Big data-based multi-protocol data synchronous acquisition and analysis system and method
By analyzing the historical alarm records of IoT devices and the memory usage of network protocols, determining the degree of impact of each protocol on memory, solving the problem of performance degradation of IoT systems during multi-protocol data acquisition, achieving a more reasonable acquisition strategy and higher system stability.
Patent Information
- Application Number
- CN202510190337.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-02-20
AI Technical Summary
In the field of the Internet of Things, existing systems need to consume a large amount of memory resources when collecting and processing multiple protocol data at the same time, resulting in system performance degradation or crashes, and lack effective collection strategy optimization.
By obtaining the historical alarm records of computer equipment, extracting and analyzing the memory usage of each network protocol, determining the degree of impact of each network protocol on memory usage, and determining whether early warning prompts and optimization of the collection strategy is needed based on this information.
It effectively avoids unreasonable resource allocation, improves the system's comprehensive data analysis capabilities, and prevents system performance degradation and crashes.
Smart Images

Figure CN120144284A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of big data, and specifically to a multi-protocol data synchronization acquisition and analysis system and method based on big data. Background Art
[0002] At present, there are a wide variety of protocols in the Internet of Things field. Common ones include HTTP, MQTT, CoAP, Modbus, etc. Various sensing devices transmit data to computer devices by means of different protocols. Accurately identifying and parsing these protocols and collecting data on this basis, and carrying out real-time fusion and correlation analysis can deeply explore the data value, provide comprehensive and in-depth data insights for Internet of Things applications, and significantly improve the comprehensive data analysis ability.
[0003] However, when collecting and processing data of multiple protocols simultaneously, the system needs to consume a large amount of memory resources. Once the resource allocation is unreasonable or there is a lack of effective optimization, such as the acquisition and analysis tasks of the protocols being overly concentrated, it is very likely to cause a significant decline in system performance, and in severe cases, even lead to system crashes. Therefore, it is necessary to analyze the current acquisition strategy, judge whether the acquisition strategy is reasonable, and timely prompt possible acquisition risks. Summary of the Invention
[0004] The purpose of the present invention is to provide a multi-protocol data synchronization acquisition and analysis system and method based on big data to solve the problems raised in the prior art.
[0005] To achieve the above purpose, the present invention provides the following technical solutions:
[0006] A multi-protocol data synchronization acquisition and analysis method based on big data, comprising the following steps:
[0007] Step S100: Obtain the historical alarm records of the computer device. The alarm records are the records that the memory occupancy of the computer device is detected to be outside the normal occupancy range by the memory detection tool deployed on the computer device; data is transmitted between the computer device and multiple sensing devices through different network protocols. Extract and analyze the memory occupancy of each network protocol corresponding to the alarm records, and then extract feature records from the alarm records;
[0008] Step S200: Take the combination formed by various network protocols according to their respective set acquisition frequencies as the target protocol combination; according to the target protocol combination and the feature records, conduct data acquisition tests on each network protocol on the computer device, and according to the test results, obtain the influence degree of each network protocol on memory occupancy;
[0009] Step S300: Generate corresponding monitoring records based on the memory occupancy at each historical moment recorded by the memory detection tool; intercept the detection records from the monitoring records according to the alarm times corresponding to the alarm records in the monitoring records.
[0010] It should be noted that the purpose of intercepting the detection records here is as follows: Since the target protocol combination is only in the stage of judging whether the acquisition strategy is reasonable, that is to say, it is only an estimated situation. In order to better illustrate the rationality of the current estimated situation, it is necessary to intercept from the historical monitoring records the detection records with reasonable duration and containing as many characteristic records as possible, so as to increase the rationality of the current estimate.
[0011] Step S400: According to the memory detection tool, obtain the memory occupancy ratio of each network protocol corresponding to each acquisition moment in the detection records, and according to the influence degree, obtain the resource occupancy value at each acquisition moment, and judge whether to give an early warning prompt for the target protocol combination according to the resource occupancy value.
