A device fingerprint-based monitoring method and apparatus

By using a device fingerprint-based monitoring method to dynamically adjust the monitoring cycle of power equipment, the problems of resource waste and inaccurate results in traditional monitoring methods are solved, achieving efficient and economical equipment status monitoring and improving the stability and reliability of the power system.

CN119561862BActive Publication Date: 2025-11-18BEIJING UNIV OF POSTS & TELECOMM +3
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411420325.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-12
Publication Date
2025-11-18
Estimated Expiration
2044-10-12

AI Technical Summary

Technical Problem

Traditional power equipment monitoring methods use fixed monitoring cycles, which are difficult to adapt to real-time changes in equipment status, resulting in wasted resources and inaccurate monitoring results.

Method used

A device fingerprint-based monitoring method is adopted, which determines the importance of device attributes through the hierarchical analysis-entropy method and divides them into three levels. SNMP, Syslog, smart probes and heartbeat mechanisms are used to collect device information and the monitoring cycle is dynamically adjusted to achieve three-state monitoring of device status.

Benefits of technology

It has improved the effectiveness and efficiency of the monitoring system, reduced operation and maintenance costs, enhanced the accuracy and timeliness of data monitoring, and strengthened the stability and reliability of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119561862B_ABST
    Figure CN119561862B_ABST
Patent Text Reader

Abstract

The application discloses a device fingerprint-based monitoring method and device, and belongs to the technical field of device monitoring. Device importance level division: the importance degree of device attributes is determined by using an analytic hierarchy process-entropy method, devices are divided into first, second and third levels (Three) according to the importance degree of the device attributes, and different monitoring intervals are set for each level; device data collection: device information is collected by using SNMP, Syslog, intelligent probe or heartbeat mechanism technology; device state analysis: the health state of the device is divided into three categories (Three) according to the information fed back by the device, i.e., a stable state, a risk working state and a dangerous working state, so that three-state monitoring of the device state is realized; and device monitoring cycle dynamic adjustment: the monitoring cycle is adaptively adjusted according to the device importance level and the device health state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of equipment monitoring technology and relates to a monitoring method and device based on equipment fingerprinting. Background Technology

[0002] Monitoring the health status of power equipment is crucial for ensuring the safety and stability of the power grid. Traditional monitoring methods often employ fixed monitoring cycles, which are ill-suited to adapt to real-time changes in equipment status. Applying a uniform monitoring frequency to different types of equipment or systems often overlooks the specific attributes and operating characteristics of the equipment. This can not only waste resources but also affect the effectiveness of monitoring, compromising the accuracy and real-time nature of the results. Furthermore, the setting of commonly used monitoring frequencies often lacks a scientific methodology and clear standards, relying heavily on the experience and judgment of maintenance personnel. This can result in monitoring frequencies being set too high or too low, failing to achieve optimal monitoring results. Summary of the Invention

[0003] This invention addresses the problems of existing technologies by providing a monitoring method and apparatus based on device fingerprinting.

[0004] A device fingerprint-based apparatus, comprising:

[0005] The equipment classification module is used to classify equipment.

[0006] The device data acquisition module is used to receive heartbeat data sent periodically by the monitored device. It includes an encryption / decryption module, which is used to encrypt, decrypt, receive, or send information.

[0007] The device status analysis module analyzes the health status of the device based on the device attribute information in the heartbeat data.

[0008] The cycle adjustment module dynamically adjusts the information transmission cycle of the monitored object based on the equipment's importance level and status.

[0009] A device fingerprint-based monitoring method includes the following steps:

[0010] Step S1: Classification of equipment importance levels: The importance level of equipment attributes is determined by the analytic hierarchy process (AHP-entropy method). Based on the importance level of equipment attributes, the equipment is divided into three levels: Level 1, Level 2, and Level 3, with different monitoring intervals set for each level.

[0011] Step S2: Device Data Acquisition: Collect device information using SNMP, Syslog, smart probes, or heartbeat mechanisms.

