Network equipment monitoring method, system, device and medium based on industrial internet of things

By constructing a performance fluctuation matrix and a feature matrix, combined with an equipment status assessment model, the problem that traditional methods cannot adapt to periodic fluctuations in the industrial IoT environment is solved. This enables high-precision and rapid anomaly identification and scoring of network devices, improving the accuracy and efficiency of operation and maintenance response.

CN121309401BActive Publication Date: 2026-03-24CHENGDU QINCHUAN IOT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-12
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

Traditional network device monitoring methods cannot adapt to periodic fluctuations in the industrial IoT environment, leading to false alarms or missed alarms. Furthermore, long-term baseline models are difficult to adapt quickly to changes in device status, making it impossible to achieve rapid and accurate anomaly diagnosis.

Method used

By acquiring time-series data of network device performance parameters, a performance fluctuation matrix is ​​constructed, the intrinsic deviation feature matrix and the group deviation feature matrix are determined, and the device status assessment model is used to generate device monitoring results, including abnormal devices and anomaly scores.

Benefits of technology

It achieves high-precision and high-efficiency identification of abnormal network device status in industrial IoT environments, overcomes the problems of high false alarms and false negatives of traditional methods and the adaptability limitations of long-term baseline models, and improves the accuracy and efficiency of operation and maintenance response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121309401B_ABST
    Figure CN121309401B_ABST
Patent Text Reader

Abstract

The application discloses a network equipment monitoring method and system based on an industrial Internet of Things, equipment and a medium, relates to the technical field of the industrial Internet of Things, and the method comprises the following steps: acquiring performance parameter time series data of each network equipment in the i, i+1,..., i+k monitoring periods, and determining a performance fluctuation matrix of the network equipment in each monitoring period according to the performance parameter time series data; for each network equipment, determining an intrinsic deviation feature matrix corresponding to a single network equipment according to the performance fluctuation matrix, and determining a group deviation feature matrix corresponding to the single network equipment according to the performance fluctuation matrix; generating a device monitoring result based on a device state evaluation model and according to the intrinsic deviation feature matrix and the group deviation feature matrix, wherein the device monitoring result comprises an abnormal network equipment and an abnormality score of the abnormal network equipment. The application has the effect of accurate network equipment state monitoring.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of industrial Internet of Things (IIoT), and in particular to network device monitoring methods, systems, devices, and media based on IIoT. Background Technology

[0002] With the rapid development of Industrial Internet of Things (IIoT) technology, the scale of network devices deployed in modern industrial production environments is becoming increasingly large and their structures increasingly complex. These devices are the core foundation for ensuring reliable transmission of production data and stable operation of services, and real-time monitoring of their performance status and early warning of anomalies have become top priorities for operation and maintenance.

[0003] In current technological practices, network device monitoring typically relies on threshold-based alarm mechanisms for performance metrics (such as latency, throughput, and packet loss rate) or static baseline models trained on long-term historical data. However, in highly periodic and regular scenarios such as industrial production, device load, network traffic, and user behavior patterns often exhibit repetitive patterns with fixed cycles (such as by shift, day, or week). In such scenarios, traditional monitoring methods face significant challenges: First, static thresholds cannot adapt to periodic fluctuations, easily leading to false alarms during peak periods or missed alarms during off-peak periods; second, baseline models based on long-term historical data require a lengthy data accumulation period and are difficult to adapt to the initial deployment phase of devices or the slow drift in operating modes, failing to achieve rapid response and accurate diagnosis. Therefore, the industry urgently needs a new solution for network device status monitoring that can deeply integrate the characteristics of periodic scenarios to achieve fast, accurate, and adaptive monitoring. Summary of the Invention

[0004] To improve the accuracy of network device status monitoring, this application provides a network device monitoring method, system, device, and medium based on the Industrial Internet of Things.

[0005] Firstly, this application provides a network device monitoring method based on the Industrial Internet of Things, which adopts the following technical solution:

[0006] A network device monitoring method based on the Industrial Internet of Things (IIoT) is applied to an IIoT system, which includes a management platform, a sensor network platform, and an object platform connected in sequence. The method is executed by the management platform and includes:

[0007] Obtain the time-series data of performance parameters of each network device in the i-th, i+1, ..., i+k-th monitoring periods, and determine the performance fluctuation matrix of each network device in each monitoring period based on the time-series data of performance parameters, wherein the performance fluctuation matrix is ​​used to represent the performance fluctuation status of a single network device.