[0012] Further, step S100 includes:
[0013] Step S110: Obtain the normal occupancy range [0, R] of memory occupancy, where R is the maximum occupancy ratio preset by the system; obtain a number of historical alarm records of the computer device, and capture the alarm time, memory occupancy ratio corresponding to each alarm record, and the acquisition frequency corresponding to each network protocol.
[0014] Step S120: Deploy a memory detection tool on the computer device. When the memory occupancy ratio for data transmission between the computer device and the perception devices corresponding to each network protocol is detected at the alarm time corresponding to an alarm record by the memory detection tool; add up the memory occupancy ratios corresponding to each occupancy in an alarm record to obtain the total occupancy ratio. If the total occupancy ratio is greater than the preset ratio threshold, then regard the alarm record as a characteristic record, and thus obtain all the characteristic records.
[0015] In the prior art, some manufacturers of perception devices usually provide corresponding APIs to allow users to obtain relevant information of the devices, including the memory occupancy during data transmission. By calling these APIs, developers can write programs to obtain the memory occupancy information of data transmission between specific perception devices and computer devices and calculate the corresponding ratios, which will not be specifically presented in this embodiment. Characteristic records are those alarm records that are determined to be affected by multi-protocol data acquisition. Obtaining characteristic records is also to exclude the influence caused by other application programs on the computer device that also occupy memory.
[0016] Further, step S200 includes:
[0017] Step S210: Extract the collection frequency corresponding to each network protocol in the target protocol combination; according to the collection frequency corresponding to each network protocol in the target protocol combination and the collection frequency corresponding to each network protocol in a historical feature record F, use the network protocols with different collection frequencies as the detection protocols;
[0018] Step S220: Take the collection frequency corresponding to a certain detection protocol A in the target protocol combination as H 1 , and take the collection frequency corresponding to it in a certain feature record F as H 2 ; According to the collection frequency H 1 , obtain the collection interval duration D between two adjacent collection points 1 , according to the collection frequency H 2 , obtain the collection interval duration D between two adjacent collection points 2 ;
[0019] Configure the collection frequency of a certain detection protocol A on the computer device to be H 1 , and the collection duration to be an integer multiple of D 1 , and stop using all application programs and the remaining network protocols on the computer device, and conduct the first data collection test on a certain detection protocol A on the computer device; obtain the memory occupancy ratio at each moment within each collection cycle during the test, and for each collection cycle, calculate the average value of the memory occupancy ratio according to the corresponding moments within the cycle, and establish the first line graph of the memory occupancy ratio changing with time according to the average values;
[0020] Similarly, according to the collection frequency H 2 corresponding to a certain detection protocol A and the collection duration of D 2 , conduct the second data collection test on a certain detection protocol A on the computer device; and establish the second line graph of the memory occupancy ratio changing with time;
[0021] Step S230: Take the maximum memory occupancy ratio in the first line graph as the feature value T 1 , and take the maximum memory occupancy ratio in the second line graph as the feature value T 2 , and then obtain the influence degree W of the network protocol A on the memory occupancy within a certain feature record F: F A =1 - T 1 / T 2 , and calculate the average value according to the influence degree corresponding to the network protocol A in each feature record to obtain the influence degree W of the network protocol A on the memory occupancy; A ; Then obtain the influence degree of each network protocol on the memory occupancy.
[0022] The purpose of conducting tests here is as follows: By analyzing according to the protocols of multiple historical feature records, summarizing experience, the obtained influence degree is more representative and persuasive, which can better analyze the influence degree of each network protocol on memory occupancy, and provide valuable experience for setting a more reasonable acquisition strategy subsequently.