[0012] Step S3: Equipment Status Analysis: Based on the information fed back by the equipment, the health status of the equipment is divided into three categories: stable status, risky working status, and dangerous working status, so as to realize the three-state monitoring of equipment status.

[0013] Step S4: Dynamic adjustment of equipment monitoring cycle: The monitoring cycle is adaptively adjusted according to the importance level and health status of the equipment.

[0014] The advantages of this invention are:

[0015] The implemented monitoring methods and devices significantly enhance the effectiveness and efficiency of the monitoring system by intelligently monitoring the importance and operating status of power equipment.

[0016] First, by accurately assessing the importance of equipment and monitoring its status in real time, the system can perform more frequent and detailed monitoring of critical equipment. This not only ensures the reliable operation of critical equipment but also effectively reduces the risk of equipment failure. Simultaneously, for stable-operating equipment, the system can reduce excessive monitoring, thereby optimizing resource allocation and significantly reducing operating costs.

[0017] Secondly, the dynamic adjustment monitoring frequency strategy adopted in this invention greatly improves the accuracy and timeliness of data monitoring. Through intelligent scheduling of monitoring resources, the system can respond promptly to changes in equipment status, ensuring that equipment faults and performance degradation can be quickly identified and effectively addressed. This provides strong data support for equipment maintenance and fault prevention, improving maintenance efficiency and preventative effectiveness.

[0018] Furthermore, the system's intelligent monitoring methods not only improve the overall effectiveness and efficiency of the monitoring system but also optimize resource utilization. Through differentiated management, the system can centrally monitor key equipment, avoiding resource waste and thus improving the overall economic benefits of the monitoring system.

[0019] Finally, by dynamically adjusting the monitoring frequency and employing intelligent monitoring methods, the system significantly enhanced the stability of the power system. It reduced the impact of equipment failures on the system, improving its overall reliability and economic efficiency. This intelligent monitoring system not only ensures the normal operation of power equipment but also provides a solid foundation for the long-term stable and efficient operation of the power system. Attached Figure Description

[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. As shown in the figures:

[0021] Figure 1 This is an architecture diagram of the device monitoring method of this application.

[0022] Figure 2 This is a flowchart of the equipment monitoring method of this application.

[0023] Figure 3 This is a structural diagram of the analytic hierarchy process (AHP) proposed in this application.

[0024] Figure 4 This is a diagram illustrating the architecture of the analytic hierarchy process described in this application.

[0025] Figure 5 This is a diagram illustrating the architecture of the analytic hierarchy process (AHP) and entropy method in this application.

[0026] Figure 6 This is a schematic diagram of the equipment data acquisition process in this application.

[0027] Figure 7 This is a schematic diagram of the equipment monitoring device of this application.

[0028] Figure 8 This is a schematic diagram of the device monitoring device in the embodiments of this application. Detailed Implementation

[0029] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0030] Example 1: As Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 , Figure 6 and Figure 7 As shown, a monitoring method and device based on device fingerprinting are used for power equipment to solve the problems existing in traditional power equipment health status monitoring, especially the problem that fixed monitoring cycles are difficult to adapt to real-time changes in equipment status.

[0031] A device fingerprint-based monitoring method (adaptive TT (Three-Three)) includes the following steps:

[0032] Step S1: Classification of equipment importance levels: The importance level of equipment attributes is determined by the analytic hierarchy process (AHP-entropy method). Based on the importance level of equipment attributes, the equipment is divided into three levels: Level 1, Level 2, and Level 3. Each level corresponds to a different monitoring interval, such as 16 min, 64 min, or 256 min.

[0033] Step S2: Equipment Data Acquisition: Collect equipment information using technologies such as SNMP, Syslog, smart probes, and heartbeat mechanisms.

[0034] Step S3: Equipment Status Analysis: Based on the information fed back by the equipment, the health status of the equipment is divided into three categories: stable status, risky working status, and dangerous working status, so as to realize the three-state monitoring of equipment status.

