Multi-element network equipment strategy distribution real-time monitoring method and system

By obtaining the performance data and topology diagram of network devices to calculate the tolerance threshold, the problem of untimely discovery of abnormal devices in the distribution of multi-network device policies is solved, and real-time monitoring and early warning are achieved to ensure the normal operation of the equipment.

CN120639360APending Publication Date: 2025-09-12HUANENG INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510714268.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-29
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

During the policy distribution process for multiple network devices, abnormal devices cannot be discovered in time, resulting in the inability of network devices to operate normally.

Method used

By obtaining the performance data of network devices after policy distribution, abnormal parameters are determined; the tolerance threshold is calculated using the initial cluster topology map, and a multi-level cluster topology map is generated in combination with the PPHM algorithm to determine the status parameters of network devices, and the danger level is divided according to the status parameters for early warning.

Benefits of technology

It realizes real-time monitoring of multiple network devices, timely discovers and warns of abnormal devices, and ensures the normal operation of network equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639360A_ABST
    Figure CN120639360A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network equipment monitoring, and discloses a multi-element network equipment strategy distribution real-time monitoring method and system, and the method comprises the steps: obtaining the performance data of network equipment after strategy distribution, and determining the abnormal parameters of the network equipment according to the performance data of the network equipment after strategy distribution; obtaining an initial cluster topological graph of the multi-element network equipment, determining a bearing threshold value of each piece of network equipment according to the initial cluster topological graph, and determining network equipment state parameters according to the bearing threshold values of the network equipment and the abnormal parameters; and determining a network equipment danger level according to the network equipment state parameter, and performing network equipment danger early warning according to the network equipment danger level. According to the invention, each network device can be quickly and accurately monitored in real time when the security policy is distributed, the dangerous network device can be found in time, danger early warning is carried out, and normal operation of the network device is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of network device monitoring, and more specifically, to a method and system for real-time monitoring of multiple network device policies. Background Art

[0002] In today's internet age, cybersecurity threats are increasingly becoming a major threat to businesses. Large enterprises often utilize a variety of network security devices, brands, and models, to support security operations when developing network security management systems. These devices, such as firewalls, host monitoring systems, vulnerability scanners, and antivirus software, each offer functional advantages and strategic defense features. Some devices also share or share similar security policies.

[0003] During the security policy distribution process for network devices, due to the complex topological relationships between network devices, when a policy distribution anomaly occurs on a certain network device, the problem of the abnormal network device cannot be discovered in time, resulting in the network device being unable to operate normally. Summary of the Invention

[0004] The present invention provides a real-time monitoring method and system for policy distribution of multiple network devices, which is used to solve the problem in the prior art that multiple network devices cannot detect anomalies in a timely manner during policy distribution, including: Acquire performance data of the network device after the policy is distributed, and determine abnormal parameters of the network device based on the performance data of the network device after the policy is distributed; Obtain an initial cluster topology diagram of multiple network devices, determine a tolerance threshold of each network device based on the initial cluster topology diagram, and determine a network device status parameter based on the tolerance threshold and abnormal parameters of the network device; Determine the network equipment danger level based on the network equipment status parameters, and issue a network equipment danger warning based on the network equipment danger level.

[0005] Furthermore, determining abnormal parameters of the network device according to the performance data of the network device after the policy distribution includes: Obtaining a response time of the network device to the distribution policy, and determining a response time parameter according to the response time of the network device to the distribution policy; Obtaining traffic change data of network devices after policy distribution, and drawing a traffic change curve based on the traffic change data of network devices after policy distribution; Divide the flow change curve into several flow change curve segments, and calculate the slope value of each flow change curve segment; Obtain the absolute value of the difference between the slope values ​​of any two adjacent flow change curve segments, screen out the maximum absolute value of the difference, and determine the flow mutation parameter based on the maximum absolute value of the difference; Determine the abnormal parameters of the network device based on the response time parameters and traffic mutation parameters of the network device.