[0023] Further, step S300 includes:
[0024] Step S310: Take the corresponding minimum acquisition frequency among historical network protocols as H 3 , and according to the acquisition frequency H 3 , obtain the acquisition interval duration D between two adjacent acquisition points 3 ; Take the minimum acquisition frequency among the network protocols corresponding to the target protocol combination as H 4 , and according to the acquisition frequency H 4 , obtain the acquisition interval duration D between two adjacent acquisition points 4 ;
[0025] Step S320: Set the feature duration as D = K * (D 3 + D 4 ), where K is a feature coefficient and K > 1; Randomly intercept M sub-monitoring records with a duration equal to D from historical monitoring records. Each sub-monitoring record contains several feature records, and take the sub-monitoring record with the largest number of feature records as the detection record.
[0026] Further, step S400 includes:
[0027] Step S410: According to the memory detection tool, obtain the memory occupancy ratio of each network protocol corresponding to each acquisition moment in the detection record; Obtain the memory occupancy ratio of each network protocol corresponding to a certain acquisition moment, and according to the influence degree corresponding to each network protocol, obtain the resource occupancy value at a certain acquisition moment: Among them, N is the number of network protocols, B n is the memory occupancy ratio of the nth network protocol at a certain acquisition moment, and W n is the influence degree corresponding to the nth network protocol, and then obtain the resource occupancy value of each acquisition moment in the detection record;
[0028] Step S420: If there are several consecutive resource occupancy values in the detection record that are all outside the normal occupancy range, take these several resource occupancy values as an abnormal combination. If the number of abnormal combinations is greater than the quantity threshold, give a warning prompt for the target protocol combination, and prompt relevant personnel that they need to re-determine the acquisition strategy.
[0029] A multi - protocol data synchronization acquisition and analysis system based on big data, including a feature record extraction module, an impact degree determination module, a detection record intercepting module, and a warning prompt module;
[0030] Feature record extraction module: It is used to obtain the historical alarm records of computer devices. The alarm records are the records that the memory detection tool deployed on the computer device monitors that the memory occupancy of the computer device is not within the normal occupancy range; data is transmitted between the computer device and multiple sensing devices through different network protocols. Extract and analyze the memory occupancy of each network protocol corresponding to the alarm records, and then extract feature records from the alarm records;
[0031] Impact degree determination module: It is used to take the combination composed of various network protocols according to their respective set acquisition frequencies as the target protocol combination; according to the target protocol combination and the feature records, conduct data acquisition tests on each network protocol on the computer device, and based on the test results, obtain the impact degree of each network protocol on memory occupancy;
[0032] Detection record intercepting module: It is used to generate corresponding monitoring records through the memory occupancy of each moment recorded by the memory detection tool; according to the alarm time corresponding to each alarm record in the monitoring records, intercept detection records from the monitoring records;
[0033] Warning prompt module: It is used to obtain the memory occupancy ratio of each network protocol corresponding to each acquisition moment in the detection records according to the memory detection tool, and obtain the resource occupancy value of each acquisition moment according to the impact degree, and judge whether to give a warning prompt to the target protocol combination according to the resource occupancy value.
[0034] Furthermore, the impact degree determination module includes a detection protocol determination unit, a line graph establishment unit, and an impact degree determination unit;
[0035] Detection protocol determination unit: It is used to extract the acquisition frequency corresponding to each network protocol in the target protocol combination; according to the acquisition frequency corresponding to each network protocol in the target protocol combination and the acquisition frequency corresponding to each network protocol in the historical feature records, take the network protocols with different acquisition frequencies as the detection protocols;
[0036] Line graph establishment unit: It is used to establish a first line graph of the memory occupancy ratio changing with time according to the acquisition frequency of the detection protocol in the target protocol combination; establish a second line graph of the memory occupancy ratio changing with time according to the acquisition frequency of the detection protocol in the feature records;
[0037] Impact degree determination unit: It is used to analyze according to the maximum memory occupancy ratio in the first line graph and the second line graph to obtain the impact degree of each network protocol on memory occupancy.
