System parameter detection method and system based on USB flash disk

By obtaining the system operation log data of the USB flash drive and using sliding window scanning technology, combining the page access fluctuation index and memory fragment distribution location for cross-verification, the problem of traditional methods being difficult to monitor memory status in real time is solved, efficient and accurate memory exception detection is achieved, and the stability and security of the system are improved.

CN120011117AInactive Publication Date: 2025-05-16SHENZHEN LESONMEN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510023219.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-07
Publication Date
2025-05-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional USB disk-based system parameter detection methods are difficult to reflect the memory operating status in real time, and the resource consumption is high, making it difficult to deploy in scenarios with limited resources.

Method used

By obtaining the system operation log data of the USB flash drive, using sliding window scanning technology to dynamically monitor the physical address space of the memory, cross-verification is performed based on the page access fluctuation index and the memory fragment distribution location, and a system detection report is generated.

Benefits of technology

It realizes efficient and accurate memory exception detection and analysis, improves the comprehensiveness and real-time nature of system monitoring, reduces resource consumption, and improves the stability and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120011117A_ABST
    Figure CN120011117A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, in particular to a system parameter detection method and system based on a USB flash disk. The method comprises the following steps: acquiring system operation log data of the USB flash disk; performing sliding window scanning on the memory physical address space according to the system operation log data, and performing statistical analysis on continuous idle pages in each scanning window to obtain memory address mapping data; the memory page access frequency is subjected to weighted calculation according to the memory address mapping data and a preset time length, so that a page access fluctuation index is obtained, and the weighted calculation specifically comprises the steps that the weight of 0.6 is given to access records within the preset time length, and the weight of 0.4 is given to access records beyond the preset time length. According to the method, the abnormal feature data of the memory can be accurately captured through multi-time-scale analysis, a detailed system diagnosis report is generated, and more accurate maintenance and optimization are supported.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular to a method and system for detecting system parameters based on a USB flash drive. Background Art

[0002] A USB flash drive (USB Flash Drive) is a portable data storage device that utilizes flash memory technology and connects to a computer or other device via a USB interface for data storage, transfer, and backup. USB flash drive system parameters refer to variables related to system status, functionality, and behavior, and play a key role in computing. These parameters can alter system behavior through system calls, thereby affecting overall performance. These parameters include hardware, performance, file system, compatibility, boot functionality, and security.

[0003] However, traditional USB-based system parameter detection methods often suffer from the following issues: They often rely on snapshots of memory status at fixed points in time and lack the ability to capture dynamic changes in memory status in a granular manner. This approach fails to reflect the operating status of memory in real time, which can easily lead to potential issues being overlooked or delayed in discovery. Many memory monitoring technologies require specialized hardware or external analysis systems, increasing both the barrier to entry and the cost. These technologies are particularly difficult to deploy on a large scale in resource-constrained scenarios, such as embedded systems or mobile devices. Summary of the Invention

[0004] Based on this, it is necessary for the present invention to provide a system parameter detection method and system based on a USB flash drive to solve at least one of the above technical problems.

[0005] To achieve the above object, a method for detecting system parameters based on a USB flash drive includes the following steps:

[0006] Step S1: Obtain system operation log data from the USB flash drive; perform a sliding window scan on the memory physical address space based on the system operation log data, and perform statistical analysis on consecutive free pages in each scanning window to obtain memory address mapping data;

[0007] Step S2: performing a weighted calculation on the memory page access frequency based on the memory address mapping data and the preset time length to obtain a page access fluctuation index, wherein the weighted calculation specifically assigns a weight of 0.6 to access records within the preset time length and a weight of 0.4 to access records outside the preset time length;

[0008] Step S3: Cross-validate the memory status based on the page access fluctuation index and the memory fragmentation distribution position in the memory address mapping data to obtain memory anomaly feature data. When the difference between the end address and the start address of adjacent scan windows is less than a preset page, merge the scan windows into a detection unit. When the difference between the end address and the start address of adjacent scan windows is greater than or equal to a preset page, mark the scan windows independently and record the gap area as an independent potential anomaly point.

[0009] Step S4: Calculate the Pearson correlation coefficient of the memory abnormality feature data at different time scales, and perform difference comparison and abnormality cluster analysis to obtain emergency abnormality warning data;

[0010] Step S5: Generate system detection report data based on the emergency anomaly warning data, memory anomaly feature data, and page access fluctuation index.

[0011] The present invention realizes efficient and accurate memory anomaly detection and analysis, and significantly improves the comprehensiveness and real-time performance of system monitoring. Step S1 obtains system operation log data and combines it with sliding window scanning technology to dynamically monitor the usage of memory physical address space, avoiding the waste of resources of global scanning, and quickly locates continuous idle pages or abnormal areas in the memory, providing comprehensive and accurate memory address mapping data for subsequent analysis. Step S2 performs weighted calculation based on memory address mapping data and page access records to quantify the fluctuation of page access. By assigning different weights to access records in different time ranges, the time characteristics of memory usage can be reflected, so that recent changes have a greater impact on the analysis results, and the dynamic characteristics of page access are accurately captured, thereby distinguishing active pages from memory areas that may be abused or inefficiently used. Step S3 uses a cross-validation method combined with the page access fluctuation index and the memory fragmentation distribution position to further accurately locate potential anomalies. By detecting the address difference between adjacent scanning windows and dynamically adjusting the detection unit, memory fragmentation and abnormal growth areas can be effectively identified, laying the foundation for anomaly point marking and feature extraction. Step S4 uses Pearson correlation coefficient calculations and anomaly clustering analysis at different time scales to uncover hidden anomaly patterns and trends from memory anomaly feature data. Multi-time-scale analysis can capture long-term trends and short-term fluctuations, while anomaly clustering summarizes the correlations between anomalies, improving the reliability and accuracy of early warnings and providing the system with the possibility of early intervention. Finally, step S5 generates a system detection report based on the comprehensive analysis results, presenting the memory operating status, abnormal areas, potential risks, and optimization suggestions in an intuitive form. This report is not only highly practical and can provide system administrators with a basis for rapid problem troubleshooting, but also supports the optimization of memory management strategies and the improvement of system stability. Overall, this method, through distributed detection, dynamic analysis, and multi-dimensional verification, not only improves the accuracy and real-time performance of anomaly detection, but also reduces resource consumption, improves the reliability and efficiency of system monitoring, and provides comprehensive support for memory optimization and system security.

[0012] Preferably, step S1 includes the following steps:

[0013] Step S11: collecting and analyzing the system operation log in real time through the connection between the USB disk and the system, thereby obtaining the system operation log data;

[0014] Step S12: Segment the memory physical address space of the USB flash drive into 4KB pages according to the system operation log data, thereby obtaining memory page partition data;

[0015] Step S13: using the memory page to divide the data into 8 pages, sequentially scanning the sliding window, thereby obtaining scanning window sequence data;

[0016] Step S14: Counting the number of consecutive idle pages and their distribution positions in each scanning window according to the scanning window sequence data, thereby obtaining idle page distribution feature data;

[0017] Step S15: marking the risk area according to the free page distribution characteristic data and the preset continuous free page threshold, thereby obtaining memory address mapping data.

[0018] The present invention achieves efficient parsing and precise tagging of the physical address space of USB flash drive memory, providing a solid data foundation for memory anomaly detection and optimized management. Step S11 ensures the timeliness and accuracy of the data by real-time collection and parsing of system operation log data, while also providing comprehensive basic data for memory status analysis. This real-time performance can dynamically reflect the memory usage during system operation, avoiding misjudgments caused by data lag. Step S12 achieves standardized memory partitioning by segmenting the memory physical address space into 4KB page sizes. The 4KB segmentation granularity is not only compatible with the memory management mechanism of modern operating systems, but also can more finely capture the details of memory usage, providing high-resolution data support for subsequent analysis. Step S13 converts the memory page partition data into scan window sequence data through sliding window scanning technology. The design of a sliding window size of 8 pages can not only balance computational complexity and accuracy, but also effectively capture the continuity and correlation between pages, improving the efficiency of memory analysis. Step S14 uses the scan window sequence data to count the number and distribution location of consecutive free pages in each window and extract the distribution feature data of the free pages. By focusing on continuous free pages, this process can quickly identify potential inefficiently used areas or abnormally growing areas, providing guidance for optimizing memory utilization. Step S15 accurately marks the risk areas and generates memory address mapping data based on the free page distribution feature data and the preset continuous free page threshold. By scientifically setting the threshold, this step can dynamically adapt to different memory usage scenarios, effectively distinguish between normal free areas and potential risk areas, and ensure the accuracy and practicality of the marking. Overall, this method constructs a clear-layered, high-resolution memory analysis framework through real-time acquisition, standardized division, efficient scanning and precise marking, which not only improves the accuracy and efficiency of data processing, but also provides comprehensive support for memory anomaly detection and optimization management, significantly enhancing the system's operational stability and security.

[0019] Preferably, step S2 includes the following steps:

[0020] Step S21: Recording the number of accesses to each memory page within a time window of a preset length according to the memory address mapping data, thereby obtaining page access frequency data;

[0021] Step S22: Analyze and eliminate the fluctuation impact of the page access frequency data based on the current system load level, thereby obtaining normalized access frequency data;

[0022] Step S23: assigning a weight of 0.6 to access records within a preset time period according to the access frequency data for a first calculation, thereby obtaining recent access feature data;

[0023] Step S24: assigning a weight of 0.4 to access records outside the preset time length according to the access frequency data and performing a second calculation to obtain historical access feature data;

[0024] Step S25: performing access fluctuation analysis based on recent access feature data and historical access feature data through weighted superposition operation to obtain a page access fluctuation index.

