间以何种规则进行通信,就是网络模型研究的问题。网络模型一般是指OSI七层参考模型和TCP/IP四层参考模型。网络流量的建立和变化是离不开网络模型的,因此根据虚拟化网络中网络模型的层级来采集数据包是十分全面而没有遗失的。
此外,网络流量模型中包含有三个要素:一是表征系统组成元素的节点。二是体现各组成元素之间关系的箭线(有时是边)。三是在网络中流动的流量,它一方面反映了元素间的量化关系,同时也决定着网络模型优化的目标与方向。本发明针对网络流量增量进行统计分析 时候,网络模型中的这三个要素也是必不可少的,因此针对网络模型进行数据包的采集能够更加获取更加全面的种类的数据。
作为一个优选的实施方案,其虚拟化网络网络模型为传统的TCP/IP四层参考模型,而数据包采集自应用层、传输层、网络层以及网络接口层。其中采集自所述应用层的数据包包括结构化数据、半结构化数据、非结构化数据。对于结构化数据存储在云平台或分布式计算环境中,并根据实际应用需求存储在数据库或者文件中。对于半结构化数据和非结构化数据。在云平台或分布式计算环境中以文件形式表示,并将关键检索信息进行提取分析,以便于后续快速灵活检索。本发明提供增量分析器,将增量采集到的网络流量数据包分配到各个对应的存储空间中,并与历史网络数据包进行合并,同时更新各类数据的检索并键数据。
作为一个可选的实施方案,如图2所示,实时获取并保存虚拟化网络网络模型的各个层级的数据包,是通过运行于虚拟机VM(Virtual Machine)上的虚拟网络功能VNF(Virtualized Network Function)从虚拟网络环境中获取数据包。虚拟网络功能VNF(Virtualized Network Function)是一个软件包,运行于虚拟机VM之上,并与MANO(Manager and Orchestration)交互,实现网络流量控制和转发。MANO平台基于TOSCA(Topology and Orchestration Specification for Cloud Application)模板实现对虚拟网络功能、虚拟部署单元、虚拟连接、网络连接点的描述,基于多向转发图FG(Forwarding Graph)构建网络服务NS(Network Service)。多向转发图涵盖VNF、PNF(Physical Network Function)、VL(Virtual Link)、CP(Connection Point),支持对虚拟网络功能转发路径的描述,支持对虚拟网络功能转发点的描述,实现虚拟网络功能结点到TOSCA模板结点的映射,以及到虚拟 部署单元的分解,实现VDU(Virtual Deployment Unit)到VM的映射。因此VNF能够很好采集数据包并上传。
在本实施方案中,在虚拟网络环境中,如现在较为流行的云环境中,设置采集管理器、VNF/存储系统以及增量分析器。采集管理器用于下发采集指令和参数,VNF在受到指令后按照参数进行实时采集数据,其存储系统存储VNF上传的虚拟网络流量数据,增量分析器则对新增及历史数据合成并存储。
S2:将所述数据包按照一个特征项对应一个维度的方式保存于高维度空间,并沿预设的模展开得到高阶矩阵。
如图3步骤①所示,设有特征项的数据包是趋向于数据的抽象的,直接进行分析则仅仅是通过一些算法对数据进行处理,这种处理是抽象的且可能是缺乏实际依据的。本发明则对数据进行建模,即将数据包按照一个特征项对应一个维度的方式保存在高维度空间,这样数据包不再仅仅是一系列堆积的数据,而是在高维空间中的各个坐标、区间。在完成数据包转化至高维空间的建模后,为了能够进一步处理,通过预设的模将该高维度空间进行展开得到高阶矩阵。
具体来说,以ASCII形式将设有N个特征项的数据包表示在高维度空间中。定义的N维空间模型为
其中I
1,I
2,I
3,…,I
N表示N维空间的第一至第N阶。其中将N维空间沿着第P阶展开,得到的P模矩阵定义为
其中P模矩阵的行数为I
P,列数为
(IP+1IP+2...I1I2...IP-1)。高维空间沿特定模展开得到的模展开矩阵,可以用于网络流量后续处理算法,例如分类、趋势预测、聚类算法等。
举例来说,一个9维空间定义为
9维空间的9个阶分别表示为I
TIM,I
SM,I
DM,I
SI,I
DI,I
SP,I
DP,I
VI,I
CN代表时间Time、源MAC地址SrcMAC、目的MAC地址DstMAC、源IP地址SrcIP、目的IP地 址DstIP、源端口SrcPort、目的端口DstPort、虚拟网络功能标识符VNFID、虚拟网络流量内容Cnt。将这个9维空间沿第三阶展开得到的模3展开矩阵行数为I
3,列数为I
4I
5I
6I
7I
8I
9I
1I
2。
S3:去除所述高阶矩阵中的重复以及错误数据后,还原至高维度空间得到实时核心数据集合。
如图3步骤②所示,在采样过程中,难免出现重复以及错误的数据,因此在当前的高阶矩阵中时存在不一致、重复、冗余的数据的,这些数据可能对分析工作造成不良影响甚至导致分析出错,因此,需要首先去除高阶矩阵中的重复以及错误数据后,才能够还原至高维度空间得到实时核心数据集合。进一步在高维空间上的核心集合上进行数据分析与挖掘,比直接在原始数据集上进行处理分析,效果更精确。
需要说明的是,高阶矩阵的去除重复不一致数据可以通过多种本领域技术人员已知的技术方案,如果对高阶矩阵使用HOSVD(High-Order Singular Value Decomposition高阶奇异值分解)高阶奇异值分解技术能够去除重复、冗余、不一致的低质量数据,得到高质量核心数据集。另外,卡尔曼滤波和回归方法可以消除噪音数据与不确定数据,实现时空数据清洗。基于概率统计方法,在一定置信度下删除异常数据或冗余数据,可以确保不会影响处理结果的有效性。模糊匹配技术通过设计相似度函数计算数据的近似程度,从而实现重复冗余数据的清洗。
S4:按时间顺序,沿着高维空间中的时间维度实时保存所述实时核心数据集合,得到高质量核心数据总集。
如图4所示,在对采集得到的实时数据处理得到高质量的实时核心数据集合,为了能够进行整体分析,需要逐个将实时核心数据集合存储到一起,供分析时候,作为整体使用。而虚拟网络流量数据的马 氏性很强,即在时间维度联系是较大的,因此,将得到实时核心数据集合在高维空间中对应时间维度进行保存,得到高质量的核心数据总集。这样保存得到的高质量核心数据总集能够通过展开矩阵的最优基向量,并通过增量的方式利用新增虚拟网络流量数据不断更新左奇异向量空间,将新增非零元素投影到各个截断的单位正交基空间中,从而实现增量式网络流量优质数据提取与分析。