[0038] Further, the early warning prompt module includes a resource occupancy value calculation unit and an early warning prompt unit;
[0039] The resource occupancy value calculation unit: is used to obtain the memory occupancy ratio of each network protocol corresponding to each collection moment in the detection record according to the memory detection tool, and obtain the resource occupancy value of each collection moment according to the influence degree;
[0040] The early warning prompt unit: is used to judge whether to give an early warning prompt to the target protocol combination according to the resource occupancy value.
[0041] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention provides a multi-protocol data synchronization acquisition and analysis system and method based on big data, including: obtaining the historical alarm records of computer devices, extracting and analyzing the memory occupancy of each network protocol corresponding to the alarm records, and then extracting feature records from the alarm records; obtaining a target protocol combination, and obtaining the influence degree of each network protocol on memory occupancy according to the target protocol combination and the feature records; generating corresponding monitoring records, and intercepting detection records from the monitoring records; obtaining the memory occupancy ratio of each network protocol corresponding to each collection moment in the detection record, and then judging whether to give an early warning prompt to the target protocol combination. By analyzing the historical alarm records in combination with the current target protocol combination, the present invention judges whether the currently set acquisition strategy is reasonable, optimizes the acquisition and analysis of the current protocol, and effectively avoids the situation of unreasonable resource allocation. Description of the Drawings
[0042] Figure 1 It is a schematic flow chart of the multi-protocol data synchronization acquisition and analysis method based on big data of the present invention;
[0043] Figure 2 It is a structural diagram of the multi-protocol data synchronization acquisition and analysis system based on big data of the present invention. Detailed Embodiments
[0044] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0045] Embodiment: As Figure 1 shown, the present invention provides a technical solution for a multi-protocol data synchronization acquisition and analysis method based on big data, including the following steps:
[0046] Step S100: Obtain the historical alarm records of the computer device. The alarm records are the records that the memory occupancy of the computer device is detected to be outside the normal occupancy range by the memory detection tool deployed on the computer device. Data is transmitted between the computer device and various sensing devices through different network protocols. Extract and analyze the memory occupancy of each network protocol corresponding to the alarm records, and then extract the feature records from the alarm records.
[0047] Step S110: Obtain the normal occupancy range [0, R] of the memory occupancy, where R is the maximum occupancy ratio preset by the system. Obtain a number of historical alarm records of the computer device, and capture the alarm time, memory occupancy ratio, and the collection frequency corresponding to each network protocol for each alarm record.
[0048] Step S120: Deploy a memory detection tool on the computer device. Use the memory detection tool to detect the memory occupancy ratio when the computer device and the sensing devices corresponding to each network protocol transmit data at the alarm time corresponding to a certain alarm record. Add up the memory occupancy ratios corresponding to each of a certain alarm record to obtain the total occupancy ratio. If the total occupancy ratio is greater than the preset ratio threshold, then regard a certain alarm record as a feature record, and thus obtain all the feature records.
[0049] In the prior art, some manufacturers of sensing devices usually provide corresponding APIs that allow users to obtain relevant information of the devices, including the memory occupancy during data transmission. By calling these APIs, developers can write programs to obtain the memory occupancy information of data transmission between a specific sensing device and the computer device and calculate the corresponding ratio, which is not specifically presented in this embodiment. Feature records are those alarm records that are determined to be affected by multi-protocol data collection. Obtaining feature records is also to exclude the influence caused by other applications on the computer device that also occupy memory.
[0050] Step S200: Take the combination composed of the collection frequencies set by various network protocols as the target protocol combination. According to the target protocol combination and the feature records, conduct data collection tests on each network protocol on the computer device, and obtain the influence degree of each network protocol on the memory occupancy according to the test results.
[0051] Step S210: Extract the collection frequency corresponding to each network protocol in the target protocol combination. According to the collection frequency corresponding to each network protocol in the target protocol combination and the collection frequency corresponding to each network protocol in a certain historical feature record F, regard the network protocols with different collection frequencies as the detection protocols.
