Device-based situational awareness methods, systems, terminals, and storage media
By filtering detection servers in the device group and grouping them according to operating conditions and business types, the problems of resource waste and insufficient identification accuracy in existing situational awareness methods are solved, and more efficient situational awareness is achieved.
Patent Information
- Application Number
- CN202411576434.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-06
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-11-06
AI Technical Summary
In existing situational awareness methods, setting up a separate detection server consumes system resources and makes it difficult to accurately identify abnormal devices.
By identifying equipment groups, we can filter out the testing server equipment and group them according to operating conditions and business types. We can then use the testing server to obtain and analyze the data collected by the equipment to identify abnormal equipment.
It improves equipment utilization, saves system resources, and more accurately identifies abnormal devices in the network, thereby enhancing the accuracy of situational awareness results.
Smart Images

Figure CN119561863B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of situational awareness technology, and more particularly to situational awareness methods, systems, terminals, and storage media based on device grouping. Background Technology
[0002] Situational awareness involves perceiving environmental elements within a specific time and space, understanding the meaning of these elements, and ultimately predicting their future development. Utilizing big data analytics, situational awareness can classify, statistically analyze, and comprehensively examine attack events, threat alerts, and attack sources, thereby enhancing the ability to detect, identify, analyze, and respond to security threats from a global perspective.
[0003] Current situational awareness methods primarily involve setting up a dedicated detection server to identify anomalous devices based on data collected from various equipment. However, this approach consumes significant system resources. Furthermore, current detection servers mainly aggregate and analyze data from all devices; however, system devices are diverse, with varying operating systems and functionalities, and attack methods targeting different devices can vary greatly, presenting numerous unknown risks. Simply aggregating and analyzing data from all devices is insufficient to accurately identify anomalous devices.
[0004] Therefore, existing technologies still need improvement and development. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide a situational awareness method, system, terminal and storage medium based on device grouping, in order to address the above-mentioned defects of the prior art. The invention aims to solve the problems that the existing method of setting up a separate detection server requires a lot of system resources and that the existing data analysis method of the detection server is difficult to correctly identify abnormal devices.
[0006] The technical solution adopted by this invention to solve the problem is as follows:
[0007] In a first aspect, embodiments of the present invention provide a situational awareness method based on device grouping, the method comprising:
[0008] Determine the group of devices to be sensed, and based on the status data of each device in the group, select the devices to serve as the detection server.
[0009] The devices in the equipment group are grouped according to their operating conditions and business types to obtain several equipment groups;
[0010] The detection server acquires the collected data from each device, and analyzes the collected data of each device in each device group to identify abnormal devices in the device group. Based on all the identified abnormal devices, a situational awareness result is generated.
[0011] In one implementation, determining the group of devices to be sensed includes:
[0012] Obtain the network topology and filter out important devices in the network as the device group to be sensed based on the topology;
[0013] Alternatively, obtain device selection information input by the user, and determine the group of devices to be sensed based on the device selection information.
[0014] In one implementation, the step of grouping the devices in the device group according to operating conditions and service types to obtain several device groups includes:
[0015] Obtain the operating status information and service information corresponding to each device in the device group;
[0016] Input the operating condition information and business information of each device into a pre-established device grouping algorithm;
[0017] The device grouping algorithm is used to group devices according to their operating conditions and business information to obtain several device groups.
[0018] In one implementation, the devices in each device group have the same operating conditions, the similarity of the business information between each pair of devices is higher than the similarity threshold, and the number of devices in each device group is higher than a preset number.
[0019] In one implementation, the step of analyzing the collected data from each device in the device group to identify abnormal devices in the device group includes:
[0020] The collected data from each device in the device group is input into a pre-established risk analysis algorithm;
[0021] The risk analysis algorithm performs horizontal and vertical analysis based on the collected data of each device in the device group, and identifies abnormal devices in the device group.
[0022] In one implementation, the lateral analysis is a comparison and analysis of the same type of data collected from various devices; the longitudinal analysis is a comparison and analysis of multiple types of data collected from the same device.
[0023] In one embodiment, the method further includes:
[0024] For each malfunctioning device, determine the corresponding backup device from the device group corresponding to that malfunctioning device;
[0025] All business flows on the faulty device are transferred to the backup device for processing; or all business flows on the faulty device with a security level higher than a preset threshold are transferred to the backup device for processing.
