Enterprise network diagnosis report management system based on data analysis
Through the enterprise network diagnostic report management system of data analysis, real-time monitoring and comprehensive analysis of the enterprise network, the problem of manual diagnosis in the existing technology is solved, and accurate network failure detection and potential problem prediction is achieved to ensure the stable operation of enterprise business.
Patent Information
- Application Number
- CN202510632485.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2045-05-16
AI Technical Summary
The network diagnosis of existing enterprises relies on manual inspection, which is time-consuming and labor-intensive and prone to missed inspections, and cannot monitor network performance in real time, resulting in inaccurate diagnosis and affecting business operations.
The enterprise network diagnostic report management system based on data analysis is adopted, including data acquisition, storage, processing, analysis and report generation modules, to build a scoring system, monitor and generate structured reports in real time, provide a visual interface, and identify network problems through comprehensive analysis of multiple parameters.
Real-time and accurate network failure detection and potential problem prediction are achieved, reducing human negligence and ensuring the normal operation of enterprise business.
Smart Images

Figure CN120498972A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network management, and in particular relates to an enterprise network diagnosis report management system based on data analysis. Background Art
[0002] Currently, enterprises are accelerating their digital transformation and expanding their networks. Different departments and business scenarios have varying network requirements, leading to increasingly complex network architectures, a significant increase in the number of network nodes, and an increasingly complex network environment. To ensure that enterprises can achieve normal data exchange and business collaboration, network troubleshooting is necessary to optimize network performance.
[0003] Existing enterprise network diagnostics primarily rely on administrators manually checking network device status, port connectivity, and device logs. When a network failure occurs, administrators must troubleshoot each network node individually, a time-consuming and labor-intensive process that can easily lead to missing critical information due to negligence, resulting in inaccurate diagnostics and disrupting the normal operation of the enterprise's business. Furthermore, traditional diagnostic methods are often performed post-facto, meaning they only investigate and repair network failures after they have already occurred and significantly impacted business operations. This inability to comprehensively monitor network performance indicators in real time prevents the timely identification of potential network risks, which can easily lead to losses for the enterprise's business. Summary of the Invention
[0004] The purpose of the present invention is to provide an enterprise network diagnosis report management system based on data analysis to solve the problems faced in the above background technology.
[0005] The purpose of the present invention can be achieved through the following technical solutions:
[0006] An enterprise network diagnosis report management system based on data analysis, the system includes: a data acquisition module, a data storage and processing module, a data analysis module and a report generation module;
[0007] The data acquisition module is used to collect the operation data of the enterprise network in real time and upload it to the data storage and processing module;
[0008] The data storage and processing module is used to process the acquired operation data and store the acquired operation data;
[0009] The data analysis module is used to analyze the acquired operation data to identify network problems and generate diagnostic results;
[0010] The report generation module is used to convert the diagnosis results into a structured report and provide a visual interface for users to view.
[0011] Furthermore, the data analysis module works as follows:
[0012] First, a scoring system is constructed based on historical data and data from big data. Each operating data has its own corresponding scoring system, and the higher the score, the worse the operating data condition.
[0013] Obtain various operational data of the enterprise network and input them into the constructed scoring system to obtain scores for each operational data item. These scores are then compared with the fault scoring thresholds for each operational data item. When the obtained scores exceed the fault scoring thresholds, a problem is diagnosed with the operational data item and a diagnostic fault is generated.