[0006] Furthermore, determining abnormal parameters of the network device based on the response time parameters and traffic mutation parameters of the network device includes: The abnormal parameters of the network device are calculated according to the abnormal parameter calculation formula, and the abnormal parameter calculation formula is specifically:

[0007] in, is an abnormal parameter, is the response time of the network device to the distribution strategy, is the historical average response time of network devices to the distribution strategy, is the first preset range coefficient, is the maximum absolute value of the difference, is the slope value of the flow change curve, is the second preset range coefficient.

[0008] Furthermore, determining the tolerance threshold of each network device according to the initial cluster topology diagram includes: Determine the topological potential of each network device node based on the cluster topology diagram of multiple network devices; A multi-level cluster topology map is generated according to the initial cluster topology map based on the PPHM algorithm, and the tolerance threshold of each network device is determined according to the multi-level cluster topology map.

[0009] Furthermore, the determining of the topological potential of each network device node according to the cluster topology diagram of the multi-network devices includes: The topological potential of each network device node is calculated according to the topological potential calculation formula. The topological potential calculation formula is specifically:

[0010] in, is the topological potential of node i, is the processing capacity value of node i, is the load capacity value of node i, is the preset standard load capacity value, is the preset range coefficient, is the shortest path length from node j to node i, is the impact factor.

[0011] Furthermore, the determining of the tolerance threshold of each network device according to the multi-level cluster topology diagram includes: Obtaining a preset ratio, and converting the topological potential of each network device node in the multi-level cluster topology diagram into a radius according to the preset ratio; Create a circle based on the radius of the network device node to obtain the influence range of the network device node; Calculate the shortest path length between the network device node and the affected network device node within its influence range, and determine the influence coefficient of the affected network device node based on the shortest path length; All the influence coefficients of the affected network device nodes are superimposed to obtain the comprehensive influence coefficient of the affected network device nodes; The load capacity value of each network device node is obtained, an initial bearing threshold is determined according to the load capacity value, and the initial bearing threshold is multiplied by the comprehensive influence coefficient to obtain the bearing threshold of the network device node.

[0012] Furthermore, the determining of the network device status parameters according to the tolerance threshold and abnormal parameters of the network device includes: The difference between the abnormal parameter of the network device and the tolerance threshold is calculated, and the state parameter of the network device is determined according to the difference between the abnormal parameter of the network device and the tolerance threshold.

[0013] Furthermore, determining the network device status parameter according to the difference between the abnormal parameter of the network device and the tolerance threshold includes: Collect statistics on the difference between abnormal parameters of network equipment and tolerance thresholds, and draw a difference change curve based on the difference changes; Perform curve fitting on the difference change curve to obtain the state parameter prediction curve; The time required for the state parameter to reach a first preset threshold is determined according to the state parameter prediction curve, and the state parameter of the network device is determined according to the time required for the state parameter to reach the first preset threshold.

[0014] Furthermore, determining the network device risk level according to the network device status parameters includes: Obtaining preset standard network device status parameters, and calculating the difference between the network device status parameters of the current network device and the preset standard network device status parameters; determining whether a difference between the network device status parameter and a preset standard network device status parameter is greater than a second preset threshold, and setting the first level as a danger level of the network device if the difference between the network device status parameter and the preset standard network device status parameter is greater than the second preset threshold; If the difference between the network device status parameter and the preset standard network device status parameter is less than or equal to the second preset threshold, determining whether the difference between the network device status parameter and the preset standard network device status parameter is greater than a third preset threshold; If the difference between the network device status parameter and the preset standard network device status parameter is greater than a third preset threshold, setting the second level as the danger level of the network device; If the difference between the network device status parameter and the preset standard network device status parameter is less than or equal to the second preset threshold, the third level is set as the danger level of the network device.