[0026] Secondly, embodiments of the present invention also provide a situational awareness system based on device grouping, the system comprising:
[0027] The filtering module is used to determine the group of devices to be detected, and to filter out the devices that can be used as the detection server based on the status data of each device in the group.
[0028] The grouping module is used to group the devices in the device group according to the working conditions and service types, resulting in several device groups;
[0029] The identification module is used to acquire the collected data of each device through the detection server, and analyze the collected data of each device in each device group to identify abnormal devices in the device group, and generate situational awareness results based on all the identified abnormal devices.
[0030] Thirdly, embodiments of the present invention also provide a terminal, the terminal including a memory and one or more processors; the memory stores one or more programs; the programs include instructions for executing the situational awareness method based on device grouping as described above; the processor is used to execute the programs.
[0031] Fourthly, embodiments of the present invention also provide a computer-readable storage medium having stored thereon a plurality of instructions adapted to be loaded and executed by a processor to implement the steps of the device grouping-based situational awareness method as described above.
[0032] The beneficial effects of this invention are as follows: In this embodiment, the invention determines a group of devices to be sensed, and based on the status data of each device in the group, selects a device to serve as a detection server. The devices in the group are then grouped according to operating conditions and service types, resulting in several device groups. The detection server acquires the collected data from each device, and for each device group, analyzes the collected data of each device in that group to identify abnormal devices. Based on all identified abnormal devices, a situational awareness result is generated. This invention selects one device from the group of devices to be sensed as the detection server, which can improve device utilization and save system resources. Furthermore, the detection server groups devices according to operating conditions and service types, and then compares and analyzes the collected data of devices in the same group, which can more accurately identify abnormal devices in the network, thereby improving the accuracy of the situational awareness result. Attached Figure Description
[0033] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0034] Figure 1 This is a flowchart illustrating the situational awareness method based on device grouping provided in an embodiment of the present invention.
[0035] Figure 2 This is a schematic diagram illustrating the types of data acquired by the detection server provided in this embodiment of the invention.
[0036] Figure 3 This is a schematic diagram of the functional modules of the detection server provided in an embodiment of the present invention.
[0037] Figure 4 This is a schematic diagram of the internal modules of the situational awareness system based on device grouping provided in an embodiment of the present invention.
[0038] Figure 5 This is a schematic diagram of the terminal provided in the embodiment of the present invention. Detailed Implementation
[0039] This invention discloses a situational awareness method, system, terminal, and storage medium based on device grouping. To make the objectives, technical solutions, and effects of this invention clearer and more explicit, the invention is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only for explaining the invention and are not intended to limit the invention.
[0040] Those skilled in the art will understand that, unless specifically stated otherwise, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. It should be further understood that the term “comprising” as used in this specification means the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. It should be understood that when we say an element is “connected” or “coupled” to another element, it can be directly connected or coupled to the other element, or there may be intermediate elements. Furthermore, “connected” or “coupled” as used herein can include wireless connections or wireless coupling. The term “and / or” as used herein includes all or any units and all combinations of one or more associated listed items.
[0041] It will be understood by those skilled in the art that, unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. It should also be understood that terms such as those defined in general dictionaries should be understood to have the same meaning as in the context of the prior art, and should not be interpreted in an idealized or overly formal sense unless specifically defined as herein.
[0042] Situational awareness involves perceiving environmental elements within a specific time and space, understanding the meaning of these elements, and ultimately predicting their future development. Utilizing big data analytics, situational awareness can classify, statistically analyze, and comprehensively examine attack events, threat alerts, and attack sources, thereby enhancing the ability to detect, identify, analyze, and respond to security threats from a global perspective.
[0043] Current situational awareness methods primarily involve setting up a dedicated detection server to identify anomalous devices based on data collected from various devices. This approach consumes significant system resources. Furthermore, current detection servers mainly aggregate and analyze data from all devices; however, system devices are diverse, with varying operating systems and functionalities. Attack methods targeting different devices can also vary greatly, presenting numerous unknown risks. Simply aggregating and analyzing data from all devices is insufficient to accurately identify anomalous devices.
[0044] To address the aforementioned shortcomings of existing technologies, this invention provides a situational awareness method based on device grouping. The method includes: determining a group of devices to be monitored; selecting a device to serve as a detection server based on the status data corresponding to each device in the device group; grouping the devices in the device group according to operating conditions and service types to obtain several device groups; acquiring the collected data from each device through the detection server; and analyzing the collected data of each device in each device group to identify abnormal devices within that group; and generating a situational awareness result based on all identified abnormal devices. This invention selects a device from the group of devices to be monitored as the detection server, which can improve device utilization and save system resources. Furthermore, the detection server groups devices according to operating conditions and service types, and then compares and analyzes the collected data of devices in the same group, which can more accurately identify abnormal devices in the network, thereby improving the accuracy of the situational awareness result.