[0014] Furthermore, the data analysis module working method also includes:
[0015] When no type 1 fault is generated, the scores of various operating data within the Δt time are obtained and divided into multiple feature libraries LD according to the data source. Each feature library corresponds to the corresponding operating data score value XH of each project type. j , where the mathematical expression of the running data score value of each project type is: The corresponding feature library expression is: LD = (XH1, ..., XH j ,…,XH m ), where α1 and α2 are weight coefficients, is the average score of the running data of the corresponding project type within Δt time, maxPF is the highest score of the running data of the corresponding project type within Δt time, th is the duration of the highest score, m is the total number of project types in the corresponding type library, and j∈[1,m];
[0016] First, the operating data score of each project type is compared with the respective preset score thresholds. If the preset score threshold is exceeded, it is diagnosed that there is a problem with the operating data and a second-class diagnostic fault is generated;
[0017] Otherwise, by formula Obtain the running score LD of each feature library XH , and then compare the operation scores of each feature library with their respective preset operation score thresholds. When the preset operation score threshold is exceeded, it is determined that there is a problem with the operation data of the feature library, and three types of diagnostic faults are generated;
[0018] Otherwise, by formula The network operation score is obtained; then it is compared with the preset network operation score threshold. When the network operation score threshold is exceeded, it is judged that there is a problem with the entire network operation data, and four types of diagnostic faults are generated. Where n is the number of feature libraries, Score the running of the i-th feature library, and i∈[1,n].
[0019] Furthermore, the data analysis module is also used to diagnose potential problems of the enterprise network based on the obtained operation scores of each feature library when no diagnostic fault is generated.
[0020] Furthermore, the method by which the data analysis module diagnoses potential problems of the enterprise network is:
[0021] Continuously obtain the running score PM of the feature library within x Δt time periods LD , and formulate the curve function PM of running score changing with time period LD (x);
[0022] By formula Obtain the potential fault value YU;
[0023] When YU>YU z When , it indicates that there is a potential problem in the enterprise network, and five types of diagnostic faults are generated;
[0024] Among them, τ is the stability coefficient, maxK is PM LD The maximum slope value of (x), minK is PM LD (x), ΔK is the slope comparison value, x b is the last Δt time period, YU is the preset running score threshold function. z The potential fault judgment threshold is set.
[0025] Furthermore, the stability coefficient τ is obtained as follows:
[0026] By formula The stability coefficient τ is obtained;
[0027] Where b is the total number of Δt time periods, and s∈[1,b], The running score of the feature library obtained for the s-th Δt period.
[0028] Furthermore, the report generation module is provided with an alarm unit, which generates a corresponding alarm according to the generated diagnostic fault;
[0029] When a Class I diagnostic fault and a Class II diagnostic fault are generated, a Class I alarm is generated; when a Class III diagnostic fault and a Class IV diagnostic fault are generated, a Class II alarm is generated; when a Class V diagnostic fault is generated, a Class III alarm is generated.
[0030] Beneficial effects of the present invention:
[0031] The present invention can not only monitor various operating parameters of the enterprise network online in real time, but also immediately issue an alarm once an anomaly is detected, thereby quickly determining the cause of the anomaly. It can also conduct comprehensive analysis based on multiple parameters to more accurately judge the operating status of the enterprise network, reducing the occurrence of inaccurate diagnosis caused by personnel negligence and omission of key information, thereby ensuring the normal operation of the enterprise business.
[0032] The present invention can not only perform real-time inspections on the enterprise network to discover relatively abnormal fault problems, but also diagnose subtle fault problems and potential fault problems of the enterprise network, thereby discovering faults in a timely manner and taking corresponding measures to ensure the normal operation of the enterprise business.
[0033] Of course, any product implementing the present invention does not necessarily need to achieve all of the advantages described above at the same time. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0035] Figure 1 This is a system structure diagram of the present invention. DETAILED DESCRIPTION
[0036] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.
[0037] In one embodiment, an enterprise network diagnostic report management system based on data analysis is disclosed, such as Figure 1 As shown, the management system includes: a data acquisition module, a data storage and processing module, a data analysis module and a report generation module;
[0038] The data acquisition module is used to collect the operation data of the enterprise network in real time and upload it to the data storage and processing module;
[0039] The data storage and processing module is used to process and store the acquired operation data;
[0040] The data analysis module is used to analyze the acquired operation data to identify network problems and generate diagnostic results;
[0041] The report generation module is used to convert the diagnostic results into a structured report and provide a visual interface for users to view.
