A data analysis-based enterprise network diagnosis report management system
By using a data-driven enterprise network diagnostic report management system, the system monitors and analyzes enterprise networks in real time, solving the problems of time-consuming, labor-intensive, and missed detections in existing technologies. It achieves accurate network fault detection and prediction of potential problems, ensuring the stable operation of enterprise business.
Patent Information
- Application Number
- CN202510632485.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-16
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2045-05-16
AI Technical Summary
Existing enterprise network diagnostics rely on manual inspections, which are time-consuming, labor-intensive, and prone to missing detections. They also cannot monitor network performance in real time, leading to inaccurate diagnostics and impacting business operations.
Design an enterprise network diagnostic report management system based on data analysis, including modules for data acquisition, storage, processing, analysis, and report generation. By constructing a scoring system and performing multi-source data analysis, the system can monitor and generate structured reports in real time and provide a visual interface.
It enables real-time online monitoring and anomaly alarms for enterprise networks, reduces human error in detection, and can promptly identify potential faults to ensure the normal operation of enterprise business.
Smart Images

Figure CN120498972B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of network management, and particularly relates to an enterprise network diagnosis report management system based on data analysis. BACKGROUND
[0002] At present, the process of enterprise digital transformation is accelerating, and the scale of enterprise network is expanding. Different departments and different business scenarios have different demands for the network, resulting in increasingly complex network architecture, a substantial increase in the number of network nodes, and increasingly complex network environment. In order to ensure that the enterprise can normally realize data interaction and business collaboration, it is necessary to diagnose the network to optimize the network performance.
[0003] The existing enterprise network diagnosis mainly relies on manual inspection of network equipment state, port connection and checking of equipment logs by administrators. When the network fails, the administrator needs to check each network node one by one, which is time-consuming and laborious, and is easy to miss key information due to human negligence, resulting in inaccurate diagnosis and affecting the normal operation of enterprise business. Moreover, most of the traditional diagnosis methods are post-processing, that is, the troubleshooting and repair are carried out after the network failure has occurred and has a significant impact on business. It cannot monitor the performance indicators of the network in real time and comprehensively, and cannot discover potential network risks in time, thus easily causing losses to the enterprise business. SUMMARY
[0004] The purpose of the present application is to provide an enterprise network diagnosis report management system based on data analysis to solve the problems in the background art.
[0005] The purpose of the present application can be achieved by the following technical solutions:
[0006] An enterprise network diagnosis report management system based on data analysis, comprising a data acquisition module, a data storage module, a data processing module, a data analysis module and a report generation module.
[0007] The data acquisition module is used to collect the running data of the enterprise network in real time and upload it to the data storage and processing module.
[0008] The data storage and processing module is used to process and store the acquired running data.
[0009] The data analysis module is used to analyze the acquired running data to identify network problems and generate diagnosis results.
[0010] The report generation module is used to convert the diagnosis results into structured reports and provide a visual interface for users to view.
[0011] Further, the data analysis module working method is:
[0012] Firstly, based on historical data and data in big data, a scoring system is constructed, each running data corresponds to a respective scoring system, and the higher the score, the worse the running data condition is;
[0013] Obtain each running data of the enterprise network, input into the constructed scoring system, obtain the score of each running data, and compare with the fault score threshold of each running data respectively, when the obtained score exceeds the fault score threshold, it is diagnosed that the running data has a problem, and a type of diagnostic fault is generated.
[0014] Further, the data analysis module working method further comprises:
[0015] When a type of fault is not generated, the scores of each running data within Δt time are obtained, and the data sources are divided into a plurality of feature libraries LD according to the data sources, each feature library corresponds to respective running data score values XH of each project type j , wherein the mathematical expression of the running data score value of each project type is: The corresponding feature library expression is: LD=(XH1, …, XH j , …, XH m ), wherein α1 and α2 are weight coefficients, is the average score of the running data of the corresponding project type within Δt time, maxPF is the highest score of the running data of the corresponding project type within Δt time, th is the duration of the highest score, m is the total number of project types stored in the corresponding type library, and j∈[1, m];
[0016] Firstly, compare the running data score value of each project type with the respective preset score threshold, when the preset score threshold is exceeded, it is diagnosed that the running data has a problem, and a second type of diagnostic fault is generated;
[0017] Otherwise, the running score LD of each feature library is obtained by the formula XH , and then the obtained running score of each feature library is compared with the respective preset running score threshold, when the preset running score threshold is exceeded, it is judged that the running data of the feature library has a problem, and a third type of diagnostic fault is generated;
[0018] Otherwise, the running score of the network is obtained by the formula , and then it is compared with the preset network running score threshold, when the network running score threshold is exceeded, it is judged that the running data of the entire network has a problem, and a fourth type of diagnostic fault is generated, wherein n is the number of feature libraries, is the running score of the i-th feature library, and i∈[1, n].
