Network device policy distribution anomaly detection and response method and system
By building an exception detection model, the abnormal situation in network equipment policy distribution is detected in real time, the problem of inefficient detection in the existing technology is solved, efficient and accurate exception handling and response are achieved, and the management and security of network equipment are improved.
Patent Information
- Application Number
- CN202510511345.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-08-08
Smart Images

Figure CN120455261A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet technology, and in particular to a method and system for detecting and responding to anomalies in network device policy distribution. Background Art
[0002] In today's digital age, network devices play a vital role in businesses and organizations, responsible for transmitting data, connecting users, and supporting various business functions. To ensure the normal operation of network devices and the security of data transmission, network administrators need to closely monitor the distribution of network device policies. However, due to the complexity and variability of network environments, various anomalies may occur during the network device policy distribution process.
[0003] To effectively deal with these anomalies, the network management team needs to establish a comprehensive anomaly detection and response mechanism. Once an anomaly is detected, an alarm can be automatically issued to notify the administrator or preset response measures can be taken to quickly address the problem and reduce the impact of the failure on the business. Summary of the Invention
[0004] In order to solve the above technical problems, the present invention provides a network device policy distribution anomaly detection and response method and system, including: Obtain historical log data during the network device policy distribution process, and filter the historical log data to identify abnormal log data in the historical log data; Extract abnormal data features from abnormal log data, and build an anomaly detection model based on the extracted abnormal data features and a preset neural network model; Obtain current log data during the network device policy distribution process, and perform anomaly detection based on an anomaly detection model to determine abnormal log data in the current log data; Analyze abnormal log data in the current log data to determine abnormal patterns in network device policy distribution; Analyze and evaluate the degree of abnormality of network device policy distribution based on the abnormal pattern, obtain a policy distribution abnormality value, and determine the abnormality level according to the policy distribution abnormality value; The response method for the network device policy distribution anomaly is comprehensively determined based on the anomaly level and anomaly mode of the network device policy distribution.
[0005] Furthermore, the obtaining of historical log data during the network device policy distribution process, screening the historical log data, and determining abnormal log data in the historical log data includes: Obtain historical log data from the network device policy distribution process from the log database and preprocess the historical log data, including data cleaning, formatting, and parsing; The pre-processed historical log data is filtered by using an anomaly detection algorithm, and the filtered abnormal data points are determined as abnormal log data in the historical log data.
[0006] Furthermore, the method of extracting abnormal data features from abnormal log data and building an abnormality detection model based on the extracted abnormal data features and a preset neural network model includes: Obtain a pre-set feature extraction model, and extract abnormal data features from abnormal log data through the feature extraction model; A data set is constructed based on the abnormal data characteristics and historical temperature data, and the data set is input into a preset neural network model to build an initial anomaly detection model; The dataset is divided into a training set and a test set according to a preset ratio, and the training set and the test set are input into the initial anomaly detection model; The initial anomaly detection model is trained and tested until the initial anomaly detection model meets the preset convergence conditions to obtain an anomaly detection model.
[0007] Furthermore, the obtaining of current log data during the network device policy distribution process, and performing anomaly detection based on an anomaly detection model to determine abnormal log data in the current log data, includes: The current log data in the process of network device policy distribution is obtained, and the current log data is input into the anomaly detection model. The anomaly detection model detects and outputs the anomaly log data in the current log data.
[0008] Furthermore, analyzing abnormal log data in the current log data to determine abnormal patterns of network device policy distribution includes: Obtaining a pre-set standard abnormal pattern of network device policy distribution and determining abnormal log data corresponding to the standard abnormal pattern, wherein the standard abnormal pattern includes policy distribution timeout, policy distribution interruption, policy distribution error, policy distribution conflict, policy distribution duplication, and incomplete policy distribution; The similarity between the abnormal log data in the current log data and the abnormal log data of the standard abnormal pattern is calculated, and the standard abnormal pattern with the highest similarity between the data is determined as the abnormal pattern for network device policy distribution.
[0009] Furthermore, the abnormality degree of the network device policy distribution is analyzed and evaluated based on the abnormality pattern to obtain the abnormality degree value of the policy distribution, including: Determine the proportion of abnormal log data in the current log data, and evaluate the proportion to obtain an abnormality degree value of the abnormal log data in the current log data; The preset weight corresponding to the abnormal pattern is obtained, and the abnormal degree value of the abnormal log data in the current log data is multiplied by the preset weight corresponding to the abnormal pattern to obtain the policy distribution abnormal degree value.