[0025] Through systematic analysis and processing of memory page access frequencies, the present invention provides an effective method for dynamically assessing memory status and identifying abnormal fluctuations, significantly enhancing the intelligent level of memory management. Step S21 generates page access frequency data by recording the number of accesses to each memory page in the memory address mapping data, laying the foundation for dynamic monitoring of memory status. This precise access frequency record comprehensively reflects memory page usage and provides high-quality raw data for further analysis. Step S22 ensures data normalization by analyzing and eliminating the impact of fluctuations in access frequency data based on the current system load level. This elimination effectively removes the interference of load fluctuations on the analysis results, ensuring that the generated access frequency data is more accurate and reliable. Step S23 uses the normalized access frequency data to assign a higher weight to access records within a preset time period, and through a first calculation, obtains recent access feature data. This process effectively captures recent memory page access dynamics and helps identify abnormal changes in short-term memory usage. Step S24 performs a second calculation by assigning a lower weight to access records outside the preset time period, generating historical access feature data. This weighted processing method takes into account the importance of historical data, provides a basis for identifying long-term usage trends, and avoids the dilution of recent dynamic data. Step S25 performs weighted superposition operations on recent access feature data and historical access feature data to comprehensively analyze the degree of access fluctuation and generate a page access fluctuation index. This comprehensive analysis not only reveals the dynamic changes in memory page access, but also reflects the overall stability of memory usage through a scientific weighted algorithm. Overall, this method achieves an accurate assessment of memory page access patterns through dynamic monitoring, normalization processing, weighted analysis and comprehensive superposition calculations, and can effectively identify abnormal fluctuations and potential problems in memory usage, providing key data support for system optimization and risk warning. This multi-dimensional analysis method significantly improves the efficiency and reliability of memory management, and provides important guarantees for the stability and security of system operation.

[0026] The present invention also provides a system parameter detection system based on a U disk, which is used to execute the above-mentioned system parameter detection method based on a U disk. The system parameter detection system based on a U disk includes:

[0027] The log parsing module is used to obtain the system operation log data of the USB flash drive; based on the system operation log data, a sliding window scan is performed on the memory physical address space, and a statistical analysis is performed on the continuous free pages in each scanning window to obtain the memory address mapping data;

[0028] An access frequency analysis module is used to perform weighted calculation on the memory page access frequency based on the memory address mapping data and a preset time length, thereby obtaining a page access fluctuation index. Specifically, the weighted calculation assigns a weight of 0.6 to access records within the preset time length and a weight of 0.4 to access records outside the preset time length.

[0029] The memory status verification module is used to cross-validate the memory status based on the page access fluctuation index and the memory fragmentation distribution position in the memory address mapping data to obtain memory anomaly feature data. When the difference between the end address and the start address of adjacent scan windows is less than a preset page, the scan windows are merged into a detection unit. When the difference between the end address and the start address of adjacent scan windows is greater than or equal to a preset page, the scan windows are independently marked and the gap area is recorded as an independent potential anomaly point.

[0030] The anomaly analysis module is used to calculate the Pearson correlation coefficient of memory anomaly feature data at different time scales, perform difference comparison and anomaly cluster analysis, and thus obtain emergency anomaly warning data;

[0031] The system detection module is used to generate system detection report data based on emergency anomaly warning data, memory anomaly feature data and page access fluctuation index.

[0032] Through multi-dimensional data analysis and processing, the present invention comprehensively enhances the system's memory management capabilities, promptly detects and addresses potential anomalies, and improves system stability and performance. First, the log parsing module acquires system operation log data from a USB flash drive and performs a sliding window scan of the memory physical address space. This module monitors memory usage in real time and statistically analyzes consecutive free pages within each scan window. This method, by acquiring memory address mapping data, provides critical foundational data for subsequent analysis, helping to identify memory free space distribution and potential fragmentation issues. The access frequency analysis module performs a weighted calculation of memory page access frequencies, assigning different weights based on preset time periods, to generate a page access fluctuation index. This process accurately measures memory access frequency fluctuations within different time periods, providing insight into memory access patterns and fluctuations, and helping the system identify load spikes or potential performance bottlenecks. The memory status verification module cross-validates the memory status based on the page access fluctuation index and memory fragmentation distribution data. By marking gap areas within the scan window and merging detection units, it accurately detects anomalies in memory fragmentation distribution and potential risk points, thereby identifying and preventing sharp drops in system performance or memory overflows at an early stage. The anomaly analysis module calculates the Pearson correlation coefficient, analyzes and compares differences across different time scales, and accurately determines the type and severity of memory anomalies. It then performs anomaly cluster analysis and generates emergency anomaly warning data. This module's purpose is to detect anomalies early through multi-angle analysis and trigger alerts promptly, preventing problems from escalating. Finally, the system detection module generates a comprehensive system detection report based on emergency anomaly warning data, memory anomaly signature data, and page access fluctuation index. This report provides system administrators with a comprehensive understanding of the system's health, identifies possible root causes of failures, and implements targeted optimization measures. This series of steps, working in concert, effectively enhances the system's monitoring, diagnostic, and optimization capabilities, maintaining system stability under complex workloads and ensuring optimal resource utilization, ultimately ensuring efficient and stable system operation. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Other features, objects and advantages of the present invention will become more apparent upon reading the detailed description of non-limiting embodiments thereof made with reference to the following drawings:

[0034] Figure 1 This is a schematic diagram of the steps of the USB-based system parameter detection method of the present invention;

[0035] Figure 2 for Figure 1 Detailed step flow diagram of step S1;

[0036] Figure 3 for Figure 1Detailed step flow chart of step S2 in FIG. DETAILED DESCRIPTION

[0037] The following is a clear and complete description of the technical method of the present invention in conjunction with the accompanying drawings. It is obvious that the embodiments described are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making any creative efforts are within the scope of protection of the present invention.

[0038] In addition, the accompanying drawings are merely schematic illustrations of the present invention and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor and / or microcontroller approaches.

[0039] It should be understood that although the terms "first," "second," and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are used solely to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element, without departing from the scope of the exemplary embodiments. The term "and / or" as used herein includes any and all combinations of one or more of the listed associated items.

[0040] To achieve this, please refer to Figures 1 to 3 The present invention provides a method for detecting system parameters based on a USB flash drive, the method comprising the following steps:

[0041] Step S1: Obtain system operation log data from the USB flash drive; perform a sliding window scan on the memory physical address space based on the system operation log data, and perform statistical analysis on consecutive free pages in each scanning window to obtain memory address mapping data;

[0042] An embodiment of the present invention can obtain system operation log data of a USB flash drive by connecting the USB flash drive to a target computer system through a USB interface, and using a log analysis tool to extract an operation log file containing memory operation records; then, when performing a sliding window scan on the memory physical address space, first, the size of the scanning window is set according to the physical address range of the system memory (such as 4MB), and the window slides in sequence with a step size of 1MB. The memory block is accessed page by page through the memory monitoring program, and the number of consecutive free pages is counted in each scanning window. For example, it is recorded whether the page flag is set to the "free" state, and a memory address mapping table containing the start address, end address and free page statistics is generated.

[0043] Step S2: performing a weighted calculation on the memory page access frequency based on the memory address mapping data and the preset time length to obtain a page access fluctuation index, wherein the weighted calculation specifically assigns a weight of 0.6 to access records within the preset time length and a weight of 0.4 to access records outside the preset time length;

[0044] The embodiment of the present invention extracts the memory page access records within a preset time length (e.g., the past 24 hours) based on the memory address mapping data obtained in step S1, and calculates them using a weighted formula: the access records within the time length are assigned a weight of 0.6, specifically by multiplying the page access frequency within the time period by 0.6; the access records exceeding the time length are assigned a weight of 0.4, and these access frequencies are multiplied by 0.4; the weighted access frequencies are then accumulated to obtain the page access fluctuation index. For example, if a page is accessed 20 times within 24 hours, the weight is 0.6; if the access is recorded 10 times beyond 24 hours, the weight is 0.4, then the fluctuation index of the page is 20×0.6+10×0.4=16.

[0045] Step S3: Cross-validate the memory status based on the page access fluctuation index and the memory fragmentation distribution position in the memory address mapping data to obtain memory anomaly feature data. When the difference between the end address and the start address of adjacent scan windows is less than a preset page, merge the scan windows into a detection unit. When the difference between the end address and the start address of adjacent scan windows is greater than or equal to a preset page, mark the scan windows independently and record the gap area as an independent potential anomaly point.

[0046] This embodiment of the present invention performs a cross-validation operation on the memory state based on the page access fluctuation index generated in step S2 and the memory address mapping data in step S1. The memory address space is divided into multiple scanning windows based on page units of a certain size, assuming that each scanning window is 4MB in size. Within each window, consecutive free pages are counted, and the end and start addresses of each window are marked. The difference between the end and start addresses of adjacent scanning windows is then calculated. For example, for two adjacent scanning windows, the end address is 0x7FFF0000 and the start address is 0x80000000, with a difference of 1MB. If the difference between adjacent windows is less than a preset page threshold (e.g., 64KB), the windows are merged into a single detection unit. For example, if the difference between the end and start addresses of three consecutive scanning windows is less than 64KB, they are merged into a single detection unit. Windows with a difference greater than or equal to the threshold are individually marked, and the difference gap area is recorded as a potential outlier. Statistical analysis is performed on the recorded potential outliers and the abnormal features in the merged detection unit. For example, in a test scenario, the memory address mapping data of a certain system showed that there were multiple gaps of less than 64KB between the address range 0x60000000 and 0x61000000. These areas were marked as potential anomalies, and the access frequency and free page distribution of each page within the range were recorded. Ultimately, through the above operations, memory anomaly feature data was obtained, including the distribution of memory fragmentation, detailed records of potential anomalies, and a description of the overall status of each detection unit, providing a data foundation for subsequent steps.