[0008] For each network device, an intrinsic deviation feature matrix corresponding to a single network device is determined based on the performance fluctuation matrix, and a group deviation feature matrix corresponding to a single network device is determined based on the performance fluctuation matrix. The intrinsic deviation feature matrix is ​​used to represent the difference between the performance fluctuation of a single network device in the (i+k)th monitoring period and the average performance fluctuation level of the previous k monitoring periods. The group deviation feature matrix is ​​used to represent the difference between the performance fluctuation of a single network device in the (i+k)th monitoring period and the average performance fluctuation level of the same type of network devices in the i, i+1, ..., i+k-1th monitoring periods, respectively.

[0009] Based on the device status assessment model, and according to the intrinsic deviation feature matrix and the group deviation feature matrix, device monitoring results are generated, wherein the device monitoring results include abnormal network devices and the abnormality scores of the abnormal network devices.

[0010] By adopting the above technical solution, firstly, the time-series data of performance parameters of each network device in the i-th, i+1, ..., i+k-th monitoring periods are obtained. Then, based on the time-series data, the performance fluctuation matrix of each network device in each monitoring period is determined. This performance fluctuation matrix represents the performance fluctuation status of a single network device. Next, for each network device, the intrinsic deviation feature matrix corresponding to the single network device is determined based on the performance fluctuation matrix, and the group deviation feature matrix corresponding to the single network device is also determined based on the performance fluctuation matrix. The intrinsic deviation feature matrix represents the difference between the performance fluctuation of a single network device in the i+k-th monitoring period and the average performance fluctuation level of the previous k monitoring periods. The group deviation feature matrix represents the difference between the performance fluctuation of a single network device in the i+k-th monitoring period and the average performance fluctuation level of the previous k monitoring periods. The method identifies the differences in performance fluctuation levels among similar network devices within a monitoring period. Then, based on a device status assessment model and using intrinsic deviation feature matrices and group deviation feature matrices, it generates device monitoring results, including abnormal network devices and their anomaly scores. This method leverages the performance fluctuation patterns of network devices within recent monitoring windows and their relative differences from the historical performance of similar devices to achieve high-precision and high-efficiency identification of abnormal network device states in highly periodic industrial IoT environments. This overcomes the limitations of traditional static threshold methods, which suffer from high false alarms and false negatives under periodic fluctuations, and the slow deployment and difficulty in adapting to changes in long-term baseline models. It can quickly generate monitoring results that combine abnormal device identification and severity scores, thereby improving the accuracy and efficiency of maintenance responses.

[0011] Optionally, the step of determining the performance fluctuation matrix of each network device in each monitoring period based on the time-series data of the performance parameters includes:

[0012] For each network device in the i-th, i+1-th, ..., i+k-th monitoring period, the corresponding performance parameter time series data is matrixed to obtain the corresponding performance parameter matrix, wherein the rows of the performance parameter matrix are used to represent the various performance parameters of the network device;

[0013] Obtain the importance weights of each performance parameter, and perform a weighted transformation on the performance parameter matrix according to the importance weights to obtain the corresponding weighted matrix;

[0014] The weighted matrix is ​​subjected to row differencing to obtain the corresponding performance fluctuation matrix.

[0015] By adopting the above technical solution, in order to determine the performance fluctuation matrix, for each network device in the i, i+1, ..., i+k monitoring periods, the corresponding performance parameter time series data is matrixed to obtain the corresponding performance parameter matrix. The rows of the performance parameter matrix are used to represent the various performance parameters of the network device. Then, the importance weights of each performance parameter are obtained, and the performance parameter matrix is ​​weighted according to the importance weights to obtain the corresponding weighted matrix. Then, the weighted matrix is ​​subjected to row difference processing to obtain the corresponding performance fluctuation matrix.