[0010] Furthermore, the determining of the abnormality level by distributing the abnormality degree value according to the strategy includes: Pre-set abnormality level-strategy distribution abnormality value interval correspondence For each strategy distribution abnormality value interval, a corresponding abnormality level is associated; Obtain the policy distribution abnormality degree value, and based on the mapping relationship between the policy distribution abnormality degree value interval to which the policy distribution abnormality degree value belongs and the abnormality level-policy distribution abnormality degree value interval correspondence, select the abnormality level corresponding to the policy distribution abnormality degree value interval as the corresponding abnormality level of the network device policy distribution.
[0011] Furthermore, the method of comprehensively determining a response method to an abnormality in network device policy distribution based on an abnormality level and abnormality mode of the network device policy distribution includes: Determine the level of the abnormality, and determine the notification method corresponding to the network device policy distribution abnormality according to the abnormality level; If the exception level is level 1, the corresponding notification method for the network device policy distribution exception is to send an email notification of the network device policy distribution exception and prompt to quickly handle the exception; If the abnormality level is level 2, the corresponding notification method for the network device policy distribution abnormality is to send a text message notification of the network device policy distribution abnormality and prompt to handle the abnormality urgently; If the abnormality level is level three, the corresponding notification method for the network device policy distribution abnormality is to issue a telephone notification of the network device policy distribution abnormality and prompt to handle the abnormality immediately; Determine the response means corresponding to the network device policy distribution anomaly based on the anomaly pattern; If the exception mode is policy distribution timeout, the response to the network device policy distribution exception is to check the network connection and device load, and retry the policy distribution operation; If the abnormal mode is policy distribution interruption, the response to the network device policy distribution abnormality is to restart the policy distribution operation and switch to a stable network connection; If the abnormal pattern is a policy distribution error, the response means for the network device policy distribution abnormality is to analyze the specific content of the erroneous policy and correct the error in the specific content; If the abnormal mode is a policy distribution conflict, the response method for the network device policy distribution abnormality is to analyze the specific content of the conflicting policy and adjust the priority of policy distribution; If the abnormal pattern is repeated policy distribution, the response means for the abnormal policy distribution of the network device is to stop the repeated distribution, determine the specific content of the repeated policy distribution, and delete the repeated distribution content; If the abnormal mode is incomplete policy distribution, the response means for the network device policy distribution abnormality is to check the distribution log to confirm whether the policy distribution content is complete and re-distribute the missing content; The notification method corresponding to the network device policy distribution exception and the response means corresponding to the network device policy distribution exception constitute the response method of the network device policy distribution exception.
[0012] The present invention also provides a network device policy distribution anomaly detection and response system, comprising: An acquisition module is used to obtain historical log data during the network device policy distribution process, and to filter the historical log data to determine abnormal log data in the historical log data; A modeling module is used to extract abnormal data features from abnormal log data and build an anomaly detection model based on the extracted abnormal data features and a preset neural network model; The detection module is used to obtain the current log data in the process of network device policy distribution, and perform anomaly detection based on the anomaly detection model to determine the abnormal log data in the current log data; An analysis module is used to analyze abnormal log data in the current log data and determine abnormal patterns of network device policy distribution; A determination module is used to analyze and evaluate the degree of abnormality of network device policy distribution based on the abnormal pattern, obtain a policy distribution abnormality degree value, and determine the abnormality level according to the policy distribution abnormality degree value; The response module is used to comprehensively determine the response method of the network device policy distribution anomaly based on the anomaly level and anomaly mode of the network device policy distribution.
[0013] Compared with the prior art, the network device policy distribution anomaly detection and response method and system according to the embodiment of the present invention have the following advantages: The present invention uses the constructed anomaly detection model to perform real-time anomaly detection, which can promptly discover potential problems in the current log data, improve the efficiency and accuracy of anomaly detection, and provide data support for subsequent data analysis; By analyzing the abnormal logs in the current log data, the present invention can determine the abnormal pattern of network device policy distribution, providing an important reference for subsequent problem solving and prevention; The present invention analyzes and evaluates the degree of anomalies, which can quantify the severity of anomalies in network device policy distribution and help administrators prioritize high-risk issues; Based on the comprehensive analysis of anomaly levels and anomaly patterns, the present invention can intelligently determine the response mode for network device policy distribution anomalies, thereby improving response efficiency and accuracy; By continuously monitoring and analyzing abnormal data, the present invention can discover the trend of potential problems and take preventive measures in a timely manner, thereby improving the stability and security of network equipment operation; In summary, the present invention can help improve the automation level of network equipment management, fault handling efficiency and system security, and provide better support and decision-making basis for network operation and maintenance personnel. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 1 is a schematic diagram of the process structure of a network device policy distribution anomaly detection and response method according to an embodiment of the present invention; Figure 2 Schematic diagram of the composition of a network device policy distribution anomaly detection and response system in an embodiment of the present invention. DETAILED DESCRIPTION
[0015] The following embodiments are used to illustrate the present invention, but are not intended to limit the scope of the present invention.
