A method, apparatus, edge node and system for monitoring the network status of a device
By receiving and parsing heartbeat packets from multiple protocols, generating multi-protocol sending packets, and detecting network layer and application layer indicators, the problem of application layer anomalies that cannot be identified in existing technologies is solved. This enables a comprehensive assessment of the network status of multi-protocol devices, reducing system complexity and resource waste.
Patent Information
- Application Number
- CN202511053886.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-30
- Publication Date
- 2026-01-13
- Estimated Expiration
- 2045-07-30
AI Technical Summary
Existing device network status monitoring technologies cannot identify application layer anomalies, and separate tools need to be developed for various protocols, resulting in system complexity and wasted resources.
By receiving protocol heartbeat packets from various target devices, parsing the protocol types and generating multi-protocol sending packets, and simultaneously detecting network layer and application layer indicators, the network status is determined by combining the dual-dimensional detection results.
It enables joint network detection of devices with multiple protocols, reduces system complexity, avoids missed detection of application layer anomalies, and ensures the comprehensiveness and reliability of device network status assessment.
Smart Images

Figure CN120729755B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The embodiment of the present application relates to the technical field of network security, in particular to a networking state monitoring method and device of equipment, an edge node and system. BACKGROUND
[0002] The existing equipment networking state monitoring technology mainly depends on periodically sending ICMP (control message protocol) or HTTP (hypertext transfer protocol) to verify network layer connectivity, but cannot identify the application layer protocol state, so that the scene of application layer exception but network smoothness cannot be monitored. In addition, if the equipment has multiple protocols, an independent tool needs to be developed for each type of protocol, resulting in high system complexity and resource waste. SUMMARY
[0003] The technical problem to be solved by the embodiment of the present application is to provide a networking state monitoring method and device of equipment, an edge node and system, which can simultaneously perform network layer and application layer detection through multi-protocol heartbeat packets, can effectively identify the scene of "network smoothness but application layer exception", and avoid missed detection.
[0004] To solve the above technical problems, the technical scheme of the embodiment of the present application is as follows:
[0005] A networking state monitoring method of equipment, comprising:
[0006] Receiving protocol heartbeat packets sent by at least two target devices according to different communication protocol types;
[0007] Analyzing the protocol heartbeat packets to obtain the protocol types of the protocol heartbeat packets, and generating multi-protocol sending packets according to the protocol types;
[0008] Sending the multi-protocol sending packets to a plurality of target devices;
[0009] Receiving multi-protocol response packets fed back by the plurality of target devices according to the multi-protocol sending packets, wherein the multi-protocol response packets carry network layer indicators and application layer indicators;
[0010] According to the network layer indicators carried by the multi-protocol response packets, detecting the network layer states in the multi-protocol response packets to obtain a first detection result;
[0011] According to the application layer indicators carried by the multi-protocol response packets, detecting the application layer states in the multi-protocol response packets to obtain a second detection result;
[0012] According to the first detection result and the second detection result, determining the networking state of the target device.
[0013] Optionally, the protocol heartbeat packet is parsed to obtain a protocol type of the protocol heartbeat packet, and a multi-protocol sending packet is generated according to the protocol type, including:
[0014] The protocol heartbeat packet is parsed to obtain a network layer protocol type and an application layer protocol type.
[0015] According to the network layer protocol type and the application layer protocol type, a multi-protocol sending packet is generated.
[0016] Optionally, according to the network layer protocol type and the application layer protocol type, a multi-protocol sending packet is generated, including:
[0017] In N1 network layer protocol types and N2 application layer protocol types, N1*N2 protocol sending packets are generated according to any combination of a network layer protocol type and an application layer protocol type; N1 and N2 are positive integers.
[0018] Optionally, the network layer indicators include: a round-trip delay and a packet loss rate of the network layer.
[0019] According to network layer indicators carried in the multi-protocol response packet, a network layer state in the multi-protocol response packet is detected to obtain a first detection result, including:
[0020] If R < R k , and L < L k , the first detection result is that the network layer state is normal, otherwise the network layer state is abnormal.
[0021] Wherein, R is a round-trip delay of the network layer, R k is a round-trip delay threshold, L is a packet loss rate of the network layer, L k is a packet loss rate threshold.
[0022] If R > R k , and L < L k , the first detection result is that the network layer state is abnormal, but R < R p +R j , the first detection result is corrected to be normal.
[0023] Wherein, R is a round-trip delay of the network layer, R k is a round-trip delay threshold, R p is an average value of historical round-trip delays,R j The variance of historical round-trip delays;
[0024] like R < R k ,and L > L k The first detection result indicates an abnormal network layer state, but L < L k + H ,and n / m < D If so, the first detection result will be corrected to normal;
[0025] in, L For packet loss rate at the network layer, L k The packet loss rate threshold. H The elastic threshold, n To reduce packet loss rate m Number of anomalies D This is the threshold for the number of abnormal occurrences.
[0026] Optionally, based on the application layer indicators carried in the multi-protocol response packet, the application layer status in the multi-protocol response packet is detected to obtain a second detection result, including:
[0027] If both the first and second application layer indicators carried in the multi-protocol response packet are normal, then the second detection result indicates that the application layer status is normal; otherwise, the application layer status is abnormal.