实施例二
如图5所示,本发明实施例提供一种网络流量增量分析方法,其基于实施例一种的网络流量统计方法,其在完成实施例一的统计方法后,进行如下步骤:
A1:设置特征项与虚拟网络流量状态的对应关系。
数据包的特征项可以是多个选项,也可以是一系列连续的数值,而虚拟网络的网络流量中的选项数值可能有十分多的选项,如果对每一个单一特征项的独特的数据进行分析,将需要巨量的计算资源。而实际分析可能并不需要如此高的精度,进而造成资源的浪费和成本的提升。
作为一个优选的实施方案,虚拟网络流量状态为所述高维度空间的至少一个区间。即高维度空间中部分特征项的某个区间进行组合形成一个虚拟网络流量状态,同一部分特征项的另一些区间组合形成另一个虚拟网络流量状态,并最终以多个虚拟网络流量状态划分上述的部分特征项。
本发明设置特征项与虚拟网络流量状态进行对应,设置某个网络端口流量0-10M/s为“低速”状态,10-20M/s为“中速”状态,20-100M/s为“高速”状态。在实际进行分析时候,数据5.01M/s、5.02M/s对后续的分析均为低速状态,分析时也只需要对三个状态量进行处理,十 分方便快捷,而进行精细化分析,数据诸如5.01M/s、5.02M/s则作为不同的数据进行详细计算,对模糊分析并没有太大影响。而如果上述状态分类并不能满足要求时,还可以进一步详细的分类,直至达到分析的需求。这种对应提高了分析的效率以及计算成本。
进一步的,上述举例是对单个特征项的状态对应,如果涉及高维空间中的多个特征项的状态区分,传统的针对所有数据进行详细分析可能难以达成,而本发明则可以进一步的细分其他特征项状态,如除了流量特征项,还有端口特征项,对应状态时候可以:A端口以及B端口的流量0-10M/s,为“低速”状态,10-20M/s为“中速”状态,20-100M/s为“高速”状态,A端口流量0-10M/s,B端口流量10-20M/s为“低中速”状态等等。这样状态对应保证了不同特征项之间能够更加直观的联系,同时,在分析时候,状态的变更意味着多个特征项的变更,对状态的分析实际上就达成了对多个特征项的分析,而多个特征项作为一个状态进行统计是联系在一起的,分析的结果即可以表现当前虚拟网络流量状态的实际表示的内容,如对虚拟网络中各个硬件以特征项进行表述并对应不同的状态,在分析完毕后,即通过各个状态所表示的虚拟网络中硬件的负载、计算损耗大致变化,即可了解虚拟网络的硬件状态,更加效率,成本低,同时十分直观。除了硬件状态,还可以是网络流量、接口切换、报错等等虚拟网络的数据。
作为一个可选的实施方案,虚拟网络流量状态为实时核心数据集合一个以上的特征项的数值/选项区间。
除了数值区间外,特征项还有可能是选项,如端口A、B、C等等,只要是在高维度空间上一维度进行表征的区间即可。
A2:获取当前时刻和前一时刻的实时核心数据集合的虚拟网络流量状态。
对实时核心数据总集进行分析,即总结虚拟网络中前后的变化,在时间上,是存在先后的,因此,需要对实时核心数据中心行区分。将当前添加的实时核心数据集合作为当前时刻的实时核心数据集合,前一次添加的实时核心数据结合作为前一时刻的实时核心数据集合即可,其中的时刻的间隔既可以是1s、3min、6h、也可以是其他人为规定的时间,只需根据需要分析的变化时间间隔进行具体限定即可。
因此,在需要对当前虚拟网络流量状态进行预测时,首先需要获取预测时刻之前的关联较大的虚拟网络流量状态,即当前时刻、前一时刻的实时核心数据集合的虚拟网络流量状态。
A3:根据所述高质量核心数据总集中各个实时核心数据集合的虚拟网络流量状态,分析下一时刻的实时核心数据集合的虚拟网络流量状态及其概率。
在获取当前时刻、前一时刻的实时核心数据集合的虚拟网络流量状态,即知道了虚拟网络流量状态的初始条件,随后需要根据整个高质量核心数据总集中各个实时核心数据集合进行整体分析,得到状态的变化规律,并结合上述的初始条件,即可求取下一时刻网络流量的状态。如初始条件为虚拟网络的网络流量中硬件使用率状态为“高”“中”“低”,初始条件为,从“高”状态直接转化为“低”状态,经过对高质量核心数据总集的整体分析得出转化规律后,输入初始调节:其从高”状态直接转化为“低”状态后80%概率转化为“低”状态,15%状态转化为“中”状态,5%状态转化为“高”状态,即为下一时刻预测的预测结果。
下面以一个例子来进一步说明,以便于整体理解本方案。
当前网络流量处于9M/s至26M/s之间,设置特征项与网络流量状态的对应关系为:将9M/s至14M/s标识为状态10,15M/s至20M/s 标识为状态17,21M/s至26M/s标识为状态23,因此当前虚拟网络流量状态空间包括10、17、23三个状态。
例如有一个虚拟网络流量状态序列,整个状态序列中出现以10为首三元序列的概率为2/9,也就是说出现(10,x,x)这种三元序列的概率为2/9,x取值为17、23;整个状态序列中出现以17为首三元序列的概率为3/9,也就是说出现(17,x,x)这种三元序列的概率为3/9,x取值为10、23;整个状态序列中出现以23为首三元序列的概率为4/9,也就是说出现(23,x,x)这种三元序列的概率为4/9,x取值为10、17。本实施例截取这个序列中间一段为(10,17,23,10,17,17,10,10,17,23,10,17,23,17,10,23,10,23,10,23,23),上边这个包含21个元素序列中,(10,x,x)这种三元序列有8个,分别为(10,17,23)、(10,17,17)、(10,10,17)、(10,17,23)、(10,17,23)、(10,23,10)、(10,23,10)、(10,23,23)。这8个三元序列中的第一个值10表示上一时刻状态为10,第二个值表示当前时刻状态,第三个值表示下一时刻状态。上述8个三元序列中,第二个值为10的只有第三个序列(10,10,17),表示上一时刻状态为10,当前时刻状态为10,下一时刻状态为17的概率为1。上述8个三元序列中,第二个值为17的有四个序列,分别为(10,17,23)、(10,17,17)、(10,17,23)、(10,17,23),表明上一时刻状态为10,当前时刻状态为17,下一时刻状态为17的概率为1/4。同理表明上一时刻状态为10,当前时刻状态为17,下一时刻状态为23的概率为3/4。根据上述8个三元序列,我们同样可以计算出上一时刻状态为10,当前时刻状态为23,下一时刻状态为10的概率为2/3。上一时刻状态为10,当前时刻状态为23,下一时刻状态为23的概率为1/3。