[0016] In the description of this application, it should be understood that the terms "center", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating the orientation or position relationship, are based on the orientation or position relationship shown in the accompanying drawings, and are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the platform or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as a limitation on this application.
[0017] The terms "second" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Therefore, a feature specified with "second" or "second" may explicitly or implicitly include one or more of the features. In the description of this application, unless otherwise specified, "plurality" means two or more.
[0018] In the description of this application, it should be noted that, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood broadly. For example, they can refer to fixed, detachable, or integral connections; mechanical or electrical connections; direct or indirect connections through an intermediate medium; and internal communication between two components. Persons of ordinary skill in the art will understand the specific meanings of the above terms in this application based on specific circumstances.
[0019] like Figure 1 As shown, in an embodiment of the present application, a network device policy distribution anomaly detection and response method is provided, including: S100: obtaining historical log data in the network device policy distribution process, and screening the historical log data to determine abnormal log data in the historical log data; S200: extracting abnormal data features from the abnormal log data, and constructing an anomaly detection model based on the extracted abnormal data features and a preset neural network model; S300: obtaining current log data in the network device policy distribution process, and performing anomaly detection based on the anomaly detection model to determine abnormal log data in the current log data; S400: analyzing the abnormal log data in the current log data to determine the abnormal pattern of the network device policy distribution; S500: analyzing and evaluating the degree of abnormality of the network device policy distribution based on the abnormal pattern to obtain a policy distribution abnormality degree value, and determining the abnormality level according to the policy distribution abnormality degree value; S600: comprehensively determining the response method for the network device policy distribution abnormality based on the abnormality level and abnormal pattern of the network device policy distribution.
[0020] Furthermore, the present invention utilizes the constructed anomaly detection model to perform real-time anomaly detection, which can timely discover potential problems in the current log data, improve the efficiency and accuracy of anomaly discovery, and provide data support for subsequent data analysis; the present invention can determine the abnormal pattern of network device policy distribution by analyzing the abnormal logs in the current log data, and provide an important reference for subsequent problem solving and prevention; the present invention analyzes and evaluates the degree of anomaly, and can quantify the severity of the network device policy distribution anomaly, helping administrators to prioritize high-risk problems; based on the comprehensive analysis of anomaly levels and anomaly patterns, the present invention can intelligently determine the response method for network device policy distribution anomalies, and improve response efficiency and accuracy; by continuously monitoring and analyzing abnormal data, the present invention can discover the trend of potential problems and take preventive measures in time, thereby improving the stability and security of network device operation; Overall, the present invention can help improve the automation level, fault handling efficiency and system security of network device management, and provide better support and decision-making basis for network operation and maintenance personnel.
[0021] In an embodiment of the present application, a network device policy distribution anomaly detection and response method is provided, which obtains historical log data in the network device policy distribution process, filters the historical log data, and determines abnormal log data in the historical log data, including: obtaining historical log data in the network device policy distribution process from a log database, and preprocessing the historical log data, the preprocessing including data cleaning, formatting and parsing; filtering the preprocessed historical log data by using an anomaly detection algorithm, and determining the filtered abnormal data points as abnormal log data in the historical log data.
[0022] Specifically, historical log data from the network device policy distribution process is extracted from the log database. These logs typically contain information such as device operating status, event records, and configuration changes. Data cleansing is first performed to remove incomplete, duplicate, or invalid log entries to ensure data integrity and accuracy. The log data is formatted to conform to a unified data format for easy processing and analysis. The log data is parsed to extract key information, such as timestamps, event types, and device IDs, for subsequent analysis and anomaly detection. Anomaly detection algorithms (such as Isolation Forest, LOF, and One-Class Support Vector Machine) are then used to analyze and filter the preprocessed historical log data to identify anomalous data points. Anomaly detection algorithms identify unusual patterns or deviations in the data, helping to identify data points that deviate from normal behavior and may indicate potential problems or anomalies. This step, through data cleansing, formatting, and anomaly detection algorithms, improves the accuracy of anomaly data identification and reduces false positives. Preprocessing and anomaly detection help administrators promptly identify anomalies in historical log data, providing early warnings and enabling appropriate action. Anomaly detection algorithms can automatically filter and identify anomalies in historical log data, reducing administrator workload and improving efficiency. Through the above process, administrators can extract anomalies from historical log data, providing important reference for subsequent anomaly analysis, problem troubleshooting and network device management, helping to improve network security and stability.