[0016] Optionally, the step of determining the intrinsic deviation feature matrix corresponding to a single network device based on the performance fluctuation matrix includes:

[0017] For each network device, the performance fluctuation matrix of the same network device in the i, i+1, ..., i+k-1 monitoring periods is averaged to obtain n first performance fluctuation average matrices, where the first performance fluctuation average matrix is ​​used to represent the average performance fluctuation level of the same network device in the first k monitoring periods, and n is the total number of network devices.

[0018] The performance fluctuation matrix of the same network device in the (i+k)th monitoring period is subtracted from the corresponding first performance fluctuation average matrix to obtain n intrinsic deviation feature matrices.

[0019] By adopting the above technical solution, in order to determine the intrinsic deviation feature matrix, for each network device, the performance fluctuation matrix of the same network device in the i, i+1, ..., i+k-1 monitoring periods is subjected to matrix averaging to obtain n first performance fluctuation average matrices. The first performance fluctuation average matrix is ​​used to represent the average performance fluctuation level of the same network device in the first k monitoring periods, and n is the total number of network devices. Then, the performance fluctuation matrix of the same network device in the i+k monitoring period is subjected to matrix subtraction with the corresponding first performance fluctuation average matrix to obtain n intrinsic deviation feature matrices.

[0020] Optionally, the step of determining the group deviation feature matrix corresponding to a single network device based on the performance fluctuation matrix includes:

[0021] For each monitoring period in the i, i+1, ..., i+k-1th monitoring period, the performance fluctuation matrix corresponding to the same type of network devices is obtained, and the performance fluctuation matrix corresponding to the same type of network devices is subjected to matrix averaging to obtain the second performance fluctuation average matrix corresponding to the same type of network devices, wherein the second performance fluctuation average matrix is ​​used to represent the average performance fluctuation level of the same type of network devices.

[0022] For the (i+k)th monitoring period, matrix subtraction is performed on the performance fluctuation matrix corresponding to each network device and the second average performance fluctuation matrix corresponding to the same type of network device to obtain k*m*n group deviation feature matrices, where m is the number of categories of the network devices.

[0023] By adopting the above technical solution, in order to determine the group deviation feature matrix, for each monitoring period in the i, i+1, ..., i+k-1th monitoring period, the performance fluctuation matrix corresponding to the same type of network devices is obtained, and the performance fluctuation matrix corresponding to the same type of network devices is subjected to matrix averaging to obtain the second performance fluctuation average matrix corresponding to the same type of network devices. The second performance fluctuation average matrix is ​​used to represent the average performance fluctuation level of the same type of network devices. Then, for the i+kth monitoring period, matrix subtraction is performed on the performance fluctuation matrix corresponding to each network device and the second performance fluctuation average matrix corresponding to the same type of network device to obtain k*m*n group deviation feature matrices, where m is the number of network device categories.

[0024] Optionally, the equipment status assessment model includes an input layer, a hidden layer, and an output layer. The step of generating equipment monitoring results based on the equipment status assessment model and according to the intrinsic deviation feature matrix and the population deviation feature matrix includes:

[0025] Through the input layer, an input feature vector is generated based on the intrinsic deviation feature matrix and the population deviation feature matrix;

[0026] Through the hidden layer, a feature extraction vector is generated based on the input feature vector;

[0027] Through the output layer, an output matrix is ​​generated based on the feature extraction vector, wherein the dimension of the output matrix is ​​2×o, the first row of the output matrix is ​​used to represent abnormal network devices, the second row of the output matrix is ​​used to represent the abnormality score of the abnormal network devices, and o is the number of abnormal network devices;

[0028] Based on the output matrix, network evaluation results are generated.

[0029] By adopting the above technical solution, in order to generate equipment monitoring results, the input layer generates an input feature vector based on the intrinsic deviation feature matrix and the population deviation feature matrix. Then, the hidden layer generates a feature extraction vector based on the input feature vector. Finally, the output layer generates an output matrix based on the feature extraction vector. The output matrix has a dimension of 2×o. The first row of the output matrix represents abnormal network devices, the second row represents the abnormality score of the abnormal network devices, and o is the number of abnormal network devices. Then, based on the output matrix, the network evaluation result is generated.