根据上述的方法,对整个虚拟网络流量状态序列进行统计,可以 得到转移概率,为了便于阐述,本实施例假定转移概率如表1所示。表1最上边一行表示上一时刻三个状态,其中10(2/9)表示上一时刻状态10出现的概率为2/9,17(3/9)表示上一时刻状态17出现的概率为3/9,23(4/9)表示上一时刻状态23出现的概率为4/9。这个三状态的概率值之和为1。表1有12列,第1列、第5列、第9列表示当前状态。表1有5行,第2行表示下一状态。表1第3行第2、3、4列、第4行第2、3、4列、第5行第2、3、4列一共有9个状态转移概率,表示上一时刻状态为10时,当前时刻与下一时刻各状态值的转移概率。例如,表1第3行第3列的值为1,表示上一时刻状态为10,当前时刻状态为10,下一时刻状态为17的概率为1,同理,表1第4行第4列的值为3/4,表示上一时刻状态为10,当前时刻状态为17,下一时刻状态为23的概率为3/4。表1第3行第6、7、8列、第4行第6、7、8列、第5行第6、7、8列一共有9个状态转移概率,表示上一时刻状态为17时,当前时刻与下一时刻各状态值的转移概率。表1第3行第10、11、12列、第4行第10、11、12列、第5行第10、11、12列一共有9个状态转移概率,表示上一时刻状态为23时,当前时刻与下一时刻各状态值的转移概率。
表1
将表1第一行上一时刻状态值对应的概率与下边的转移概率值相乘,计算出三维空间转移概率值,如表2所示。表2中,第三行、第四行、第五行的转移概率之和都为1。例如,第三行转移概率为2/9,1/3,4/9,相加为1。
表2
而随着时间推移,初始的高质量核心数据总集中不断添加新的实时核心数据集合,各状态概率值发生改变。假设更新后状态10的概率从2/9减小为1/9,状态17的概率保持3/9不变,状态23的概率从4/9增大为5/9,当前状态和下一状态的状态转移概率保持不变(即沿用表1中3,4,5行的概率数据),则三维转移空间也同时增量更新。表3为增量更新后的三维转移空间元素转移概率值:
表3
在统计出概率后,即可以对虚拟网络的流量状态进行预测:假如上一时刻网络流量状态为23,当前时刻网络流量状态为17,根据表4第4行第10、11、12列,可以得知,下一时刻网络流量状态为17 的概率为5/36,为23的概率为15/36。因为概率大可能性就大,所以下一时该网络流量状态值最有可能为23,即网络流量在21M/s至26M/s之间。计算得出下一时刻网络流量状态后,可以接着计算下下时刻网络流量状态,根据表3第5行第6、7、8列,下下时刻网络流量最有可能为10,即网络流量在9M/s至14M/s之间。进一步的,对下下一时刻,可能的流量状态进行必要措施,以及灾害预防。
实施例三
如图6和图7所示,在实施例二的基础上,本发明实施例提供一种网络流量分析方法,其基于前述的网络流量分析方法,包括以下步骤:
B1:以NFVC、NFVP、NFVN为维度建立三维转移空间,其中,NFVC代表当前时刻的实时核心数据集合的虚拟网络流量状态,NFVP代表前一时刻的实时核心数据集合的虚拟网络流量状态,NFVN代表下一时刻的实时核心数据集合的虚拟网络流量状态。
为了更加直观的进行分析,建立三维转移空间,并以NFVC代表当前时刻的实时核心数据集合的虚拟网络流量状态,NFVP代表前一时刻的实时核心数据集合的虚拟网络流量状态,NFVN代表下一时刻的实时核心数据集合的虚拟网络流量状态。
高维度空间对于人来说,仍然过于抽象,而如果能将虚拟网络流量状态的变化通过三维空间进行表示,则将更加直观,同时低维度的数据将更加易于分析。使用当前时刻、前一时刻以及下一时刻的虚拟网络流量状态作为三维空间的的三个维度,其每一个维度均和时间是有关的,能够十分直观的表现虚拟网络的虚拟网络流量状态的变化。在进行分析时,对三个和时间有关的参数进行分析,能够更加体现实时核心数据集合随着时间的变化。
具体来说,特征项还包括硬件使用参数,所述硬件使用参数包括CPU利用率、内存占用百分比,所述实时核心数据集合所表示的虚拟网络流量状态为当前硬件所处的状态。
B2:设置当前时刻的实时核心数据集合的虚拟网络流量状态为A
Cx,前一时刻的实时核心数据集合的虚拟网络流量状态为A
Px,下一时刻的实时核心数据集合的虚拟网络流量状态为A
Nx;
在预测下一虚拟网络流量状态时,首先获取当前时刻的实时核心数据集合的虚拟网络流量状态为A
Cx,前一时刻的实时核心数据集合的虚拟网络流量状态为A
Px,由于虚拟网络流量状态变化的多种多样,其下一时刻的实时核心数据集合的虚拟网络流量状态可能有多种均以A
Nx来代表。
B3:统计三维转移空间内,虚拟网络流量状态从A
Px变化至A
Cx最后变化至各种A
Nx的概率P。
在创建三维转移空间后,高质量核心数据总集的所有实时核心数据集合的虚拟网络流量状态均表示于其中,其中包含有虚拟网络流量状态A
Px以及虚拟网络流量状态A
Cx,此时可以统计下一时刻A
Nx的种类以及变化次数,从而得到最后变化至各种A
Nx的概率P。
B4:将所述A
Cx、A
Px和各个A
Nx作为三维转移空间的坐标值,各个A
Nx相应的P为A
Cx、A
Px和各个A
Nx在所述三维转移空间表示点的值,并表示于所述三维转移空间内,得到三维预测转移空间。
在得到各种A
Nx,A
Cx、A
Px和各个A
Nx也是可以表示到三维转移空间中的,但是该点并不是100%的实心点,而是所有点的概率加起来为100%的虚点,如果使用颜色的深浅来表示A
Cx、A
Px和各个A
Nx在三维转移空间的概率的话,那么则可以看到一块区域/线/至少两个点深浅不一,较为直观的体现了A
Nx的可能概率,即下一时刻虚拟网 络的虚拟网络流量状态的趋势,同时在将A
Cx、A
Px和各个A
Nx标识到三维转移空间后,其该三维空间中实际还包含预测的空间,即设为三维预测转移空间。