[0023] In an embodiment of the present application, a network device policy distribution anomaly detection and response method is provided, which extracts abnormal data features from abnormal log data and constructs an anomaly detection model based on the extracted abnormal data features and a preset neural network model, including: obtaining a preset feature extraction model, and extracting abnormal data features from the abnormal log data through the feature extraction model; constructing a data set based on the abnormal data features and historical temperature data, and inputting the data set into the preset neural network model to construct an initial anomaly detection model; dividing the data set into a training set and a test set according to a preset ratio, and inputting the training set and the test set into the initial anomaly detection model; training and testing the initial anomaly detection model until the initial anomaly detection model meets the preset convergence condition, thereby obtaining the anomaly detection model.
[0024] Specifically, the feature extraction model can be a pre-trained model used to extract key features from anomaly log data, such as timestamps, event types, and device IDs. The feature extraction model extracts anomaly data features from the anomaly log data. These features can help distinguish normal data from anomaly data, providing important information for subsequent anomaly detection. A dataset is constructed based on the anomaly data features and historical temperature data. The anomaly data features are combined with the historical data to form training and test sets. The dataset is input into a pre-set neural network model to construct an initial anomaly detection model, which is a deep learning model. The dataset is divided into training and test sets according to a certain ratio. The initial anomaly detection model is trained with the training set, and then the test set is used to verify and evaluate the model's performance. Through multiple training and testing cycles, the model parameters are adjusted until the model meets the preset convergence criteria, resulting in the final anomaly detection model. This step, through feature extraction and the neural network model, improves the accuracy of the anomaly detection model and effectively identifies anomaly data. Through training and testing, the anomaly detection model can have good generalization capabilities and adapt to different anomaly situations. The constructed anomaly detection model can automatically identify anomaly data, helping administrators quickly identify problems and take appropriate measures. Through the above process, the constructed anomaly detection model can effectively identify anomalies in the policy distribution process of network devices, improve network security and operational stability, and provide important decision-making support for the network management team.
[0025] In an embodiment of the present application, a network device policy distribution anomaly detection and response method is provided, which obtains current log data in the network device policy distribution process, performs anomaly detection based on an anomaly detection model, and determines abnormal log data in the current log data, including: obtaining current log data in the network device policy distribution process, and inputting the current log data into the anomaly detection model, which is detected and output by the anomaly detection model to obtain abnormal log data in the current log data.
[0026] In an embodiment of the present application, a network device policy distribution anomaly detection and response method is provided, which analyzes the abnormal log data in the current log data and determines the abnormal pattern of the network device policy distribution, including: obtaining a preset standard abnormal pattern of network device policy distribution, and determining the abnormal log data corresponding to the standard abnormal pattern, wherein the standard abnormal pattern includes policy distribution timeout, policy distribution interruption, policy distribution error, policy distribution conflict, policy distribution duplication, and incomplete policy distribution; calculating the similarity between the abnormal log data in the current log data and the abnormal log data of the standard abnormal pattern, and determining the standard abnormal pattern with the highest similarity between the data as the abnormal pattern of the network device policy distribution.
[0027] Specifically, a set of standard network device policy distribution anomaly patterns is pre-defined, including anomalies such as policy distribution timeouts, interruptions, errors, conflicts, duplications, and incompleteness. Each anomaly pattern is defined and described, and its corresponding anomaly log data characteristics are determined. For the anomaly log data in the current log data, the similarity between the characteristics of the anomaly log data and the standard anomaly patterns is calculated using various similarity metrics, such as cosine similarity, Euclidean distance, and Jaccard similarity. The anomaly log data in the current log data is then compared with the anomaly log data of the standard anomaly patterns one by one to calculate similarity. Ultimately, the standard anomaly pattern that is most similar to the current log data is determined as the anomaly pattern for network device policy distribution. By calculating anomaly pattern similarity, this step accurately identifies anomalies in the current log data and categorizes them into pre-defined standard anomaly patterns. Rapidly calculating anomaly pattern similarity can help administrators promptly detect anomalies, accelerating troubleshooting and problem resolution. The pre-defined standard anomaly patterns can be expanded and adjusted based on actual conditions, making the anomaly detection system more flexible and adaptable. Through the above process, administrators can quickly and accurately identify abnormal situations in the network device policy distribution process based on pre-set standard abnormal patterns and combined with real-time log data, thereby improving network management efficiency and operational stability.