[0019] Further, the data analysis module is further configured to diagnose potential problems of the enterprise network according to the running scores of the acquired respective feature libraries when no diagnostic fault is generated.
[0020] Further, the method for diagnosing potential problems of the enterprise network by the data analysis module is as follows:
[0021] The running scores PM of the feature libraries in x Δt time periods are continuously acquired LD , and a running score time period variation curve function PM (x) is formulated LD .
[0022] A potential fault value YU is obtained through the formula .
[0023] When YU > YU z , it indicates that there is a potential problem in the enterprise network, and five types of diagnostic faults are generated.
[0024] Wherein, τ is a stability coefficient, maxK is the maximum slope value of PM LD (x), minK is the minimum slope value of PM LD (x), ΔK is a slope ratio value, x b is the last Δt time period, is a preset running score threshold function, YU z is a set potential fault judgment threshold.
[0025] Further, the stability coefficient τ is acquired by the following method:
[0026] A stability coefficient τ is obtained through the formula .
[0027] In the formula, b is the total number of Δt time periods, and s∈[1, b], is the running score of the feature library acquired in the s-th Δt time period.
[0028] Further, an alarm unit is arranged in the report generation module, and the alarm unit generates corresponding alarms according to the generated diagnostic faults.
[0029] When a first type of diagnostic fault and a second type of diagnostic fault are generated, a first-level alarm is generated; when a third type of diagnostic fault and a fourth type of diagnostic fault are generated, a second-level alarm is generated; and when a fifth type of diagnostic fault is generated, a third-level alarm is generated.
[0030] The beneficial effects of the present application are as follows:
[0031] The application can not only monitor various operation parameters of the enterprise network in real time, but also can immediately send an alarm when detecting an exception, so as to quickly determine the cause of the exception, and can also combine various parameters for comprehensive analysis to more accurately determine the operation status of the enterprise network, reduce inaccurate diagnosis caused by personnel negligence and missing of key information, and thus ensure the normal operation of the enterprise business.
[0032] The application can not only check the enterprise network in real time to find abnormal fault problems, but also can diagnose non-obvious fault problems and potential fault problems of the enterprise network, so as to timely find faults in advance and perform corresponding processing to ensure the normal operation of the enterprise business.
[0033] Of course, any product implementing the application does not necessarily need to achieve all the advantages described above. BRIEF DESCRIPTION OF DRAWINGS
[0034] In order to more clearly illustrate the technical solutions of the embodiments of the application, the following will briefly introduce the drawings needed to be used in the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.
[0035] Figure 1 The system structure diagram of the application. DETAILED DESCRIPTION
[0036] The technical solutions in the embodiments of the application will be described clearly and completely in the following with reference to the drawings in the embodiments of the application. Obviously, the described embodiments are only some embodiments of the application, not all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor are within the protection scope of the application.
[0037] In one embodiment, an enterprise network diagnosis report management system based on data analysis is disclosed, as shown in Figure 1 The management system includes a data acquisition module, a data storage and processing module, a data analysis module, and a report generation module.
[0038] The data acquisition module is used to collect the operation data of the enterprise network in real time and upload the operation data to the data storage and processing module.
[0039] The data storage and processing module is used to process the acquired operation data and store the acquired operation data.
[0040] The data analysis module is used to analyze the acquired operational data to identify network problems and generate diagnostic results.
[0041] The report generation module is used to convert diagnostic results into structured reports and provides a visual interface for users to view them.
[0042] Through the above technical solution, this application first obtains data information related to the enterprise network operation status from multiple data ports, uploads it to the data storage and processing module for data processing, including data cleaning, deletion, and normalization, so as to obtain standardized data information with consistent format, which facilitates subsequent data analysis. At the same time, the obtained data and the analysis results are stored, thereby providing more basis for judgment in subsequent analysis. Then, the data analysis module analyzes the obtained operation data, including real-time analysis and cumulative analysis, to determine whether there are corresponding problems in the enterprise network, and transforms the diagnostic results into a structured report, providing a visual interface for users to view. In this way, this application can monitor various operating parameters of the enterprise network online in real time. Once an anomaly is detected, an alarm can be issued immediately to quickly determine the cause of the anomaly. It can also combine multiple parameters for comprehensive analysis to accurately judge the operating status of the enterprise network, reducing the occurrence of inaccurate diagnosis due to human negligence and omission of key information, thereby ensuring the normal operation of enterprise business. At the same time, this application can not only check the enterprise network in real time to find obvious faults, but also diagnose less obvious faults and potential faults in the enterprise network, thereby discovering faults early and handling them in a timely manner to ensure the normal operation of enterprise business.
