Intelligent network detection device

Through the collaborative work of multiple modules of the intelligent network detection device, the problem of low network problem detection efficiency in the prior art is solved, real-time and accurate detection and monitoring of the network is realized, the reliability of the detection results is improved and labor costs are reduced.

CN120110973APending Publication Date: 2025-06-06HENAN SHUNBO INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510279084.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

The existing technology is inefficient when troubleshooting network problems, requires joint processing by multiple personnel, and cannot quickly process real-time data, resulting in complex and inaccurate data processing.

Method used

It provides intelligent network detection devices, including data acquisition module, data preprocessing module, feature extraction module, central processing module, analysis and detection module, data storage module, result presentation module, early warning module and wireless communication module. Through the coordinated work of these modules, real-time collection, preprocessing, analysis and detection of network data can be realized, and reports and alarms are generated.

Benefits of technology

It realizes multi-dimensional detection of the network, obtains more comprehensive information, can monitor and issue alarms in real time, improves the accuracy and reliability of detection results, reduces labor costs, and accurately and completely store detection data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110973A_ABST
    Figure CN120110973A_ABST
Patent Text Reader

Abstract

The invention provides an intelligent network detection device. The intelligent network detection device comprises a data acquisition module, a data preprocessing module, a feature extraction module, a central processing module, an analysis and detection module, a data storage module, a result presentation module, an early warning module and a wireless communication module. And the input end of the data preprocessing module is connected to the output end of the data acquisition module. According to the intelligent network detection device provided by the invention, the target network can be detected from multiple dimensions, more comprehensive information can be obtained, the target network can be monitored in real time, and an alarm or a prompt can be immediately given once an abnormal condition is found, so that related personnel can take measures in time; the problems of negligence caused by subjective judgment difference and fatigue possibly occurring in manual detection are avoided, so that the accuracy and reliability of a detection result are improved, the requirement for a large number of manual detection personnel is reduced, and the labor cost of an enterprise is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network detection, and in particular to an intelligent network detection device. Background Art

[0002] In today's Internet age, the Internet is closely related to people's lives, such as taxis, shopping, dining, entertainment and other aspects of life can be done on the Internet. Therefore, how to ensure the data security of each user on the Internet is particularly important in today's era.

[0003] The situation of network security protection is becoming increasingly severe. With the increasing number of front-end protection devices for enterprise network business systems, the problem of network access between business systems is also increasing. In the scenario of large enterprises, with the development of business, the requirements for network security are getting higher and higher, and the network structure of enterprise networks is becoming increasingly complex.

[0004] With the rapid development and widespread application of the Internet, network attacks, network failures and other events are becoming more and more frequent. However, when troubleshooting network problems, manual processing is required, and multiple personnel are required to jointly query and coordinate hosts, networks, applications and databases. The data processing process is relatively complicated, resulting in low efficiency, and real-time data cannot be processed quickly.

[0005] Therefore, it is necessary to provide an intelligent network detection device to solve the above technical problems. Summary of the invention

[0006] The present invention provides an intelligent network detection device, which solves the problems in the background technology.

[0007] To solve the above technical problems, the intelligent network detection device provided by the present invention includes: a data acquisition module, a data preprocessing module, a feature extraction module, a central processing module, an analysis and detection module, a data storage module, a result presentation module, an early warning module and a wireless communication module.

[0008] The input end of the data preprocessing module is connected to the output end of the data acquisition module, the input end of the feature extraction module is connected to the output end of the data preprocessing module, the input end of the central processing module is connected to the output end of the feature extraction module, the input end of the analysis and detection module is connected to the output end of the central processing module, the input end of the data storage module is connected to the output end of the analysis and detection module, the input end of the result presentation module is connected to the output end of the data storage module, the input end of the early warning module is connected to the output end of the analysis and detection module, the output end of the early warning module is connected to the input end of the central processing module, the input end of the wireless communication module is connected to the output end of the central processing module, and the wireless communication module is bidirectionally connected to the data storage module.

[0009] Preferably, the data acquisition module includes a network traffic acquisition unit and a device information acquisition unit; the network traffic acquisition unit is used to obtain data packets from the network link, and the device information acquisition unit is used to collect basic information of various devices in the network.