[0028] In an embodiment of the present application, a network device policy distribution anomaly detection and response method is provided, which analyzes and evaluates the degree of abnormality in network device policy distribution based on the abnormal pattern to obtain a policy distribution anomaly degree value, including: determining the proportion of abnormal log data in current log data in the current log data, and evaluating the proportion to obtain the abnormality degree value of the abnormal log data in the current log data; obtaining the preset weight corresponding to the abnormal pattern, and multiplying the abnormality degree value of the abnormal log data in the current log data by the preset weight corresponding to the abnormal pattern to obtain the policy distribution anomaly degree value.
[0029] Specifically, the system determines the number of abnormal log data in the current log data and calculates its proportion of the total log data. This proportion is used to assess the importance and impact of the abnormality in the log data. The proportion of abnormal log data is evaluated and weights are preset for each abnormality pattern. These weights reflect the impact of different abnormalities on the system, which is then taken into account when calculating the abnormality severity value. The abnormality severity value of the abnormal log data in the current log data is multiplied by the preset weight of the abnormality pattern to obtain the policy distribution abnormality severity value. This value helps determine the severity and urgency of the abnormality. This step quantifies the abnormality by calculating the abnormality severity value, helping administrators more intuitively understand the severity of the abnormality. Based on the abnormality severity value, abnormalities can be prioritized, helping to prioritize the more severe abnormalities and improve troubleshooting efficiency. The abnormality severity value provides decision support for administrators, helping them quickly respond to and resolve abnormalities in network device policy distribution, thereby ensuring network stability. Through the above process, administrators can quickly and accurately assess the severity of abnormalities in the current log data based on the abnormality severity value and take targeted measures to improve the efficiency and response speed of abnormality handling in network device policy distribution.
[0030] In an embodiment of the present application, a network device policy distribution anomaly detection and response method is provided, which determines the anomaly level according to the policy distribution anomaly degree value, including: pre-setting an anomaly level-policy distribution anomaly degree value interval correspondence relationship, and associating a corresponding anomaly level for each policy distribution anomaly degree value interval; obtaining the policy distribution anomaly degree value, and based on the mapping relationship between the policy distribution anomaly degree value interval to which the policy distribution anomaly degree value belongs within the anomaly level-policy distribution anomaly degree value interval correspondence relationship, selecting the anomaly level corresponding to the policy distribution anomaly degree value interval as the corresponding anomaly level of the network device policy distribution.
[0031] Specifically, for each abnormality level, a corresponding policy distribution abnormality degree value interval is pre-set; the current policy distribution abnormality degree value is obtained, which can be obtained through the process of calculating the abnormality degree value before; according to the policy distribution abnormality degree value interval to which the policy distribution abnormality degree value belongs, the corresponding abnormality level is found in the abnormality level-policy distribution abnormality degree value interval correspondence; the abnormality level corresponding to the policy distribution abnormality degree value interval is selected as the abnormality level of the network device policy distribution, and this level can reflect the severity and urgency of the abnormal situation. This step can standardize the abnormality level by pre-setting the abnormality level-policy distribution abnormality degree value interval correspondence, so that it is associated with the abnormality degree value, which is convenient for administrators to understand and handle abnormal situations; using a unified abnormality level standard can make different abnormal situations have consistent measurement and comparison standards, helping administrators to quickly judge the urgency of abnormal situations; abnormality levels can provide decision support for administrators, helping them to prioritize abnormal situations with higher severity and improve fault handling efficiency. Through the above process, administrators can map the policy distribution anomaly degree value to the corresponding anomaly level based on the pre-set anomaly level-policy distribution anomaly degree value interval correspondence, so as to more intuitively understand the severity and urgency of the anomaly situation, take corresponding measures in a targeted manner, and improve the efficiency and response speed of network device policy distribution anomaly handling.