[0042] Through the above technical solution, this application first obtains data information related to the operation status of the enterprise network from multiple source data ports, and uploads it to the data storage and processing module for data processing. Data processing includes data cleaning, deletion, normalization, etc., so that standard data information with consistent format can be obtained, which is convenient for subsequent data analysis. At the same time, the acquired data and the analysis results are stored, thereby providing more judgment basis for subsequent analysis. Then the data analysis module analyzes the acquired operation data, including real-time analysis and cumulative analysis, etc., to determine whether there are corresponding problems in the enterprise network, thereby converting the diagnostic results into a structured report and providing a visual interface for users to view. In this way, the present application can monitor various operating parameters of the enterprise network online in real time. Once an anomaly is detected, an alarm can be issued immediately to quickly determine the cause of the anomaly. It can also combine multiple parameters for comprehensive analysis to accurately judge the operating status of the enterprise network, reducing the occurrence of inaccurate diagnosis caused by personnel negligence and omission of key information, thereby ensuring the normal operation of the enterprise business; at the same time, the present application can not only check the enterprise network in real time to discover relatively abnormal fault problems, but also diagnose the enterprise network's less obvious fault problems and potential fault problems, so as to discover the fault in time and deal with it early, ensuring the normal operation of the enterprise business.
[0043] The data analysis module works as follows: First, a scoring system is constructed based on historical data and data from big data. Each operating data has its own corresponding scoring system, and the higher the score, the worse the operating data condition.
[0044] Obtain various operational data of the enterprise network and input them into the constructed scoring system to obtain scores for each operational data item. These scores are then compared with the fault scoring thresholds for each operational data item. When the obtained scores exceed the fault scoring thresholds, a problem is diagnosed with the operational data item and a diagnostic fault is generated.
[0045] The above solution provides a method for the data analysis module to diagnose more obvious fault problems. First, a scoring system is constructed based on historical data and data in big data. Each operating data has its own corresponding scoring system, and the higher the score, the worse the operating data condition. Then, various operating data of the enterprise network, such as bandwidth utilization, protocol distribution, abnormal traffic, DDoS attacks, abnormal login attempts, etc., are obtained and input into the corresponding scoring system to obtain a score for each operating data. Then, the obtained score is compared with the fault scoring threshold of each operating data. When the obtained score exceeds the fault scoring threshold, it indicates that the parameter of this type is abnormal. The operating data is diagnosed as having a problem and a type of diagnostic fault is generated. For example, if the input bandwidth utilization score is 5, its fault scoring threshold is set to 4. At this time, it indicates that the bandwidth utilization is significantly abnormal, so an alarm is generated to remind you to restore the network in time and ensure the normal operation of the network.
[0046] The working method of the data analysis module also includes: when a type of diagnostic fault is not generated, obtaining the scores of various operating data within the Δt time, and dividing them into multiple feature libraries LD according to the data source, each feature library corresponds to the corresponding operating data score value XH of each project type j , where the mathematical expression of the running data score value of each project type is: The corresponding feature library expression is: LD = (XH1, ..., XH j ,…,XH m ), where α1 and α2 are weight coefficients, is the average score of the running data of the corresponding project type within Δt time, maxPF is the highest score of the running data of the corresponding project type within Δt time, th is the duration of the highest score, m is the total number of project types in the corresponding type library, and j∈[1,m];
[0047] First, the operating data score of each project type is compared with the respective preset score thresholds. If the preset score threshold is exceeded, it is diagnosed that there is a problem with the operating data and a second-class diagnostic fault is generated;
[0048] Otherwise, by formula Obtain the running score LD of each feature library XH , and then compare the operation scores of each feature library with their respective preset operation score thresholds. When the preset operation score threshold is exceeded, it is determined that there is a problem with the operation data of the feature library, and three types of diagnostic faults are generated;
[0049] Otherwise, by formula The network operation score is obtained; then it is compared with the preset network operation score threshold. When the network operation score threshold is exceeded, it is judged that there is a problem with the entire network operation data, and four types of diagnostic faults are generated. Where n is the number of feature libraries, Score the running of the i-th feature library, and i∈[1,n].