[0035] Step S4: Dynamic adjustment of equipment monitoring cycle: The monitoring cycle is adaptively adjusted according to the importance level and health status of the equipment.

[0036] Step S1 includes: using the analytic hierarchy process (AHP) to determine the subjective weights of the equipment attributes, using the entropy method to determine the objective weights of the equipment attributes, and combining the subjective and objective weights to divide the equipment into three levels: Level 1 (T1), Level 2 (T2), and Level 3 (T3), with different monitoring intervals set for each level.

[0037] Step S2 includes: obtaining device information by deploying smart probes, setting agents based on protocols such as SNMP, and receiving periodically sent heartbeat packets based on protocols such as MQTT. The monitoring information includes the device's operating status and performance parameters.

[0038] Step S3 includes: the equipment assesses the health status N of the equipment based on the deviation between the collected data and historical data, where a stable state is 0, a risky operation is 1, and a dangerous operation is 2.

[0039] Step S3, the three-state monitoring based on device status, includes the following steps:

[0040] To determine the "health status" of the equipment, the equipment periodically and autonomously sends heartbeat packets to the main station or backend to report its current health status N, where a stable state is 0, a risky operation is 1, and a dangerous operation is 2.

[0041] The system adaptively adjusts the monitoring frequency based on the importance and status of the equipment. For equipment in a high-risk state, the monitoring cycle is shortened to closely track its operational status and improve the accuracy and timeliness of fault prediction and detection. Conversely, when equipment is in a low-risk state, the monitoring cycle is extended to reduce monitoring costs and effectively utilize monitoring resources. This dynamic adjustment mechanism ensures that monitoring activities are both efficient and economical, maximizing the system's operational stability and security.

[0042] Step S4 includes: when the equipment health status is stable, it is recorded as health status 0, and the original monitoring cycle is maintained; when the equipment health status is at risk, it is recorded as health status 1, and the monitoring cycle is shortened; when the equipment health status is dangerous, it is recorded as health status 2, and a higher monitoring frequency is set to closely monitor the equipment parameters.

[0043] According to the formula t = 2 N ×w determines the actual monitoring interval t of the equipment, where w is the monitoring interval for the importance of the equipment, and N is the health status of the equipment.

[0044] Example 2: Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 , Figure 6 and Figure 7 As shown, a device fingerprint-based apparatus includes:

[0045] The equipment classification module is used to classify equipment.

[0046] The device data acquisition module is used to receive heartbeat data sent periodically by the monitored device. It includes an encryption / decryption module, which is used to encrypt, decrypt, receive, or send information.

[0047] The device status analysis module analyzes the health status of the device based on the device attribute information in the heartbeat data.

[0048] The cycle adjustment module dynamically adjusts the information transmission cycle of the monitored object based on the equipment's importance level and status.

[0049] Example 3: As Figure 1 , Figure 2 , Figure 3 , Figure 4 , Figure 5 , Figure 6 and Figure 7 As shown, a device fingerprint-based monitoring method (adaptive TT (Three-Three)) includes the following steps:

[0050] Step S1, which classifies equipment importance levels, includes: constructing a key parameter system for the equipment based on the analytic hierarchy process (AHP) and the entropy method, and then determining the equipment level based on the scoring.

[0051] The Analytic Hierarchy Process (AHP) is a decision-making method that combines qualitative and quantitative approaches. Its basic steps include establishing a hierarchical structure, constructing a judgment matrix, determining the weight vectors of the judgment matrix, checking the consistency of the judgment matrix, and ranking and checking the consistency of the hierarchy.

[0052] The levels are divided into three categories:

[0053] ① The highest level (goal level): This is the predetermined goal or result of the problem analysis.

[0054] ② Intermediate layer (structural layer): The intermediate links involved in achieving the goal, which can be composed of several layers.

[0055] ③ Bottom layer (indicator layer): Various indicators and measures to achieve the goal.