[0032] In an embodiment of the present application, a network device policy distribution anomaly detection and response method is provided, which comprehensively determines the response method of the network device policy distribution anomaly based on the anomaly level and anomaly mode of the network device policy distribution, including: determining the level of the anomaly level, and determining the notification method corresponding to the network device policy distribution anomaly according to the level of the anomaly level; if the anomaly level is level one, the notification method corresponding to the network device policy distribution anomaly is to send an email notification of the network device policy distribution anomaly, and prompt to quickly handle the anomaly; if the anomaly level is level two, the notification method corresponding to the network device policy distribution anomaly is to send an SMS notification of the network device policy distribution anomaly, and prompt to urgently handle the anomaly; if the anomaly level is level three, the notification method corresponding to the network device policy distribution anomaly is to send a telephone notification of the network device policy distribution anomaly, and prompt to immediately handle the anomaly; determining the response means corresponding to the network device policy distribution anomaly according to the anomaly mode; if the anomaly mode is policy distribution timeout, the response means to the network device policy distribution anomaly is to check the network connection and device load load situation, retry the policy distribution operation; if the abnormal mode is policy distribution interruption, the response means for the network device policy distribution abnormality is to restart the policy distribution operation and change to a stable network connection; if the abnormal mode is policy distribution error, the response means for the network device policy distribution abnormality is to analyze the specific content of the erroneous policy and correct the error in the specific content; if the abnormal mode is policy distribution conflict, the response means for the network device policy distribution abnormality is to analyze the specific content of the conflicting policy and adjust the priority of policy distribution; if the abnormal mode is policy distribution duplication, the response means for the network device policy distribution abnormality is to stop the repeated distribution, determine the specific content of the repeated policy distribution, and delete the repeated distribution content; if the abnormal mode is incomplete policy distribution, the response means for the network device policy distribution abnormality is to check the distribution log, confirm whether the policy distribution content is complete, and re-distribute the missing content; the notification method corresponding to the network device policy distribution abnormality and the response means corresponding to the network device policy distribution abnormality constitute the response method for the network device policy distribution abnormality.
[0033] Specifically, determine the abnormality level and the corresponding notification method. For level one abnormality, send an email notification to prompt the abnormality to be handled quickly; for level two abnormality, send a text message notification to prompt the abnormality to be handled urgently; for level three abnormality, send a phone notification to prompt the abnormality to be handled immediately; determine the abnormality mode and the corresponding response means. If the policy distribution times out, check the network connection and device load, and try the policy distribution operation again; if the policy distribution is interrupted, restart the policy distribution operation and switch to a stable network connection; if the policy distribution is wrong, analyze the specific content of the wrong policy and correct the error; if the policy distribution conflicts, analyze the specific content of the conflicting policy and adjust the priority of the policy distribution; if the policy distribution is repeated, stop the repeated distribution, determine the specific content of the repeated policy distribution, and delete the repeated distribution content; if the policy distribution is incomplete, check the distribution log, confirm whether the policy distribution content is complete, and re-issue the missing content; combine the notification method corresponding to the abnormality level and the response means corresponding to the abnormality mode to form a response method for network device policy distribution abnormalities. This step, by setting different exception levels and corresponding notification methods, allows administrators to quickly understand the urgency of the exception and take appropriate measures. Selecting different notification methods based on the exception level ensures that the exception is promptly communicated to relevant personnel. Selecting appropriate response methods based on the exception pattern helps administrators effectively handle various exceptions, reduce fault recovery time, and improve system stability. Through the above process, administrators can quickly and accurately respond to network device policy distribution anomalies based on the exception level and pattern. By setting different notification methods and response methods, the efficiency and accuracy of exception handling are improved, ensuring the normal operation and stability of network device policy distribution.
[0034] like Figure 2 As shown, in an embodiment of the present application, a network device policy distribution anomaly detection and response system is provided, including: an acquisition module for acquiring historical log data in the process of network device policy distribution, and screening the historical log data to determine abnormal log data in the historical log data; a modeling module for extracting abnormal data features from the abnormal log data, and building an anomaly detection model based on the extracted abnormal data features and a preset neural network model; a detection module for acquiring current log data in the process of network device policy distribution, and performing anomaly detection based on the anomaly detection model to determine abnormal log data in the current log data; an analysis module for analyzing the abnormal log data in the current log data to determine the abnormal pattern of network device policy distribution; a determination module for analyzing and evaluating the degree of abnormality of network device policy distribution based on the abnormal pattern, obtaining a policy distribution abnormality degree value, and determining the abnormality level according to the policy distribution abnormality degree value; a response module for comprehensively determining a response method for the network device policy distribution abnormality based on the abnormality level and abnormal pattern of network device policy distribution.