[0028] Optionally, determining the network status of the target device based on the first detection result and the second detection result includes:
[0029] If both the first and second detection results are normal, then the network connection status of the target device is determined to be normal.
[0030] If both the first and second detection results are abnormal, then the network connection status of the target device is determined to be abnormal.
[0031] If either the first or second detection result is abnormal, a retry monitoring will be initiated.
[0032] Optionally, the above method further includes:
[0033] Based on the first detection result, adjust the transmission interval of the next multi-protocol packet.
[0034] Embodiments of the present invention also provide a device for monitoring the network status of a device, comprising:
[0035] The transceiver module is used to receive protocol heartbeat packets sent by at least two target devices according to different communication protocol types; and to receive multi-protocol response packets fed back by multiple target devices according to multi-protocol sent packets, wherein the multi-protocol response packets carry network layer indicators and application layer indicators;
[0036] The processing module is configured to parse the protocol heartbeat packet to obtain the protocol type of the protocol heartbeat packet, and generate a multi-protocol sending packet according to the protocol type; send the multi-protocol sending packet to multiple target devices; detect the network layer status in the multi-protocol response packet according to the network layer indicators carried in the multi-protocol response packet to obtain a first detection result; detect the application layer status in the multi-protocol response packet according to the application layer indicators carried in the multi-protocol response packet to obtain a second detection result; and determine the network status of the target device based on the first detection result and the second detection result.
[0037] Embodiments of the present invention also provide an edge node, including a device for monitoring the network status of the device as described above.
[0038] Embodiments of the present invention also provide a system for monitoring the network status of a device, comprising:
[0039] An edge node is used to receive protocol heartbeat packets sent by at least two target devices according to different communication protocol types; parse the protocol heartbeat packets to obtain the protocol type of the protocol heartbeat packets, and generate multi-protocol sending packets according to the protocol type; and send the multi-protocol sending packets to multiple target devices.
[0040] The system receives multi-protocol response packets from multiple target devices, each packet carrying network layer and application layer indicators. Based on the network layer indicators, the system detects the network layer status within the multi-protocol response packets to obtain a first detection result. Based on the application layer indicators, the system detects the application layer status within the multi-protocol response packets to obtain a second detection result. Based on the first and second detection results, the system determines the network connection status of the target devices.
[0041] The above-described solutions of the embodiments of the present invention have at least the following beneficial effects:
[0042] The above-described solution of this invention enables joint network detection of multiple devices that support industrial protocols, Internet protocols, Internet of Things protocols, and proprietary protocols, without the need to develop independent tools for each type of protocol, thus significantly reducing system complexity and resource waste.
[0043] By synchronously detecting network layer and application layer indicators through multi-protocol packet transmission, and through dual-dimensional joint judgment, the problem of application layer anomaly missed detection is solved, ensuring the comprehensiveness of device network status assessment. Attached Figure Description
[0044] Figure 1 This is a flowchart of a method for monitoring the network status of a device according to an embodiment of the present invention.
[0045] Figure 2 This is a schematic diagram of the module of the device for monitoring the network status of the equipment according to an embodiment of the present invention. Detailed Implementation
[0046] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this invention will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.
[0047] like Figure 1 As shown, an embodiment of the present invention provides a method for monitoring the network status of a device, including:
[0048] Step 11: Receive protocol heartbeat packets sent by at least two target devices according to different communication protocol types; specifically, the communication protocols include network layer protocols and application layer protocols;
[0049] Step 12: Parse the protocol heartbeat packet to obtain the protocol type of the protocol heartbeat packet, and generate a multi-protocol sending packet according to the protocol type;
[0050] Step 13: Send the multi-protocol packet to multiple target devices;
[0051] Step 14: Receive multi-protocol response packets from multiple target devices based on multi-protocol sending packets. The multi-protocol response packets carry network layer indicators and application layer indicators.
[0052] Step 15: Based on the network layer indicators carried in the multi-protocol response packet, detect the network layer status in the multi-protocol response packet to obtain the first detection result;
[0053] Step 16: Based on the application layer indicators carried in the multi-protocol response packet, detect the application layer status in the multi-protocol response packet to obtain a second detection result;
[0054] Step 17: Determine the network status of the target device based on the first detection result and the second detection result.
[0055] Specifically, the protocol heartbeat packet can be generated by the target device according to the different communication protocol types of the target device.
[0056] The types of network layer protocols may include: IP (Internet Protocol), ICMP (Control Message Protocol), IGMP (Internet Group Management Protocol), RIP (Routing Information Protocol), OSPF (Open Shortest Path First), ARP (Address Resolution Protocol), and RARP (Reverse Address Resolution Protocol).
[0057] The IP protocol (Internet Protocol) is a core protocol of the network layer, responsible for addressing and routing data packets, and defines the data packet format and address system.
[0058] The ICMP (Internet Control Message Protocol) is used for network error reporting and diagnosis, such as sending a "target unreachable" message, and is commonly used in tools such as ping and traceroute.
[0059] The IGMP (Internet Group Management Protocol) is used to manage multicast membership, allowing hosts to dynamically join / leave multicast groups.
[0060] The types of application layer protocols may include: industrial protocols, Internet protocols, Internet of Things protocols, and proprietary protocols, etc.