[0015] In order to achieve the above object, the present invention also provides a multi-network device policy distribution real-time monitoring system, comprising: An acquisition module is used to acquire performance data of the network device after the policy is distributed, and determine abnormal parameters of the network device based on the performance data of the network device after the policy is distributed; A detection module is used to obtain an initial cluster topology diagram of multiple network devices, determine the tolerance threshold of each network device based on the initial cluster topology diagram, and determine the network device status parameters based on the tolerance threshold and abnormal parameters of the network device; The early warning module is used to determine the network device danger level according to the network device status parameters and to issue a network device danger early warning according to the network device danger level.

[0016] The beneficial effects of the present invention are: By applying the above technical solution, the present invention obtains performance data of network devices after policy distribution, determines abnormal parameters of network devices based on the performance data of network devices after policy distribution; obtains an initial cluster topology diagram of multiple network devices, determines the tolerance threshold of each network device based on the initial cluster topology diagram, determines network device status parameters based on the tolerance threshold and abnormal parameters of the network devices; determines the network device danger level based on the network device status parameters, and issues a network device danger warning based on the network device danger level. The present invention can quickly and accurately monitor each network device in real time during security policy distribution, promptly detect dangerous network devices and issue danger warnings, thereby ensuring the normal operation of network devices. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0018] Figure 1 The present invention shows an overall flow chart of a multi-network device policy distribution and real-time monitoring distribution method proposed in an embodiment of the present invention; Figure 2 The diagram shows the structure of a real-time monitoring system for policy distribution of multiple network devices proposed in an embodiment of the present invention. DETAILED DESCRIPTION

[0019] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0020] The embodiment of the present application provides a real-time monitoring method for policy distribution of multiple network devices, such as Figure 1 Shown, including: S101, obtaining performance data of the network device after policy distribution, and determining abnormal parameters of the network device according to the performance data of the network device after policy distribution; In some embodiments of the present application, the method of determining abnormal parameters of a network device based on the performance data of the network device after policy distribution includes: obtaining the response time of the network device to the distribution policy, and determining the response time parameter based on the response time of the network device to the distribution policy; obtaining the traffic change data of the network device after the policy distribution, and drawing a traffic change curve based on the traffic change data of the network device after the policy distribution; dividing the traffic change curve into a number of traffic change curve segments, and calculating the slope value of each traffic change curve segment; obtaining the absolute value of the difference between the slope values ​​of any two adjacent traffic change curve segments, screening out the maximum absolute value of the difference, and determining the traffic mutation parameter based on the maximum absolute value of the difference; and determining the abnormal parameters of the network device based on the response time parameter and the traffic mutation parameter of the network device.

[0021] In some embodiments of the present application, determining the abnormal parameters of the network device based on the response time parameter and the traffic mutation parameter of the network device includes: calculating the abnormal parameters of the network device according to an abnormal parameter calculation formula, wherein the abnormal parameter calculation formula is specifically:

[0022] in, is an abnormal parameter, is the response time of the network device to the distribution strategy, is the historical average response time of network devices to the distribution strategy, is the first preset range coefficient, is the maximum absolute value of the difference, is the slope value of the flow change curve, is the second preset range coefficient.

[0023] In this embodiment, the abnormal parameters of the network device are calculated based on the response time parameters and traffic mutation parameters of the network device after policy distribution, which can effectively reflect the stability of the network device after policy distribution and realize accurate monitoring of the operating status of the network device.

[0024] S102, obtaining an initial cluster topology of multiple network devices, determining a tolerance threshold of each network device based on the initial cluster topology, and determining a network device status parameter based on the tolerance threshold and abnormal parameters of the network device; In some embodiments of the present application, determining the tolerance threshold of each network device based on the initial cluster topology diagram includes: determining the topological potential of each network device node based on the cluster topology diagram of multiple network devices; generating a multi-level cluster topology diagram based on the initial cluster topology diagram based on the PPHM algorithm, and determining the tolerance threshold of each network device based on the multi-level cluster topology diagram.

[0025] In some embodiments of the present application, determining the topological potential of each network device node according to the cluster topology diagram of the multi-network device includes: calculating the topological potential of each network device node according to a topological potential calculation formula, wherein the topological potential calculation formula is specifically:

[0026] in, is the topological potential of node i, is the processing capacity value of node i, is the load capacity value of node i, is the preset standard load capacity value, is the preset range coefficient, is the shortest path length from node j to node i, is the impact factor.