作为一个优选的实施方案,在得到各种A
Nx的概率P,将概率P也作为高维空间中点所表示的值。
进一步的,将所述三维预测转移空间作为三维转移空间,进一步预测后续添加实时核心数据集合后所有可能达成虚拟网络流量状态的概率,并表示在所述网络转移空间内,得到三维预测转移概率空间。
在预测下一时刻,可能的虚拟网络状态以及概率后,进一步预测下下一时刻的可能的虚拟网络状态以及概率,能够更好的分析网络状态的变更,并提供虚拟网络状态预警,初始虚拟网络能够对应后续可能出现的较坏的状态进行合理的预防以及准备处理措施。
需要说明的是,上述网络转移空间除了三维转移空间,还包括四维转移空间、五维转移空间等。
三维转移空间包括三维预测转移空间;三维转移空间中的数据用于预测未来流量趋势,并在三维空间表示预测结果得到三维预测转移空间。三维转移空间中的数据用于统计分析历史流量特征,并在三维空间中表示统计结果得到三维统计转移空间。
三维预测转移空间包括三维预测转移概率空间。如果三维预测转移空间采用概率分析方法进行预测,并在三维空间中表示预测结果得到就是三维预测转移概率空间。三维预测转移空间也可以采用集合论中的逻辑推理方法进行预测,并在三维空间中表示预测结果得到三维预测转移推理空间。
实施例四
如图8所示,本发明实施例提供一种网络流量增量统计系统,其 包括,采集模块1、计算模块2、提取模块3以及存储模块4:
采集模块1,用于实时获取并保存虚拟化网络网络模型的各个层级的数据包,所述数据包设有多个特征项,所述特征项包括时间。
采集模块1以虚拟化网络的网络模型作为提取对象,网络流量的建立和变化是离不开网络模型的,因此根据虚拟化网络中网络模型的层级来采集数据包是十分全面而没有遗失的。同时,网络流量模型中包含有三个要素:一是表征系统组成元素的节点。二是体现各组成元素之间关系的箭线(有时是边)。三是在网络中流动的流量,它一方面反映了元素间的量化关系,同时也决定着网络模型优化的目标与方向。因此针对网络模型进行数据包的采集能够更加获取更加全面的种类的数据。
作为一个优选的实施方案,虚拟化网络网络模型为传统的TCP/IP四层参考模型,而数据包采集自应用层、传输层、网络层以及网络接口层。其中采集自所述应用层的数据包包括结构化数据、半结构化数据、非结构化数据。对于结构化数据存储在云平台或分布式计算环境中,并根据实际应用需求存储在数据库或者文件中。对于半结构化数据和非结构化数据。在云平台或分布式计算环境中以文件形式表示,并将关键检索信息进行提取分析,以便于后续快速灵活检索。本发明提供增量分析器,将增量采集到的虚拟网络流量数据包分配到各个对应的存储空间中,并与历史网络数据包进行合并,同时更新各类数据的检索并键数据。
作为一个可选的实施方案,采集模块1通过运行于虚拟机VM(Virtual Machine)上的虚拟网络功能VNF(Virtualized Network Function)从虚拟网络环境中获取数据包。虚拟网络功能VNF(Virtualized Network Function)是一个软件包,运行于虚拟机VM 之上,并与MANO(Manager and Orchestration)交互,实现网络流量控制和转发。MANO平台基于TOSCA(Topology and Orchestration Specification for Cloud Application)模板实现对虚拟网络功能、虚拟部署单元、虚拟连接、网络连接点的描述,基于多向转发图FG(Forwarding Graph)构建网络服务NS(Network Service)。多向转发图涵盖VNF、PNF(Physical Network Function)、VL(Virtual Link)、CP(Connection Point),支持对虚拟网络功能转发路径的描述,支持对虚拟网络功能转发点的描述,实现虚拟网络功能结点到TOSCA模板结点的映射,以及到虚拟部署单元的分解,实现VDU(Virtual Deployment Unit)到VM的映射。因此VNF能够很好采集数据包并上传。
计算模块2,用于将所述数据包按照一个特征项对应一个维度的方式保存于高维度空间,并沿预设的模展开得到高阶矩阵。
计算模块2对获取的数据进行建模,即将数据包按照一个特征项对应一个维度的方式保存在高维度空间,这样数据包不在仅仅是一系列堆积的数据,而是在高维空间中的各个坐标、区间。在完成数据包转化至高维空间的建模后,为了能够进一步处理,通过预设的模将该高维度空间进行展开得到高阶矩阵。
具体来说,定义N维空间模型为
其中I
1,I
2,I
3,…,I
N表示N维空间的第一至第N阶。其中将N维空间沿着第P阶展开,得到的P模矩阵定义为
其中P模矩阵的行数为I
P,列数为(I
P+1I
P+2...I
1I
2...I
P-1)。高维空间沿特定模展开得到的模展开矩阵,可以用于网络流量后续处理算法,例如分类、趋势预测、聚类算法等。
举例来说,一个9维空间定义为
9维空间的9个阶分别表示为I
TIM,I
SM,I
DM,I
SI,I
DI,I
SP,I
DP,I
VI,I
CN代表时间Time、源MAC地 址SrcMAC、目的MAC地址DstMAC、源IP地址SrcIP、目的IP地址DstIP、源端口SrcPort、目的端口DstPort、虚拟网络功能标识符VNFID、虚拟网络流量内容Cnt。将这个9维空间沿第三阶展开得到的模3展开矩阵行数为I
3,列数为I
4I
5I
6I
7I
8I
9I
1I
2。
提取模块3,用于去除所述高阶矩阵中的重复以及错误数据后,还原至高维度空间得到实时核心数据集合。
提取模块3去除高阶矩阵中的重复以及错误数据后,才能够还原至高维度空间得到实时核心数据集合。进一步在高维空间上的核心集合上进行数据分析与挖掘,比直接在原始数据集上进行处理分析,效果更精确。
需要说明的是,高阶矩阵的去除重复不一致数据可以通过多种本领域技术人员已知的技术方案,如果对高阶矩阵使用HOSVD(High-Order Singular Value Decomposition高阶奇异值分解)
存储模块4,用于按时间顺序,沿着高维空间中的时间维度实时保存所述实时核心数据集合,得到高质量核心数据总集。