[0061] The industrial protocols may include: Modbus, Profibus / Profinet, DeviceNet, or Ethernet / IP.
[0062] The Internet protocols may include: TCP (Transmission Control Protocol), UDP (User Datagram Protocol), SCTP (Stream Control Transfer Protocol), HTTP / HTTPS (Hypertext Transfer Protocol / Secure Hypertext Transfer Protocol), FTP (File Transfer Protocol), or DNS (Domain Name System Protocol).
[0063] The IoT protocol may include: 6LoWPAN (IPv6 protocol based on low-power wireless personal area network), LoRaWAN (long-range wide area network), NB-IoT (narrowband Internet of Things), or MQTT (message queue telemetry transport).
[0064] The proprietary protocol may include: a device communication proprietary protocol, a data encryption proprietary protocol, a control system proprietary protocol, or an industry-specific proprietary protocol.
[0065] The HTTP (Hypertext Transfer Protocol) is used to transmit hypertext data between web browsers and servers, supporting web page browsing. It is based on the TCP protocol and uses a request-response model.
[0066] The FTP (File Transfer Protocol) provides file upload and download functions, and supports interactive access and permission management.
[0067] In this embodiment, the present invention can perform joint network detection on multiple devices that support industrial protocols, Internet protocols, Internet of Things protocols and private protocols respectively, without the need to develop independent tools for each type of protocol, which significantly reduces system complexity and resource waste.
[0068] By synchronously detecting network layer and application layer indicators through multi-protocol packet transmission, and through dual-dimensional joint judgment, the problem of application layer anomaly missed detection is solved, ensuring the comprehensiveness of device network status assessment.
[0069] In an optional embodiment of the present invention, step 12 involves parsing the protocol heartbeat packet to obtain the protocol type of the protocol heartbeat packet, and generating a multi-protocol sending packet according to the protocol type, including:
[0070] Step 121: Parse the protocol heartbeat packet to obtain the network layer protocol type and application layer protocol type; specifically, the protocol type field of the protocol heartbeat packet can be parsed according to the protocol description file (YAML format) to obtain the network layer protocol type; the application layer protocol type can be obtained by dynamically loading a private protocol plugin (.so file) or protocol plugins such as industrial protocols, Internet protocols, and Internet of Things protocols through a hot-plug interface.
[0071] Step 122: Generate a multi-protocol packet based on the network layer protocol type and the application layer protocol type.
[0072] In an optional embodiment of the present invention, step 122, generating a multi-protocol packet based on the network layer protocol type and the application layer protocol type, includes:
[0073] Step 1221: From N1 network layer protocol types and N2 application layer protocol types, generate N1*N2 protocol transmission packets according to any combination of any network layer protocol type and any application layer protocol type; N1 and N2 are positive integers.
[0074] For example, a protocol packet might have ICMP as its network layer protocol and HTTP as its application layer protocol. This pattern continues, allowing for the generation of multi-protocol packets.
[0075] The multi-protocol packet may carry at least one of the following:
[0076] Preset function codes and preset register addresses for industrial protocol transmission packets;
[0077] The preset device fingerprint and preset status code of the Internet Protocol (IP) packet;
[0078] The preset identifier and preset token of the IoT protocol transmission packet;
[0079] The preset function code and preset checksum of the private protocol transmission packet;
[0080] The timestamps of packets sent by network layer protocols and the total number of packets sent by multiple protocols.
[0081] In this embodiment, a preset protocol description file is loaded through the protocol adaptation layer, which supports the dynamic parsing and generation of network layer protocols and application layer protocols without the need to develop independent tools for each type of protocol.
[0082] The network layer protocol transmission packet (including timestamp and total number of transmissions) and the application layer protocol transmission packet (including various preset parameters) together form a multi-protocol transmission packet, which synchronously carries the detection elements of the network layer and the application layer.
[0083] In an optional embodiment of the present invention, step 13, sending the multi-protocol packet to multiple target devices, may include:
[0084] Step 131: Integrate the multi-protocol transmission packets (including at least one of the following: timestamp, total number of transmissions, preset function code and preset register address of industrial protocol, preset device fingerprint and preset status code of Internet protocol, preset identifier and preset token of IoT protocol or preset function code and preset check bit of private protocol), encapsulate them into a standard frame structure through the unified interface of the protocol adaptation layer, query the network layer address and access link type of multiple target devices from the device address table of the edge computing node, and send the multi-protocol transmission packets to multiple target devices simultaneously through multi-threading.
[0085] In an optional embodiment of the present invention, step 14, receiving multi-protocol response packets from multiple target devices according to multi-protocol transmission packets, may include at least one of the following:
[0086] Step 141: The target device receives multi-protocol transmission packets respectively and records the total number of multi-protocol transmission packets received;
[0087] Step 142: The target device parses and reads the industrial protocol transmission packet to obtain the actual function code and the actual register address;
[0088] Step 143: The target device parses and reads the Internet Protocol (IP) packets to obtain the actual device fingerprint and the actual status code.