[0027] In this embodiment, the topological potential in the multi-level cluster topology diagram of network devices is collected to calculate the tolerance threshold of each network device. The degree of influence between each network device is obtained through the multi-level cluster topology diagram, so as to accurately calculate the tolerance threshold of each network device.

[0028] In some embodiments of the present application, the determination of the tolerance threshold of each network device based on the multi-level cluster topology diagram includes: obtaining a preset ratio, and converting the topological potential of each network device node in the multi-level cluster topology diagram into a radius according to the preset ratio; establishing a circle according to the radius of the network device node to obtain the influence range of the network device node; calculating the shortest path length between the network device node and the affected network device node within the influence range of the network device node, and determining the influence coefficient of the affected network device node based on the shortest path length; superimposing all the influence coefficients of the affected network device nodes to obtain the comprehensive influence coefficient of the affected network device nodes; obtaining the load capacity value of each network device node, determining the initial tolerance threshold according to the load capacity value, and multiplying the initial tolerance threshold by the comprehensive influence coefficient to obtain the tolerance threshold of the network device node.

[0029] In this embodiment, by converting the topological potential into a radius and drawing a circle, the influence range of each network device node can be accurately reflected. The influence coefficient of the affected network device is obtained through a preset path length-influence coefficient mapping table. The initial tolerance threshold is determined by multiplying the load capacity value of the network device with the preset conversion coefficient. The initial tolerance threshold is corrected by the comprehensive influence coefficient of each affected network device to obtain the tolerance threshold of the corrected network device node.

[0030] In some embodiments of the present application, determining the network device status parameters based on the tolerance threshold and abnormal parameters of the network device includes: calculating the difference between the abnormal parameters of the network device and the tolerance threshold, and determining the network device status parameters based on the difference between the abnormal parameters of the network device and the tolerance threshold.

[0031] In some embodiments of the present application, the method of determining the status parameters of a network device based on the difference between an abnormal parameter of the network device and a tolerance threshold value includes: statistically calculating changes in the difference between the abnormal parameter of the network device and the tolerance threshold value, and drawing a difference change curve based on the difference changes; performing curve fitting on the difference change curve to obtain a status parameter prediction curve; determining the time required for the status parameter to reach a first preset threshold value based on the status parameter prediction curve, and determining the network device status parameter based on the time required for the status parameter to reach the first preset threshold value.

[0032] In this embodiment, a curve fitting is performed on the difference change curve based on the least square method to obtain a state parameter prediction curve, and then the network device state parameter is determined.

[0033] S103, determining the network device danger level according to the network device status parameters, and performing a network device danger warning according to the network device danger level.

[0034] In some embodiments of the present application, determining the danger level of a network device based on network device status parameters includes: obtaining preset standard network device status parameters, calculating the difference between the network device status parameters of the current network device and the preset standard network device status parameters; judging whether the difference between the network device status parameters and the preset standard network device status parameters is greater than a second preset threshold value, and if the difference between the network device status parameters and the preset standard network device status parameters is greater than the second preset threshold value, setting the first level as the danger level of the network device; if the difference between the network device status parameters and the preset standard network device status parameters is less than or equal to the second preset threshold value, judging whether the difference between the network device status parameters and the preset standard network device status parameters is greater than a third preset threshold value; if the difference between the network device status parameters and the preset standard network device status parameters is greater than the third preset threshold value, setting the second level as the danger level of the network device; if the difference between the network device status parameters and the preset standard network device status parameters is less than or equal to the second preset threshold value, setting the third level as the danger level of the network device.

[0035] In this embodiment, the danger level of the network device is obtained by the difference between the network device status parameters of the current network device and the preset standard network device status parameters. The larger the difference, the higher the corresponding danger level ranking, and the more dangerous the network device is. The danger level of the network device is divided according to the danger level, and the network device is given a danger warning in time to ensure safe operation.