[0047] Step S4: Calculate the Pearson correlation coefficient of the memory abnormality feature data at different time scales, and perform difference comparison and abnormality cluster analysis to obtain emergency abnormality warning data;

[0048] The embodiment of the present invention uses the memory anomaly feature data obtained in step S3 to analyze the memory status of different time scales. First, the memory status data in different time periods (such as 1 hour, 6 hours, and 24 hours) are selected, and the Pearson correlation coefficient is calculated for these data to evaluate the similarity of the memory status in different time periods; the specific operation is to use the page access fluctuation index in each time period as a variable, and calculate the correlation between it and the memory anomaly feature in the corresponding time period. Subsequently, by calculating the difference in the correlation between the time periods, significant abnormal change points are identified. For example, in the past 24 hours, the Pearson correlation coefficient of a certain time period is 0.8, while the adjacent time period drops to 0.5. This significant change point will be marked as an anomaly. Further cluster analysis is performed on the marked abnormal time period and feature data, and the K-means algorithm is used to group similar abnormal data to form emergency abnormality warning data.

[0049] Step S5: Generate system detection report data based on the emergency anomaly warning data, memory anomaly feature data, and page access fluctuation index.

[0050] The embodiment of the present invention combines the emergency anomaly warning data generated in step S4, the memory anomaly feature data in step S3, and the page access fluctuation index in step S2 to construct a system detection report. The specific operations are: extracting statistical information on memory fragmentation distribution and potential anomaly points based on the memory anomaly feature data; generating a time series graph of the memory status based on the emergency anomaly warning data to intuitively display the time when the anomaly occurred and the scope of impact; generating an access heat map based on the page access fluctuation index to highlight high-frequency access pages and access patterns. Finally, the system detection report is presented in a visual manner, including an overall description of the memory status, anomaly distribution statistical charts, time series analysis results, and recommended processing measures. For example, in a certain test scenario, the system detection report shows that the memory usage rate is as high as 90%, and there have been 3 access fluctuation anomalies in the past 6 hours. It is recommended to immediately optimize the memory management strategy or expand the physical memory capacity.

[0051] Preferably, step S1 includes the following steps:

[0052] Step S11: collecting and analyzing the system operation log in real time through the connection between the USB disk and the system, thereby obtaining the system operation log data;

[0053] After the embodiment of the present invention is connected to the system via a USB flash drive, a log collection tool (such as Log Parser) is used to obtain the system operation log in real time. In the specific implementation process, first, the USB interface is used to detect whether the USB flash drive is successfully connected. After the connection is established, the system's log collection service module is called to collect the latest operation log data at a frequency of once per second, and store it in a designated memory buffer in JSON format. Subsequently, the collected log is parsed using a log parsing engine, and is decomposed into structured information such as timestamp, event type, memory operation address, and data size. For example, in actual operation, the collected operation log contains the information "0x7FFF0000 has a write operation, the size is 256 bytes", which is recorded as a record in a structured data table after parsing, which is convenient for subsequent analysis.

[0054] Step S12: Segment the memory physical address space of the USB flash drive into 4KB pages according to the system operation log data, thereby obtaining memory page partition data;

[0055] The embodiment of the present invention performs segmentation processing on the memory physical address space of the USB flash drive in 4KB page size according to the system operation log data collected and parsed in step S11. During the implementation process, the memory operation address range in the log is first extracted. For example, the operation address is from 0x60000000 to 0x61000000, and the range is divided into 256 pages in units of 4KB. Subsequently, the label of each page is numbered from P1 to P256 to generate memory page partition data. For example, the address 0x60001000 to 0x60001FFF is divided into page P2, and the operation type and frequency statistics are attached to form a complete page partition data table for use in subsequent steps.

[0056] Step S13: using the memory page to divide the data into 8 pages, sequentially scanning the sliding window, thereby obtaining scanning window sequence data;

[0057] The embodiment of the present invention utilizes the memory page partitioning data generated in step S12 and adopts a sliding window based on an 8-page size for sequential scanning processing. During implementation, the sliding window size is set to 8 pages (32KB), and the sliding step size is 1 page (4KB) each time. For example, the initial scanning window includes pages P1 to P8. After counting their operation frequencies, the window slides to P2 to P9, and the statistics are repeated until all pages are covered. In the actual test scenario, if the total number of pages is 256, 249 scanning windows (256-8+1) can be generated. The data of each window includes the window number, the starting page, the ending page and the operation statistics information, and finally forms a scanning window sequence data table.

[0058] Step S14: Counting the number of consecutive idle pages and their distribution positions in each scanning window according to the scanning window sequence data, thereby obtaining idle page distribution feature data;

[0059] The embodiment of the present invention performs statistical analysis on the number of consecutive idle pages and their distribution positions in each window based on the scan window sequence data generated in step S13. In specific implementation, the operation frequency mark of each page is detected to determine whether it is an idle page (the operation frequency is 0). For example, for windows P1 to P8, if the operation frequency of pages P2 to P5 is 0, it is recorded as 4 consecutive idle pages, located from P2 to P5. This statistical process is performed on all scan windows, and the results are recorded as idle page distribution feature data, including the number of idle pages in each window and their specific locations.

[0060] Step S15: marking the risk area according to the free page distribution characteristic data and the preset continuous free page threshold, thereby obtaining memory address mapping data.

[0061] The embodiment of the present invention marks high-risk areas based on the idle page distribution characteristic data generated in step S14 and in combination with a preset continuous idle page threshold (for example, 3 pages). During implementation, for each scanning window, it is determined whether the number of continuous idle pages exceeds the threshold. If the number of continuous idle pages in a window is 4, which exceeds the threshold 3, the window is marked as a high-risk area, and its specific memory address range is recorded. For example, the address range of windows P2 to P5 is 0x60001000 to 0x60004FFF, which is marked as a high-risk area and stored in the memory address mapping data table for subsequent analysis and processing.

[0062] The present invention achieves efficient parsing and precise tagging of the physical address space of USB flash drive memory, providing a solid data foundation for memory anomaly detection and optimized management. Step S11 ensures the timeliness and accuracy of the data by real-time collection and parsing of system operation log data, while also providing comprehensive basic data for memory status analysis. This real-time performance can dynamically reflect the memory usage during system operation, avoiding misjudgments caused by data lag. Step S12 achieves standardized memory partitioning by segmenting the memory physical address space into 4KB page sizes. The 4KB segmentation granularity is not only compatible with the memory management mechanism of modern operating systems, but also can more finely capture the details of memory usage, providing high-resolution data support for subsequent analysis. Step S13 converts the memory page partition data into scan window sequence data through sliding window scanning technology. The design of a sliding window size of 8 pages can not only balance computational complexity and accuracy, but also effectively capture the continuity and correlation between pages, improving the efficiency of memory analysis. Step S14 uses the scan window sequence data to count the number and distribution location of consecutive free pages in each window and extract the distribution feature data of the free pages. By focusing on continuous free pages, this process can quickly identify potential inefficiently used areas or abnormally growing areas, providing guidance for optimizing memory utilization. Step S15 accurately marks the risk areas and generates memory address mapping data based on the free page distribution feature data and the preset continuous free page threshold. By scientifically setting the threshold, this step can dynamically adapt to different memory usage scenarios, effectively distinguish between normal free areas and potential risk areas, and ensure the accuracy and practicality of the marking. Overall, this method constructs a clear-layered, high-resolution memory analysis framework through real-time acquisition, standardized division, efficient scanning and precise marking, which not only improves the accuracy and efficiency of data processing, but also provides comprehensive support for memory anomaly detection and optimization management, significantly enhancing the system's operational stability and security.

[0063] Preferably, step S2 includes the following steps:

[0064] Step S21: Recording the number of accesses to each memory page within a time window of a preset length according to the memory address mapping data, thereby obtaining page access frequency data;

[0065] The embodiment of the present invention sets a 10-minute time window based on the memory address mapping data obtained in step S15, and records the number of accesses to the memory page. For example, the memory access monitoring module counts the read and write operations of each memory page. When page P1 is accessed 5 times within 10 minutes, the number of accesses is recorded as 5. For the entire memory address space, the access frequency is counted page by page according to the time window to form a page access frequency data table, which includes the page number, the start and end time of the time window, and the number of accesses. For example, page P3 is accessed 3 times within a 10-minute window and is recorded as part of the access frequency data.

[0066] Step S22: Analyze and eliminate the fluctuation impact of the page access frequency data based on the current system load level, thereby obtaining normalized access frequency data;

[0067] The embodiment of the present invention performs a fluctuation impact analysis and normalization process on the page access frequency data generated in step S21 based on the current load level of the system. In actual operation, the system load monitoring module is used to obtain indicators such as CPU occupancy rate and memory usage rate in real time, assuming that the current CPU load is 60%. In this case, the number of page accesses is scaled proportionally. For example, for a page with an access frequency of 5, the normalized frequency calculation formula is: normalized frequency = number of accesses ÷ (1 + CPU load). According to this formula, the normalized frequency is 5 ÷ (1 + 0.6) ≈ 3.125. After normalization, the access frequency data is obtained and stored in the form of a page number and a normalized frequency pair.

[0068] Step S23: assigning a weight of 0.6 to access records within a preset time period according to the access frequency data for a first calculation, thereby obtaining recent access feature data;

[0069] This embodiment of the present invention uses the access frequency data generated in step S22 to perform a weighted calculation, assigning a weight of 0.6 to access records within a preset time period. In practice, the preset time period is 10 minutes, and the access frequencies within this time period are extracted and weighted page by page. For example, the normalized frequency of page P2 within 10 minutes is 3.125, which, after weighted calculation, is 3.125 × 0.6 = 1.875. After performing the weighting operation on all pages, a recent access feature data table is generated, recording the weighted access features of each page within that time period.

[0070] Step S24: assigning a weight of 0.4 to access records outside the preset time length according to the access frequency data and performing a second calculation to obtain historical access feature data;

[0071] In the embodiment of the present invention, for the access frequency data in step S22, a weight of 0.4 is assigned to access records outside the time length for weighted calculation. In the specific operation, the access frequency data within a time range of more than 10 minutes is selected, and the weight is calculated page by page. For example, the normalized frequency of page P5 within a time window of more than 10 minutes is 2.5, and after weighted calculation, it is 2.5×0.4=1.0. After performing this weighted operation on all pages, a historical access feature data table is generated, including the weighted access features of each page in the non-recent time period.