[0045] like Figure 1 As shown, the method includes:
[0046] Step S100: Determine the group of devices to be sensed, and based on the status data of each device in the group, select the devices to serve as the detection server.
[0047] Specifically, for systems requiring situational awareness, a group of devices to be sensed can be formed by combining all devices within it, or by selecting key devices from this group. To improve device utilization and conserve system resources, this embodiment does not assign an additional device as a detection server; instead, it selects one device from the group of devices to be sensed. In practical applications, since the detection service requires certain computing resources, to ensure the normal operation of services on each device, this embodiment first acquires the status data of each device and then uses this status data to select an idle device as the detection server. Devices in the device group not designated as detection servers act as agents, only needing to collect their own data and provide it to the detection server; that is, they only need to perform data collection. Devices designated as detection servers also need to perform data analysis, achieving situational awareness by analyzing the data collected by each device.
[0048] In one implementation, the status data of each device includes at least one of the following: computing resources, trustworthiness, and service priority. Computing resources can be determined based on data such as CPU utilization, memory usage, disk space, and network traffic. Trustworthiness can be determined based on historical behavior records (e.g., whether it has been attacked or subjected to unauthorized operations), security patch levels, etc. Service priority can be determined based on device performance and divided into multiple levels, such as low, medium, and high. Low-priority devices have weak performance and do not participate in detection; medium-priority devices are general-purpose devices that can handle low-complexity data; high-priority devices are typically high-performance devices that can handle high-complexity data. In practical applications, the priority can be further subdivided if necessary.
[0049] Furthermore, if each device's status data contains multiple data types, since different data types have varying impacts on the device's suitability as a detection server, a weight value can be assigned to each type of data. This weight value can be set based on business needs, user experience, and pre-defined optimization algorithms. The weight value reflects the relative importance of that data in the overall evaluation. Taking a single device as an example, the device's status data is collected, and each data point is multiplied by its weight value to obtain a weighted value. The suitability of the device as a detection server is determined based on the weighted value of all data. The suitability of each device is compared, and the device with the highest suitability or multiple devices with relatively high suitability are selected as the detection server.
[0050] In one implementation, the status data of each device can be acquired periodically according to a preset time interval, and the attribution of the detection server can be dynamically adjusted.
[0051] In one implementation, determining the group of devices to be sensed includes:
[0052] Obtain the network topology and filter out important devices in the network as the device group to be sensed based on the topology;
[0053] Alternatively, obtain device selection information input by the user, and determine the group of devices to be sensed based on the device selection information.
[0054] Specifically, this embodiment provides several selection methods for choosing the group of devices to be monitored. One method is selection based on network topology, which describes the connection relationships and layout of various devices in the network. Network topology can be physical topology, i.e., the physical layout of actual cabling and devices, or logical topology, i.e., the transmission path of data flow in the network. Based on the network topology, it is possible to analyze which devices play key roles in the network, such as core switches, main servers, border routers, etc., and then select important devices to form the group of devices to be monitored. Another method is selection based on user needs. The device selection information input by the user can reflect the user's own needs or preferences, and the set of devices selected based on this information can better meet the user's monitoring requirements.
[0055] In another implementation, the user's frequently used devices can be automatically identified based on their network behavior and usage logs, and device selection information can be automatically generated.
[0056] In another implementation, the group of devices to be sensed can be determined by the device's functions, bandwidth usage, number of connected users, and impact on business continuity.
[0057] Step S200: Group the devices in the device group according to the working conditions and service types to obtain several device groups.
[0058] Specifically, operating conditions refer to the working conditions or operating environment of the equipment, which may include factors such as equipment operating time, load, and ambient temperature and humidity. Business type refers to the business processes or application scenarios supported by the equipment; for example, some equipment may be specifically used for research and development testing, while others may be used for customer service. Different business types may have different performance requirements for the equipment. Figure 2 As shown, the detection server includes a data grouping module and a detection module. To facilitate data analysis, all devices in the equipment group are first grouped according to two indicators: operating conditions and business type. Devices with similar operating conditions and business types are grouped together, while devices with different operating conditions and business types are grouped into different groups, resulting in multiple equipment groups. Since the operating conditions and business types of devices within the same equipment group are similar, the comparability of the collected data from these devices is higher. Data analysis based on grouping can effectively improve the reliability and accuracy of the analysis results.