[0089] Step 144: The target device parses and reads the IoT protocol transmission packet to obtain the actual identifier and the actual token;
[0090] Step 145: The target device parses and reads the private protocol transmission packet to obtain the actual function code and the actual check bit;
[0091] Step 146: The target device encapsulates the network layer indicators (timestamp of the network layer protocol packet sent, total number of network layer protocol packets sent, and total number of network layer protocol packets received) and application layer indicators (preset function code, preset register address, actual function code and actual register address of industrial protocol or preset device fingerprint, preset status code, actual device fingerprint and actual status code of Internet protocol or preset identifier, preset token, actual identifier and actual token of IoT protocol or preset function code, preset check bit, actual function code and actual check bit of private protocol) into a multi-protocol response packet and feeds it back to the edge computing node;
[0092] Step 147: The edge computing node generates a timestamp of the received network layer protocol response packet and adds it to the network layer metrics.
[0093] In this embodiment, multi-protocol packets are sent simultaneously to multiple target devices via multiple threads. Combined with the device address table of the edge computing node, the network layer address and access link type of the target devices are quickly queried, enabling parallel detection of batch devices. Compared to the mode of detecting a single device one by one, this significantly reduces the overall detection time.
[0094] During the response process, the target device not only records the total number of network layer protocol packets received, but also parses and feeds back actual parameters for different application layer protocols (such as the actual function codes of industrial protocols and the actual status codes of Internet protocols), and encapsulates the preset parameters and actual parameters together into the response packet. This paired feedback of "preset-actual" parameters provides complete data support for subsequent network layer status detection and application layer status detection (such as whether the actual function code matches the preset function code).
[0095] The multi-protocol transmission packets are encapsulated into a standard frame structure through a unified interface of the protocol adaptation layer. Similarly, the multi-protocol response packets integrate network layer and application layer metrics using a standardized format, ensuring data structure consistency and facilitating rapid parsing and processing by edge computing nodes. Furthermore, the edge computing nodes add a receiving timestamp to the multi-protocol response; combined with the sending timestamp, round-trip latency can be accurately calculated.
[0096] In an optional embodiment of the present invention, the network layer metrics include: network layer round-trip delay and packet loss rate; in step 15, the network layer state in the multi-protocol response packet is detected based on the network layer metrics carried by the multi-protocol response packet to obtain a first detection result, which may include:
[0097] Step 151, according to R = R 2- R 1. Determine the round-trip delay of the network layer; among which, R For the round-trip delay of the network layer, R 2 represents the timestamp of the received network layer protocol response packet. R 1 represents the timestamp of the network layer protocol packet being sent;
[0098] Step 152, according to L =( L 2- L 1) / L 2 × 100%, determine the packet loss rate of the network layer; where, L For packet loss rate at the network layer, L 2 represents the total number of packets sent via the network layer protocol. L 1 represents the total number of packets received from network layer protocols;
[0099] Step 153, if R < R k ,and L < L k If the first detection result is positive, the network layer is considered to be in a normal state; otherwise, the network layer is considered to be in an abnormal state. R For the round-trip delay of the network layer, R k The round-trip delay threshold, L For packet loss rate at the network layer, L k The packet loss rate threshold is set; by calculating the round-trip delay and packet loss rate, the network layer status is transformed from a qualitative description into a quantitative indicator; setting round-trip delay threshold and packet loss rate threshold as the judgment conditions for the normal operation of the network layer avoids the subjectivity of relying on experience judgment, ensures the consistency of detection standards in different scenarios, and improves the reliability of detection.
[0100] Step 154, if R > R k ,and L < L k The first detection result indicates an abnormal network layer state, but R < R p +R j If the result is negative, the first detection result will be corrected to normal; where, R For the round-trip delay of the network layer,R k The round-trip delay threshold, R p This is the average of historical round-trip delays. R j The variance of historical round-trip delays;
[0101] Step 155, if R < R k ,and L > L k The first detection result indicates an abnormal network layer state, but L < L k + H ,and n / m < D If the result is negative, the first detection result will be corrected to normal; where, L For packet loss rate at the network layer, L k The packet loss rate threshold. H The elastic threshold, n To reduce packet loss rate m Number of anomalies D This is the threshold for the number of abnormal occurrences.
[0102] In this embodiment, when the round-trip delay exceeds the threshold but does not exceed the sum of the historical average delay and variance, or the packet loss rate exceeds the threshold but is within the elasticity threshold range and close to the threshold... m When the percentage of abnormal occurrences does not exceed the threshold, the abnormal result is corrected to normal. This judgment logic based on historical trends and fluctuation range can effectively filter out misjudgments caused by instantaneous network jitter and reduce unnecessary maintenance interventions.
[0103] By dynamically adjusting the judgment criteria using historical data and flexible parameters, the detection logic can be made to better match the actual network characteristics.
[0104] In an optional embodiment of the present invention, step 16 involves detecting the application layer status in the multi-protocol response packet based on the application layer indicators carried by the multi-protocol response packet to obtain a second detection result, including:
[0105] Step 161: If the first application layer indicator (the actual function code of the industrial protocol, the actual device fingerprint of the Internet protocol, the actual identifier of the IoT protocol, or the actual function code of the private protocol) and the second application layer indicator (the actual register address of the industrial protocol, the actual status code of the Internet protocol, the actual token of the IoT protocol, or the actual check bit of the private protocol) carried in the multi-protocol response packet are both normal (matching the corresponding preset indicators, such as whether the actual register address of the industrial protocol is within the preset address range, or whether the actual status code of the Internet protocol is the preset normal code), then the second detection result is that the application layer status is normal; otherwise, the application layer status is abnormal.