[0030] Optionally, the hidden layer includes a first hidden layer, a second hidden layer, and a third hidden layer, wherein the neuron ratio among the first hidden layer, the second hidden layer, and the third hidden layer is 64:16:1. The step of generating a feature extraction vector based on the input feature vector through the hidden layer includes:

[0031] Based on the first hidden layer, and according to the input feature vector, a first intermediate feature vector is generated;

[0032] Based on the second hidden layer, and according to the first intermediate feature vector, a second intermediate feature vector is generated;

[0033] Based on the third hidden layer and according to the second intermediate feature vector, a feature extraction vector is generated.

[0034] By adopting the above technical solution, in order to generate the feature extraction vector, firstly, based on the first hidden layer and the input feature vector, a first intermediate feature vector is generated; then, based on the second hidden layer and the first intermediate feature vector, a second intermediate feature vector is generated; and finally, based on the third hidden layer and the second intermediate feature vector, the feature extraction vector is generated.

[0035] Optionally, the step of generating the equipment condition assessment model includes:

[0036] Acquire model training data and divide the model training data according to a preset ratio to obtain a training set and a test set, wherein the model training data includes historical intrinsic deviation feature data and population deviation feature data;

[0037] The hyperparameters of the pre-built neural network model are set according to the random network search algorithm, and the root mean square error (RMSE) and the coefficient of determination (R²) are used as evaluation indicators.

[0038] The pre-built neural network model is trained based on the training set to obtain a trained neural network model;

[0039] The trained neural network model is tested according to the test set, and the corresponding error is determined according to the evaluation index. If it is, the trained neural network model is used as the device status evaluation model.

[0040] By adopting the above technical solution, in order to generate an equipment condition assessment model, model training data is obtained and divided into training and test sets according to a preset ratio. The model training data includes historical intrinsic deviation feature data and population deviation feature data. Then, the hyperparameters of the pre-built neural network model are set according to a random network search algorithm, and the root mean square error (RMSE) and coefficient of determination (R²) are used as evaluation indicators. The pre-built neural network model is then trained on the training set to obtain a trained neural network model. The trained neural network model is then tested on the test set, and the corresponding error is judged according to the evaluation indicators to determine whether it is within a preset range. If the error is within the preset range, the trained neural network model is used as the equipment condition assessment model.

[0041] Secondly, this application also provides a network device monitoring system based on the Industrial Internet of Things, which adopts the following technical solution:

[0042] An industrial IoT-based network device monitoring system includes a management platform, a sensor network platform, and an object platform that are sequentially connected in communication. The management platform is configured with:

[0043] The performance fluctuation matrix generation module is used to obtain the time-series data of the performance parameters of each network device in the i, i+1, ..., i+k monitoring periods, and to determine the performance fluctuation matrix of each network device in each monitoring period based on the time-series data of the performance parameters, wherein the performance fluctuation matrix is ​​used to represent the performance fluctuation status of a single network device.

[0044] The feature matrix generation module is used to determine, for each network device, the intrinsic deviation feature matrix corresponding to a single network device based on the performance fluctuation matrix, and to determine the group deviation feature matrix corresponding to a single network device based on the performance fluctuation matrix. The intrinsic deviation feature matrix is ​​used to represent the difference between the performance fluctuation of a single network device in the (i+k)th monitoring period and the average performance fluctuation level of the previous k monitoring periods. The group deviation feature matrix is ​​used to represent the difference between the performance fluctuation of a single network device in the (i+k)th monitoring period and the average performance fluctuation level of the same type of network devices in the (i), (i+1), ..., (i+k-1)th monitoring periods, respectively.

[0045] The device status assessment module is used to generate device monitoring results based on the device status assessment model and according to the intrinsic deviation feature matrix and the group deviation feature matrix. The device monitoring results include abnormal network devices and the abnormality scores of the abnormal network devices.

[0046] Thirdly, this application also provides a computer device, which adopts the following technical solution:

[0047] A computer device includes a memory and a processor, the memory storing a computer program executable on the processor, the processor executing the computer program to implement the method described in the first aspect.

[0048] Fourthly, this application also provides a computer-readable storage medium, which adopts the following technical solution:

[0049] A computer-readable storage medium storing a computer program capable of being loaded by a processor and executing the method described in the first aspect.