[0050] The above scheme provides a method for the data analysis module to diagnose non-obvious fault problems. The above generation of a type of diagnostic fault is only applicable to the judgment of real-time and relatively obvious abnormal problems, and cannot identify non-obvious faults. For example, the score of a certain project type has been high in a certain period of time but no alarm has been issued. This also indicates that there is a problem with the network. Therefore, when a type of diagnostic fault is not generated, the scores of various operating data within the Δt time are obtained. First, the data is divided into multiple feature libraries LD according to the source. Each feature library corresponds to the corresponding operating data score value XH of each project type. j , where the mathematical expression of the running data score value of each project type is: The corresponding feature library expression is: LD = (XH1, ..., XH j ,…,XH m ), where α1 and α2 are weight coefficients, is the average score of the operation data of the corresponding project type within Δt time, maxPF is the highest score of the operation data of the corresponding project type within Δt time, th is the duration of the highest score, and m is the total number of project types in the corresponding type library. For example, according to the network device log situation, traffic monitoring situation, security event situation, and application performance situation, there are four feature libraries. Each corresponding feature library has multiple project type parameters. For example, in the case of security events, the alarm data of the IDS / IPS system can be integrated to obtain data information such as the number of DDoS attacks, the number of abnormal login attempts, and the number of system vulnerabilities. Then, through the formula The operation data score value of each project type is obtained. It combines the average score of a single project type within the Δt time, the maximum score, and the duration of the maximum score for a comprehensive analysis. It can more accurately indicate the operation status of a single type within the Δt time. Obviously, the larger the value, the greater the possibility of a fault. α1 and α2 in the formula are determined based on experience. For example, if the maximum score lasts for a long time within a certain period of time, then a higher weight can be assigned, such as α2 = 0.6 and α1 = 0.4. If the average score within a certain period of time is large, then α2 = 0.45 and α1 = 0.55 can be set. The specific assignment is determined according to the specific situation and will not be described in detail here. After obtaining the operation data score value of each project type, the operation data score value of each project type is first compared with the respective preset score threshold. When the preset score threshold is exceeded, it is diagnosed that there is a problem with the operation data and a second-class diagnostic fault is generated. In this way, fault problems that are not obvious for a single project type can be diagnosed, thereby more accurately judging the operation status of each project type and avoiding omissions. Then if no second-class diagnostic fault is generated, the formula Obtain the running score LD of each feature library XH , and then compare the operation scores of each feature library with their respective preset operation score thresholds. When the preset operation score threshold is exceeded, it is determined that there is a problem with the operation data of the feature library, and three types of diagnostic faults are generated; it comprehensively analyzes the operation data of all project types in the entire feature library, which can provide a more comprehensive perspective on the problem to diagnose the enterprise network and discover difficult-to-find faults to ensure the performance of the enterprise network. Similarly, when the three types of diagnostic faults are not generated, the formula The operation score of the entire network is obtained; it is then compared with the preset network operation score threshold. When the network operation score threshold is exceeded, it is judged that there is a problem with the entire network operation data and four types of diagnostic faults are generated; it comprehensively analyzes the operation status of all feature libraries of the entire enterprise network, and can diagnose not only surface abnormalities of the entire enterprise network, but also timely carry out maintenance to ensure the normal operation of the enterprise network.
[0051] The data analysis module is also used to diagnose potential problems in the enterprise network based on the operation scores of each feature library when no diagnostic fault is generated. The diagnosis method is as follows:
[0052] Continuously obtain the running score PM of the feature library within x Δt time periods LD , and formulate the curve function PM of running score changing with time period LD (x);
[0053] By formula Obtain the potential fault value YU;
[0054] When YU>YU z When , it indicates that there is a potential problem in the enterprise network, and five types of diagnostic faults are generated;
[0055] Among them, τ is the stability coefficient, maxK is PM LD The maximum slope value of (x), minK is PM LD (x), ΔK is the slope comparison value, x b is the last Δt time period, YU is the preset running score threshold function. z To set the potential fault judgment threshold, the stability coefficient τ is obtained by: The stability coefficient τ is obtained;
[0056] Where b is the total number of Δt time periods, and s∈[1,b], The running score of the feature library obtained for the s-th Δt period.