[0056] Figure 4 The specific steps of the analytic hierarchy process in this invention include:

[0057] Step S201: Establish a hierarchical structure system for equipment evaluation: such as Figure 3 As shown, the target layer is equipment importance, the criteria layer is equipment value, operating benefits, monitoring costs, and performance status, and the solution layer includes equipment cost, maintenance cost, operating intensity, work efficiency, downtime loss, communication costs, embedding costs, reliable lifespan, failure rate, and repair rate.

[0058] Step S202, Expert Scoring: Experts score the various indicators, including quantitative scores for equipment cost, maintenance cost, reliable life, failure rate, and return rate, as shown in Table 1; and qualitative scores for operational intensity, work efficiency, downtime loss, communication overhead, and embedded overhead, with evaluation levels of excellent, good, medium, poor, and relatively poor, as shown in Table 1, with scores of 5, 4, 3, 2, and 1 respectively.

[0059] Table 1:

[0060]

[0061] Step S203: Construct the judgment matrix: The specific criteria are shown in Table 2.

[0062] Table 2:

[0063]

[0064] The weight vectors are obtained as follows: AB = [0.375 0.170 0.303 0.152], B1-C = [0.750 0.250], B2-C = [0.169 0.461 0.370], B3-C = [0.333 0.667], and B4-C = [0.548 0.241 0.211].

[0065] Step S204, Matrix consistency check: CI = (λ) max -n) / (n-1) and CR=CI / RI are used to calculate the consistency index CI and the consistency ratio CR.

[0066] In the formula: λ max Let be the largest eigenvalue, n be the order of the judgment matrix, and RI be the average random consistency index, which is related to the matrix order. If the calculated CR is less than 0.1, we generally consider the judgment matrix to have satisfactory consistency; otherwise, if it is greater than 0.1, it indicates that there may be contradictions in the comparison or judgment process, and the judgment matrix needs to be adjusted and modified. The above steps are repeated for the processed matrix until CR is less than 0.1.

[0067] Entropy is an objective method for determining weights, relying solely on the dispersion of the source data. In information entropy theory, a smaller entropy value indicates greater uncertainty in the information source and less information contained within it. Conversely, a larger entropy value indicates less uncertainty and more information contained within it. Based on this characteristic, information entropy theory is applied to judging the dispersion between indicators; the greater the dispersion of an indicator, the greater its influence on the system, i.e., the greater its weight.

[0068] It also includes the following specific steps:

[0069] Step ①: Calculate the weight of the index value of the i-th scheme under the j-th index.

[0070]

[0071] Step 2: Calculate the entropy value of the j-th index. Where, k = 1 / ln(n) > 0;

[0072] Step 3: Calculate the entropy weight of the j-th index.

[0073] Step 4: Determine the comprehensive weights of the indicators.

[0074] Where, r ij Let α be the quantitative evaluation value of the j-th indicator for the i-th evaluation object, where i = 1, 2, ..., n, j = 1, 2, ..., m, m is the number of indicators, n is the sample size, and α is the value of the j-th indicator for the i-th evaluation object. j The weights for the subjective assignment method.

[0075] As shown in Table 3.

[0076] Table 3:

[0077]

[0078] like Figure 5 As shown, the subjective weights of equipment attributes are determined using the analytic hierarchy process (AHP), and the objective weights of equipment attributes are determined using the entropy method. By combining the subjective and objective weights, the total score of the equipment is calculated, and the equipment is divided into three levels: Level 1, Level 2, and Level 3, with different monitoring intervals w set for each level.

[0079] In this embodiment, the preset device scores are 0-1 for Level 1, 1-2.5 for Level 2, and above 2.5 for Level 3. The preset monitoring intervals are 2048 min, 512 min, and 64 min. Device A scores 1.687, is Level 2, and has a monitoring interval w of 512 minutes; Device B scores 0.863, is Level 1, and has a monitoring interval w of 2048 minutes; Device C scores 2.538, is Level 3, and has a monitoring interval w of 64 minutes.