[0106] In this embodiment, by comparing the first application layer indicator (such as the actual function code of the industrial protocol, the actual device fingerprint of the Internet protocol, etc.) and the second application layer indicator (such as the actual register address of the industrial protocol, the actual status code of the Internet protocol, etc.) with the corresponding preset indicators, it is possible to accurately determine whether the application layer service is normal. This solves the problem of existing technologies that only verify network layer connectivity while ignoring application layer status, and covers the scenario of "network is smooth but application layer is abnormal".
[0107] For the industrial protocols, Internet protocols, Internet of Things protocols, and private protocols, corresponding detection indicators are set (such as the actual identifier of the Internet of Things protocol matching the preset identifier, and the actual check bit of the private protocol matching the preset check bit). The detection of the application layer status of multiple protocols is realized through a unified "actual indicator matching preset indicator" logic, without the need to develop independent detection tools for each type of protocol.
[0108] In an optional embodiment of the present invention, step 17, determining the network status of the target device based on the first detection result and the second detection result, includes:
[0109] Step 171: If both the first detection result and the second detection result are normal, then the network connection status of the target device is determined to be normal.
[0110] Step 172: If both the first detection result and the second detection result are abnormal, then the network connection status of the target device is determined to be abnormal.
[0111] Step 173: If either the first detection result or the second detection result is abnormal, then start retry monitoring.
[0112] In this embodiment, the results of both the network layer and the application layer are used as the basis for judgment, which solves the limitation of the prior art that judges the network status only by the network layer connectivity.
[0113] For a single abnormal metric (such as momentary jitter at the network layer but normal operation at the application layer), further verification is performed by initiating retry monitoring (up to 3 times) to avoid false alarms triggered by momentary fluctuations. This design complements the composite judgment logic of the alarm suppression unit (a fault is confirmed only when both the network layer and application layer are abnormal), reducing operation and maintenance costs.
[0114] In an optional embodiment of the present invention, the method further includes:
[0115] Step 18: Based on the first detection result, adjust the transmission interval of the next multi-protocol packet; specifically, this may include:
[0116] Step 181, according to T =T 1 / (1+ a ×( L - L f )+ b ×( R - R f (), to determine the next transmission interval of the multi-protocol packet;
[0117] in, T The interval for sending the next multi-protocol packet. T 1 represents the transmission interval of the multi-protocol packet in this instance. a As a weight for packet loss rate, L For packet loss rate, L f As the first parameter, b For delayed weights, R For round-trip delay, R f The second parameter;
[0118] Step 182: Send the next multi-protocol packet according to the sending interval of the next multi-protocol packet.
[0119] In this embodiment, the transmission interval is dynamically adjusted based on the packet loss rate and round-trip delay: when the link quality is poor (high packet loss, high delay), the interval is shortened to ensure monitoring sensitivity, and when the link quality is good (low delay, low packet loss), the interval is extended to reduce the transmission frequency.
[0120] Compared to the fixed-frequency detection method in existing technologies, this dynamic adjustment mechanism can optimize the detection rhythm in real time according to network quality, ensuring a rapid response to abnormal states while avoiding resource waste in high-quality links.
[0121] Example 1
[0122] Example 1 provides a method for monitoring the network status of three types of target equipment in a factory that requires monitoring their network connectivity, including:
[0123] Step 21, Receive protocol heartbeat packets:
[0124] The three categories of target equipment include: industrial robots (supporting Modbus protocol), surveillance cameras (supporting HTTP / HTTPS protocol), and IoT sensors (supporting MQTT protocol).
[0125] Receive protocol heartbeats from three types of devices: Modbus heartbeat (containing device ID and register status), HTTP heartbeat (containing device IP and online identifier), and MQTT heartbeat (containing client ID and subscribed topic).
[0126] Step 22, parse the heartbeat packet and generate a multi-protocol packet:
[0127] The analysis revealed that the network layer protocol is ICMP, and the application layer protocols are Modbus, HTTP, and MQTT.
[0128] The network layer protocol of the generated multi-protocol packet is ICMP, which includes the sending timestamp (e.g., 2024-07-01 10:00:00) and the total number of packets sent (e.g., 10).
[0129] Application layer protocols include: Industrial Protocol Transmission Packets (Modbus): Preset function code 0x03 (Read Register), preset register addresses 0x0001-0x0004; or
[0130] Internet Protocol (HTTP): Default device fingerprint MD5 (camera ID) = abc123, default status code 200 (normal); or
[0131] IoT protocol MQTT: default identifier sensor-001, default token token=xyz456;
[0132] Step 23, send a multi-protocol packet:
[0133] The protocol adaptation layer encapsulates network layer ICMP packets with at least one of the three application layer protocols into a standard frame structure;
[0134] Query the network layer address of the target device from the device address table (e.g., industrial robot IP: 192.168.1.10, link type: Ethernet).
[0135] Simultaneously send multi-protocol packets to 10 devices using multiple threads;
[0136] Step 24, Receive multiprotocol response packets:
[0137] After processing, the target device sends back a response packet. Taking an industrial robot as an example:
[0138] The total number of ICMP packets received was recorded as 10 (consistent with the total number of packets sent).