[0072] Step S25: performing access fluctuation analysis based on recent access feature data and historical access feature data through weighted superposition operation to obtain a page access fluctuation index.

[0073] The embodiment of the present invention analyzes the page access fluctuation degree through weighted superposition operation based on the recent access feature data of step S23 and the historical access feature data of step S24. In a specific implementation, for each page, the recent feature data and the historical feature data are superimposed according to a weight ratio of 1:1. For example, for page P7, the recent access feature value is 2.0, and the historical access feature value is 1.5. Its page access fluctuation index is calculated as: (2.0×0.5)+(1.5×0.5)=1.75. A page access fluctuation index data table is formed by page-by-page calculation for subsequent memory status analysis and anomaly detection.

[0074] Through systematic analysis and processing of memory page access frequencies, the present invention provides an effective method for dynamically assessing memory status and identifying abnormal fluctuations, significantly enhancing the intelligent level of memory management. Step S21 generates page access frequency data by recording the number of accesses to each memory page in the memory address mapping data, laying the foundation for dynamic monitoring of memory status. This precise access frequency record comprehensively reflects memory page usage and provides high-quality raw data for further analysis. Step S22 ensures data normalization by analyzing and eliminating the impact of fluctuations in access frequency data based on the current system load level. This elimination effectively removes the interference of load fluctuations on the analysis results, ensuring that the generated access frequency data is more accurate and reliable. Step S23 uses the normalized access frequency data to assign a higher weight to access records within a preset time period, and through a first calculation, obtains recent access feature data. This process effectively captures recent memory page access dynamics and helps identify abnormal changes in short-term memory usage. Step S24 performs a second calculation by assigning a lower weight to access records outside the preset time period, generating historical access feature data. This weighted processing method takes into account the importance of historical data, provides a basis for identifying long-term usage trends, and avoids the dilution of recent dynamic data. Step S25 performs weighted superposition operations on recent access feature data and historical access feature data to comprehensively analyze the degree of access fluctuation and generate a page access fluctuation index. This comprehensive analysis not only reveals the dynamic changes in memory page access, but also reflects the overall stability of memory usage through a scientific weighted algorithm. Overall, this method achieves an accurate assessment of memory page access patterns through dynamic monitoring, normalization processing, weighted analysis and comprehensive superposition calculations, and can effectively identify abnormal fluctuations and potential problems in memory usage, providing key data support for system optimization and risk warning. This multi-dimensional analysis method significantly improves the efficiency and reliability of memory management, and provides important guarantees for the stability and security of system operation.

[0075] Preferably, step S25 includes the following steps:

[0076] Step S251: constructing a dual-time-scale feature matrix based on recent access feature data and historical access feature data, thereby obtaining time series feature mapping data;

[0077] The embodiment of the present invention uses the recent access feature data and historical access feature data generated in steps S23 and S24 to construct a dual-time-scale feature matrix. In specific operations, the rows of the feature matrix are set to represent the memory page numbers, and the columns are set to represent the recent and historical feature values, respectively. For example, if the recent feature value of page P1 is 2.5 and the historical feature value is 1.8, the matrix record is: [P1, 2.5, 1.8]. After processing all pages, a complete feature matrix is ​​generated, and an index is established based on the memory page number for subsequent analysis, forming time series feature mapping data.

[0078] Step S252: performing a quantitative analysis of the discrete degree of the characteristic value based on standard deviation calculation through the time series characteristic mapping data, thereby obtaining characteristic fluctuation intensity data;

[0079] In this embodiment of the present invention, the time series feature mapping data generated in step S251 is used to calculate the dispersion of the feature values ​​using the standard deviation to quantify the intensity of fluctuations. Specifically, for each page, the standard deviation of its recent and historical feature values ​​is calculated. For example, the recent feature value of page P3 is 3.2, and the historical feature value is 2.4. The formula for calculating its intensity of fluctuations is: standard deviation = sqrt(((3.2-2.8) 2 +(2.4-2.8) 2 )÷2)≈0.4, where 2.8 is the average of the two. After processing all pages, a feature fluctuation intensity data table is generated, containing the fluctuation intensity value of each page.

[0080] Step S253: performing fluctuation trend determination on the characteristic fluctuation intensity data, thereby obtaining fluctuation trend marking data;

[0081] The embodiment of the present invention performs trend determination on the characteristic fluctuation intensity data generated in step S252 to determine whether the fluctuation shows an upward, downward or stable trend. During the operation, the sliding window method is used to calculate the rate of change of the fluctuation intensity. For example, the fluctuation intensity of page P5 in the last three time windows is 0.3, 0.5, and 0.8, respectively. The rate of change is (0.8-0.3)÷0.3≈166.67%, which is marked as "increasing". Similarly, when the rate of change is close to 0%, it is marked as "stable", and when the rate of change is negative, it is marked as "declining". Generate fluctuation trend marking data, including page number and trend label.

[0082] Step S254: comparing and analyzing the fluctuation trend mark data according to the system preset benchmark value to obtain fluctuation level assessment data;

[0083] The embodiment of the present invention compares and analyzes the fluctuation trend marking data generated in step S253 with the benchmark value preset by the system to evaluate the fluctuation level. For example, the preset benchmark value is: fluctuation intensity <0.5 is "low", 0.5-1 is "medium", and >1 is "high". Assuming that the fluctuation intensity of page P7 is 0.7, it is evaluated as "medium" level after comparison. At the same time, combined with the trend mark, if it is marked as "rising" and the fluctuation intensity is at the "high" level, it is further marked as "urgent". After processing all pages, fluctuation level evaluation data is generated, including page number, fluctuation intensity level and trend analysis results.

[0084] Step S255: quantifying the degree of fluctuation through normalization processing according to the fluctuation level evaluation data, thereby obtaining a page access fluctuation index.

[0085] The embodiment of the present invention performs normalized quantification processing on the degree of fluctuation based on the fluctuation level assessment data generated in step S254 to generate a page access fluctuation index. In the specific operation, numerical weights are assigned according to the levels, for example, "low" is 1, "medium" is 2, and "high" is 3; the trend mark "stable" is assigned a value of 1, "rising" is assigned a value of 2, and "falling" is assigned a value of 0.5. Combined with the weight calculation, for example, the fluctuation level of page P9 is "high" (weight 3), and the trend is "rising" (weight 2), the page access fluctuation index calculation formula is: Fluctuation index = level weight × trend weight = 3 × 2 = 6. Finally, a fluctuation index data table containing all pages is generated for system memory status evaluation and abnormality monitoring.

[0086] Through multi-dimensional analysis and calculation, the present invention provides detailed quantitative metrics for accurately assessing memory page access fluctuations, helping to improve system stability and optimize memory management strategies. Step S251 constructs a dual-time-scale feature matrix, combining recent access feature data with historical access feature data to generate time series feature mapping data. This integrated approach comprehensively captures the timing characteristics of memory accesses, providing sufficient data support for subsequent fluctuation analysis, and is particularly effective in reflecting short-term and long-term dynamic changes in memory usage. Step S252 performs quantitative analysis of the time series feature mapping data based on standard deviation calculations to generate feature fluctuation intensity data. The application of standard deviation effectively quantifies the degree of discreteness of memory page accesses, accurately revealing unstable access behavior in the system and providing a precise metric for identifying potential issues. Step S253 determines the fluctuation trend of the feature fluctuation intensity data to generate fluctuation trend marker data. This process dynamically monitors the trend of memory page access fluctuations, enabling timely detection of abnormal changes in access patterns and providing early warning of potential memory bottlenecks or other system issues. Step S254 compares and analyzes the fluctuation trend marker data against a system-preset baseline value to generate fluctuation level assessment data. This comparative analysis provides a standardized assessment of the severity of the fluctuation trend, which can help developers quickly judge the operating status of the system and effectively formulate response strategies. Step S255 quantifies the fluctuation level assessment data through normalization processing, and finally obtains the page access fluctuation index. This fluctuation index converts the degree of fluctuation of the system access pattern into an operational digital indicator, which is convenient for users to quantitatively evaluate the stability of the system, help optimize memory management solutions and prevent system overload or crash risks. Overall, this series of steps not only enhances the understanding of memory page access fluctuations through multi-level data analysis and processing, but also enables system administrators to identify potential problems in a timely manner and take appropriate optimization measures by quantifying the intensity and trend of fluctuations, thereby effectively improving the overall operational stability and efficiency of the system.

[0087] Preferably, step S3 includes the following steps:

[0088] Step S31: extracting and analyzing the spatial distribution characteristics of memory fragments based on the page access fluctuation index and the memory address mapping data, thereby obtaining fragment distribution characteristic data;

[0089] Step S32: Calculating the address difference between adjacent scanning windows using the fragment distribution feature data, and comparing it with the preset page size to obtain window interval evaluation data;

[0090] Step S33: When the time difference in the window interval evaluation data is less than a preset page, the scanning window is merged to obtain detection unit division data;

[0091] Step S34: When the time difference in the window interval evaluation data is greater than or equal to the preset page, the scanning window is independently marked and the gap area is recorded to obtain potential abnormal point data;

[0092] Step S35: performing cross-validation analysis on the memory state according to the detection unit division data and the potential abnormal point data, thereby obtaining memory abnormality feature data.