[0059] In one implementation, the process of grouping the devices in the device group according to operating conditions and service types to obtain several device groups includes:
[0060] Obtain the operating status information and service information corresponding to each device in the device group;
[0061] Input the operating condition information and business information of each device into a pre-established device grouping algorithm;
[0062] The device grouping algorithm is used to group devices according to their operating conditions and business information to obtain several device groups.
[0063] Specifically, to quickly achieve device grouping, this embodiment pre-establishes a device grouping algorithm. This algorithm can classify devices based on their multidimensional attributes (operating condition information and business information). The device grouping algorithm can be generated based on machine learning, such as using clustering algorithms to automatically group devices according to their multidimensional attributes. In practical application scenarios, the detection server inputs the operating condition information and business information of each device into the device grouping algorithm. The algorithm then determines which group each device should belong to based on the input parameters and generates the final device grouping results. This ensures that the devices in each group have similar operating condition and business characteristics, facilitating subsequent data analysis.
[0064] In one implementation, the devices in each device group have the same operating conditions, the similarity of the business information between each pair of devices is higher than the similarity threshold, and the number of devices in each device group is higher than a preset number.
[0065] Specifically, since the accuracy of device grouping is crucial for subsequent data analysis steps, this embodiment defines the conditions that the device grouping results must meet to ensure that each device can be classified into an appropriate group. First, devices in the same group need to be under similar operating conditions and handle similar tasks, thereby improving the comparability of data collected from different devices in the same group. Second, the number of devices in the same group cannot be too small, as an insufficient number of devices will reduce the reliability of the data comparison results and deviate from the actual situation.
[0066] In one implementation, the device grouping algorithm is specifically used for:
[0067] Based on the operating condition information of each device, several device groups are obtained; wherein, the operating conditions of each device in each device group are the same.
[0068] For each device group, the similarity of the business information between each pair of devices in the device group is calculated, and it is determined whether the similarity is higher than a preset similarity threshold. If not, the device group is regrouped.
[0069] If the number of devices in each device group is higher than a preset value, the similarity threshold is adjusted, and the process is repeated for each device group. The similarity of the business information between each pair of devices in the device group is calculated, and the similarity is determined to be higher than the preset similarity threshold. If not, the device group is regrouped until the working conditions of each device in each device group are the same, the similarity of the business information between each pair of devices is higher than the similarity threshold, and the number of devices in each device group is higher than the preset value, thus obtaining the final device grouping result.
[0070] Specifically, this embodiment can establish a device grouping algorithm based on machine learning technology and use an iterative approach to continuously adjust the similarity threshold, thereby obtaining device grouping results that can simultaneously meet the requirements of operating conditions, similarity, and number of devices.
[0071] Step S300: Obtain the collected data of each device through the detection server, and analyze the collected data of each device in each device group to identify abnormal devices in the device group, and generate situational awareness results based on all the identified abnormal devices.
[0072] Specifically, the data collected by each device can include operational status, performance indicators, log information, network traffic, and other data. Each device transmits its collected data to the detection server, which receives and stores the data for analysis. The detection server obtains group labels for each device based on the device grouping results. During data analysis, the collected data of devices in the same group are aggregated according to the group labels, and all aggregated data is analyzed to determine the similarities and differences between devices in that group. This allows for the identification of devices that deviate from normal conditions, which are then marked as anomalous devices. Finally, these identified anomalous devices are used to assess the overall network condition, such as evaluating potential connections between anomalous devices and their impact on network stability, thereby obtaining situational awareness results.
[0073] For example, the technical solution of this embodiment can be applied to the HarmonyOS system. Leveraging the characteristic of IoT device groups where a large number of devices with identical or similar functions exist in certain scenarios, the system and functional key data of these devices are collected through the communication capabilities of the soft bus, and horizontal and / or vertical comparisons are performed to identify abnormal data, thereby discovering potential risks.
[0074] In one implementation, the step of analyzing the collected data from each device in the device group to identify abnormal devices in the device group includes:
[0075] The collected data from each device in the device group is input into a pre-established risk analysis algorithm;
[0076] The risk analysis algorithm performs horizontal and vertical analysis based on the collected data of each device in the device group, and identifies abnormal devices in the device group.