[0052] Step S220: Take the collection frequency corresponding to a certain detection protocol A in the target protocol combination as H 1, the acquisition frequency corresponding to a certain feature record F is taken as H 2 ; According to the acquisition frequency H 1 , the acquisition interval duration D between two adjacent acquisition points is obtained 1 , according to the acquisition frequency H 2 , the acquisition interval duration D between two adjacent acquisition points is obtained 2 ;
[0053] Configure the acquisition frequency of a certain detection protocol A on the computer device to be H 1 , and the acquisition duration is an integer multiple of D 1 , and stop using all applications and the remaining network protocols on the computer device, and conduct the first data acquisition test on a certain detection protocol A on the computer device; obtain the memory occupancy ratio at each moment within each acquisition cycle during the test, and for each acquisition cycle, calculate the average value of the memory occupancy ratio according to the corresponding moments within the cycle, and establish the first line graph of the memory occupancy ratio changing with time according to each average value;
[0054] Similarly, according to the acquisition frequency H corresponding to a certain detection protocol A 2 and the acquisition duration is D 2 , conduct the second data acquisition test on a certain detection protocol A on the computer device; and establish the second line graph of the memory occupancy ratio changing with time.
[0055] Step S230: Take the largest memory occupancy ratio in the first line graph as the eigenvalue T 1 , and the largest memory occupancy ratio in the second line graph as the eigenvalue T 2 , and then obtain the influence degree of network protocol A on memory occupancy within a certain feature record F: W F A =1 - T 1 / T 2 , and according to the influence degree corresponding to network protocol A within each feature record, find the average value to obtain the influence degree W of network protocol A on memory occupancy A ; and then obtain the influence degree of each network protocol on memory occupancy.
[0056] The role of conducting the test here is: by analyzing the protocols of multiple historical feature records, summarizing experience, the obtained influence degree is more representative and persuasive, better analyzing the influence degree of each network protocol on memory occupancy, and providing valuable experience for more reasonable setting of the acquisition strategy in the future.
[0057] Step S300: Generate corresponding monitoring records based on the memory occupancy situation at each historical moment recorded by the memory detection tool; intercept the detection records from the monitoring records according to the alarm times corresponding to each alarm record in the monitoring records.
[0058] It should be noted that the purpose of intercepting the detection record here is as follows: Since the target protocol combination is only in the stage of judging whether the acquisition strategy is reasonable, that is to say, it is only a predicted situation. In order to better illustrate the reasonableness of the current predicted situation, it is necessary to intercept from the historical monitoring records a detection record with a reasonable duration and containing as many feature records as possible, so as to increase the reasonableness of the current prediction.
[0059] Step S310: Take the corresponding minimum acquisition frequency in the historical network protocols as H 3 , and according to the acquisition frequency H 3 , obtain the acquisition interval duration D between two adjacent acquisition points 3 ; take the minimum acquisition frequency in the network protocols corresponding to the target protocol combination as H 4 , and according to the acquisition frequency H 4 , obtain the acquisition interval duration D between two adjacent acquisition points 4 ;
[0060] Step S320: Set the feature duration as D = K * (D 3 + D 4 ), where K is a feature coefficient and K > 1; randomly intercept M sub-monitoring records with a duration equal to D from the historical monitoring records. Each sub-monitoring record contains several feature records, and take the sub-monitoring record with the largest number of feature records as the detection record.
[0061] In this solution, intercepting a reasonable duration means that the duration of the detection record should not be too long or too short. If it is too long, it may lead to overly complicated data calculation. If it is too short, the data will not be representative and lack persuasive power; and to contain as many feature records as possible, mainly because in the detection records with more feature records, the memory occupancy is generally higher, which can provide strong data support for calculating the following memory occupancy value and analyzing whether to give an early warning prompt for the target protocol combination.
[0062] Step S400: According to the memory detection tool, obtain the memory occupancy ratio of each network protocol corresponding to each acquisition moment in the detection record, and according to the influence degree, obtain the resource occupancy value at each acquisition moment, and judge whether to give an early warning prompt for the target protocol combination according to the resource occupancy value.