[0010] Preferably, the data preprocessing module includes a data cleaning unit and a data conversion unit; the data cleaning unit is used to clean the collected data to remove noise data, duplicate data and incomplete data, and the data conversion unit is used to convert the collected raw data into a format suitable for subsequent analysis and processing.

[0011] Preferably, the feature extraction module is used to extract parameters that can reflect network behavior characteristics from network traffic data, and to extract features that can characterize device status and behavior based on information about network devices.

[0012] Preferably, the central processing module is used to receive information from the feature extraction module and the early warning module, read the information and perform related operations.

[0013] Preferably, the analysis and detection module includes an anomaly detection unit, an intrusion detection unit, a performance analysis unit and a fault detection unit; the anomaly detection unit is used to analyze network data and detect abnormal behavior or events in the network, the intrusion detection unit is used to detect intrusion behavior in the network, the performance analysis unit is used to analyze and evaluate performance indicators of the network, and the fault detection unit is used to quickly locate when a network device fails.

[0014] Preferably, the data storage module is used to store the network data and intermediate analysis results collected in real time for quick access and processing, and is responsible for storing the processed and analyzed historical data for long-term trend analysis and data mining.

[0015] Preferably, the result presentation module is used to generate a detailed report based on the results of the analysis and testing, and to present the results of the analysis and testing in a graphical manner.

[0016] Preferably, the early warning module is used to generate corresponding alarm information when an abnormal event or security threat is detected in the network, and send the generated alarm information to the network administrator in a timely manner.

[0017] Preferably, the alarm information includes the alarm level, alarm content, and occurrence time; the sending method includes email, text message, and system pop-up window.

[0018] Compared with the related art, the intelligent network detection device provided by the present invention has the following beneficial effects:

[0019] The present invention provides an intelligent network detection device. The present invention can detect the target network from multiple dimensions to obtain more comprehensive information, and can monitor the target network in real time. Once an abnormal situation is found, an alarm or prompt can be immediately issued so that relevant personnel can take timely measures, thereby avoiding problems such as subjective judgment differences and negligence caused by fatigue that may occur in manual detection, thereby improving the accuracy and reliability of the detection results, reducing the demand for a large number of manual detection personnel, reducing the manpower costs of the enterprise, and being able to accurately and completely store the data generated during the detection process, facilitating subsequent query, statistics and analysis. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] Figure 1 A schematic diagram of a preferred embodiment of the intelligent network detection device provided by the present invention;

[0021] Figure 2 for Figure 1 Schematic diagram of the data acquisition module shown;

[0022] Figure 3 for Figure 1 Schematic diagram of the data preprocessing module shown;

[0023] Figure 4 for Figure 1 Schematic diagram of the analysis and detection module shown. DETAILED DESCRIPTION

[0024] The present invention will be further described below in conjunction with the accompanying drawings and implementation modes.

[0025] Please refer to Figure 1 , Figure 2 , Figure 3 , Figure 4 ,in, Figure 1 A schematic diagram of a preferred embodiment of the intelligent network detection device provided by the present invention; Figure 2 for Figure 1 Schematic diagram of the data acquisition module shown; Figure 3 for Figure 1 Schematic diagram of the data preprocessing module shown; Figure 4 for Figure 1 The schematic diagram of the analysis and detection module is shown. The intelligent network detection device includes: a data acquisition module, a data preprocessing module, a feature extraction module, a central processing module, an analysis and detection module, a data storage module, a result presentation module, an early warning module and a wireless communication module.

[0026] The input end of the data preprocessing module is connected to the output end of the data acquisition module, the input end of the feature extraction module is connected to the output end of the data preprocessing module, the input end of the central processing module is connected to the output end of the feature extraction module, the input end of the analysis and detection module is connected to the output end of the central processing module, the input end of the data storage module is connected to the output end of the analysis and detection module, the input end of the result presentation module is connected to the output end of the data storage module, the input end of the early warning module is connected to the output end of the analysis and detection module, the output end of the early warning module is connected to the input end of the central processing module, the input end of the wireless communication module is connected to the output end of the central processing module, and the wireless communication module is bidirectionally connected to the data storage module.

[0027] The data acquisition module includes a network flow acquisition unit and a device information acquisition unit; the network flow acquisition unit is used to obtain data packets from the network link, and the device information acquisition unit is used to collect basic information of various devices in the network.