[0139] Parse the Modbus transmit packet to obtain the actual function code 0x03 and the actual register addresses 0x0001-0x0004 (which match the preset).
[0140] Encapsulate network layer metrics (send timestamp 10:00:00, total number of sends 10, total number of receives 10) and application layer metrics (preset and actual function codes, register addresses).
[0141] The edge computing node records the timestamp of the received response packet as 10:00:00.2;
[0142] Step 25, Detect network layer status:
[0143] Calculate round-trip delay R =10:00:00.2-10:00:00=200ms;
[0144] Packet loss rate L =(10-10) / 10×100%=0%;
[0145] Assuming a threshold R k =500ms L k =5%, because R ≤ R k and L ≤ L k The first test result showed that the network layer was normal;
[0146] Step 26, Detect application layer status:
[0147] Take surveillance cameras as an example:
[0148] The actual device fingerprint is abc123 (matches the preset), and the actual status code is 200 (consistent with the preset normal code); the second detection result indicates that the application layer is normal.
[0149] Step 27, Determine network connection status:
[0150] The first test result (network layer normal) + the second test result (application layer normal) determine that the device's network connection status is normal;
[0151] Step 28, Adjust the sending interval:
[0152] This transmission interval T 1 = 60s, packet loss rate L =0%, round-trip delay R =200ms, weight a =0.2、 b =0.8、 L f =10%, R f =1.175s;
[0153] Calculate the next interval T =60 / (1+0.2×(0-0.1)+0.8×(0.2-1.175))=300s (The interval is increased due to the good link quality);
[0154] Send the next multiprotocol packet after 300 seconds.
[0155] This invention supports multiple protocol types, including network layer protocols (such as ICMP, IGMP, etc.), industrial protocols (such as Modbus, Profibus / Profinet, etc.), Internet protocols (such as TCP, HTTP / HTTPS, etc.), IoT protocols (such as 6LoWPAN, MQTT, etc.), and proprietary protocols (such as proprietary device communication protocols, etc.). It eliminates the need to develop separate tools for each protocol and can directly adapt to different types of target objects (such as industrial equipment, IoT terminals, Internet servers, etc.) in heterogeneous network environments. This solves the limitations of traditional monitoring methods on protocol types and greatly improves the universality of the method.
[0156] The network layer metrics (round-trip delay, packet loss rate) reflect the reachability and communication quality of the underlying network, while the application layer metrics (such as the actual function code and register address of industrial protocols, the actual device fingerprint and status code of Internet protocols, and the validity of various protocol responses) reflect the service availability of the target object, thus achieving dual verification of "network connectivity + service availability".
[0157] It avoids the drawbacks of single network layer detection (which can only determine physical connectivity and cannot confirm normal service) or single application layer detection (which ignores the impact of network fluctuations), ensuring that the monitoring results truly reflect the "actual availability status" of the target object.
[0158] Combining historical data (such as the average and variance of historical round-trip delays, packet loss rate, etc.) m The frequency of anomalies is used to correct network layer metrics and filter out invalid anomalies caused by instantaneous fluctuations (such as network jitter and occasional packet loss), thereby reducing the operational burden.
[0159] The transmission interval is dynamically adjusted based on network quality to avoid resource waste (too short intervals consume bandwidth) or the risk of missed detection (too long intervals delay fault detection), thus achieving "on-demand monitoring".
[0160] By adopting a unified multi-protocol processing mechanism (generation, parsing, sending, and judgment process), the traditional decentralized model of developing independent tools for various protocols is replaced, reducing the number of system components and interaction links, while facilitating centralized management and upgrades, and improving system maintainability.
[0161] The system determines "simultaneous normality of network layer and application layer" as normal and "simultaneous abnormality" as abnormal, thereby enhancing the reliability of the results. For "single indicator abnormality", retry monitoring is initiated (up to 3 times) to avoid directly determining abnormality due to momentary interference. This achieves hierarchical processing of "timely response to real abnormalities and effective filtering of momentary fluctuations", improving the efficiency of fault location.
[0162] like Figure 2As shown, embodiments of the present invention also provide a device 20 for monitoring the network status of a device, comprising:
[0163] Transceiver module 21 is used to receive protocol heartbeat packets sent by at least two target devices according to different communication protocol types; and to receive multi-protocol response packets fed back by multiple target devices according to multi-protocol sent packets, wherein the multi-protocol response packets carry network layer indicators and application layer indicators;
[0164] Processing module 22 is configured to parse the protocol heartbeat packet to obtain the protocol type of the protocol heartbeat packet, and generate a multi-protocol sending packet according to the protocol type; send the multi-protocol sending packet to multiple target devices; detect the network layer status in the multi-protocol response packet according to the network layer indicators carried in the multi-protocol response packet to obtain a first detection result; detect the application layer status in the multi-protocol response packet according to the application layer indicators carried in the multi-protocol response packet to obtain a second detection result; and determine the network status of the target device based on the first detection result and the second detection result.
[0165] Optionally, the protocol heartbeat packet is parsed to obtain the protocol type of the protocol heartbeat packet, and a multi-protocol sending packet is generated according to the protocol type, including:
[0166] The protocol heartbeat packets are parsed to obtain the network layer protocol type and application layer protocol type;
[0167] A multi-protocol packet is generated based on the network layer protocol type and the application layer protocol type.