[0057] The above solution provides a method for diagnosing potential problems of the enterprise network by using a data analysis module. Since the first to fourth diagnostic faults are all for diagnosing faults that have already occurred, they cannot predict potential faults. Therefore, when no diagnostic fault is generated, this embodiment continuously obtains the running score PM of the feature library within x Δt time periods. LD , and formulate the curve function PM of running score changing with time period LD (x), and by the formula The potential fault value YU is obtained; where τ is the stability coefficient, maxK is PM LD The maximum slope value of (x), minK is PM LD (x), ΔK is the slope comparison value, determined based on experimental comparison data, x b is the last Δt time period, YU is the preset running score threshold function. z is the potential fault judgment threshold set, both of which can be formulated based on empirical data and mechanical energy; in the formula It is expressed as the difference between the proposed running score change and the preset running score threshold change. It represents the change trend of the proposed operation score. Although the obtained operation score exceeds the alarm threshold, if the operation score is always near the alarm threshold and gradually increases, it means that the possibility of potential failure is greater. Therefore, when as well as The larger the value of is, the greater the possibility of potential failure in the enterprise network under this feature. It is expressed as the stability of the operation score of the feature library in x Δt time periods. The larger the value, the more unstable it is, indicating that the greater the fluctuation of the operation score, and the greater the possibility of potential failure in the enterprise network under this feature. Therefore, after obtaining the potential failure value YU, it is compared with the set potential failure judgment threshold YU z Compare, when YU>YU z When the score is 0, it indicates that there is a potential problem in the enterprise network, and five types of diagnostic faults are generated. This method can comprehensively analyze the changing trends, fluctuations, and changes in the operation scores of each feature, accurately diagnosing potential faults in the enterprise network, thereby issuing timely alarms and taking appropriate measures to eliminate hidden dangers and reduce business losses.
[0058] An alarm unit is provided in the report generation module, and the alarm unit issues corresponding alarms according to the generated diagnostic faults; when a Class I diagnostic fault and a Class II diagnostic fault are generated, a Class I alarm is generated; when a Class III diagnostic fault and a Class IV diagnostic fault are generated, a Class II alarm is generated; when a Class V diagnostic fault is generated, a Class III alarm is generated.
[0059] In the above scheme, the severity and processing priority of the first-level alarm are higher than those of the second-level alarm. Similarly, the severity and processing priority of the second-level alarm are higher than those of the third-level alarm. By diagnosing faults and classifying alarms into levels, it is possible to clearly judge more obvious faults, less obvious faults and potential faults, distinguish the priority and processing priorities, and ensure the timely recovery of the enterprise network.
[0060] It should be noted that, in order to facilitate analysis and calculation, the above calculation expressions are dimensionless operations performed after the units are selected in advance.
[0061] The above content is merely an example and explanation of the concept of the present invention. Those skilled in the art may make various modifications or additions to the described specific embodiments or replace them in a similar manner. As long as they do not deviate from the concept of the invention or exceed the scope defined by the claims, they should all fall within the scope of protection of the present invention.
Claims
1. An enterprise network diagnosis report management system based on data analysis, characterized in that: The system includes: a data acquisition module, a data storage and processing module, a data analysis module and a report generation module; The data acquisition module is used to collect the operation data of the enterprise network in real time and upload it to the data storage and processing module; The data storage and processing module is used to process the acquired operation data and store the acquired operation data; The data analysis module is used to analyze the acquired operation data to identify network problems and generate diagnostic results; The report generation module is used to convert the diagnosis results into a structured report and provide a visual interface for users to view.