[0028] The network traffic collection unit can be implemented through technologies such as port mirroring and network probes of network devices. For example, port mirroring is set up on the core switch of the enterprise network to copy the network traffic of a specific port to the data collection module for analysis. It can collect information including source IP address, destination IP address, port number, protocol type, packet size, etc., and provide raw data for subsequent analysis.

[0029] Collect basic information about various devices in the network, such as device type, model, operating system, hardware configuration, etc. For network devices such as routers and switches, collect operating status information such as port status, routing table, switching table, etc.; for host devices such as servers, collect performance indicator information such as CPU usage, memory usage, disk space, etc.

[0030] The data preprocessing module includes a data cleaning unit and a data conversion unit; the data cleaning unit is used to clean the collected data to remove noise data, duplicate data and incomplete data, and the data conversion unit is used to convert the collected raw data into a format suitable for subsequent analysis and processing.

[0031] The data cleaning unit can ensure the accuracy and consistency of data. For example, it can filter out some abnormal and obviously erroneous data packets in network traffic data, and supplement or mark missing key parameters in device information.

[0032] The data conversion unit converts log files of different formats into a unified structured data format to facilitate batch processing and analysis.

[0033] The feature extraction module is used to extract parameters that can reflect network behavior characteristics from network traffic data, such as traffic peak, mean, variance, packet length distribution, traffic time distribution, etc., and for network device information, extract features that can characterize device status and behavior, such as normal operating status characteristics of the device, feature changes under abnormal status, etc.

[0034] For example, when the server's CPU usage suddenly increases or the memory usage remains high, it may indicate that the server has performance problems or is under attack.

[0035] The central processing module is used to receive information from the feature extraction module and the early warning module, read the information and perform related operations.

[0036] The analysis and detection module includes an anomaly detection unit, an intrusion detection unit, a performance analysis unit, and a fault detection unit; the anomaly detection unit is used to analyze network data and detect abnormal behaviors or events in the network, and the intrusion detection unit is used to detect intrusion behaviors in the network, such as hacker attacks, malware propagation, etc. This module will match and analyze network data based on known attack feature libraries and behavior patterns, identify potential intrusion behaviors, and issue alarms in a timely manner; the performance analysis unit is used to analyze and evaluate network performance indicators, including network bandwidth utilization, latency, packet loss rate, etc. By monitoring and analyzing these performance indicators, network performance bottlenecks and problems can be discovered in a timely manner, providing a basis for network optimization; the fault detection unit is used to quickly locate network equipment when a fault occurs.

[0037] For example, when a large number of abnormal connection requests from the same IP address are detected attempting to access sensitive servers within the enterprise, the system will issue an intrusion alarm.

[0038] The fault detection unit can quickly determine whether the problem is with a router, switch, or other network device when a network fault occurs. For example, if part of an enterprise campus network cannot access the Internet, the network intelligent detection system can quickly locate the fault on a port of a core switch by analyzing the connection status between network devices, the operating parameters of the devices, etc.

[0039] At the same time, it can timely detect the interruption or performance degradation of network links (such as optical fiber, cable, etc.). In the network of telecom operators, there are a large number of optical fiber links connecting different base stations and switching centers. The system can quickly detect link failures by monitoring indicators such as optical signal strength and bit error rate, so as to repair them in time and reduce the impact on user services.

[0040] The data storage module is used to store the network data and intermediate analysis results collected in real time for quick access and processing. It has high read and write performance and data processing capabilities, can meet the storage and query needs of real-time data, and is responsible for storing historical data after processing and analysis to conduct long-term trend analysis and data mining. It can provide network administrators with historical data query and statistical functions to help them understand the long-term operation status and change trends of the network.

[0041] The result presentation module is used to generate detailed reports based on the results of the analysis and detection, including abnormal event reports, performance analysis reports, equipment status reports, etc. The reports will contain specific event time, event type, impact range, processing suggestions and other information, which is convenient for network administrators to view and understand, and the results of the analysis and detection are presented in a graphical manner, such as bar charts, line charts, pie charts, topology diagrams, etc. Visual display can more intuitively present the network's operating status and detection results, helping network administrators quickly grasp the overall situation and key information of the network.