[0093] The embodiment of the present invention utilizes the page access fluctuation index and memory address mapping data to extract the spatial distribution characteristics of fragmentation by analyzing the relationship between the access frequency of memory pages and the distribution of free pages. In a specific operation, the locations of continuous free pages are first marked according to the memory address mapping data, for example, the continuous free page range [0x000A-0x0010]. Then, the high fluctuation area is screened in combination with the page access fluctuation index, and the range overlapping with the free pages is extracted as the fragmentation area, and a fragmentation distribution characteristic data table containing information such as address range and fluctuation intensity is generated. Based on the fragmentation distribution characteristic data generated in step S31, the difference between the end address and the start address of adjacent scanning windows is calculated. For example, the end address of scanning window W1 is 0x0020, and the start address of W2 is 0x0030. The difference is calculated as 0x0030-0x0020=0x0010 (expressed in hexadecimal). The calculated result is compared with a preset page size (e.g., 4KB). If the difference is less than 4KB, it is marked as "tight", otherwise it is marked as "loose". Finally, a window interval evaluation data table is generated, which contains the address difference and evaluation results of each pair of adjacent windows. Based on the window interval evaluation data generated in step S32, a merge operation is performed on the adjacent windows marked as "tight". In the specific operation, when the address difference is less than 4KB, the window range is merged into one detection unit. For example, the window W1 range is [0x0010-0x0020], and the window W2 range is [0x0020-0x0030]. After merging, the detection unit range is [0x0010-0x0030]. All windows that meet the conditions are merged, and finally a detection unit division data table is generated, which records the address range and associated page information of each detection unit. For the window pairs marked as "loose" in step S32, independent marking processing is performed and the gap area is recorded. For example, when the end address of window W3 is 0x0040 and the start address of window W4 is 0x0060, the address difference is 0x0060-0x0040=0x0020 (greater than 4KB). Windows W3 and W4 are independently marked, and the gap area [0x0040-0x0060] is recorded as a potential outlier. A potential outlier data table is ultimately generated, containing the gap area address range and window marking information for further anomaly analysis. Combined with the detection unit partitioning data from step S33 and the potential outlier data from step S34, a cross-validation analysis of the memory state is performed. Specifically, for each detection unit, a check is performed to determine whether its range contains a potential outlier. If there is overlap, it is marked as an "abnormal area." For example, if the detection unit range [0x0010-0x0030] overlaps with the potential outlier [0x0025-0x0027], the detection unit is marked as abnormal; if there is no overlap, it is marked as "normal." Finally, a memory anomaly feature data table is generated, which includes the address range, type and related feature information of the abnormal area, providing support for memory management optimization.

[0094] The present invention can effectively identify and manage memory fragmentation through detailed spatial and temporal analysis, thereby improving the efficiency and accuracy of system memory management. Step S31 extracts and analyzes the spatial distribution characteristics of memory fragmentation through the page access fluctuation index and memory address mapping data to obtain fragmentation distribution feature data. Through this process, the distribution pattern of memory fragmentation in the system memory space can be clarified, thereby providing basic data support for subsequent memory optimization and anomaly monitoring. Step S32 uses the fragmentation distribution feature data to calculate the address difference between adjacent scanning windows, and compares it with the preset page size to obtain window interval evaluation data. This operation can reveal the access association between different memory areas, help determine whether memory fragmentation affects system performance, and provide a basis for subsequent memory optimization. Step S33 performs a scanning window merging operation when the time difference in the window interval evaluation data is less than the preset page, thereby obtaining detection unit division data. By merging adjacent scanning windows, not only can the computational complexity be reduced, but also the focus can be effectively placed on memory areas with greater potential risks, thereby improving the accuracy and efficiency of memory monitoring. In step S34, when the time difference in the window interval evaluation data is greater than or equal to the preset page, independent marking is performed and the gap area is recorded to obtain potential anomaly point data. This judgment strategy can timely identify abnormal fluctuations and irregular distributions in memory access, mark potential memory failures or performance bottlenecks in advance, and provide accurate data for exception handling and risk prediction. In step S35, cross-validation analysis is performed based on the detection unit partition data and potential anomaly point data to obtain memory anomaly feature data. Through cross-validation, the accuracy and reliability of memory anomaly detection are further improved, ensuring that multi-dimensional information can be integrated to reveal potential abnormal patterns in system memory. Taken together, these steps not only help to accurately identify memory fragmentation and its impact on system performance, but also maximize the stability of the system and the utilization efficiency of memory resources through cross-validation and anomaly detection early warning mechanisms, thereby optimizing the overall performance of the system.

[0095] Preferably, step S35 includes the following steps:

[0096] Step S351: establishing a time series feature set of the memory state based on the detection unit partition data and the potential outlier data, thereby obtaining memory state time series data, wherein the memory state includes address distribution, access frequency, and fragmentation level;

[0097] Step S352: Calculating the short-term state change trend based on the sliding average method according to the memory state time series data, thereby obtaining short-term trend feature data;

[0098] Step S353: Analyze the long-term state change rules of the memory state time series data using the exponential smoothing method to obtain long-term trend feature data;

[0099] Step S354: performing trend change correlation calculation and comparison on the short-term trend feature data and the long-term trend feature data to obtain trend deviation data, wherein the correlation calculation and comparison specifically includes the address distribution change rate, access frequency fluctuation value, and fragmentation aggregation degree;

[0100] Step S355: Perform comprehensive evaluation of abnormal characteristics on the trend deviation data according to a preset abnormality determination threshold, thereby obtaining memory abnormality feature data.

[0101] The embodiment of the present invention divides the data and potential anomaly data by the detection unit, extracts the key features of the memory state, and establishes a time series feature set. First, based on the address distribution information of the detection unit, the page address range of each time point is recorded. For example, the address range of the detection unit A at time T1 is [0x0010-0x0030]; secondly, the access frequency is recorded and the number of accesses to each detection unit per unit time is calculated. For example, the access frequency of the detection unit A is 50 times / second; finally, the size and distribution density of the fragmentation area are statistically analyzed based on the potential anomaly data. For example, the degree of fragmentation is 20%. This information is integrated into a data set containing a time dimension to form memory state time series data, which is convenient for subsequent trend analysis. The sliding average method is used to calculate the short-term change trend of the memory state time series data. The specific operation is that at each time point Tn, the data of the first N time points are selected for mean calculation. For example, for the access frequency feature, the short-term trend value of point Tn is the average of the past three time points (Tn-1, Tn-2, Tn-3): short-term trend = (frequency Tn―1 +Frequency Tn―2 +Frequency Tn―3 / 3. Similarly, the address distribution change rate and fragmentation level are calculated to generate a feature data table containing multiple short-term trend indicators, which is convenient for capturing short-term fluctuation information. The exponential smoothing method is used to analyze the long-term state change pattern of memory state time series data. The specific method is to give a higher weight to the recent data and recursively calculate the long-term trend value. For example, for the access frequency, the calculation formula of the long-term trend value is: Long-term trend Tn =α·frequency Tn +(1―α) Long-term trend Tn―1 The smoothing coefficient α is usually set to 0.3. The same method is used to process the address distribution change rate and the degree of fragmentation to generate a data table containing long-term trend indicators, revealing the long-term evolution of the memory state. The short-term trend feature data is correlated with the long-term trend feature data to evaluate the trend deviation between the two. The specific operation is to calculate the difference between the address distribution change rate, the access frequency fluctuation value and the fragmentation aggregation degree respectively. For example, for the address distribution change rate, the calculation formula is: Deviation = | Short-term trend Tn - Long-term trend Tn|The deviation is then standardized to a value between 0 and 1 to facilitate comprehensive evaluation. Trend deviation data is generated by calculating the weighted average of the three features to evaluate abnormal trend changes in the memory state. The trend deviation data is comprehensively evaluated and processed according to the preset abnormal judgment threshold. Set the abnormal threshold, for example, when the deviation exceeds 0.7, it is marked as "abnormal". The specific method is to traverse all time points, compare the deviation of each time point with the threshold, and record the features that exceed the threshold. For example, at time Tn, the access frequency deviation is 0.75, which exceeds the threshold and is marked as "frequency abnormality". Finally, all abnormal features are integrated to generate memory abnormality feature data, including abnormality type, time point and related indicators, to provide a basis for memory optimization and problem location.

[0102] By analyzing the time series characteristics of memory states, the present invention can deeply explore and predict memory operating conditions, improving the system's early warning capabilities and anomaly identification accuracy. Step S351 generates memory state time series data by establishing a memory state time series feature set and combining key indicators such as address distribution, access frequency, and fragmentation. This process comprehensively covers multiple key memory characteristics, ensuring data integrity and accuracy, and laying a solid foundation for subsequent trend analysis and anomaly detection. Step S352 uses the sliding average method to calculate the short-term state change trend of the memory state time series data to obtain short-term trend feature data. This method, by smoothing short-term fluctuations, can clearly reveal the system's immediate changing trends, providing an important reference for quickly identifying the system's current operating status. Step S353 uses the exponential smoothing method to analyze the long-term changes in the memory state to obtain long-term trend feature data. The exponential smoothing method can effectively reduce external noise interference, making long-term trend changes more stable and reliable, helping to determine whether the system is experiencing long-term performance degradation or potential failures. Step S354 calculates and compares the trend change correlation between the short-term trend feature data and the long-term trend feature data to obtain trend deviation data. This process can reveal abnormal deviations between short-term and long-term trends, and provide a multi-level perspective to judge the abnormality of the memory state. Specific calculations and comparisons, including indicators such as the address distribution change rate, access frequency fluctuation value, and fragmentation aggregation, can monitor potential problems in memory operation from multiple angles to ensure accurate diagnosis. Finally, step S355 performs a comprehensive evaluation and processing of the trend deviation data based on the preset abnormality judgment threshold to obtain memory abnormality feature data. Through this comprehensive evaluation, it is possible to effectively distinguish between normal fluctuations and true anomalies, and to provide early warning of potential system failures or memory resource bottlenecks. Overall, the above steps not only improve the accuracy of memory anomaly detection through multi-dimensional time series analysis, trend calculation and comprehensive evaluation, but also enhance the system's early warning capability for memory anomalies, providing strong support for subsequent memory optimization and system stability assurance.

[0103] Preferably, step S355 includes the following steps:

[0104] Step S3551: performing weighted calculation on the address distribution change rate, access frequency fluctuation value, and fragment aggregation degree in the trend deviation data based on preset weights to obtain comprehensive deviation data;

[0105] Step S3552: The comprehensive deviation data is classified into abnormality levels according to a preset abnormality determination threshold, thereby obtaining abnormality level labeling data, wherein the abnormality level classification is specifically as follows: when the deviation is greater than 0.8, it is marked as a severe abnormality; when the deviation is between 0.5 and 0.8, it is marked as a moderate abnormality; when the deviation is less than 0.5, it is marked as a mild abnormality;

[0106] Step S3553: Calculate the duration and frequency of each type of anomaly in the last 10 minutes based on the anomaly level tag data. When an anomaly of the same level lasts for more than 5 minutes or occurs more than 3 times, perform an anomaly upgrade process to obtain anomaly persistence data.