[0050] In summary, this application includes at least the following beneficial technical effects: First, it acquires the time-series data of performance parameters of each network device within the i-th, i+1, ..., i+k-th monitoring periods, and determines the performance fluctuation matrix of each network device within each monitoring period based on the time-series data of performance parameters. The performance fluctuation matrix represents the performance fluctuation status of a single network device. Then, for each network device, it determines the intrinsic deviation feature matrix corresponding to the single network device based on the performance fluctuation matrix, and determines the group deviation feature matrix corresponding to the single network device based on the performance fluctuation matrix. The intrinsic deviation feature matrix represents the difference between the performance fluctuation of a single network device in the i+k-th monitoring period and the average performance fluctuation level of the previous k monitoring periods, and the group deviation feature matrix represents the difference between the performance fluctuation of a single network device in the i+k-th monitoring period and the average performance fluctuation level of the previous k monitoring periods. The method identifies the differences in performance fluctuation levels among similar network devices over i+k-1 monitoring periods. Then, based on a device status assessment model and using the intrinsic deviation feature matrix and the group deviation feature matrix, it generates device monitoring results, including abnormal network devices and their anomaly scores. This method leverages the performance fluctuation patterns of network devices within recent monitoring windows and their relative differences from the historical performance of similar devices to achieve high-precision and high-efficiency identification of abnormal network device states in highly periodic industrial IoT environments. This overcomes the limitations of traditional static threshold methods, which suffer from high false alarms and false negatives under periodic fluctuations, and the slow deployment and difficulty in adapting to changes in long-term baseline models. It can quickly generate monitoring results that combine abnormal device identification and severity scores, thereby improving the accuracy and efficiency of maintenance responses. Attached Figure Description

[0051] Figure 1 This is a schematic diagram of the overall process of an embodiment of this application.

[0052] Figure 2 This is a structural diagram of one application scenario of the system according to an embodiment of this application.

[0053] Figure 3 This is a structural diagram of another application scenario of the system according to an embodiment of this application.

[0054] Figure 4 This is a structural block diagram of the computer device described in this application. Detailed Implementation

[0055] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0056] This application discloses a method for monitoring network devices based on the Industrial Internet of Things (IIoT).

[0057] Reference Figure 1 A network device monitoring method based on the Industrial Internet of Things (IIoT) is applied to an IIoT system. The IIoT system includes a management platform, a sensor network platform, and an object platform that are sequentially connected via communication. The method is executed by the management platform and includes:

[0058] Step S11: Obtain the time-series data of the performance parameters of each network device in the i, i+1, ..., i+k monitoring periods, and determine the performance fluctuation matrix of each network device in each monitoring period based on the time-series data of the performance parameters.

[0059] The performance fluctuation matrix is ​​used to represent the performance fluctuation status of a single network device.

[0060] It should be noted that in step S11, the (i+k)th monitoring period is the current monitoring period, and the i, i+1, ..., i+k-1th monitoring periods (a total of k monitoring periods) are historical monitoring periods. Within the (k+1) consecutive periods starting from the i-th monitoring period, time-series data of key performance parameters of each network device (such as throughput, latency, packet loss, CPU / memory utilization, etc.) are collected at a preset frequency. The performance parameters of the same network device in each period are aggregated into a performance matrix, and then the performance fluctuation matrix is ​​determined based on the performance matrix. In addition, k is a positive integer set manually. The specific value of k is based on the types of performance parameters and the collection frequency of performance parameters. If there are fewer types of performance parameters and the collection frequency of performance parameters is lower, k can take a larger value. If there are more types of performance parameters and the collection frequency of performance parameters is higher, k can take a smaller value, thereby achieving a balance between computational load and data volume.

[0061] Step S12: For each network device, determine the intrinsic deviation feature matrix corresponding to the single network device based on the performance fluctuation matrix, and determine the group deviation feature matrix corresponding to the single network device based on the performance fluctuation matrix.

[0062] Among them, the intrinsic deviation feature matrix is ​​used to represent the difference between the performance fluctuation of a single network device in the (i+k)th monitoring period and the average performance fluctuation of the previous k monitoring periods, and the group deviation feature matrix is ​​used to represent the difference between the performance fluctuation of a single network device in the (i+k)th monitoring period and the average performance fluctuation of the same type of network devices in the (i), (i+1), ..., (i+k-1)th monitoring periods, respectively.