[0077] Specifically, to quickly identify anomalous devices, this embodiment pre-establishes a risk analysis algorithm. This algorithm assesses whether a device is in an abnormal state based on its collected data. The risk analysis algorithm can be constructed using various methods, such as statistics, machine learning, and expert systems; for example, a supervised learning algorithm model can be employed. In practical applications, the detection server groups each device and passes the collected data from all devices in that group as input parameters to the risk analysis algorithm. The algorithm performs horizontal and vertical analyses based on the input parameters, assesses the degree of anomalousness for each device based on the analysis results, and ultimately identifies anomalous devices exhibiting significant differences or abnormal conditions.
[0078] In one implementation, the horizontal analysis involves comparing and analyzing data of the same type collected from various devices; the vertical analysis involves comparing and analyzing multiple types of data collected from the same device.
[0079] Specifically, after the risk analysis algorithm obtains the collected data from each device, it will perform data analysis tasks from two dimensions: horizontal analysis and vertical analysis. Horizontal analysis refers to comparing and analyzing multiple data of the same type collected from multiple devices, while vertical analysis refers to comparing and analyzing multiple data collected from the same device.
[0080] For cross-sectional analysis: First, the collected data from each device is categorized. The purpose of categorization is to group data of the same or similar types together for easier subsequent processing and analysis. The categorization criteria can be determined based on one or more characteristics such as data source, type, format, and purpose. Each group of data obtained after categorization becomes a data set, and each data set contains data of the same type from different devices. Different data sets correspond to different data types, such as temperature data, functional data, CPU data, memory data, etc. (e.g., ...) Figure 3 (As shown). For each data set, all data within that set are compared. The purpose of this comparison is to identify data that is significantly different from the other data and define these deviations as similar deviations. The cross-sectional analysis results are then obtained based on all similar deviations. In practical applications, the cross-sectional analysis comparison process can employ one or more comparison methods, such as statistical analysis methods or machine learning algorithms. For example, using statistical analysis methods, the mean and / or standard deviation can be used to identify data that deviates from the normal range.
[0081] For longitudinal analysis: Data collected from each device is analyzed independently, rather than by combining data from multiple devices. For each device, all collected data is internally compared to identify data whose generation / change trends significantly differ from other data from that device. This deviation is defined as "device-specific deviation data." The longitudinal analysis results are obtained based on all device-specific deviation data. In practical applications, the longitudinal analysis comparison process can employ one or more comparison methods, such as statistical analysis methods, time series analysis methods, and machine learning algorithms.
[0082] By comparing and analyzing the data, we can identify anomalous data that shows significant differences or deviates from the normal range, and further analyze which devices these anomalous data originate from. We calculate the percentage of anomalous data in the data collected by each device, and determine whether a device is anomalous based on this percentage. For example, if a device shows anomalous data in multiple data groups, or if the quantity and severity of its anomalous data are significantly higher than other devices, then that device can be identified as anomalous. This embodiment, through data grouping and comparative analysis, can more accurately locate anomalous data and anomalous devices, thereby achieving more detailed and comprehensive situational awareness.
[0083] In one implementation, the method for identifying outlier data in each data group during lateral analysis specifically includes:
[0084] For each data group, determine whether the data in the data group is time-series data;
[0085] If the data in the data set is time series data, then perform year-on-year and / or month-on-month analysis on each time series data to obtain the corresponding trend of change; compare the trends of change of each time series data, and identify abnormal data based on the comparison results;
[0086] If the data in the data set is not time-series data, a scatter plot is generated based on the data in the data set, and the distance value between each point and its surrounding points is calculated. Candidate outliers are identified based on the distance values. For each candidate outlier, the surrounding density of the candidate outlier and the surrounding density of its neighboring points are calculated. The surrounding density of each data point is determined based on the number of data points within a preset range around it. The relative density of the candidate outlier is calculated based on its surrounding density and the surrounding density of its neighboring points. The degree of anomalousness of the candidate outlier is determined based on the relative density. The final anomalous data is identified based on the degree of anomalousness of each candidate outlier.
[0087] In one implementation, the method further includes:
[0088] For each malfunctioning device, determine the corresponding backup device from the device group corresponding to that malfunctioning device;
[0089] All business flows on the faulty device are transferred to the backup device for processing; or all business flows on the faulty device with a security level higher than a preset threshold are transferred to the backup device for processing.