[0042] The early warning module is used to generate corresponding alarm information when abnormal events or security threats are detected in the network, and send the generated alarm information to the network administrator in a timely manner. The alarm level can be divided according to the severity of the event so that the network administrator can quickly determine the urgency of the event.

[0043] The alarm information includes the alarm level, alarm content, and occurrence time; the sending method includes email, text message, and system pop-up window, ensuring that the network administrator can receive the alarm information as soon as possible so as to take corresponding processing measures in time.

[0044] Compared with the related art, the intelligent network detection device provided by the present invention has the following beneficial effects:

[0045] The present invention can detect the target network from multiple dimensions to obtain more comprehensive information, and can monitor the target network in real time. Once an abnormal situation is found, an alarm or prompt can be issued immediately so that relevant personnel can take timely measures, avoiding problems such as subjective judgment differences and negligence caused by fatigue that may occur in manual detection, thereby improving the accuracy and reliability of the detection results, reducing the demand for a large number of manual detection personnel, reducing the manpower costs of the enterprise, and being able to accurately and completely store the data generated during the detection process, facilitating subsequent query, statistics and analysis.

[0046] The above descriptions are merely embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. Intelligent network detection device, characterized in that: include: Data acquisition module, data preprocessing module, feature extraction module, central processing module, analysis and detection module, data storage module, result presentation module, early warning module and wireless communication module. The input end of the data preprocessing module is connected to the output end of the data acquisition module, the input end of the feature extraction module is connected to the output end of the data preprocessing module, the input end of the central processing module is connected to the output end of the feature extraction module, the input end of the analysis and detection module is connected to the output end of the central processing module, the input end of the data storage module is connected to the output end of the analysis and detection module, the input end of the result presentation module is connected to the output end of the data storage module, the input end of the early warning module is connected to the output end of the analysis and detection module, the output end of the early warning module is connected to the input end of the central processing module, the input end of the wireless communication module is connected to the output end of the central processing module, and the wireless communication module is bidirectionally connected to the data storage module.

2. The intelligent network detection device according to claim 1, characterized in that: The data acquisition module includes a network flow acquisition unit and a device information acquisition unit; the network flow acquisition unit is used to obtain data packets from the network link, and the device information acquisition unit is used to collect basic information of various devices in the network.

3. The intelligent network detection device according to claim 1, characterized in that: The data preprocessing module includes a data cleaning unit and a data conversion unit; the data cleaning unit is used to clean the collected data to remove noise data, duplicate data and incomplete data, and the data conversion unit is used to convert the collected raw data into a format suitable for subsequent analysis and processing.

4. The intelligent network detection device according to claim 1, characterized in that: The feature extraction module is used to extract parameters that can reflect network behavior characteristics from network traffic data, and to extract features that can characterize device status and behavior based on network device information.

5. The intelligent network detection device according to claim 1, characterized in that: The central processing module is used to receive information from the feature extraction module and the early warning module, read the information and perform related operations.

6. The intelligent network detection device according to claim 1, characterized in that: The analysis and detection module includes an anomaly detection unit, an intrusion detection unit, a performance analysis unit and a fault detection unit; the anomaly detection unit is used to analyze network data and detect abnormal behavior or events in the network, the intrusion detection unit is used to detect intrusion behavior in the network, the performance analysis unit is used to analyze and evaluate the performance indicators of the network, and the fault detection unit is used to quickly locate when a network device fails.

7. The intelligent network detection device according to claim 1, characterized in that: The data storage module is used to store the real-time collected network data and intermediate analysis results for quick access and processing, and is responsible for storing the processed and analyzed historical data for long-term trend analysis and data mining.

8. The intelligent network detection device according to claim 1, characterized in that: The result presentation module is used to generate a detailed report based on the analysis and detection results, and to present the analysis and detection results in a graphical manner.

9. The intelligent network detection device according to claim 1, characterized in that: The early warning module is used to generate corresponding alarm information when abnormal events or security threats are detected in the network, and send the generated alarm information to the network administrator in a timely manner.

10. The intelligent network detection device according to claim 9, characterized in that: The alarm information includes the alarm level, alarm content, and occurrence time; the sending method includes email, text message, and system pop-up window.