[0036] Based on the same technical concept, such as Figure 2 As shown, the present invention also provides a multi-network device policy distribution real-time monitoring system, including: The acquisition module is used to obtain the performance data of the network equipment after the policy is distributed, and determine the abnormal parameters of the network equipment based on the performance data of the network equipment after the policy is distributed; the detection module is used to obtain the initial cluster topology diagram of multiple network devices, determine the tolerance threshold of each network device based on the initial cluster topology diagram, and determine the network device status parameters based on the tolerance threshold and abnormal parameters of the network device; the early warning module is used to determine the network device danger level based on the network device status parameters, and issue a network device danger warning based on the network device danger level.

[0037] By applying the above technical solutions, the present invention obtains performance data of network devices after policy distribution, determines abnormal parameters of network devices based on the performance data of network devices after policy distribution; obtains an initial cluster topology diagram of multiple network devices, determines the tolerance threshold of each network device based on the initial cluster topology diagram, determines network device status parameters based on the tolerance threshold and abnormal parameters of the network devices; determines the network device danger level based on the network device status parameters, and issues a network device danger warning based on the network device danger level. The present invention can quickly and accurately monitor each network device in real time during security policy distribution, promptly detect dangerous network devices and issue danger warnings, thereby ensuring the normal operation of network devices.

[0038] Through the above description of the embodiments, those skilled in the art will clearly understand that the present invention can be implemented via hardware or via software combined with a necessary general-purpose hardware platform. Based on this understanding, the technical solution of the present invention can be embodied in the form of a software product. This software product can be stored on a non-volatile storage medium (such as a CD-ROM, USB flash drive, or external hard drive) and includes instructions for enabling a computer device (such as a personal computer, server, or network device) to execute the methods described in various implementation scenarios of the present invention.

[0039] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A real-time monitoring method for policy distribution of multiple network devices, characterized in that: include: Acquire performance data of the network device after the policy is distributed, and determine abnormal parameters of the network device based on the performance data of the network device after the policy is distributed; Obtain an initial cluster topology diagram of multiple network devices, determine a tolerance threshold of each network device based on the initial cluster topology diagram, and determine a network device status parameter based on the tolerance threshold and abnormal parameters of the network device; Determine the network equipment danger level based on the network equipment status parameters, and issue a network equipment danger warning based on the network equipment danger level.

2. The method for real-time monitoring of policy distribution of multiple network devices according to claim 1, characterized in that: The determining of abnormal parameters of the network device according to the performance data of the network device after the policy distribution includes: Obtaining a response time of the network device to the distribution policy, and determining a response time parameter according to the response time of the network device to the distribution policy; Obtaining traffic change data of network devices after policy distribution, and drawing a traffic change curve based on the traffic change data of network devices after policy distribution; Divide the flow change curve into several flow change curve segments, and calculate the slope value of each flow change curve segment; Obtain the absolute value of the difference between the slope values ​​of any two adjacent flow change curve segments, screen out the maximum absolute value of the difference, and determine the flow mutation parameter based on the maximum absolute value of the difference; Determine the abnormal parameters of the network device based on the response time parameters and traffic mutation parameters of the network device.

3. The method for real-time monitoring of policy distribution of multiple network devices according to claim 2, characterized in that: Determining abnormal parameters of the network device according to the response time parameters and traffic mutation parameters of the network device includes: The abnormal parameters of the network device are calculated according to the abnormal parameter calculation formula, and the abnormal parameter calculation formula is specifically: in, is an abnormal parameter, is the response time of the network device to the distribution strategy, is the historical average response time of network devices to the distribution strategy, is the first preset range coefficient, is the maximum absolute value of the difference, is the slope value of the flow change curve, is the second preset range coefficient.

4. The method for real-time monitoring of policy distribution of multiple network devices according to claim 3, characterized in that: Determining the tolerance threshold of each network device according to the initial cluster topology diagram includes: Determine the topological potential of each network device node based on the cluster topology diagram of multiple network devices; A multi-level cluster topology map is generated according to the initial cluster topology map based on the PPHM algorithm, and the tolerance threshold of each network device is determined according to the multi-level cluster topology map.