[0043] The data analysis module works as follows: First, based on historical data and big data, a scoring system is constructed. Each set of data has its own scoring system, and the higher the score, the worse the condition of the data.
[0044] The system acquires various operational data from the enterprise network, inputs them into a constructed scoring system, and obtains scores for each operational data point. These scores are then compared with the fault score thresholds for each operational data point. If the acquired score exceeds the fault score threshold, a problem is diagnosed for that operational data point, and a diagnostic fault is generated.
[0045] The above solution provides a method for diagnosing obvious faults using a data analysis module. First, a scoring system is constructed based on historical and large-scale data. Each operational data point has its own corresponding scoring system, with higher scores indicating worse operational conditions. Then, various operational data points of the enterprise network are acquired, such as bandwidth utilization, protocol distribution, abnormal traffic, DDoS attacks, and abnormal login attempts, and input into the corresponding scoring system to obtain scores for each operational data point. These scores are then compared with fault score thresholds for each operational data point. If a score exceeds the fault score threshold, it indicates an anomaly in that parameter type, and a fault diagnosis is generated for that operational data point. For example, if the input bandwidth utilization score is 5, its fault score threshold is set to 4, indicating a significant anomaly in bandwidth utilization. This generates an alarm to alert the user and promptly restore network operations, ensuring network normalcy.
[0046] The data analysis module's working method also includes: when no diagnostic fault type is generated, acquiring scores for various operational data within a time interval Δt, and dividing them into multiple feature libraries LD based on the data source. Each feature library corresponds to a specific operational data score value XH for each item type. j The mathematical expressions for the operational data score values of each project type are as follows: The corresponding feature library expression is: LD = (XH1, ..., XH) j ..., XH m In the formula, α1 and α2 are weighting coefficients. Let be the average score of the running data of the corresponding project type within time Δt, maxPF be the highest score of the running data of the corresponding project type within time Δt, th be the duration of the highest score, m be the total number of project types in the corresponding type library, and j∈[1,m];
[0047] First, the running data score of each project type is compared with its respective preset score threshold. If the score exceeds the preset score threshold, a problem is diagnosed in the running data and a second-class diagnostic fault is generated.
[0048] Otherwise, through the formula The running score (LD) of each feature library is obtained. XH Then, the running scores of each feature library are compared with their respective preset running score thresholds. When the scores exceed the preset running score thresholds, it is determined that there is a problem with the running data of that feature library, and three types of diagnostic faults are generated.
[0049] Otherwise, through the formula obtaining a running score of the network; comparing the running score with a preset network running score threshold; when the network running score exceeds the network running score threshold, determining that the entire network running data has a problem, and generating four types of diagnostic faults, wherein n is the number of feature libraries, is the running score of the i-th feature library, and i ∈ [1, n].
[0050] The above scheme provides a method for diagnosing non-obvious fault problems by the data analysis module. The above generation of a first diagnostic fault is only applicable to real-time and relatively obvious abnormal problem judgment, and cannot identify non-obvious faults. For example, the score of a certain project type is always high in a certain time period, but no alarm is given. At this time, it also indicates that the network has a problem. Therefore, when the first diagnostic fault is not generated, the scores of the running data of each item in the Δt time are obtained, and the data is divided into multiple feature libraries LD according to the data source. Each feature library has corresponding running data score values XH j of each project type. The corresponding feature library expression is: LD = (XH1, …, XH j , …, XH m , wherein α1 and α2 are weight coefficients, is the average score of the running data of the corresponding project type in the Δt time, maxPF is the highest score of the running data of the corresponding project type in the Δt time, th is the duration of the highest score, and m is the total number of project types in the corresponding type library. For example, according to the network equipment log, traffic monitoring, security event, and application performance, four feature libraries are divided, and each feature library has multiple project type parameters. For example, in the security event, the alarm data of the IDS / IPS system can be integrated to obtain the number of DDoS attacks, the number of abnormal login attempts, the number of system vulnerabilities, and other data information. Then, the formula The running data score value of each project type is obtained, which combines the average score of the single project type in the time period of Δt, the maximum score and the time length of the maximum score, etc. for comprehensive analysis, which can more accurately indicate the running condition of the single project type in the time period of Δt. Obviously, the larger the value is, the greater the possibility of failure is. In the formula, α1 and