[0035] In summary, an embodiment of the present invention provides a network device policy distribution anomaly detection and response method and system, which includes: obtaining historical log data in the network device policy distribution process, and screening it to determine abnormal log data; determining the abnormal data characteristics of the abnormal log data, and building an anomaly detection model based on it and a preset neural network model, and detecting the current log data based on it to obtain abnormal log data; analyzing the abnormal log data to determine the abnormal pattern of network device policy distribution; analyzing and evaluating the degree of abnormality of network device policy distribution based on the abnormal pattern, obtaining a policy distribution abnormality degree value, and determining the abnormality level; comprehensively determining the response method based on the abnormality level and abnormal pattern. The present invention detects abnormal log data in log data by building an anomaly detection model, and further analyzes it to determine the abnormal pattern and normality value, so as to accurately determine the response method and improve response efficiency and accuracy.
[0036] Finally, it should be noted that it is apparent that various modifications and variations may be made by those skilled in the art without departing from the spirit and scope of the present invention. Thus, the present invention is intended to include such modifications and variations as long as they fall within the scope of the present invention and its equivalents.
[0037] The above description is only an example of an embodiment of the present invention, but it does not limit the scope of the present invention. Any structural changes made according to the present invention, as long as they do not lose the essence of the present invention, should be considered to fall within the scope of protection of the present invention and be subject to restrictions. Technical personnel in the relevant technical field can clearly understand that for the convenience and simplicity of description, the specific working process and related instructions of the platform described above can refer to the corresponding process in the aforementioned platform embodiment, and will not be repeated here.
[0038] The term "comprise," "comprising," or any other similar term is intended to cover a non-exclusive inclusion such that a process, platform, article, or apparatus / platform that comprises a list of elements includes not only those elements but also other elements not expressly listed or inherent to such process, platform, article, or apparatus / platform.
[0039] Thus far, the technical solutions of the present invention have been described in conjunction with the further embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art may make equivalent changes or substitutions to closely related technical features, and the technical solutions after such changes or substitutions will fall within the scope of protection of the present invention.
[0040] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention.
Claims
1. A network device policy distribution anomaly detection and response method, characterized in that: include: Obtain historical log data during the network device policy distribution process, and filter the historical log data to identify abnormal log data in the historical log data; Extract abnormal data features from abnormal log data, and build an anomaly detection model based on the extracted abnormal data features and a preset neural network model; Obtain current log data during the network device policy distribution process, and perform anomaly detection based on an anomaly detection model to determine abnormal log data in the current log data; Analyze abnormal log data in the current log data to determine abnormal patterns in network device policy distribution; Analyze and evaluate the degree of abnormality of network device policy distribution based on the abnormal pattern, obtain a policy distribution abnormality value, and determine the abnormality level according to the policy distribution abnormality value; The response method for the network device policy distribution anomaly is comprehensively determined based on the anomaly level and anomaly mode of the network device policy distribution.
2. A network device policy distribution anomaly detection and response method according to claim 1, characterized in that: The obtaining of historical log data during the network device policy distribution process, screening the historical log data, and determining abnormal log data in the historical log data includes: Obtain historical log data from the network device policy distribution process from the log database and preprocess the historical log data, including data cleaning, formatting, and parsing; The pre-processed historical log data is filtered by using an anomaly detection algorithm, and the filtered abnormal data points are determined as abnormal log data in the historical log data.
3. A network device policy distribution anomaly detection and response method according to claim 2, characterized in that: The method of extracting abnormal data features from abnormal log data and building an abnormality detection model based on the extracted abnormal data features and a preset neural network model includes: Obtain a pre-set feature extraction model, and extract abnormal data features from abnormal log data through the feature extraction model; A data set is constructed based on the abnormal data characteristics and historical temperature data, and the data set is input into a preset neural network model to build an initial anomaly detection model; The dataset is divided into a training set and a test set according to a preset ratio, and the training set and the test set are input into the initial anomaly detection model; The initial anomaly detection model is trained and tested until the initial anomaly detection model meets the preset convergence conditions to obtain an anomaly detection model.
4. A network device policy distribution anomaly detection and response method according to claim 3, characterized in that: The obtaining of current log data in the process of distributing network device policies, and performing anomaly detection based on an anomaly detection model to determine abnormal log data in the current log data includes: The current log data in the process of network device policy distribution is obtained, and the current log data is input into the anomaly detection model. The anomaly detection model detects and outputs the anomaly log data in the current log data.
5. A network device policy distribution anomaly detection and response method according to claim 4, characterized in that: The analyzing of abnormal log data in the current log data to determine abnormal patterns of network device policy distribution includes: Obtaining a pre-set standard abnormal pattern of network device policy distribution and determining abnormal log data corresponding to the standard abnormal pattern, wherein the standard abnormal pattern includes policy distribution timeout, policy distribution interruption, policy distribution error, policy distribution conflict, policy distribution duplication, and incomplete policy distribution; The similarity between the abnormal log data in the current log data and the abnormal log data of the standard abnormal pattern is calculated, and the standard abnormal pattern with the highest similarity between the data is determined as the abnormal pattern for network device policy distribution.