[0063] It should be noted that the intrinsic deviation feature matrix focuses on "self-comparison," representing the degree of deviation of a network device's performance fluctuation in the current monitoring period from the average performance fluctuation level of similar devices in historical monitoring periods, reflecting local anomalies or short-term trends. The group deviation feature matrix focuses on "peer comparison," determining the degree of deviation of a network device's performance fluctuation in the current monitoring period from the average performance fluctuation level of similar devices in various historical monitoring periods. Through these two types of deviation features, both the self-changing characteristics of individual devices and the relative differences at the group level can be captured simultaneously for subsequent anomaly detection.

[0064] Step S13: Based on the equipment condition assessment model, generate equipment monitoring results according to the intrinsic deviation feature matrix and the group deviation feature matrix.

[0065] The equipment monitoring results include abnormal network devices and their abnormality scores.

[0066] In the above implementation, firstly, the time-series data of performance parameters of each network device within the i-th, i+1, ..., i+k-th monitoring periods are obtained. Then, based on the time-series data, the performance fluctuation matrix of each network device within each monitoring period is determined. This performance fluctuation matrix represents the performance fluctuation status of a single network device. Next, for each network device, the intrinsic deviation feature matrix corresponding to the single network device is determined based on the performance fluctuation matrix, and the group deviation feature matrix corresponding to the single network device is also determined based on the performance fluctuation matrix. The intrinsic deviation feature matrix represents the difference between the performance fluctuation of a single network device in the i+k-th monitoring period and the average performance fluctuation level of the previous k monitoring periods. The group deviation feature matrix represents the difference between the performance fluctuation of a single network device in the i+k-th monitoring period and the average performance fluctuation level of the previous k monitoring periods. The method identifies the differences in performance fluctuation levels among similar network devices within a monitoring period. Then, based on the device status assessment model, and according to the intrinsic deviation feature matrix and the group deviation feature matrix, it generates device monitoring results, which include abnormal network devices and their anomalousness scores. This method utilizes the performance fluctuation patterns of network devices within recent monitoring windows and their relative differences from the historical performance of similar devices to achieve high-precision and high-efficiency identification of abnormal network device states in a highly periodic industrial IoT environment. This method overcomes the limitations of traditional static threshold methods, such as high false alarms and false negatives under periodic fluctuations, as well as the slow deployment and difficulty in adapting to changes in long-term baseline models. It can quickly generate monitoring results that combine abnormal device identification and severity scores, thereby improving the accuracy and efficiency of operation and maintenance response.

[0067] As a further implementation of the method, the step of determining the performance fluctuation matrix of each network device in each monitoring period based on performance parameter time-series data includes:

[0068] Step S21: For each network device in the i, i+1, ..., i+k monitoring periods, perform matrix processing on the corresponding performance parameter time series data to obtain the corresponding performance parameter matrix, where the rows of the performance parameter matrix are used to represent the various performance parameters of the network device.

[0069] It should be noted that if the number of network devices is n, then the number of performance parameter matrices is n*(k+1).

[0070] Step S22: Obtain the importance weights of each performance parameter, and perform a weighted transformation on the performance parameter matrix according to the importance weights to obtain the corresponding weighted matrix.

[0071] Step S23: Perform row differencing on the weighted matrix to obtain the corresponding performance fluctuation matrix.

[0072] In the above implementation, in order to determine the performance fluctuation matrix, for each network device in the i, i+1, ..., i+k monitoring periods, the corresponding performance parameter time series data is matrixed to obtain the corresponding performance parameter matrix. The rows of the performance parameter matrix are used to represent the various performance parameters of the network device. Then, the importance weights of each performance parameter are obtained, and the performance parameter matrix is ​​weighted according to the importance weights to obtain the corresponding weighted matrix. Then, the weighted matrix is ​​subjected to row difference processing to obtain the corresponding performance fluctuation matrix.