[0168] Optionally, a multi-protocol packet is generated based on the network layer protocol type and the application layer protocol type, including:
[0169] Among N1 network layer protocol types and N2 application layer protocol types, N1*N2 protocol transmission packets are generated by combining any network layer protocol type with any application layer protocol type; N1 and N2 are positive integers.
[0170] Optionally, the network layer metrics include: network layer round-trip latency and packet loss rate;
[0171] Based on the network layer indicators carried in the multi-protocol response packet, the network layer status in the multi-protocol response packet is detected to obtain a first detection result, including:
[0172] like R < R k ,and L < L k If the first detection result is that the network layer is in normal condition, then the network layer is in abnormal condition.
[0173] in, RFor the round-trip delay of the network layer, R k The round-trip delay threshold, L For packet loss rate at the network layer, L k This is the packet loss rate threshold;
[0174] like R > R k ,and L < L k The first detection result indicates an abnormal network layer state, but R < R p +R j If so, the first detection result will be corrected to normal;
[0175] in, R For the round-trip delay of the network layer, R k The round-trip delay threshold, R p This is the average of historical round-trip delays. R j The variance of historical round-trip delays;
[0176] like R < R k ,and L > L k The first detection result indicates an abnormal network layer state, but L < L k + H ,and n / m < D If so, the first detection result will be corrected to normal;
[0177] in, L For packet loss rate at the network layer, L k The packet loss rate threshold. H The elastic threshold, n To reduce packet loss rate m Number of anomalies D This is the threshold for the number of abnormal occurrences.
[0178] Optionally, if the application layer indicators carried in the multi-protocol response packet are used to detect the application layer status in the multi-protocol response packet to obtain a second detection result, the result includes:
[0179] If both the first and second application layer indicators carried in the multi-protocol response packet are normal, then the second detection result is that the application layer status is normal; otherwise, the application layer status is abnormal.
[0180] Optionally, determining the network status of the target device based on the first detection result and the second detection result includes:
[0181] If both the first and second detection results are normal, then the network connection status of the target device is determined to be normal.
[0182] If both the first and second detection results are abnormal, then the network connection status of the target device is determined to be abnormal.
[0183] If either the first or second detection result is abnormal, a retry monitoring will be initiated.
[0184] Optionally, the processing module 22 is further configured to:
[0185] Based on the first detection result, adjust the transmission interval of the next multi-protocol packet.
[0186] It should be noted that this device is a device corresponding to the above method. All implementation methods in the above method embodiments are applicable to this embodiment and can achieve the same technical effect.
[0187] Embodiments of the present invention also provide an edge node, including a device for monitoring the network status of the device as described above.
[0188] Embodiments of the present invention also provide a system for monitoring the network status of a device, comprising:
[0189] An edge node is used to receive protocol heartbeat packets sent by at least two target devices according to different communication protocol types; parse the protocol heartbeat packets to obtain the protocol type of the protocol heartbeat packets, and generate multi-protocol sending packets according to the protocol type; and send the multi-protocol sending packets to multiple target devices.
[0190] The system receives multi-protocol response packets from multiple target devices, each packet carrying network layer and application layer indicators. Based on the network layer indicators, the system detects the network layer status within the multi-protocol response packets to obtain a first detection result. Based on the application layer indicators, the system detects the application layer status within the multi-protocol response packets to obtain a second detection result. Based on the first and second detection results, the system determines the network connection status of the target devices.
[0191] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for monitoring the network status of a device, characterized in that, include: Receive protocol heartbeat packets sent by at least two target devices according to different communication protocol types; The protocol heartbeat packets are parsed to obtain the protocol type of the protocol heartbeat packets, and multi-protocol sending packets are generated according to the protocol type; The multi-protocol packet is sent to multiple target devices; Receive multi-protocol response packets from multiple target devices according to multi-protocol sent packets, wherein the multi-protocol response packets carry network layer indicators and application layer indicators; Based on the network layer indicators carried by the multi-protocol response packet, the network layer status in the multi-protocol response packet is detected to obtain a first detection result; Based on the application layer indicators carried in the multi-protocol response packet, the application layer status in the multi-protocol response packet is detected to obtain a second detection result; Based on the first and second detection results, the network status of the target device is determined; The network layer metrics include: network layer round-trip latency and packet loss rate; The application layer metrics include: first application layer metrics and second application layer metrics; The first application layer indicator includes: the actual function code of the industrial protocol, the actual device fingerprint of the Internet protocol, the actual identifier of the Internet of Things protocol, or the actual function code of the private protocol. The second application layer metrics include: the actual register address of the industrial protocol, the actual status code of the Internet protocol, the actual token of the Internet of Things protocol, or the actual check bit of the private protocol.
2. The method for monitoring the network status of a device according to claim 1, characterized in that, The protocol heartbeat packets are parsed to obtain the protocol type of the heartbeat packets, and multi-protocol sending packets are generated according to the protocol type, including: The protocol heartbeat packets are parsed to obtain the network layer protocol type and application layer protocol type; A multi-protocol packet is generated based on the network layer protocol type and the application layer protocol type.