[0107] Step S3554: Performing a time-series-based quantitative evaluation process on the abnormal state using the abnormal persistence data, thereby obtaining abnormal cumulative evaluation data;

[0108] Step S3555: Compare and analyze the abnormal accumulation evaluation data based on the system preset performance benchmark value to obtain memory abnormality feature data.

[0109] The embodiment of the present invention performs weighted calculation on the address distribution change rate, access frequency fluctuation value and fragment aggregation in the trend deviation data based on preset weights to obtain comprehensive deviation data. The specific operation is to first set the weight value of each feature. For example, the weight of the address distribution change rate is 0.4, the weight of the access frequency fluctuation value is 0.3, and the weight of the fragment aggregation is 0.3. Then, the comprehensive deviation is calculated according to the following formula: Comprehensive deviation = (address change rate × 0.4) + (access frequency fluctuation value × 0.3) + (fragment aggregation × 0.3) The comprehensive deviation of each time point is obtained by weighted calculation, and a comprehensive deviation data set is generated as the basis for subsequent abnormality level classification and sustainability evaluation. According to the preset abnormality judgment threshold, the comprehensive deviation data is classified into abnormal levels. The specific method is to compare the comprehensive deviation with the preset threshold interval at each time point and perform classification marking. For example, when the comprehensive deviation is greater than 0.8, it is labeled as a "severe anomaly"; when the deviation is between 0.5 and 0.8, it is labeled as a "moderate anomaly"; and when the deviation is less than 0.5, it is labeled as a "mild anomaly." At this point, by traversing the comprehensive deviation data for all time points, each time point is labeled with an anomaly level, generating an anomaly level labeling dataset to facilitate further persistence assessment. Based on the anomaly level labeling data, the duration and frequency of each type of anomaly in the last 10 minutes are calculated, and anomaly escalation processing is performed. For example, the duration and frequency of each anomaly level (severe, moderate, and mild) are recorded over the past 10 minutes. If a severe anomaly lasts for more than 5 minutes or occurs more than 3 times, it is considered to have entered an escalated state and is handled at a higher priority. Similarly, the duration and frequency of moderate and mild anomalies are calculated, and whether to escalate the process is determined based on the set threshold. Ultimately, anomaly persistence data is obtained, including anomaly duration, frequency, and escalation status. Through the abnormal persistence data, the abnormal state is subjected to a time-series quantitative evaluation process. For example, the time-series quantitative score of each abnormal type is calculated using the weighted average method. The weight parameters are set, and the evaluation is performed based on the abnormal duration and frequency in the abnormal persistence data. For example, if the duration of a severe abnormality is 6 minutes and the frequency of occurrence is 4 times, the quantitative score is calculated as: severe abnormality quantitative score = (duration weight × 6) + (frequency weight × 4). The cumulative score of each abnormality type is obtained through the time-series quantitative evaluation, forming the time-series quantitative evaluation data of the abnormal state, which is used as the basis for further analysis and processing. Based on the system's preset performance benchmark value, the abnormal cumulative evaluation data is compared and analyzed to obtain the memory abnormality feature data. First, the system's performance benchmark value is set. For example, the system's allowable fluctuation range for memory access frequency is ±10%, and the allowable range for fragmentation aggregation is ±15%.The accumulated abnormality assessment data is then compared and analyzed against these baseline values. Any assessment value exceeding the baseline range is flagged as memory anomaly signature data. For example, a severely abnormal access frequency fluctuation exceeding 10% is flagged as "memory performance anomaly"; a fluctuation in fragmentation concentration exceeding 15% is flagged as "severe memory fragmentation." Ultimately, these comparative analyses yield memory anomaly signature data, providing detailed information for system optimization and problem diagnosis.

[0110] By analyzing the time series characteristics of memory states, the present invention can deeply explore and predict memory operating conditions, improving the system's early warning capabilities and anomaly identification accuracy. Step S351 generates memory state time series data by establishing a memory state time series feature set and combining key indicators such as address distribution, access frequency, and fragmentation. This process comprehensively covers multiple key memory characteristics, ensuring data integrity and accuracy, and laying a solid foundation for subsequent trend analysis and anomaly detection. Step S352 uses the sliding average method to calculate the short-term state change trend of the memory state time series data to obtain short-term trend feature data. This method, by smoothing short-term fluctuations, can clearly reveal the system's immediate changing trends, providing an important reference for quickly identifying the system's current operating status. Step S353 uses the exponential smoothing method to analyze the long-term changes in the memory state to obtain long-term trend feature data. The exponential smoothing method can effectively reduce external noise interference, making long-term trend changes more stable and reliable, helping to determine whether the system is experiencing long-term performance degradation or potential failures. Step S354 calculates and compares the trend change correlation between the short-term trend feature data and the long-term trend feature data to obtain trend deviation data. This process can reveal abnormal deviations between short-term and long-term trends, and provide a multi-level perspective to judge the abnormality of the memory state. Specific calculations and comparisons, including indicators such as the address distribution change rate, access frequency fluctuation value, and fragmentation aggregation, can monitor potential problems in memory operation from multiple angles to ensure accurate diagnosis. Finally, step S355 performs a comprehensive evaluation and processing of the trend deviation data based on the preset abnormality judgment threshold to obtain memory abnormality feature data. Through this comprehensive evaluation, it is possible to effectively distinguish between normal fluctuations and true anomalies, and to provide early warning of potential system failures or memory resource bottlenecks. Overall, the above steps not only improve the accuracy of memory anomaly detection through multi-dimensional time series analysis, trend calculation and comprehensive evaluation, but also enhance the system's early warning capability for memory anomalies, providing strong support for subsequent memory optimization and system stability assurance.

[0111] Preferably, step S4 includes the following steps:

[0112] Step S41: Calculate the Pearson correlation coefficient within a 10-second time window based on the memory abnormality feature data to obtain short-term correlation data;

[0113] Step S42: Calculating the Pearson correlation coefficient within a 1-minute time window based on the memory abnormality feature data to obtain medium-term correlation data;

[0114] Step S43: Calculate the difference between the short-term correlation data and the medium-term correlation data and compare it with a preset threshold to obtain correlation difference data;

[0115] Step S44: Perform a common feature classification analysis based on the correlation difference data. When the difference between the short-term correlation and the medium-term correlation is greater than 0.3, an emergency abnormality warning is triggered, thereby obtaining emergency abnormality warning data.

[0116] The embodiment of the present invention calculates the Pearson correlation coefficient based on the memory anomaly feature data within a 10-second time window to obtain short-term correlation data. The specific operation is to first extract the memory anomaly feature data within the past 10 seconds, including parameters such as address distribution changes, access frequency fluctuations, and fragmentation aggregation. Then, the correlation between this set of data is calculated using the Pearson correlation coefficient formula, which is: are two sets of data within the time window, and are the means of the two sets of data, respectively. A short-term correlation coefficient is calculated for subsequent analysis. Based on the memory anomaly feature data, the Pearson correlation coefficient is calculated within a 1-minute time window to obtain medium-term correlation data. Similar to step S41, the memory anomaly feature data for the past 1 minute is first extracted, covering relevant parameters such as address distribution, access frequency fluctuations, and fragmentation aggregation. Then, using the Pearson correlation coefficient calculation formula, the correlation of these parameters within 1 minute is calculated using the same method to obtain medium-term correlation data. This data represents the fluctuation characteristics of the memory state over a longer time window and can provide a broader perspective for subsequent anomaly detection. Based on the short-term correlation data and the medium-term correlation data, the difference between the two is calculated and compared with a preset threshold to obtain correlation difference data. The specific operation is to calculate the difference between the short-term correlation data and the medium-term correlation data, for example: difference = |short-term correlation - medium-term correlation|. The difference is compared with a preset threshold. If the difference exceeds the set threshold (e.g., 0.3), it is considered that there is a significant correlation difference. At this time, correlation difference data is generated to determine whether an abnormal fluctuation trend has occurred, providing a basis for further early warning processing. Based on the correlation difference data, a constant feature classification analysis is performed. When the difference between the short-term correlation and the medium-term correlation is greater than 0.3, an emergency anomaly warning is triggered, thereby obtaining emergency anomaly warning data. The specific operation is as follows: First, the constant feature classification standard is set. For example, a difference greater than 0.3 indicates a sharp change in the memory state, which may cause performance issues or system anomalies. Then, the calculated difference is compared with the preset threshold (0.3) for judgment. If the conditions are met, an emergency anomaly warning is triggered. At this time, the system immediately starts the corresponding exception handling process and outputs the emergency anomaly warning data to quickly respond to and repair possible system failures or performance bottlenecks.

[0117] Through detailed analysis and assessment of memory status anomalies, the present invention can accurately identify and classify potential issues in memory operation, significantly improving the anomaly detection capability and response speed of the memory monitoring system. Step S3551 performs a weighted calculation based on preset weights on the address distribution change rate, access frequency fluctuation value, and fragmentation concentration in the trend deviation data to obtain comprehensive deviation data. This weighted calculation allows the system to comprehensively consider the influence of various important factors, providing more accurate anomaly detection results and a clearer basis for subsequent analysis. Step S3552 classifies the comprehensive deviation data into anomaly levels based on preset anomaly determination thresholds, generating anomaly level labeling data. This step effectively distinguishes between mild, moderate, and severe anomalies in system operation by assigning specific labels to different levels of anomalies, helping operations and maintenance personnel quickly determine the severity of the problem and take appropriate countermeasures. Step S3553 calculates the duration and frequency of each type of anomaly within the last 10 minutes based on the anomaly level labeling data, ensuring timely assessment of the persistence of the anomaly. If an anomaly of the same level persists for more than 5 minutes or occurs more than 3 times, an anomaly escalation process is initiated. This process monitors the persistence of anomalies, preventing brief, sporadic anomalies from being misjudged as serious problems, thereby improving detection accuracy. Step S3554 uses the anomaly persistence data to perform a time-series quantitative assessment of the anomaly state, obtaining cumulative anomaly assessment data. This step, through time-series quantitative analysis of the persistence of the anomaly state, helps to fully understand the accumulation of anomalies, providing a reliable basis for long-term system stability prediction and optimization. Finally, step S3555 compares and analyzes the cumulative anomaly assessment data based on the system's preset performance benchmark values ​​to obtain memory anomaly feature data. Through this analysis, the system can more accurately identify anomalies that deviate significantly from the performance benchmark values ​​and provide early warnings of potential risks. Overall, the above steps, through multi-dimensional weighting of anomalies, continuous tracking, and time-series quantitative assessment, greatly improve the accuracy and response efficiency of anomaly detection, providing strong support for stable system operation and resource optimization.