[0063] Step S410: According to the memory detection tool, obtain the memory occupancy ratio of each network protocol corresponding to each acquisition moment in the detection record; obtain the memory occupancy ratio of each network protocol corresponding to a certain acquisition moment, and according to the influence degree corresponding to each network protocol, obtain the resource occupancy value at a certain acquisition moment: Among them, N is the number of network protocols, B nis the memory occupancy ratio of the nth network protocol at a certain collection moment, W n is the influence degree corresponding to the nth network protocol, and then the resource occupancy value at each collection moment in the detection record is obtained;
[0064] Step S420: If there are several consecutive resource occupancy values in the detection record that are all outside the normal occupancy range, then regard these several resource occupancy values as an abnormal combination. If the number of abnormal combinations is greater than the quantity threshold, give a warning prompt for the target protocol combination, and prompt the relevant personnel that they need to re-determine the collection strategy.
[0065] This solution also provides a multi-protocol data synchronization collection and analysis system based on big data, including a feature record extraction module, an influence degree determination module, a detection record intercepting module, and a warning prompt module;
[0066] Feature record extraction module: used to obtain the historical alarm records of the computer device. The alarm records are the records that the memory occupancy of the computer device is detected to be outside the normal occupancy range by the memory detection tool deployed on the computer device; data is transmitted between the computer device and various sensing devices through different network protocols, extract and analyze the memory occupancy of each network protocol corresponding to the alarm records, and then extract feature records from the alarm records;
[0067] Influence degree determination module: used to regard the combination composed of various network protocols according to their respective set collection frequencies as the target protocol combination; according to the target protocol combination and the feature records, conduct data collection tests on each network protocol on the computer device, and according to the test results, obtain the influence degree of each network protocol on the memory occupancy;
[0068] Detection record intercepting module: used to generate corresponding monitoring records through the memory occupancy of each moment recorded by the memory detection tool; according to the alarm time corresponding to each alarm record in the monitoring record, intercept the detection record from the monitoring record;
[0069] Warning prompt module: used to obtain the memory occupancy ratio of each network protocol corresponding to each collection moment in the detection record according to the memory detection tool, and obtain the resource occupancy value at each collection moment according to the influence degree, and judge whether to give a warning prompt for the target protocol combination according to the resource occupancy value.
[0070] It is obvious to those skilled in the art that the present invention is not limited to the details of the above-described exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention. Therefore, in all respects, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes that fall within the meaning and scope of the equivalent elements of the claims are intended to be embraced within the present invention. Any reference signs in the claims should not be construed as limiting the claims involved.
Claims
1. A multi-protocol data synchronous acquisition and analysis method based on big data, characterized in that: The following steps are involved: Step S100: obtaining historical alarm records of the computer device, wherein the alarm records are records of the memory usage of the computer device not being within the normal range monitored by a memory detection tool deployed on the computer device; data is transmitted between the computer device and a plurality of sensing devices through different network protocols, and the memory usage of each network protocol corresponding to the alarm record is extracted and analyzed, and then feature records are extracted from the alarm record; Step S200: taking a combination of various network protocols according to their respective set acquisition frequencies as a target protocol combination; performing a data acquisition test on each network protocol on the computer device according to the target protocol combination and the feature record, and obtaining the degree of influence of each network protocol on the memory usage according to the test results; Step S300: Generate corresponding monitoring records based on the memory usage at each moment in history recorded by the memory detection tool; extract detection records from the monitoring records based on the alarm time corresponding to each alarm record in the monitoring records; Step S400: According to the memory detection tool, the memory occupancy ratio of each network protocol corresponding to each collection moment in the detection record is obtained, and according to the impact degree, the resource occupancy value of each collection moment is obtained, and according to the resource occupancy value, it is determined whether to issue an early warning prompt for the target protocol combination.