[0080] Step S2, device data acquisition, also includes the following steps:

[0081] By collecting and analyzing the characteristic parameters of each device, a unique fingerprint is generated for each device. This fingerprint data includes both static and dynamic information about the device. Static information includes basic device information, operating system information, chip information, and communication information, while dynamic information includes CPU utilization, memory utilization, and disk utilization. For example, the collected information can include operating system version, operating system distribution information, port information, IP address, CPU utilization, memory utilization, and disk utilization.

[0082] A heartbeat mechanism is used to monitor device status. A suitable heartbeat mechanism, such as Ping, TCP, UDP, HTTP, MQTT or a custom protocol, is selected according to system requirements and device characteristics. The device then periodically reports heartbeat information to the server. The heartbeat packet contains identification information, a timestamp and custom device behavior information.

[0083] like Figure 6As shown, the device and server interact using the MQTT protocol. MQTT (Message Queuing Telemetry Transport) is a lightweight, open standard communication protocol, particularly suitable for communication between IoT devices. The device periodically pushes its own attribute information to the MQTT server. This MQTT information is encrypted using a symmetric key. After the MQTT server pushes the information to the platform's backend server, the platform's backend server receives the information and decrypts it using the symmetric key.

[0084] Step S3, device status analysis, also includes the following steps: determining the device's "health status" as the domain of status monitoring. After receiving a heartbeat packet, the server analyzes the device status and reports a health status N, where a stable state is 0, a risky operation is 1, and a dangerous operation is 2.

[0085] The collected data is divided into string type and numeric type.

[0086] For string-type data, such as operating system version, operating system release information, port information, IP address, etc., collect data X. i Compare with the original database device attribute information; if they are the same, then m i Calculate the string-type data state quantity M1 if it is 0 otherwise:

[0087]

[0088] For numerical data, such as CPU utilization, memory utilization, and disk utilization, the monitored and collected data is X. i The reference value for this monitoring quantity is D. i If X i >D i Then m i Calculate the numerical data state variable M2 if it is 1 otherwise:

[0089]

[0090] The total state variables M = M1 + M2, where m i For each monitoring component value, i represents each type of monitoring information, n1 represents the total number of string-type monitoring information, n2 represents the total number of numerical monitoring information, and thresholds d1 and d2 are set.

[0091] If M < d1, the equipment is determined to be in a stable state;

[0092] If d1≤M<d2, the equipment is determined to be in a risky state;

[0093] If M ≥ d2, the equipment is determined to be in a dangerous state.

[0094] Taking seven types of device information—operating system version, operating system release information, port information, IP address, CPU utilization, memory utilization, and disk utilization—as an example, the reference values ​​for the numerical monitoring quantities CPU utilization, memory utilization, and disk utilization are set to 0.92, 0.9, and 0.8, respectively, with thresholds d1 and d2 of 1 and 3, respectively. When the collected character data has the same attributes as the original database, M1 = 0. When the collected numerical data is 0.70, 0.80, and 0.82, m1 = 0, m2 = 0, m3 = 1, and M2 = 1, then M = 1, M ≥ d1 = 1, indicating a risk state.

[0095] When the device's health status is "dangerous operation," the backend server generates an alarm message and displays the warning on the visual interface.

[0096] Step S4, dynamic adjustment of the equipment monitoring cycle, also includes the following steps:

[0097] According to the formula t = 2 N ×w determines the actual monitoring interval t of the device, where w is the monitoring interval for the device's importance and N is the device's health status. The backend server initiates a request to the MQTT server, and the MQTT server pushes the information to the device.

[0098] Example 4: Figure 2 As shown, a device fingerprint-based monitoring method includes the following steps:

[0099] Step 1: Using the analytic hierarchy process (AHP) and entropy method, the importance of the equipment is determined to be in three levels: T1, T2, and T3.

[0100] Step 2: Determine the initial monitoring cycle W based on the importance level of the equipment.

[0101] Step 3: Collect device behavior characteristic parameters.

[0102] Step 4: Assess the health status of the equipment based on the monitoring parameters and determine the health level N.