[0118] Preferably, step S5 includes the following steps:

[0119] Step S51: establishing a comprehensive feature matrix based on the emergency anomaly warning data, combined with the anomaly feature data and the page access fluctuation index, thereby obtaining system status assessment data;

[0120] Step S52: performing risk level classification based on the system status assessment data, and locating and analyzing the system performance bottlenecks, thereby obtaining performance assessment report data;

[0121] Step S53: Record the time series, duration, and impact range of the abnormality according to the performance evaluation report data, and perform problem attribution analysis based on a preset diagnostic rule library to obtain problem location report data;

[0122] Step S54: Generate a test report including a system status overview, risk level distribution, and performance bottleneck analysis in a hierarchical structured manner based on the problem location report data, thereby obtaining system test report data.

[0123] This embodiment of the present invention creates a comprehensive feature matrix based on emergency anomaly warning data, combined with anomaly feature data and the page access fluctuation index, thereby generating system status assessment data. First, various types of information, including emergency anomaly warning data, anomaly feature data, and the page access fluctuation index, are collected and organized according to the same time window. This data is then weighted and integrated to construct a comprehensive feature matrix. The weights of each feature can be adjusted based on actual needs; for example, the page access fluctuation index accounts for 30%, the anomaly feature data accounts for 50%, and the warning data accounts for 20%. Each data item in the comprehensive feature matrix reflects the overall performance of the current system state and provides data support for subsequent risk assessment. Based on the system status assessment data, a risk level is assigned and system performance bottlenecks are located and analyzed, thereby generating performance assessment report data. Based on the comprehensive feature matrix generated in step S51, the system status is assigned a risk level using a multi-dimensional assessment model. For example, risk levels are assigned based on specific thresholds, such as a comprehensive feature score greater than 80 for high risk, 60-80 for medium risk, and below 60 for low risk. Subsequently, by analyzing performance indicators in the status data and combining them with system resource usage (such as CPU load and memory utilization), performance bottleneck location analysis is performed to identify bottleneck areas in the system. Finally, this information is integrated to generate a performance evaluation report. This report includes a detailed analysis of each risk level and a clear location of performance bottlenecks, serving as a basis for system optimization. Based on the performance evaluation report data, the time series, duration, and impact range of anomalies are recorded. Problem attribution analysis is performed based on a preset diagnostic rule base, resulting in the problem location report data. First, the anomaly time series data, duration, and impact range information from the performance evaluation report are extracted to construct a time series record. This anomaly data is then matched and analyzed using a preset diagnostic rule base. The diagnostic rule base contains common performance problem patterns, such as memory leaks and CPU bottlenecks. Through pattern matching analysis, the rule base attributes anomaly data to specific issues. Based on the results of the rule base analysis, a problem location report is generated. The report includes the time of occurrence, duration, affected module or area, and possible causes and solutions for each issue, providing system maintenance personnel with accurate troubleshooting information. Based on the problem location report data, a test report is generated using a hierarchical structured approach, including a system status overview, risk level distribution, and performance bottleneck analysis, thereby obtaining system test report data. First, based on the problem location report data, various system status information is organized into a hierarchical structure. For example, the first level is a system status overview, including the current overall health of the system and risk level distribution; the second level is a detailed risk level analysis, showing areas and modules with different risk levels; the third level is a performance bottleneck analysis, which details the bottlenecks affecting system performance and provides optimization suggestions.Each level is clearly categorized and displayed to ensure the logical and readable nature of the report data. Finally, the system test report data can be generated into standardized report documents or charts, providing system administrators or decision makers with complete test results and a reference for subsequent optimization.

[0124] By comprehensively analyzing the system's anomaly warnings, memory access fluctuations, and performance data, the present invention provides strong support for comprehensive system status assessment and problem location, enhancing the system's monitoring, diagnosis, and optimization capabilities. Step S51 first combines emergency anomaly warning data, anomaly feature data, and the page access fluctuation index to create a comprehensive feature matrix, thereby generating system status assessment data. This step comprehensively integrates multiple aspects of information, providing multi-dimensional foundational data for subsequent analysis and helping to accurately capture complex changes in system status. This comprehensive analysis not only reflects the current system operating status but also considers potential system fluctuations and risks. Step S52 uses the system status assessment data to classify risk levels and analyze the system's performance bottlenecks, ultimately generating performance assessment report data. This step provides the system with detailed risk analysis and performance bottleneck identification, allowing managers to clearly understand system weaknesses and implement targeted optimization measures to avoid system crashes or performance degradation. Step S53 records the time series, duration, and impact range of anomalies, and combines them with a pre-set diagnostic rule base to perform problem attribution analysis, ultimately generating problem location report data. This process not only helps accurately trace the source of anomalies, but also provides in-depth analysis of the causes of anomalies by comparing them with historical rules, optimizing the efficiency and accuracy of problem solving. Finally, step S54 generates a test report based on the problem location report data in a hierarchical and structured manner. The report includes a system status overview, risk level distribution, and performance bottleneck analysis, thereby obtaining system test report data. This link converts complex technical analysis results into highly readable content through structured reporting, making it easier for managers to make decisions. Through these steps, the system can not only achieve real-time monitoring and anomaly warnings, but also conduct in-depth analysis of the root causes of anomalies, providing an accurate basis for system optimization, thereby significantly improving system reliability and performance.

[0125] The present invention also provides a system parameter detection system based on a U disk, which is used to execute the above-mentioned system parameter detection method based on a U disk. The system parameter detection system based on a U disk includes:

[0126] The log parsing module is used to obtain the system operation log data of the USB flash drive; based on the system operation log data, a sliding window scan is performed on the memory physical address space, and a statistical analysis is performed on the continuous free pages in each scanning window to obtain the memory address mapping data;

[0127] An access frequency analysis module is used to perform weighted calculation on the memory page access frequency based on the memory address mapping data and a preset time length, thereby obtaining a page access fluctuation index. Specifically, the weighted calculation assigns a weight of 0.6 to access records within the preset time length and a weight of 0.4 to access records outside the preset time length.

[0128] The memory status verification module is used to cross-verify the memory status based on the page access fluctuation index and the memory fragmentation distribution position in the memory address mapping data to obtain memory anomaly feature data. When the difference between the end address and the start address of adjacent scanning windows is less than a preset page, when the difference between the end address and the start address of adjacent scanning windows is greater than or equal to a preset page, the scanning windows are merged into a detection unit, and the gap area is recorded as an independent potential anomaly point;

[0129] The anomaly analysis module is used to calculate the Pearson correlation coefficient of memory anomaly feature data at different time scales, perform difference comparison and anomaly cluster analysis, and thus obtain emergency anomaly warning data;

[0130] The system detection module is used to generate system detection report data based on emergency anomaly warning data, memory anomaly feature data and page access fluctuation index.

[0131] Through multi-dimensional data analysis and processing, the present invention comprehensively enhances the system's memory management capabilities, promptly detects and addresses potential anomalies, and improves system stability and performance. First, the log parsing module acquires system operation log data from a USB flash drive and performs a sliding window scan of the memory physical address space. This module monitors memory usage in real time and statistically analyzes consecutive free pages within each scan window. This method, by acquiring memory address mapping data, provides critical foundational data for subsequent analysis, helping to identify memory free space distribution and potential fragmentation issues. The access frequency analysis module performs a weighted calculation of memory page access frequencies, assigning different weights based on preset time periods, to generate a page access fluctuation index. This process accurately measures memory access frequency fluctuations within different time periods, providing insight into memory access patterns and fluctuations, and helping the system identify load spikes or potential performance bottlenecks. The memory status verification module cross-validates the memory status based on the page access fluctuation index and memory fragmentation distribution data. By marking gap areas within the scan window and merging detection units, it accurately detects anomalies in memory fragmentation distribution and potential risk points, thereby identifying and preventing sharp drops in system performance or memory overflows at an early stage. The anomaly analysis module calculates the Pearson correlation coefficient, analyzes and compares differences across different time scales, and accurately determines the type and severity of memory anomalies. It then performs anomaly cluster analysis and generates emergency anomaly warning data. This module's purpose is to detect anomalies early through multi-angle analysis and trigger alerts promptly, preventing problems from escalating. Finally, the system detection module generates a comprehensive system detection report based on emergency anomaly warning data, memory anomaly signature data, and page access fluctuation index. This report provides system administrators with a comprehensive understanding of the system's health, identifies possible root causes of failures, and implements targeted optimization measures. This series of steps, working in concert, effectively enhances the system's monitoring, diagnostic, and optimization capabilities, maintaining system stability under complex workloads and ensuring optimal resource utilization, ultimately ensuring efficient and stable system operation.

[0132] The present invention is therefore intended to be illustrative and non-restrictive in all respects, with the scope of the invention being defined by the appended claims rather than the foregoing description, and all changes that come within the meaning and range of equivalents of the application documents are intended to be embraced therein.