6. A network device policy distribution anomaly detection and response method according to claim 5, characterized in that: The analyzing and evaluating the abnormality degree of the network device policy distribution based on the abnormality pattern to obtain the policy distribution abnormality degree value includes: Determine the proportion of abnormal log data in the current log data, and evaluate the proportion to obtain an abnormality degree value of the abnormal log data in the current log data; The preset weight corresponding to the abnormal pattern is obtained, and the abnormal degree value of the abnormal log data in the current log data is multiplied by the preset weight corresponding to the abnormal pattern to obtain the policy distribution abnormal degree value.
7. A network device policy distribution anomaly detection and response method according to claim 6, characterized in that: The determining of the abnormality level according to the policy-based distribution abnormality degree value includes: Pre-set abnormality level-strategy distribution abnormality value interval correspondence For each strategy distribution abnormality value interval, a corresponding abnormality level is associated; Obtain the policy distribution abnormality degree value, and based on the mapping relationship between the policy distribution abnormality degree value interval to which the policy distribution abnormality degree value belongs and the abnormality level-policy distribution abnormality degree value interval correspondence, select the abnormality level corresponding to the policy distribution abnormality degree value interval as the corresponding abnormality level of the network device policy distribution.
8. A network device policy distribution anomaly detection and response method according to claim 7, characterized in that: The method of comprehensively determining a response method to an abnormality in network device policy distribution based on the abnormality level and abnormality mode of the network device policy distribution includes: Determine the level of the abnormality, and determine the notification method corresponding to the network device policy distribution abnormality according to the abnormality level; If the exception level is level 1, the corresponding notification method for the network device policy distribution exception is to send an email notification of the network device policy distribution exception and prompt to quickly handle the exception; If the abnormality level is level 2, the corresponding notification method for the network device policy distribution abnormality is to send a text message notification of the network device policy distribution abnormality and prompt to handle the abnormality urgently; If the abnormality level is level three, the corresponding notification method for the network device policy distribution abnormality is to issue a telephone notification of the network device policy distribution abnormality and prompt to handle the abnormality immediately; Determine the response means corresponding to the network device policy distribution anomaly based on the anomaly pattern; If the exception mode is policy distribution timeout, the response to the network device policy distribution exception is to check the network connection and device load, and retry the policy distribution operation; If the abnormal mode is policy distribution interruption, the response to the network device policy distribution abnormality is to restart the policy distribution operation and switch to a stable network connection; If the abnormal pattern is a policy distribution error, the response means for the network device policy distribution abnormality is to analyze the specific content of the erroneous policy and correct the error in the specific content; If the abnormal mode is a policy distribution conflict, the response method for the network device policy distribution abnormality is to analyze the specific content of the conflicting policy and adjust the priority of policy distribution; If the abnormal pattern is repeated policy distribution, the response means for the abnormal policy distribution of the network device is to stop the repeated distribution, determine the specific content of the repeated policy distribution, and delete the repeated distribution content; If the abnormal mode is incomplete policy distribution, the response means for the network device policy distribution abnormality is to check the distribution log to confirm whether the policy distribution content is complete and re-distribute the missing content; The notification method corresponding to the network device policy distribution exception and the response means corresponding to the network device policy distribution exception constitute the response method of the network device policy distribution exception.
9. A network device policy distribution anomaly detection and response system, characterized in that: include: An acquisition module is used to obtain historical log data during the network device policy distribution process, and to filter the historical log data to determine abnormal log data in the historical log data; A modeling module is used to extract abnormal data features from abnormal log data and build an anomaly detection model based on the extracted abnormal data features and a preset neural network model; The detection module is used to obtain the current log data in the process of network device policy distribution, and perform anomaly detection based on the anomaly detection model to determine the abnormal log data in the current log data; An analysis module is used to analyze abnormal log data in the current log data and determine abnormal patterns of network device policy distribution; A determination module is used to analyze and evaluate the degree of abnormality of network device policy distribution based on the abnormal pattern, obtain a policy distribution abnormality degree value, and determine the abnormality level according to the policy distribution abnormality degree value; The response module is used to comprehensively determine the response method of the network device policy distribution anomaly based on the anomaly level and anomaly mode of the network device policy distribution.