在对采集得到的实时数据处理得到高质量的实时核心数据集合,为了能够进行整体分析,需要逐个将实时核心数据集合存储到一起,供分析时候,作为整体使用。而虚拟网络流量数据的马氏性很强,即在时间维度联系是较大的,因此,存储模块4将得到实时核心数据集合在高维空间中对应时间维度进行保存,得到高质量的核心数据总集。这样保存得到的高质量核心数据总集能够通过展开矩阵的最优基向量,并通过增量的方式利用新增虚拟网络流量数据不断更新左奇异向量空间,将新增非零元素投影到各个截断的单位正交基空间中,从而实现增量式网络流量优质数据提取与分析。
实施例五
如图9所示,本发明实施例提供一种基于实施例四的网络流量增量分析系统,其包括对应模块5、采集模块6以及分析模块7:
对应模块5,用于设置特征项与虚拟网络流量状态的对应关系。
对应模块5可以进一步的细分其他特征项的状态,如除了流量特征项,还有端口特征项,状态对应保证了不同特征项之间能够更加直观的联系,同时,在分析时候,状态的变更意味着多个特征项的变更,对状态的分析实际上就达成了对多个特征项的分析,而多个特征项作为一个状态进行统计是联系在一起的,分析的结果即可以表现当前虚拟网络流量状态的实际表示的内容,如对虚拟网络中各个硬件以特征项进行表述并对应不同的状态,在分析完毕后,即通过各个状态所表示的虚拟网络中硬件的负载、计算损耗大致变化,即可了解虚拟网络的硬件状态,更加效率,成本低,同时十分直观。除了硬件状态,还可以是网络流量、接口切换、报错等等虚拟网络的数据。
作为一个可选的实施方案,虚拟网络流量状态为实时核心数据集合一个以上的特征项的数值/选项区间。
除了数值区间外,特征项还有可能是选项,如端口A、B、C等等,只要是在高维度空间上一维度进行表征的区间即可。
取样模块6,用于获取当前时刻和前一时刻的实时核心数据集合的虚拟网络流量状态。
取样模块6首先需要获取预测时刻之前的关联较大的虚拟网络流量状态,即当前时刻、前一时刻的实时核心数据集合的虚拟网络流量状态。供后续步骤使用。
需要说明的是,对实时核心数据总集进行分析,即总结虚拟网络中前后的变化,在时间上,是存在先后的,因此,需要对实时核心数 据中心进行区分。将当前添加的实时核心数据集合作为当前时刻的实时核心数据集合,前一次添加的实时核心数据结合作为前一时刻的实时核心数据集合即可,其中的时刻的间隔既可以是1s、3min、6h、也可以是其他人为规定的时间,只需根据需要分析的变化时间间隔进行具体限定即可。
分析模块7,用于根据所述高质量核心数据总集中各个实时核心数据集合的虚拟网络流量状态,分析下一时刻的实时核心数据集合的虚拟网络流量状态及其概率。
在获取当前时刻、前一时刻的实时核心数据集合的虚拟网络流量状态,即知道了虚拟网络流量状态的初始条件,分析模块7根据整个高质量核心数据总集中各个实时核心数据集合进行整体分析,得到状态的变化规律,并结合上述的初始条件,即可求取下一时刻网络流量的状态。
实施例六
如图10所示,本发明实施例提供一种基于实施例五的网络流量增量分析系统,其包括创建模块8、设置模块9、统计模块10以及分析模块11:
创建模块8,用于以NFVC、NFVP、NFVN为维度建立三维转移空间,其中,NFVC代表当前时刻的实时核心数据集合的虚拟网络流量状态,NFVP代表前一时刻的实时核心数据集合的虚拟网络流量状态,NFVN代表下一时刻的实时核心数据集合的虚拟网络流量状态。
创建模块8使用当前时刻、前一时刻以及下一时刻的虚拟网络流量状态作为三维空间的的三个维度,其每一个维度均和时间是有关的,能够十分直观的表现虚拟网络的虚拟网络流量状态的变化。在进行分析时,对三个和时间有关的参数进行分析,能够更加体现实时核心数 据集合随着时间的变化。
具体来说,特征项还包括硬件使用参数,所述硬件使用参数包括CPU利用率、内存占用百分比,所述实时核心数据集合所表示的虚拟网络流量状态为当前硬件所处的状态。
设置模块9,用于设置当前时刻的实时核心数据集合的虚拟网络流量状态为A
Cx,前一时刻的实时核心数据集合的虚拟网络流量状态为A
Px,下一时刻的实时核心数据集合的虚拟网络流量状态为A
Nx。
在预测下一虚拟网络流量状态时,设置模块9需要获取当前时刻的实时核心数据集合的虚拟网络流量状态为A
Cx,前一时刻的实时核心数据集合的虚拟网络流量状态为A
Px,由于虚拟网络流量状态变化的多种多样,其下一时刻的实时核心数据集合的虚拟网络流量状态可能有多种均以A
Nx来代表。
统计模块10,用于统计三维转移空间内,虚拟网络流量状态从A
Px变化至A
Cx最后变化至各种A
Nx的概率P。
在创建三维转移空间后,高质量核心数据总集的所有实时核心数据集合的虚拟网络流量状态均表示于其中,其中包含有虚拟网络流量状态A
Px以及虚拟网络流量状态A
Cx,此时统计模块10可以统计下一时刻A
Nx的种类以及变化次数,从而得到最后变化至各种A
Nx的概率P。
预测模块11,用于将所述A
Cx、A
Px和各个A
Nx作为三维转移空间的坐标值,各个A
Nx相应的P为A
Cx、A
Px和各个A
Nx在所述三维转移空间表示点的值,并表示于所述三维转移空间内,得到三维预测转移空间。
在得到各种A
Nx,A
Cx、A
Px和各个A
Nx也是可以表示到三维转移空间中的,但是该点并不是100%的实心点,而是所有点的概率加起 来为100%的虚点,如果使用颜色的深浅来表示A
Cx、A
Px和各个A
Nx在三维转移空间的概率的话,那么则可以看到一块区域/线/至少两个点深浅不一,较为直观的体现了A
Nx的可能概率,即下一时刻虚拟网络的虚拟网络流量状态的趋势,同时在将A
Cx、A
Px和各个A
Nx标识到三维转移空间后,其该三维空间中实际还包含预测的空间,即设为三维预测转移空间。
作为一个优选的实施方案,在得到各种A
Nx的概率P,将概率P也作为高维空间中点所表示的值。
进一步的,将所述三维预测转移空间作为三维转移空间,网络流量增量分析系统进一步预测后续添加实时核心数据集合后所有可能达成虚拟网络流量状态的概率,并表示在所述网络转移空间内,得到三维预测转移概率空间。
在预测下一时刻,可能的虚拟网络状态以及概率后,网络流量增量分析系统进一步预测下下一时刻的可能的虚拟网络状态以及概率,能够更好的分析网络状态的变更,并提供虚拟网络状态预警,初始虚拟网络能够对应后续可能出现的较坏的状态进行合理的预防以及准备处理措施。