[0090] Specifically, to ensure data security and normal business operations, this embodiment requires suppressing or blocking abnormal devices and promptly transferring services from those devices. Since the device group to which the abnormal device belongs contains devices with similar operating conditions and services, a trusted device can be selected from the group as a backup. In practical applications, the following factors should also be considered when selecting a backup device: device performance (whether the backup device's processing capacity can meet business needs); device status (whether the backup device is operating normally without faults or performance issues); and network bandwidth (whether the backup device's network connection is stable and its bandwidth is sufficient). Finally, services from the abnormal device are transferred to the selected backup device for processing, thereby ensuring the secure and uninterrupted operation of the device's services. Since service transfer also consumes certain system resources, to conserve system resources, only services with higher security levels from the abnormal device can be transferred to the backup device. Once the abnormal device recovers or the risk is eliminated, the transferred services are then transferred back to the original device.
[0091] The advantages of this invention are:
[0092] (1) Separate the functions of data acquisition and data analysis, and use the communication capabilities of the operating system's distributed soft bus to send data to the data analysis device for data analysis. This can make full use of the idle device resources in the system for situational awareness, solve the problem that low-performance devices cannot perform situational awareness, and ensure response time.
[0093] (2) The detection server will group the devices according to the working conditions and business types, and then compare and analyze the collected data of the devices in the same group. This can more accurately identify abnormal devices in the network, thereby improving the accuracy of situational awareness results.
[0094] Based on the above embodiments, the present invention also provides a situational awareness system based on device grouping, such as... Figure 4 As shown, the system includes:
[0095] The filtering module 01 is used to determine the group of devices to be detected, and to filter out the devices that can be used as the detection server based on the status data of each device in the group.
[0096] Grouping module 02 is used to group the devices in the device group according to the working conditions and service types to obtain several device groups;
[0097] The identification module 03 is used to acquire the collected data of each device through the detection server, and analyze the collected data of each device in each device group to identify abnormal devices in the device group, and generate situational awareness results based on all the identified abnormal devices.
[0098] In one implementation, the filtering module 01 specifically includes:
[0099] The data acquisition unit is used to acquire the network topology and filter out important devices in the network as the device group to be sensed based on the topology.
[0100] Alternatively, obtain device selection information input by the user, and determine the group of devices to be sensed based on the device selection information.
[0101] In one implementation, the grouping module 02 specifically includes:
[0102] An information acquisition unit is used to acquire the operating status information and business information corresponding to each device in the device group;
[0103] The device grouping unit is used to input the operating condition information and service information of each device into a pre-established device grouping algorithm; and to group the devices according to the operating condition information and service information of each device through the device grouping algorithm to obtain several device groups.
[0104] In one implementation, the devices in each device group have the same operating conditions, the similarity of the business information between each pair of devices is higher than the similarity threshold, and the number of devices in each device group is higher than a preset number.
[0105] In one implementation, the identification module 03 specifically includes:
[0106] The data input unit is used to input the collected data from each device in the device group into a pre-established risk analysis algorithm.
[0107] An anomaly identification unit is used to perform horizontal and vertical analysis based on the collected data of each device in the device group using the risk analysis algorithm, and to identify abnormal devices in the device group.
[0108] In one implementation, the horizontal analysis involves comparing and analyzing data of the same type collected from various devices; the vertical analysis involves comparing and analyzing multiple types of data collected from the same device.
[0109] In one implementation, the system further includes:
[0110] The service flow module is used to determine the backup device corresponding to each abnormal device from the device group corresponding to the abnormal device; transfer all services on the abnormal device to the backup device for processing; or transfer all services on the abnormal device with a security level higher than a preset threshold to the backup device for processing.
[0111] Based on the above embodiments, the present invention also provides a terminal, the principle block diagram of which can be as follows: Figure 5 As shown, the terminal includes a processor, memory, network interface, and display screen connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements a device-group-based situational awareness method. The display screen can be an LCD screen or an e-ink screen.
[0112] Those skilled in the art will understand that Figure 5 The schematic diagram shown is only a partial structural diagram related to the present invention and does not constitute a limitation on the terminal to which the present invention is applied. A specific terminal may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.
[0113] In one implementation, the terminal's memory stores one or more programs, and these programs are configured to be executed by one or more processors, and the programs contain instructions for performing a device-based situational awareness method.
[0114] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided by this invention can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM), etc.