2. The multi-protocol data synchronous acquisition and analysis method based on big data according to claim 1 is characterized in that: Step S100 includes: Step S110: obtaining a normal memory occupancy range [0, R], where R is a maximum occupancy ratio preset by the system; obtaining a number of historical alarm records of the computer device, capturing the alarm time, memory occupancy ratio, and collection frequency corresponding to each network protocol corresponding to each alarm record; Step S120: deploy a memory detection tool on the computer device, and use the memory detection tool to detect the memory ratio occupied by the computer device and the sensing devices corresponding to each network protocol for data transmission at the alarm time corresponding to a certain alarm record; add up each occupied memory ratio corresponding to the certain alarm record to obtain a total occupied ratio; if the total occupied ratio is greater than a preset ratio threshold, take the certain alarm record as a feature record, and then obtain all the feature records.
3. The multi-protocol data synchronous acquisition and analysis method based on big data according to claim 1 is characterized in that: Step S200 includes: Step S210: extracting the acquisition frequency corresponding to each network protocol in the target protocol combination; according to the acquisition frequency corresponding to each network protocol in the target protocol combination and the acquisition frequency corresponding to each network protocol in a certain historical feature record F, the network protocols with different acquisition frequencies are used as detection protocols; Step S220: taking the acquisition frequency corresponding to a certain detection protocol A in the target protocol combination as H1, and taking the acquisition frequency corresponding to the certain feature record F as H2; obtaining the acquisition interval duration D1 between two adjacent acquisition points according to the acquisition frequency H1, and obtaining the acquisition interval duration D2 between two adjacent acquisition points according to the acquisition frequency H2; Configure the collection frequency of a certain detection protocol A on the computer device to be H1, the collection duration to be an integer multiple of D1, and stop using all applications and other network protocols on the computer device, and perform a first data collection test on the certain detection protocol A on the computer device; obtain the memory occupancy ratio at each moment in each collection cycle during the test process, and for each collection cycle, calculate the average value of the memory occupancy ratio at the corresponding moment in the cycle, and establish a first line graph of the memory occupancy ratio changing with time based on each average value; Similarly, according to the acquisition frequency H2 and the acquisition duration D2 corresponding to a certain detection protocol A, a second data acquisition test is performed on a certain detection protocol A on a computer device; and a second line graph of the memory usage ratio changing over time is established; Step S230: The maximum memory usage ratio in the first line graph is taken as the characteristic value T1, and the maximum memory usage ratio in the second line graph is taken as the characteristic value T2, and then the influence degree of network protocol A on memory usage in a certain characteristic record F is obtained: W F A =1-T1 / T2, and according to the corresponding influence degree of network protocol A in each feature record, the average value is calculated to obtain the influence degree W of the network protocol A on the memory usage A ; And then get the impact of each network protocol on memory usage.
4. The multi-protocol data synchronous acquisition and analysis method based on big data according to claim 3 is characterized in that: Step S300 includes: Step S310: taking the corresponding minimum acquisition frequency in the historical network protocol as H3, and obtaining the acquisition interval D3 between two adjacent acquisition points according to the acquisition frequency H3; taking the minimum acquisition frequency in the network protocol corresponding to the target protocol combination as H4, and obtaining the acquisition interval D4 between two adjacent acquisition points according to the acquisition frequency H4; Step S320: Set the feature duration to D = K*(D3+D4), where K is the feature coefficient, K>1; randomly select M sub-monitoring records with a duration equal to D from the historical monitoring records, each sub-monitoring record contains several feature records, and the sub-monitoring record containing the largest number of feature records is used as the detection record.