[0133] The foregoing description is intended only to provide specific embodiments of the present invention, which will enable those skilled in the art to understand and implement the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not intended to be limited to the embodiments shown herein, but is to be construed in the widest possible manner consistent with the principles and novel features disclosed herein.

Claims

1. A method for detecting system parameters based on a USB flash drive, characterized in that: The following steps are involved: Step S1: Obtain system operation log data from the USB flash drive; Perform sliding window scanning on the memory physical address space according to the system operation log data, and perform statistical analysis on the continuous free pages in each scanning window to obtain the memory address mapping data; Step S2: performing weighted calculation on the memory page access frequency according to the memory address mapping data and the preset time length, thereby obtaining a page access fluctuation index, wherein the weighted calculation specifically assigns a weight of 0.6 to the access records within the preset time length, and assigns a weight of 0.4 to the access records outside the preset time length; Step S3: cross-validate the memory state according to the page access fluctuation index and the memory fragmentation distribution position in the memory address mapping data to obtain memory abnormality feature data; when the difference between the end address and the start address of adjacent scanning windows is less than a preset page, merge the scanning windows into a detection unit; when the difference between the end address and the start address of adjacent scanning windows is greater than or equal to a preset page, mark the scanning windows independently, and record the gap area as an independent potential abnormal point; Step S4: Calculate the Pearson correlation coefficient of the memory abnormality feature data at different time scales, and perform difference comparison and abnormality clustering analysis to obtain emergency abnormality warning data; Step S5: Generate system detection report data based on the emergency abnormality warning data, memory abnormality feature data and page access fluctuation index.

2. The method for detecting system parameters based on a USB flash drive according to claim 1, characterized in that: Step S1 includes the following steps: Step S11: Real-time collection and analysis of system operation logs are performed through the connection between the U disk and the system, thereby obtaining system operation log data; Step S12: segmenting the memory physical address space of the USB flash drive into 4KB pages according to the system operation log data, thereby obtaining memory page partitioning data; Step S13: using the memory page division data to perform sequential scanning processing based on a sliding window of 8 page sizes, thereby obtaining scanning window sequence data; Step S14: Counting the number of consecutive idle pages and their distribution positions in each scanning window according to the scanning window sequence data, thereby obtaining idle page distribution feature data; Step S15: marking the risk area according to the free page distribution characteristic data and the preset continuous free page threshold, so as to obtain the memory address mapping data.

3. The method for detecting system parameters based on a USB flash drive according to claim 2, characterized in that: Step S2 includes the following steps: Step S21: recording the number of accesses to each memory page within a time window of a preset time length according to the memory address mapping data, thereby obtaining page access frequency data; Step S22: Analyze and eliminate the fluctuation impact of the page access frequency data based on the current system load level, so as to obtain normalized access frequency data; Step S23: assigning a weight of 0.6 to the access records within a preset time length according to the access frequency data for the first calculation, thereby obtaining recent access feature data; Step S24: according to the access frequency data, the access records outside the preset time length are assigned a weight of 0.4 for a second calculation, thereby obtaining historical access feature data; Step S25: Based on the recent access feature data and the historical access feature data, access fluctuation degree analysis is performed through weighted superposition operation to obtain a page access fluctuation index.

4. The method for detecting system parameters based on a USB flash drive according to claim 3, characterized in that: Step S25 includes the following steps: Step S251: constructing a dual-time-scale feature matrix according to recent access feature data and historical access feature data, thereby obtaining time series feature mapping data; Step S252: performing quantitative analysis on the discreteness of the characteristic value based on standard deviation calculation through the time series characteristic mapping data, thereby obtaining characteristic fluctuation intensity data; Step S253: performing fluctuation trend determination on the characteristic fluctuation intensity data, thereby obtaining fluctuation trend marking data; Step S254: comparing and analyzing the fluctuation trend mark data according to the system preset benchmark value, thereby obtaining the fluctuation level evaluation data; Step S255: quantify the degree of fluctuation through normalization processing according to the fluctuation level evaluation data, so as to obtain a page access fluctuation index.

5. The method for detecting system parameters based on a USB flash drive according to claim 4, characterized in that: Step S3 includes the following steps: Step S31: extracting and analyzing the spatial distribution characteristics of memory fragments according to the page access fluctuation index and the memory address mapping data, thereby obtaining fragment distribution characteristic data; Step S32: Calculate the address difference between adjacent scanning windows through the fragment distribution characteristic data, and compare it with the preset page size to obtain window interval evaluation data; Step S33: when the time difference in the window interval evaluation data is less than the preset page, the merging operation of the scanning windows is processed to obtain the detection unit division data; Step S34: when the time difference in the window interval evaluation data is greater than or equal to the preset page, the scanning window is independently marked and the gap area is recorded, thereby obtaining potential abnormal point data; Step S35: cross-validate and analyze the memory state according to the detection unit division data and the potential abnormal point data, so as to obtain memory abnormality feature data.

6. The method for detecting system parameters based on a USB flash drive according to claim 5, characterized in that: Step S35 includes the following steps: Step S351: establishing a time series feature set of the memory state according to the detection unit partition data and the potential abnormal point data, thereby obtaining the memory state time series data, wherein the memory state includes address distribution, access frequency and fragmentation degree; Step S352: Calculate the short-term state change trend based on the sliding average method according to the memory state time series data, so as to obtain short-term trend characteristic data; Step S353: Analyze the long-term state change rules of the memory state time series data by exponential smoothing method, so as to obtain long-term trend characteristic data; Step S354: performing trend change correlation calculation and comparison on the short-term trend feature data and the long-term trend feature data, thereby obtaining trend deviation data, wherein the correlation calculation and comparison specifically includes the address distribution change rate, the access frequency fluctuation value and the fragmentation aggregation degree; Step S355: Perform comprehensive evaluation of abnormal characteristics of the trend deviation data according to a preset abnormality determination threshold, thereby obtaining memory abnormality characteristic data.

7. The method for detecting system parameters based on a USB flash drive according to claim 6, characterized in that: Step S355 includes the following steps: Step S3551: performing weighted calculation on the address distribution change rate, access frequency fluctuation value and fragment aggregation degree in the trend deviation data based on preset weights, thereby obtaining comprehensive deviation data; Step S3552: The comprehensive deviation data is classified into abnormality levels according to a preset abnormality determination threshold, thereby obtaining abnormality level labeling data, wherein the abnormality level classification is specifically as follows: when the deviation is greater than 0.8, it is marked as a severe abnormality; when the deviation is between 0.5 and 0.8, it is marked as a moderate abnormality; when the deviation is less than 0.5, it is marked as a mild abnormality; Step S3553: Calculate the duration and frequency of each type of anomaly in the last 10 minutes based on the anomaly level tag data. When the duration of an anomaly of the same level exceeds 5 minutes or the frequency of occurrence exceeds 3 times, perform an anomaly upgrade process to obtain anomaly persistence data; Step S3554: performing a quantitative evaluation process on the abnormal state based on the time series through the abnormal persistence data, thereby obtaining abnormal cumulative evaluation data; Step S3555: Compare and analyze the abnormal cumulative evaluation data based on the system preset performance benchmark value to obtain memory abnormality feature data.

8. The method for detecting system parameters based on a USB flash drive according to claim 7, characterized in that: Step S4 includes the following steps: Step S41: Calculate the Pearson correlation coefficient within a 10-second time window based on the memory abnormality feature data to obtain short-term correlation data; Step S42: Calculate the Pearson correlation coefficient within a 1-minute time window based on the memory abnormality feature data to obtain medium-term correlation data; Step S43: Calculate the difference between the short-term correlation data and the medium-term correlation data and compare them with a preset threshold value to obtain correlation difference data; Step S44: Perform a common feature classification analysis based on the correlation difference data. When the difference between the short-term correlation and the medium-term correlation is greater than 0.3, an emergency abnormality warning is triggered, thereby obtaining emergency abnormality warning data.

9. The method for detecting system parameters based on a USB flash drive according to claim 8, characterized in that: Step S5 includes the following steps: Step S51: establishing a comprehensive feature matrix based on the emergency abnormality warning data, combined with the abnormal feature data and the page access fluctuation index, thereby obtaining system status evaluation data; Step S52: Risk levels are divided according to the system status evaluation data, and the system performance bottlenecks are located and analyzed to obtain performance evaluation report data; Step S53: Record the time series, duration, and impact range of the abnormality according to the performance evaluation report data, and perform problem attribution analysis based on a preset diagnostic rule base to obtain problem location report data; Step S54: Generate a detection report including a system status overview, risk level distribution, and performance bottleneck analysis in a hierarchical structured manner based on the problem location report data, thereby obtaining system detection report data.

10. A system parameter detection system based on a USB disk, characterized in that: Used to execute the system parameter detection method based on a USB disk as claimed in claim 1, the system parameter detection system based on a USB disk comprises: The log parsing module is used to obtain the system operation log data of the USB flash drive; perform sliding window scanning on the memory physical address space according to the system operation log data, and perform statistical analysis on the continuous free pages in each scanning window to obtain the memory address mapping data; The access frequency analysis module is used to perform weighted calculation on the memory page access frequency according to the memory address mapping data and the preset time length, so as to obtain the page access fluctuation index, wherein the weighted calculation specifically assigns a weight of 0.6 to the access records within the preset time length, and assigns a weight of 0.4 to the access records outside the preset time length; A memory status verification module is used to cross-verify the memory status according to the page access fluctuation index and the memory fragmentation distribution position in the memory address mapping data to obtain memory abnormality feature data. When the difference between the end address and the start address of adjacent scanning windows is less than a preset page, the scanning windows are merged into a detection unit. When the difference between the end address and the start address of adjacent scanning windows is greater than or equal to a preset page, the scanning windows are independently marked and the gap area is recorded as an independent potential abnormal point. The anomaly analysis module is used to calculate the Pearson correlation coefficient of the memory anomaly feature data at different time scales, and perform difference comparison and anomaly cluster analysis to obtain emergency anomaly warning data; The system detection module is used to generate system detection report data based on emergency anomaly warning data, memory anomaly feature data and page access fluctuation index.