[0115] In summary, this invention discloses a situational awareness method, system, terminal, and storage medium based on device grouping, relating to the field of situational awareness technology. The method involves determining a group of devices to be sensed, selecting devices to serve as detection servers based on the status data of each device in the group, grouping the devices in the group according to operating conditions and service types to obtain several device groups, acquiring the collected data from each device through the detection server, and analyzing the collected data of each device in each device group to identify abnormal devices in that group, and generating situational awareness results based on all identified abnormal devices. This invention selects a device as the detection server from the group of devices to be sensed, which can improve device utilization and save system resources. Furthermore, the detection server groups devices according to operating conditions and service types, and then compares and analyzes the collected data of devices in the same group, which can more accurately identify abnormal devices in the network, thereby improving the accuracy of situational awareness results.
[0116] It should be understood that the application of the present invention is not limited to the examples above. Those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims.
Claims
1. A situational awareness method based on device grouping, characterized in that, The method includes: Determine the group of devices to be sensed, and based on the status data of each device in the group, select the devices to serve as the detection server. The devices in the equipment group are grouped according to their operating conditions and business types to obtain several equipment groups; The detection server acquires data from each device and analyzes the collected data of each device in each device group to identify abnormal devices in that group. This includes: inputting the collected data of each device in the group into a pre-established risk analysis algorithm; and using the risk analysis algorithm to perform horizontal and vertical analysis based on the collected data of each device in the group to identify abnormal devices in that group. The horizontal analysis involves comparing and analyzing data of the same type collected from each device; the vertical analysis involves comparing and analyzing multiple types of data collected from the same device. And generate situational awareness results based on all the identified abnormal devices.
2. The situational awareness method based on device grouping according to claim 1, characterized in that, The determination of the group of devices to be sensed includes: Obtain the network topology and filter out important devices in the network as the device group to be sensed based on the topology; Alternatively, obtain device selection information input by the user, and determine the group of devices to be sensed based on the device selection information.
3. The situational awareness method based on device grouping according to claim 1, characterized in that, The equipment in the equipment group is grouped according to operating conditions and service types to obtain several equipment groups, including: Obtain the operating status information and service information corresponding to each device in the device group; Input the operating condition information and business information of each device into a pre-established device grouping algorithm; The device grouping algorithm is used to group devices according to their operating conditions and business information to obtain several device groups.
4. The situational awareness method based on device grouping according to claim 3, characterized in that, In each of the device groups, the operating conditions of each device are the same, the similarity of the business information between each pair of devices is higher than the similarity threshold, and the number of devices in each device group is higher than the preset number.
5. The situational awareness method based on device grouping according to claim 1, characterized in that, The method further includes: For each malfunctioning device, determine the corresponding backup device from the device group corresponding to that malfunctioning device; All business flows on the faulty device are transferred to the backup device for processing; or all business flows on the faulty device with a security level higher than a preset threshold are transferred to the backup device for processing.
6. A situational awareness system based on device grouping, characterized in that, The system includes: The filtering module is used to determine the group of devices to be detected, and to filter out the devices that can be used as the detection server based on the status data of each device in the group. The grouping module is used to group the devices in the device group according to the working conditions and service types, resulting in several device groups; The identification module is used to acquire the collected data from each device through the detection server, and analyze the collected data of each device in each device group to identify abnormal devices in the device group. This includes: inputting the collected data of each device in the device group into a pre-established risk analysis algorithm; performing horizontal and vertical analysis based on the collected data of each device in the device group using the risk analysis algorithm, and identifying abnormal devices in the device group; the horizontal analysis involves comparing and analyzing data of the same type collected by each device; the vertical analysis involves comparing and analyzing multiple types of data collected by the same device. And generate situational awareness results based on all the identified abnormal devices.
7. A terminal, characterized in that, The terminal includes a memory and one or more processors; the memory stores one or more programs; the programs contain instructions for executing the device grouping-based situational awareness method as described in any one of claims 1-5; the processors are used to execute the programs.
8. A computer-readable storage medium storing a plurality of instructions thereon, characterized in that, The instructions are applicable to be loaded and executed by a processor to implement the steps of the device grouping-based situational awareness method as described in any one of claims 1-5.
Citation Information
Patent Citations
Equipment fault early warning method and device based on outlier parameters, equipment and medium
CN111882833A
Equipment fault intelligent monitoring method and device, electronic equipment and storage medium
CN115077955A