显然,本领域的技术人员可以对本发明进行各种改动和变型而不脱离本发明的精神和范围。这样,倘若本发明的这些修改和变型属于本发明权利要求及其等同技术的范围之内,则本发明也意图包含这些改动和变型在内。本发明不仅局限于上述最佳实施方式,任何人在本发明的启示下都可得出其他各种形式的产品,但不论在其形状或结构上作任何变化,凡是具有与本发明相同或相近似的技术方案,均在其保护范围之内。
Claims (24)
- 一种网络流量增量统计方法,其特征在于,其包括以下步骤:实时获取并保存虚拟化网络网络模型的各个层级的数据包,所述数据包设有多个特征项,所述特征项包括时间;将所述数据包按照一个特征项对应一个维度的方式保存于高维度空间,并沿预设的模展开得到高阶矩阵;去除所述高阶矩阵中的重复以及错误数据后,还原至高维度空间得到实时核心数据集合;按时间顺序,沿着高维空间中的时间维度实时保存所述实时核心数据集合,得到高质量核心数据总集。
- 如权利要求1所述的统计方法,其特征在于:所述网络模型为TCP/IP四层参考模型,所述数据包采集自应用层、传输层、网络层以及网络接口层。
- 如权利要去2所述的统计方法,其特征在于:采集自所述应用层的数据包包括结构化数据、半结构化数据、非结构化数据。
- 如权利要求1所述的统计方法,其特征在于,所述特征项还包括:源MAC地址、目标MAC地址、源IP地址、目的IP地址、源端口、目标端口、虚拟网络功能标识符和虚拟网络流量数据内容。
- 如权利要求1所述的统计方法,其特征在于,其通过运行于虚拟机VM(Virtual Machine)上的虚拟网络功能VNF(Virtualized Network Function)从虚拟网络环境中获取数据包。
- 如权利要求1所述的统计方法,其特征在于,通过HOSVD(High-Order Singular Value Decomposition,高阶奇异值分解)去除所述高阶矩阵中的重复以及错误数据。
- 一种基于权利要求1所述统计方法的网络流量增量分析方法, 其特征在于,在得到高质量核心数据总集后,还包括:设置特征项与虚拟网络流量状态的对应关系;获取当前时刻和前一时刻的实时核心数据集合的虚拟网络流量状态;根据所述高质量核心数据总集中各个实时核心数据集合的虚拟网络流量状态,分析下一时刻的实时核心数据集合的虚拟网络流量状态及其概率。
- 一种基于权利要求7所述的分析方法,其特征在于:以NFVC、NFVP、NFVN为维度建立三维转移空间,其中,NFVC为当前时刻的实时核心数据集合的虚拟网络流量状态的集合,NFVP为前一时刻的实时核心数据集合的虚拟网络流量状态的集合,NFVN为下一时刻的实时核心数据集合的虚拟网络流量状态的集合;设置当前时刻的实时核心数据集合的虚拟网络流量状态为ACx,前一时刻的实时核心数据集合的虚拟网络流量状态为APx,下一时刻的实时核心数据集合的虚拟网络流量状态为ANx;统计三维转移空间内,虚拟网络流量状态从APx变化至ACx最后变化至各种ANx的概率P;将所述ACx、APx和各个ANx作为三维转移空间的坐标值,各个ANx相应的P为ACx、APx和各个ANx在所述三维转移空间表示点的值,并表示于所述三维转移空间内,得到三维预测转移空间。
- 如权利要求7所述的分析方法,其特征在于:所述虚拟网络流量状态为所述高维度空间的至少一个区间。
- 如权利要求9所述的分析方法,其特征在于:所述虚拟网络流量状态为所述实时核心数据集合一个以上的特征项的数值/选项区间。
- 如权利要求8所述的分析方法,其特征在于:所述特征项还包括硬件使用参数,所述硬件使用参数包括CPU利用率、内存占用百分比,所述实时核心数据集合所表示的虚拟网络流量状态为当前硬件所处的状态。
- 如权利要求8所述的分析方法,其特征在于:将所述三维预测转移空间作为三维转移空间,进一步预测后续添加实时核心数据集合后所有可能达成虚拟网络流量状态的概率,并表示在所述网络转移空间内,得到三维预测转移概率空间。
- 一种网络流量增量统计系统,其特征在于,其包括:采集模块,用于实时获取并保存虚拟化网络网络模型的各个层级的数据包,所述数据包设有多个特征项,所述特征项包括时间;计算模块,用于将所述数据包按照一个特征项对应一个维度的方式保存于高维度空间,并沿预设的模展开得到高阶矩阵;提取模块,用于去除所述高阶矩阵中的重复以及错误数据后,还原至高维度空间得到实时核心数据集合;存储模块,用于按时间顺序,沿着高维空间中的时间维度实时保存所述实时核心数据集合,得到高质量核心数据总集。
- 如权利要求13所述的统计系统,其特征在于:所述网络模型为TCP/IP四层参考模型,所述数据包采集自应用层、传输层、网络层以及网络接口层。
- 如权利要去14所述的统计系统,其特征在于:采集自所述应用层的数据包包括结构化数据、半结构化数据、非结构化数据。
- 如权利要求13所述的统计系统,其特征在于,所述特征项还包括:源MAC地址、目标MAC地址、源IP地址、目的IP地址、源端口、目标端口、虚拟网络功能标识符和虚拟网络流量数据内容。
- 如权利要求13所述的统计系统,其特征在于,其通过运行于虚拟机VM(Virtual Machine)上的虚拟网络功能VNF(Virtualized Network Function)从虚拟网络环境中获取数据包。
- 如权利要求13所述的统计系统,其特征在于,通过HOSVD(High-Order Singular Value Decomposition,高阶奇异值分解)去除所述高阶矩阵中的重复以及错误数据.
- 一种基于权利要求13所述统计系统的网络流量增量分析系统,其特征在于,其包括:对应模块,用于设置特征项与虚拟网络流量状态的对应关系;取样模块,用于获取当前时刻和前一时刻的实时核心数据集合的虚拟网络流量状态;分析模块,用于根据所述高质量核心数据总集中各个实时核心数据集合的虚拟网络流量状态,分析下一时刻的实时核心数据集合的虚拟网络流量状态及其概率。