3. The method for monitoring the network status of a device according to claim 2, characterized in that, Based on the network layer protocol type and the application layer protocol type, a multi-protocol packet is generated, including: Among N1 network layer protocol types and N2 application layer protocol types, N1*N2 protocol transmission packets are generated by combining any network layer protocol type with any application layer protocol type; N1 and N2 are positive integers.
4. The method for monitoring the network status of a device according to claim 1, characterized in that, Based on the network layer indicators carried in the multi-protocol response packet, the network layer status in the multi-protocol response packet is detected to obtain a first detection result, including: like R≤R k ,and L≤L k If the first detection result is that the network layer is in normal condition, then the network layer is in abnormal condition. in, R For the round-trip delay of the network layer, R k The round-trip delay threshold, L For packet loss rate at the network layer, L k This is the packet loss rate threshold; like R > R k ,and L≤L k The first detection result indicates an abnormal network layer state, but R≤R p +R j If so, the first detection result will be corrected to normal; in, R For the round-trip delay of the network layer, R k The round-trip delay threshold, R p This is the average of historical round-trip delays. R j The variance of historical round-trip delays; like R≤R k ,and L>L k The first detection result indicates an abnormal network layer state, but L≤L k + H ,and n / m≤D If so, the first detection result will be corrected to normal; in, L For packet loss rate at the network layer, L k The packet loss rate threshold. H The elastic threshold, n To reduce packet loss rate m Number of anomalies D This is the threshold for the number of abnormal occurrences.
5. The method for monitoring the network status of a device according to claim 1, characterized in that, Based on the application layer indicators carried in the multi-protocol response packet, the application layer status in the multi-protocol response packet is detected to obtain a second detection result, including: If both the first and second application layer indicators carried in the multi-protocol response packet are normal, then the second detection result indicates that the application layer status is normal; otherwise, the application layer status is abnormal.
6. The method for monitoring the network status of a device according to claim 1, characterized in that, Based on the first detection result and the second detection result, the network connection status of the target device is determined, including: If both the first and second detection results are normal, then the network connection status of the target device is determined to be normal. If both the first and second detection results are abnormal, then the network connection status of the target device is determined to be abnormal. If either the first or second detection result is abnormal, a retry monitoring will be initiated.
7. The method for monitoring the network status of a device according to claim 1, characterized in that, Also includes: Based on the first detection result, adjust the transmission interval of the next multi-protocol packet.
8. A device for monitoring the network status of a device, characterized in that, include: The transceiver module is used to receive protocol heartbeat packets sent by at least two target devices according to different communication protocol types; And receive multi-protocol response packets from multiple target devices according to multi-protocol sent packets, wherein the multi-protocol response packets carry network layer indicators and application layer indicators; The processing module is used to parse the protocol heartbeat packet, obtain the protocol type of the protocol heartbeat packet, and generate a multi-protocol sending packet according to the protocol type; The multi-protocol packet is sent to multiple target devices; Based on the network layer indicators carried by the multi-protocol response packet, the network layer status in the multi-protocol response packet is detected to obtain a first detection result; Based on the application layer indicators carried in the multi-protocol response packet, the application layer status in the multi-protocol response packet is detected to obtain a second detection result; Based on the first and second detection results, the network status of the target device is determined; The network layer metrics include: network layer round-trip latency and packet loss rate; The application layer metrics include: first application layer metrics and second application layer metrics; The first application layer indicator includes: the actual function code of the industrial protocol, the actual device fingerprint of the Internet protocol, the actual identifier of the Internet of Things protocol, or the actual function code of the private protocol. The second application layer metrics include: the actual register address of the industrial protocol, the actual status code of the Internet protocol, the actual token of the Internet of Things protocol, or the actual check bit of the private protocol.
9. An edge node, characterized in that, Includes a device for monitoring the network status of the device as described in claim 8.
10. A system for monitoring the network status of a device, characterized in that, include: Edge nodes are used to receive protocol heartbeat packets sent by at least two target devices according to different communication protocol types; The protocol heartbeat packets are parsed to obtain the protocol type of the protocol heartbeat packets, and multi-protocol sending packets are generated according to the protocol type; The multi-protocol packet is sent to multiple target devices; Receive multi-protocol response packets from multiple target devices according to multi-protocol transmission packets, wherein the multi-protocol response packets carry network layer indicators and application layer indicators; detect the network layer status in the multi-protocol response packets according to the network layer indicators carried in the multi-protocol response packets to obtain a first detection result; Based on the application layer indicators carried in the multi-protocol response packet, the application layer status in the multi-protocol response packet is detected to obtain a second detection result; Based on the first and second detection results, the network status of the target device is determined; The network layer metrics include: network layer round-trip latency and packet loss rate; The application layer metrics include: first application layer metrics and second application layer metrics; The first application layer indicator includes: the actual function code of the industrial protocol, the actual device fingerprint of the Internet protocol, the actual identifier of the Internet of Things protocol, or the actual function code of the private protocol. The second application layer metrics include: the actual register address of the industrial protocol, the actual status code of the Internet protocol, the actual token of the Internet of Things protocol, or the actual check bit of the private protocol.
Citation Information
Patent Citations
Network condition detection method and device
CN105323121A
Method for detecting the ipv6 network application layer protocol
US20080172456A1