[0103] Step 5: If the health status is stable, N=0, proceed to step 8.

[0104] Step 6: If the health status is at risk, N=1, proceed to step 8.

[0105] Step 7: If the health status is dangerous, N=2, proceed to step 8.

[0106] Step 8: Set the monitoring period t = 2 N ×w.

[0107] Example 5: Figure 8As shown, an embodiment of a device fingerprint-based device includes: a device importance classification module, a receiving module, a status analysis module, an encryption / decryption module, and a period adjustment module.

[0108] The equipment classification module is used to classify equipment.

[0109] The receiving module is used to receive heartbeat data sent periodically by the monitored equipment.

[0110] The status analysis module analyzes the health status of the device based on the device attribute information in the heartbeat data.

[0111] The encryption / decryption module is used to encrypt or decrypt received or sent MQTT messages.

[0112] The cycle adjustment module dynamically adjusts the information transmission cycle of the monitored object based on the equipment's importance level and status.

[0113] The encryption / decryption module can use the national cryptographic algorithm SM4 for symmetric encryption and decryption.

[0114] The periodic adjustment module takes into account both the importance level and the status of the equipment.

[0115] When the equipment is in a stable health state, it is recorded as health state 0, and the original monitoring cycle is maintained.

[0116] When the device's health status is at risk, it is recorded as health status 1. A monitoring cycle adjustment request is sent to the MQTT server to increase the monitoring frequency. The MQTT server then pushes the information to the monitored object.

[0117] When the device health status is in a dangerous state, it is recorded as health status 2. A monitoring cycle adjustment request is sent to the MQTT server to set a higher monitoring frequency to closely monitor the device parameters.

[0118] Three-state monitoring based on device status:

[0119] To determine the "health status" of the equipment, the equipment periodically and autonomously sends heartbeat packets to the main station or backend to report its current health status N, where a stable state is 0, a risky operation is 1, and a dangerous operation is 2.

[0120] The system adaptively adjusts the monitoring frequency based on the importance and status of the equipment. For equipment in a high-risk state, the monitoring cycle is shortened to closely track its operational status and improve the accuracy and timeliness of fault prediction and detection. Conversely, when equipment is in a low-risk state, the monitoring cycle is extended to reduce monitoring costs and effectively utilize monitoring resources. This dynamic adjustment mechanism ensures that monitoring activities are both efficient and economical, maximizing the system's operational stability and security.

[0121] The above embodiments are provided merely for the purpose of describing the present invention and are not intended to limit the scope of the invention. The scope of the invention is defined by the appended claims. Various equivalent substitutions and modifications made without departing from the spirit and principles of the invention should be covered within the scope of the invention.