- 一种基于权利要求19所述的分析系统,其特征在于:创建模块,用于以NFVC、NFVP、NFVN为维度建立三维转移空间,其中,NFVC代表当前时刻的实时核心数据集合的虚拟网络流量状态,NFVP代表前一时刻的实时核心数据集合的虚拟网络流量状态,NFVN代表下一时刻的实时核心数据集合的虚拟网络流量状态;设置模块,用于设置当前时刻的实时核心数据集合的虚拟网络流量状态为A Cx,前一时刻的实时核心数据集合的虚拟网络流量状态为A Px,下一时刻的实时核心数据集合的虚拟网络流量状态为A Nx;统计模块,用于统计三维转移空间内,虚拟网络流量状态从A Px变化至ACx最后变化至各种A Nx的概率P;预测模块,用于将所述A Cx、A Px和各个A Nx作为三维转移空间 的坐标值,各个A Nx相应的P为A Cx、A Px和各个A Nx在所述三维转移空间表示点的值,并表示于所述三维转移空间内,得到三维预测转移空间。
- 如权利要求19所述的分析系统,其特征在于:所述虚拟网络流量状态为所述高维度空间的至少一个区间。
- 如权利要求21所述的分析系统,其特征在于:所述虚拟网络流量状态为所述实时核心数据集合一个以上的特征项的数值/选项区间。
- 如权利要求20所述的分析系统,其特征在于:所述特征项还包括硬件使用参数,所述硬件使用参数包括CPU利用率、内存占用百分比,所述实时核心数据集合所表示的虚拟网络流量状态为当前硬件所处的状态。
- 如权利要求20所述的分析系统,其特征在于:将所述三维预测转移空间作为三维转移空间,进一步预测后续添加实时核心数据集合后所有可能达成虚拟网络流量状态的概率,并表示在所述网络转移空间内,得到三维预测转移概率空间。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201910008924.9A CN109889366B (zh) | 2019-01-04 | 2019-01-04 | 网络流量增量统计、分析方法及系统 |
| CN201910008924.9 | 2019-01-04 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020140419A1 true WO2020140419A1 (zh) | 2020-07-09 |
Family
ID=66925550
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2019/096637 Ceased WO2020140419A1 (zh) | 2019-01-04 | 2019-07-19 | 网络流量增量统计、分析方法及系统 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN109889366B (zh) |
| WO (1) | WO2020140419A1 (zh) |
Families Citing this family (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN109889366B (zh) * | 2019-01-04 | 2020-06-16 | 烽火通信科技股份有限公司 | 网络流量增量统计、分析方法及系统 |
| CN113132415A (zh) * | 2021-05-10 | 2021-07-16 | 安徽思珀特信息科技有限公司 | 一种基于网络流量分析的威胁发现系统 |
| CN117876845A (zh) * | 2024-01-15 | 2024-04-12 | 华中科技大学 | 基于双向状态空间模型的视觉表征方法与装置 |
| CN119814589B (zh) * | 2024-12-04 | 2026-04-21 | 天翼云科技有限公司 | 内容分发网络的业务增量预测的方法、装置、设备和介质 |
Citations (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101753381A (zh) * | 2009-12-25 | 2010-06-23 | 华中科技大学 | 一种检测网络攻击行为的方法 |
| CN104462459A (zh) * | 2014-12-16 | 2015-03-25 | 芜湖乐锐思信息咨询有限公司 | 基于神经网络的大数据分析处理系统及方法 |
| CN106095921A (zh) * | 2016-06-07 | 2016-11-09 | 四川大学 | 面向海量数据流的实时并行分类方法 |
| US20170185895A1 (en) * | 2015-01-26 | 2017-06-29 | Huawei Technologies Co., Ltd. | System and Method for Training Parameter Set in Neural Network |
| CN107547154A (zh) * | 2016-06-23 | 2018-01-05 | 华为技术有限公司 | 一种建立视频流量预测模型的方法及装置 |
| CN108199928A (zh) * | 2018-02-01 | 2018-06-22 | 国网湖北省电力公司信息通信公司 | 一种多维电力通信网流量预测方法及系统 |
| CN108718257A (zh) * | 2018-05-23 | 2018-10-30 | 浙江大学 | 一种基于网络流量的无线摄像头检测及定位方法 |
| CN109889366A (zh) * | 2019-01-04 | 2019-06-14 | 烽火通信科技股份有限公司 | 网络流量增量统计、分析方法及系统 |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN100544287C (zh) * | 2006-09-26 | 2009-09-23 | 中兴通讯股份有限公司 | 宽窄带综合接入设备的网络流量统计方法 |
| CN103647670B (zh) * | 2013-12-20 | 2017-12-26 | 北京理工大学 | 一种基于sketch的数据中心网络流量分析方法 |
| CN105099757B (zh) * | 2015-06-08 | 2019-03-01 | 福建星网锐捷网络有限公司 | 网络流量统计分析方法和装置 |
| CN108965024B (zh) * | 2018-08-01 | 2021-08-13 | 重庆邮电大学 | 一种5g网络切片基于预测的虚拟网络功能调度方法 |
-
2019