α2 are determined according to experience. For example, if the time length of the maximum score in a certain period of time is long, a higher weight can be given, and α2=0.6 and α1=0.4. If the average score in a certain period of time is large, α2=0.45 and α1=0.55 can be given. The specific assignment is determined according to the specific situation, which will not be described here. After obtaining the running data score value of each project type, the running data score value of each project type is compared with the preset score threshold value. When the preset score threshold value is exceeded, it is diagnosed that the running data of the project type has a problem, and a second type of diagnostic fault is generated. In this way, the fault problem of the single project type which is not obvious can be diagnosed, so that the running condition of each project type can be more accurately judged, and omission can be avoided. Then, if the second type of diagnostic fault is not generated, the running score LD of each feature library is obtained by the formula . XH The obtained running score of each feature library is compared with the preset running score threshold value. When the preset running score threshold value is exceeded, it is judged that the running data of the feature library has a problem, and a third type of diagnostic fault is generated. The running data of all project types in the entire feature library is comprehensively analyzed, so that a more comprehensive problem perspective can be provided to diagnose the enterprise network and find the fault problem that is not easy to find, so as to ensure the performance of the enterprise network. Similarly, when the third type of diagnostic fault is not generated, the running score of the entire network is obtained by the formula . Then, it is compared with the preset network running score threshold value. When the network running score threshold value is exceeded, it is judged that the running data of the entire network has a problem, and a fourth type of diagnostic fault is generated. The running conditions of all feature libraries of the entire enterprise network are comprehensively analyzed, so that not only the surface abnormal phenomenon of the entire enterprise network can be diagnosed, and timely maintenance can be ensured to ensure the normal operation of the enterprise network.
[0051] The data analysis module is also used to diagnose the potential problems of the enterprise network according to the obtained running score of each feature library when no diagnostic fault is generated. The diagnosis method is:
[0052] The running score PM of the feature library in the time period of x Δt is continuously obtained LD , and the running score curve function PM LD (x) is drawn.
[0053] The potential fault value YU is obtained by the formula .
[0054] When YU>YU z , it indicates that there is a potential problem in the enterprise network, and five types of diagnostic faults are generated;
[0055] Wherein, τ is the stability coefficient, maxK is the maximum slope value of PM LD (x), minK is the minimum slope value of PM LD (x), ΔK is the slope ratio value, x b is the last Δt time period, is the preset running score threshold function, YU z is the set potential fault judgment threshold, and the stability coefficient τ is obtained by the formula The stability coefficient τ is obtained.
[0056] In the formula, b is the total number of Δt time periods, and s∈[1, b], is the running score of the feature library obtained in the s-th Δt time period.
[0057] The above scheme provides a data analysis module to diagnose the potential problems of the enterprise network. Since the first to fourth types of diagnostic faults are all for diagnosing the faults that have already occurred, they cannot predict potential faults. Therefore, when no diagnostic fault is generated, the running scores PM LD of the feature library in x Δt time periods are continuously obtained, and the running score curve function PM LD (x) with time period is drafted, and the potential fault value YU is obtained by the formula The stability coefficient τ, maxK is the maximum slope value of PM LD (x), minK is the minimum slope value of PM LD (x), ΔK is the slope ratio value, which is determined according to experimental comparison data, x b is the last Δt time period, is the preset running score threshold function, YU z is the set potential fault judgment threshold, both of which can be determined according to empirical data; in the formula represents the difference between the drafted running score change condition and the preset running score threshold change condition, represents the drafted running score change trend, and the obtained running score is above the alarm threshold. However, if the running score is always near the alarm threshold and gradually increases, it indicates that the possibility of potential fault is greater. Therefore, the greater the values of and , the greater the possibility of potential fault in the enterprise network under the feature, and The stability of the running score expressed as the feature library of x Δt time periods is represented, the greater the value, the more unstable, the greater the fluctuation of the running score, and the greater the possibility of potential failure of the enterprise network under the feature, so after obtaining the potential failure value YU, it is compared with the set potential failure judgment threshold YU z When YU > YU z When YU > YU
[0058] The report generation module is provided with an alarm unit, which generates corresponding alarms according to the generated diagnostic faults; when a first diagnostic fault and a second diagnostic fault are generated, a first-level alarm is generated; when a third diagnostic fault and a fourth diagnostic fault are generated, a second-level alarm is generated; and when a fifth diagnostic fault is generated, a third-level alarm is generated.