5. The multi-protocol data synchronous acquisition and analysis method based on big data according to claim 4 is characterized in that: Step S400 includes: Step S410: Obtain the memory occupancy ratio of each network protocol corresponding to each collection moment in the detection record according to the memory detection tool; obtain the memory occupancy ratio of each network protocol corresponding to a certain collection moment, and obtain the resource occupancy value of the certain collection moment according to the impact degree corresponding to each network protocol: Where N is the number of network protocols, B n is the memory usage ratio of the nth network protocol at the certain acquisition time, W n is the impact degree corresponding to the nth network protocol, and then the resource occupancy value at each collection moment in the detection record is obtained; Step S420: If there are several resource occupancy values that are continuous in time in the detection record and are all outside the normal occupancy range, the several resource occupancy values are regarded as an abnormal combination. If the number of abnormal combinations is greater than the quantity threshold, an early warning prompt is given to the target protocol combination, and relevant personnel are prompted to redefine the collection strategy.
6. A multi-protocol data synchronous acquisition and analysis system, used to execute the multi-protocol data synchronous acquisition and analysis method based on big data according to any one of claims 1 to 5, characterized in that: The system includes a feature record extraction module, an impact degree determination module, a detection record interception module and an early warning prompt module; Feature record extraction module: used to obtain historical alarm records of computer devices, where the alarm records are records of memory usage of computer devices not being within the normal range, monitored by memory detection tools deployed on computer devices; data is transmitted between computer devices and various sensing devices through different network protocols, memory usage of each network protocol corresponding to the alarm records is extracted and analyzed, and feature records are extracted from the alarm records; Impact degree determination module: used to take the combination of various network protocols according to their respective set collection frequencies as the target protocol combination; according to the target protocol combination and feature records, perform data collection tests on each network protocol on the computer device, and obtain the impact degree of each network protocol on memory usage according to the test results; Detection record interception module: used to generate corresponding monitoring records based on the memory usage at each moment in history recorded by the memory detection tool; intercept detection records from the monitoring records according to the alarm time corresponding to each alarm record in the monitoring records; Early warning prompt module: used to obtain the memory occupancy ratio of each network protocol corresponding to each collection moment in the detection record according to the memory detection tool, and obtain the resource occupancy value of each collection moment according to the impact degree, and determine whether to issue an early warning prompt for the target protocol combination according to the resource occupancy value.
7. The multi-protocol data synchronous acquisition and analysis system according to claim 6, characterized in that: The impact degree determination module includes a detection protocol determination unit, a line graph establishment unit and an impact degree determination unit; The detection protocol determination unit is used to extract the acquisition frequency corresponding to each network protocol in the target protocol combination; according to the acquisition frequency corresponding to each network protocol in the target protocol combination and the acquisition frequency corresponding to each network protocol in the historical feature record, the network protocol with different acquisition frequencies is used as the detection protocol; A line graph establishing unit: used to establish a first line graph of memory occupancy ratio changing over time according to the acquisition frequency corresponding to the detection protocol in the target protocol combination; and to establish a second line graph of memory occupancy ratio changing over time according to the acquisition frequency corresponding to the detection protocol in the feature record; The impact degree determination unit is used to analyze the maximum memory usage ratio in the first line graph and the second line graph to obtain the impact degree of each network protocol on the memory usage.
8. The multi-protocol data synchronous acquisition and analysis system according to claim 7, characterized in that: The early warning prompt module includes a resource occupancy value calculation unit and an early warning prompt unit; Resource occupancy value calculation unit: used to obtain the memory occupancy ratio of each network protocol corresponding to each collection moment in the detection record according to the memory detection tool, and obtain the resource occupancy value of each collection moment according to the impact degree; Early warning prompt unit: used to determine whether to issue an early warning prompt for the target protocol combination based on the resource occupancy value.
Citation Information
Patent Citations
Alarm correlation analysis method and system for cloud center operation and maintenance
CN110493065A
Hybrid cloud traffic collection method and system based on edge computing
CN113364624A
Application performance test method and device, medium and computer program product
CN113553267A
Equipment data acquisition and monitoring method and system based on SNMP (Simple Network Management Protocol)
CN117596119A
Platform for facilitating development of intelligence in an industrial internet of things system
EP3966695A1