2. The enterprise network diagnosis report management system based on data analysis according to claim 1, characterized in that: The working method of the data analysis module is: First, a scoring system is constructed based on historical data and data from big data. Each operating data has its own corresponding scoring system, and the higher the score, the worse the operating data condition. Obtain various operational data of the enterprise network and input them into the constructed scoring system to obtain scores for each operational data item. These scores are then compared with the fault scoring thresholds for each operational data item. When the obtained scores exceed the fault scoring thresholds, a problem is diagnosed with the operational data item and a diagnostic fault is generated.
3. The enterprise network diagnosis report management system based on data analysis according to claim 2, characterized in that: The data analysis module working method also includes: When no type 1 fault is generated, the scores of various operating data within the Δt time are obtained and divided into multiple feature libraries LD according to the data source. Each feature library corresponds to the corresponding operating data score value XH of each project type. j , where the mathematical expression of the running data score value of each project type is: The corresponding feature library expression is: LD = (XH1, ..., XH j ,…,XH m ), where α1 and α2 are weight coefficients, is the average score of the running data of the corresponding project type within Δt time, maxPF is the highest score of the running data of the corresponding project type within Δt time, th is the duration of the highest score, m is the total number of project types in the corresponding type library, and j∈[1,m]; First, the operating data score of each project type is compared with the respective preset score thresholds. If the preset score threshold is exceeded, it is diagnosed that there is a problem with the operating data and a second-class diagnostic fault is generated; Otherwise, by formula Obtain the running score LD of each feature library XH , and then compare the operation scores of each feature library with their respective preset operation score thresholds. When the preset operation score threshold is exceeded, it is determined that there is a problem with the operation data of the feature library, and three types of diagnostic faults are generated; Otherwise, by formula The network operation score is obtained; then it is compared with the preset network operation score threshold. When the network operation score threshold is exceeded, it is judged that there is a problem with the entire network operation data, and four types of diagnostic faults are generated. Where n is the number of feature libraries, Score the running of the i-th feature library, and i∈1,n].
4. The enterprise network diagnosis report management system based on data analysis according to claim 3, characterized in that: The data analysis module is further configured to diagnose potential problems of the enterprise network based on the acquired operation scores of each feature library when no diagnostic fault is generated.
5. The enterprise network diagnosis report management system based on data analysis according to claim 4, characterized in that: The method by which the data analysis module diagnoses potential problems of the enterprise network is as follows: Continuously obtain the running score PM of the feature library within x Δt time periods LD , and formulate the curve function PM of running score changing with time period LD (x); By formula Obtain the potential fault value YU; When YU>YU z When , it indicates that there is a potential problem in the enterprise network, and five types of diagnostic faults are generated; Among them, τ is the stability coefficient, maxK is PM LD The maximum slope value of (x), minK is PM LD (x), ΔK is the slope comparison value, x b is the last Δt time period, YU is the preset running score threshold function. z The potential fault judgment threshold is set.
6. The enterprise network diagnosis report management system based on data analysis according to claim 5, characterized in that: The method for obtaining the stability coefficient τ is: By formula The stability coefficient τ is obtained; Where b is the total number of Δt time periods, and s∈[1,b], The running score of the feature library obtained for the s-th Δt period.
7. The enterprise network diagnosis report management system based on data analysis according to claim 6, characterized in that: The report generation module is provided with an alarm unit, which generates a corresponding alarm according to the generated diagnostic fault; When a Class I diagnostic fault and a Class II diagnostic fault are generated, a Class I alarm is generated; when a Class III diagnostic fault and a Class IV diagnostic fault are generated, a Class II alarm is generated; when a Class V diagnostic fault is generated, a Class III alarm is generated.
Citation Information
Patent Citations
High dimension visualized analysis method facing urban electric power data analysis
CN105184455A
Intelligent sewage treatment system and method based on data analysis
CN119398319A
Enterprise information security management system based on big data analysis
CN119539262A
Financial data security risk assessment method and system based on data analysis
CN119624662A
System and method for cyber security threat assessment
US20200358807A1