[0059] In the above scheme, the severity and processing priority of the first-level alarm are higher than those of the second-level alarm, and the severity and processing priority of the second-level alarm are higher than those of the third-level alarm. By grading the diagnostic faults, the obvious faults, the not obvious faults and the potential faults can be clearly judged, and the priority of the processing can be distinguished, so that the recovery of the enterprise network can be ensured in time.
[0060] It should be noted that, in order to facilitate analysis and calculation, the above calculation expressions are all dimensionless operations after selecting units in advance.
[0061] The above content is only an example and explanation of the concept of the present application. Those skilled in the art can make various modifications or supplements to the described specific embodiments or use similar ways to replace them, as long as they do not deviate from the concept of the present application or exceed the scope defined by the present application.
Claims
1. A data analysis-based enterprise network diagnostic report management system, characterized in that, The system includes: a data acquisition module, a data storage and processing module, a data analysis module, and a report generation module; The data acquisition module is used to collect the operational data of the enterprise network in real time and upload it to the data storage and processing module; The data storage and processing module is used to process the acquired operational data and store the acquired operational data. The data analysis module is used to analyze the acquired operational data to identify network problems and generate diagnostic results. The report generation module is used to convert diagnostic results into structured reports and provide a visual interface for users to view; The data analysis module works as follows: First, based on historical data and big data, a scoring system is constructed. Each set of operational data corresponds to its own scoring system, and the higher the score, the worse the condition of the operational data. The system acquires various operational data from the enterprise network, inputs them into the constructed scoring system, obtains scores for each operational data point, and then compares them with the fault score thresholds for each operational data point. When the acquired score exceeds the fault score threshold, the system diagnoses a problem with that operational data point and generates a type of diagnostic fault. The data analysis module's working method further includes: when no type of fault is generated, obtaining... Scoring of various operational data within a given time period, and categorizing them into multiple feature libraries based on data source. Each feature library contains corresponding runtime data scores for each project type. The mathematical expressions for the operational data score values of each project type are as follows: The corresponding feature library expression is: In the formula, as well as These are the weighting coefficients. for The average score of the operational data for the corresponding project type within a given time period. for The highest score for the corresponding project type's operational data within a given time period. The duration of the highest rating. This represents the total number of item types in the corresponding type library, and ; First, the running data score of each project type is compared with its respective preset score threshold. If the score exceeds the preset score threshold, a problem is diagnosed in the running data and a second-class diagnostic fault is generated. Otherwise, through the formula Calculate the running scores for each feature library. Then, the running scores of each feature library are compared with their respective preset running score thresholds. When the scores exceed the preset running score thresholds, it is determined that there is a problem with the running data of that feature library, and three types of diagnostic faults are generated. Otherwise, through the formula The network's operational score is calculated and then compared with a preset network operational score threshold. If the score exceeds the threshold, a problem is identified in the overall network operational data, and four types of diagnostic faults are generated, where n is the number of features in the feature library. Let i be the running score for the i-th feature library, and .
2. The enterprise network diagnostic report management system based on data analysis according to claim 1, characterized in that, The data analysis module is also used to diagnose potential problems in the enterprise network based on the operational scores of the acquired feature libraries when no diagnostic faults are generated.
3. The enterprise network diagnostic report management system based on data analysis according to claim 2, characterized in that, The data analysis module diagnoses potential problems in the enterprise network using the following method: Get x consecutively Performance score of the feature library within the time period And formulate a curve function for the change of performance score over time. ; Through formula Determine potential fault values ; when If this occurs, it indicates a potential problem in the enterprise network, and five types of diagnostic faults will be generated. in, For stability coefficient, for The maximum slope value, for The minimum slope value, This is the slope comparison value. For the last one Time period The preset running score threshold function, The threshold for potential fault detection is set.
4. The enterprise network diagnostic report management system based on data analysis according to claim 3, characterized in that, The stability coefficient The method for obtaining it is as follows: Through formula derive the stability coefficient ; In the formula, For setting Total number of time periods, and , For the sth The running score of the feature library obtained over a time period.
5. The enterprise network diagnostic report management system based on data analysis according to claim 4, characterized in that, The report generation module is equipped with an alarm unit, which triggers an alarm based on the generated diagnostic fault. When a Class I or Class II diagnostic fault is generated, a Level 1 alarm is generated; when a Class III or Class IV diagnostic fault is generated, a Level 2 alarm is generated; and when a Class V diagnostic fault is generated, a Level 3 alarm is generated.
Citation Information
Patent Citations
Intelligent sewage treatment system and method based on data analysis
CN119398319A
Enterprise information security management system based on big data analysis
CN119539262A