Claims

1. A monitoring method based on device fingerprinting, characterized in that, Includes the following steps: Step S1: Classification of equipment importance: The importance of equipment attributes is determined by the analytic hierarchy process (AHP-entropy method). Based on the importance of the equipment attributes, the equipment is classified into three levels: Level 1, Level 2, and Level 3, with different monitoring intervals set for each level. Step S2: Device Data Acquisition: Collect device information using SNMP, Syslog, smart probes, or heartbeat mechanisms. Step S3: Equipment Status Analysis: Based on the information fed back by the equipment, the health status of the equipment is divided into three categories: stable status, risky working status, and dangerous working status, so as to realize the three-state monitoring of equipment status; Step S4: Dynamic adjustment of equipment monitoring cycle: The monitoring cycle is adaptively adjusted according to the equipment importance level and equipment health status; Step S3, device status analysis, also includes the following steps: After receiving the heartbeat packet, the server analyzes its device status and reports a health status N, where a stable state is 0, a risky operation is 1, and a dangerous operation is 2. The collected data is divided into string and numeric types. For string-type data, such as operating system version, operating system release information, port information, and IP address, collect data X. i Compare with the original database device attribute information; if they are the same, then m i Calculate the string-type data state quantity M1 if it is 0 otherwise: For numerical data, CPU utilization, memory utilization, and disk utilization are monitored and collected as X. i The reference value for this monitoring quantity is D. i If X i >D i Then m i Calculate the numerical data state variable M2 if it is 1 otherwise: The total state variables M = M1 + M2, where m i For each monitoring component value, where i represents each type of monitoring information, n1 represents the total number of string-type monitoring information, and n2 represents the total number of numerical monitoring information, thresholds d1 and d2 are set. If M < d1, the equipment is determined to be in a stable state; If d1≤M<d2, the equipment is determined to be in a risky state; If M ≥ d2, the equipment is determined to be in a dangerous state. The monitoring system tracks seven types of device information: operating system version, operating system release information, port information, IP address, CPU utilization, memory utilization, and disk utilization. Reference values ​​for the numerical monitoring quantities CPU utilization, memory utilization, and disk utilization are set to 0.92, 0.9, and 0.8, respectively. Thresholds d1 and d2 are 1 and 3, respectively. When the collected character data has the same attributes as the original database, M1 = 0. When the collected numerical data is 0.70, 0.80, or 0.82, m1 = 0, m2 = 0, m3 = 1, and M2 = 1. Therefore, M = 1, and M ≥ d1 = 1, indicating a risky state. When the device's health status is "dangerous operation", the backend server generates an alarm message and displays the warning on the visual interface; Step S4, dynamic adjustment of the equipment monitoring cycle, also includes the following steps: according to the formula t=2 N ×w determines the actual monitoring interval t of the device, where w is the monitoring interval for the importance of the device, and N is the health status of the device. The backend server sends a request to the MQTT server, and the MQTT server pushes the information to the device. When the equipment health status is stable, it is recorded as health status 0, and the original monitoring cycle is maintained; when the equipment health status is at risk, it is recorded as health status 1, and the monitoring cycle is shortened; when the equipment health status is dangerous, it is recorded as health status 2, and a higher monitoring frequency is set to closely monitor the equipment parameters.

2. The monitoring method based on device fingerprint according to claim 1, characterized in that, Step S2, device data acquisition, also includes the following steps: By collecting and analyzing the characteristic parameters of the devices, a unique fingerprint is generated for each device. This fingerprint data includes the static and dynamic information of the device. The static information includes basic device information, operating system information, chip information and communication information. The dynamic information includes CPU utilization, memory utilization and disk utilization. The collected information can include operating system version, operating system release information, port information, IP address, CPU utilization, memory utilization and disk utilization. A heartbeat mechanism is used to monitor device status. A suitable heartbeat mechanism, such as Ping, TCP, UDP, HTTP, MQTT or a custom protocol, is selected according to system requirements and device characteristics. The device then periodically reports heartbeat information to the server. The heartbeat packet contains identification information, a timestamp and custom device behavior information.

3. The monitoring method based on device fingerprint according to claim 1, characterized in that, Step S1 also includes the following steps: using the analytic hierarchy process to determine the subjective weights of the equipment attributes, using the entropy method to determine the objective weights of the equipment attributes, and combining the subjective and objective weights to divide the equipment into Level 1 (T1), Level 2 (T2), and Level 3 (T3), with different monitoring intervals set for each level.

4. The monitoring method based on device fingerprint according to claim 1, characterized in that, Step S2 also includes the following steps: obtaining device information by deploying smart probes, setting up an Agent based on the SNMP protocol, and receiving periodically sent heartbeat packets based on the MQTT protocol. The monitoring information includes the device's operating status and performance parameters.

5. The monitoring method based on device fingerprint according to claim 1, characterized in that, Step S3, the three-state monitoring based on device status, includes the following steps: To determine the "health status" of the equipment, the equipment periodically and autonomously sends heartbeat packets to the main station or backend, reporting its current health status N. A stable state is represented by 0, risky operation by 1, and dangerous operation by 2. The system adaptively adjusts the monitoring frequency based on the importance and status of the equipment. For equipment in a high-abnormal state, the system shortens the monitoring cycle to closely track the equipment's operating status and improve the accuracy and timeliness of fault prediction and detection. Conversely, when the equipment is in a low-abnormal state, the system extends the monitoring cycle to reduce monitoring costs and effectively utilize monitoring resources. This dynamic adjustment mechanism ensures that monitoring activities are both efficient and economical, maximizing the system's operational stability and security.