5. The method for real-time monitoring of policy distribution of multiple network devices according to claim 4, characterized in that: Determining the topological potential of each network device node according to the cluster topology diagram of the multi-network device includes: The topological potential of each network device node is calculated according to the topological potential calculation formula. The topological potential calculation formula is specifically: in, is the topological potential of node i, is the processing capacity value of node i, is the load capacity value of node i, is the preset standard load capacity value, is the preset range coefficient, is the shortest path length from node j to node i, is the impact factor.

6. The method for real-time monitoring of policy distribution of multiple network devices according to claim 5, characterized in that: Determining the tolerance threshold of each network device according to the multi-level cluster topology diagram includes: Obtaining a preset ratio, and converting the topological potential of each network device node in the multi-level cluster topology diagram into a radius according to the preset ratio; Create a circle based on the radius of the network device node to obtain the influence range of the network device node; Calculate the shortest path length between the network device node and the affected network device node within its influence range, and determine the influence coefficient of the affected network device node based on the shortest path length; All the influence coefficients of the affected network device nodes are superimposed to obtain the comprehensive influence coefficient of the affected network device nodes; The load capacity value of each network device node is obtained, an initial bearing threshold is determined according to the load capacity value, and the initial bearing threshold is multiplied by the comprehensive influence coefficient to obtain the bearing threshold of the network device node.

7. The method for real-time monitoring of policy distribution of multiple network devices according to claim 6, characterized in that: Determining the network device status parameters according to the tolerance threshold and abnormal parameters of the network device includes: The difference between the abnormal parameter of the network device and the tolerance threshold is calculated, and the state parameter of the network device is determined according to the difference between the abnormal parameter of the network device and the tolerance threshold.

8. The method for real-time monitoring of policy distribution of multiple network devices according to claim 7, characterized in that: The determining of the network device status parameter according to the difference between the abnormal parameter of the network device and the tolerance threshold value includes: Collect statistics on the difference between abnormal parameters of network equipment and tolerance thresholds, and draw a difference change curve based on the difference changes; Perform curve fitting on the difference change curve to obtain the state parameter prediction curve; The time required for the state parameter to reach a first preset threshold is determined according to the state parameter prediction curve, and the state parameter of the network device is determined according to the time required for the state parameter to reach the first preset threshold.

9. The method for real-time monitoring of policy distribution of multiple network devices according to claim 8, characterized in that: Determining the network device risk level according to the network device status parameters includes: Obtaining preset standard network device status parameters, and calculating the difference between the network device status parameters of the current network device and the preset standard network device status parameters; determining whether a difference between the network device status parameter and a preset standard network device status parameter is greater than a second preset threshold, and setting the first level as a danger level of the network device if the difference between the network device status parameter and the preset standard network device status parameter is greater than the second preset threshold; If the difference between the network device status parameter and the preset standard network device status parameter is less than or equal to the second preset threshold, determining whether the difference between the network device status parameter and the preset standard network device status parameter is greater than a third preset threshold; If the difference between the network device status parameter and the preset standard network device status parameter is greater than a third preset threshold, setting the second level as the danger level of the network device; If the difference between the network device status parameter and the preset standard network device status parameter is less than or equal to the second preset threshold, the third level is set as the danger level of the network device.

10. A real-time monitoring system for policy distribution of multiple network devices, characterized in that: include: An acquisition module is used to acquire performance data of the network device after the policy is distributed, and determine abnormal parameters of the network device based on the performance data of the network device after the policy is distributed; A detection module is used to obtain an initial cluster topology diagram of multiple network devices, determine the tolerance threshold of each network device based on the initial cluster topology diagram, and determine the network device status parameters based on the tolerance threshold and abnormal parameters of the network device; The early warning module is used to determine the network device danger level according to the network device status parameters and to issue a network device danger early warning according to the network device danger level.