- 2019-01-04 CN CN201910008924.9A patent/CN109889366B/zh active Active
- 2019-07-19 WO PCT/CN2019/096637 patent/WO2020140419A1/zh not_active Ceased
Patent Citations (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101753381A (zh) * | 2009-12-25 | 2010-06-23 | 华中科技大学 | 一种检测网络攻击行为的方法 |
| CN104462459A (zh) * | 2014-12-16 | 2015-03-25 | 芜湖乐锐思信息咨询有限公司 | 基于神经网络的大数据分析处理系统及方法 |
| US20170185895A1 (en) * | 2015-01-26 | 2017-06-29 | Huawei Technologies Co., Ltd. | System and Method for Training Parameter Set in Neural Network |
| CN106095921A (zh) * | 2016-06-07 | 2016-11-09 | 四川大学 | 面向海量数据流的实时并行分类方法 |
| CN107547154A (zh) * | 2016-06-23 | 2018-01-05 | 华为技术有限公司 | 一种建立视频流量预测模型的方法及装置 |
| CN108199928A (zh) * | 2018-02-01 | 2018-06-22 | 国网湖北省电力公司信息通信公司 | 一种多维电力通信网流量预测方法及系统 |
| CN108718257A (zh) * | 2018-05-23 | 2018-10-30 | 浙江大学 | 一种基于网络流量的无线摄像头检测及定位方法 |
| CN109889366A (zh) * | 2019-01-04 | 2019-06-14 | 烽火通信科技股份有限公司 | 网络流量增量统计、分析方法及系统 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN109889366B (zh) | 2020-06-16 |
| CN109889366A (zh) | 2019-06-14 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2020140419A1 (zh) | 网络流量增量统计、分析方法及系统 | |
| CN112640380B (zh) | 用于对事件的输入流进行异常检测的设备和方法 | |
| CN107817787B (zh) | 一种基于机器学习的智能产线机械手故障诊断方法 | |
| CN104503826B (zh) | 一种云计算数据中心的虚拟机映射方法及装置 | |
| Li et al. | DeepNFV: A lightweight framework for intelligent edge network functions virtualization | |
| CN112631725A (zh) | 一种基于云边端协同的智慧城市的管理系统及方法 | |
| CN114401516B (zh) | 一种基于虚拟网络流量分析的5g切片网络异常检测方法 | |
| CN119719248B (zh) | 多源异构数据语义对齐方法、装置及计算机设备 | |
| US20210152454A1 (en) | Network Flow Measurement Method, Network Measurement Device, and Control Plane Device | |
| CN105978711B (zh) | 一种基于最小生成树的最佳交换边查找方法 | |
| CN113467851B (zh) | 一种基于车辆聚类的动态车辆计算任务卸载方法和装置 | |
| CN113259355B (zh) | 一种基于sdn的工业互联网标识切片管理系统 | |
| CN106528815A (zh) | 一种路网移动对象概率聚集查询方法及系统 | |
| CN115473688B (zh) | 面向软件定义网络的异常检测方法、装置及设备 | |
| CN112416950B (zh) | 一种三维sketch结构的设计方法和装置 | |
| WO2024124640A1 (zh) | 基于威胁分析图谱的节点分析方法及装置 | |
| CN103051509B (zh) | 一种基于树状架构的初始化方法 | |
| Ponmalar et al. | Machine learning based network traffic predictive analysis | |
| Taneja et al. | Predictive analytics on IoT | |
| CN113660209A (zh) | 一种基于sketch与联邦学习的DDoS攻击检测系统及应用 | |
| CN110275895A (zh) | 一种缺失交通数据的填充设备、装置及方法 | |
| CN118656699A (zh) | 一种基于联邦学习的flvc异常用电检测方法 | |
| CN106708867B (zh) | 一种基于数据基类型的资源调配方法和服务器 | |
| Wang et al. | Model-based scheduling for stream processing systems | |
| JP2023064173A (ja) | データ処理装置、データ処理方法、及びデータ処理プログラム |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 19907868 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 19907868 Country of ref document: EP Kind code of ref document: A1 |