6. A monitoring device based on device fingerprinting, characterized in that, include: The equipment classification module is used to classify equipment. The device data acquisition module is used to receive heartbeat data sent periodically by the monitored device, including an encryption / decryption module, which is used to encrypt, decrypt, receive, or send information. The device status analysis module analyzes the health status of the device based on the device attribute information in the heartbeat data. This also includes: after receiving a heartbeat packet, the server analyzes its device status and reports a health status N, where a stable state is 0, a risky operation is 1, and a dangerous operation is 2. The collected data is divided into string and numeric types. For string-type data, such as operating system version, operating system release information, port information, and IP address, collect data X. i Compare with the original database device attribute information; if they are the same, then m i Calculate the string-type data state quantity M1 if it is 0 otherwise: For numerical data, CPU utilization, memory utilization, and disk utilization are monitored and collected as X. i The reference value for this monitoring quantity is D. i If X i >D i Then m i Calculate the numerical data state variable M2 if it is 1 otherwise: The total state variables M = M1 + M2, where m i For each monitoring component value, where i represents each type of monitoring information, n1 represents the total number of string-type monitoring information, and n2 represents the total number of numerical monitoring information, thresholds d1 and d2 are set. If M < d1, the equipment is determined to be in a stable state; If d1≤M<d2, the equipment is determined to be in a risky state; If M ≥ d2, the equipment is determined to be in a dangerous state. The monitoring system tracks seven types of device information: operating system version, operating system release information, port information, IP address, CPU utilization, memory utilization, and disk utilization. Reference values ​​for the numerical monitoring quantities CPU utilization, memory utilization, and disk utilization are set to 0.92, 0.9, and 0.8, respectively. Thresholds d1 and d2 are 1 and 3, respectively. When the collected character data has the same attributes as the original database, M1 = 0. When the collected numerical data is 0.70, 0.80, or 0.82, m1 = 0, m2 = 0, m3 = 1, and M2 = 1. Therefore, M = 1, and M ≥ d1 = 1, indicating a risky state. When the device's health status is "dangerous operation", the backend server generates an alarm message and displays the warning on the visual interface; The periodic adjustment module dynamically adjusts the information transmission cycle of the monitored object based on the equipment's importance level and status. It also includes: according to the formula t=2 N ×w determines the actual monitoring interval t of the device, where w is the monitoring interval for the importance of the device, and N is the health status of the device. The backend server sends a request to the MQTT server, and the MQTT server pushes the information to the device. When the equipment health status is stable, it is recorded as health status 0, and the original monitoring cycle is maintained; when the equipment health status is at risk, it is recorded as health status 1, and the monitoring cycle is shortened; when the equipment health status is dangerous, it is recorded as health status 2, and a higher monitoring frequency is set to closely monitor the equipment parameters.

7. A device fingerprint-based monitoring device according to claim 6, characterized in that, The encryption / decryption module uses the Chinese national cryptographic algorithm SM4 for symmetric encryption and decryption. The periodic adjustments are made taking into account both the importance level and the condition of the equipment. When the equipment's health status is stable, it is recorded as health status 0, and the original monitoring cycle is maintained. When the device's health status is at risk (recorded as health status 1), a monitoring cycle adjustment request is sent to the MQTT server to increase the monitoring frequency. The MQTT server then pushes the information to the monitored object. When the device health status is in a dangerous state, it is recorded as health status 2. A monitoring cycle adjustment request is sent to the MQTT server to set a higher monitoring frequency to closely monitor the device parameters.

Citation Information

Patent Citations

  • Power communication network state detection method

    CN103647677A

  • Maintenance decision-making method based on equipment comprehensive health condition analysis and management

    CN111160685A