[0073] As a further implementation of the method, the step of determining the intrinsic deviation feature matrix corresponding to a single network device based on the performance fluctuation matrix includes:

[0074] Step S31: For each network device, perform matrix averaging on the performance fluctuation matrix of the same network device in the i, i+1, ..., i+k-1 monitoring periods to obtain n first performance fluctuation average matrices, where the first performance fluctuation average matrix is ​​used to represent the average performance fluctuation level of the same network device in the first k monitoring periods, and n is the total number of network devices.

[0075] Step S32: Perform matrix subtraction on the performance fluctuation matrix of the same network device in the i+kth monitoring period and the corresponding first performance fluctuation average matrix to obtain n intrinsic deviation feature matrices.

[0076] In the above implementation, in order to determine the intrinsic deviation feature matrix, for each network device, the performance fluctuation matrix of the same network device in the i, i+1, ..., i+k-1 monitoring periods is averaged to obtain n first performance fluctuation average matrices, where the first performance fluctuation average matrix is ​​used to represent the average performance fluctuation level of the same network device in the first k monitoring periods, and n is the total number of network devices. Then, the performance fluctuation matrix of the same network device in the i+k monitoring period is subtracted from the corresponding first performance fluctuation average matrix to obtain n intrinsic deviation feature matrices.

[0077] As a further implementation of the method, the step of determining the group deviation feature matrix corresponding to a single network device based on the performance fluctuation matrix includes:

[0078] Step S41: For each monitoring period in the i, i+1, ..., i+k-1th monitoring period, obtain the performance fluctuation matrix corresponding to the same type of network devices, and perform matrix averaging on the performance fluctuation matrix corresponding to the same type of network devices to obtain the second performance fluctuation average matrix corresponding to the same type of network devices, wherein the second performance fluctuation average matrix is ​​used to represent the average performance fluctuation level of the same type of network devices.

[0079] It should be noted that the standard for classifying network devices of the same type is the consistency of the network device hardware. For example, two routers of the same model with identical hardware parameters can be considered as network devices of the same type. Similarly, two routers of different models with basically identical hardware parameters can also be considered as network devices of the same type.

[0080] Step S42: For the (i+k)th monitoring period, perform matrix subtraction on the performance fluctuation matrix corresponding to each network device and the second average performance fluctuation matrix corresponding to the same type of network device to obtain k*m*n group deviation feature matrices, where m is the number of network device categories.

[0081] It should be noted that in step S41, for each monitoring period in the i, i+1, ..., i+k-1th monitoring period, the number of network device categories is n, so there are m second performance fluctuation average matrices in each monitoring period, and there are a total of k*m second performance fluctuation average matrices in the first k monitoring periods.

[0082] In the above implementation, in order to determine the group deviation feature matrix, for each monitoring period in the i, i+1, ..., i+k-1th monitoring period, the performance fluctuation matrix corresponding to the same type of network devices is obtained, and the performance fluctuation matrix corresponding to the same type of network devices is subjected to matrix averaging to obtain the second performance fluctuation average matrix corresponding to the same type of network devices. The second performance fluctuation average matrix is ​​used to represent the average performance fluctuation level of the same type of network devices. Then, for the i+kth monitoring period, the performance fluctuation matrix corresponding to each network device and the second performance fluctuation average matrix corresponding to the same type of network device are subjected to matrix subtraction to obtain k*m*n group deviation feature matrices, where m is the number of network device categories.

[0083] As a further implementation of the method, the equipment condition assessment model includes an input layer, a hidden layer, and an output layer. The step of generating equipment monitoring results based on the equipment condition assessment model and according to the intrinsic deviation feature matrix and the population deviation feature matrix includes:

[0084] Step S51: Through the input layer, an input feature vector is generated based on the intrinsic deviation feature matrix and the population deviation feature matrix.

[0085] Step S52: Generate a feature extraction vector based on the input feature vector through the hidden layer.

[0086] Step S53: Through the output layer, an output matrix is ​​generated based on the feature extraction vector. The output matrix has a dimension of 2×o. The first row of the output matrix is ​​used to represent abnormal network devices, and the second row of the output matrix is ​​used to represent the abnormality score of the abnormal network devices. o is the number of abnormal network devices.

[0087] Step S54: Generate network evaluation results based on the output matrix.

[0088] In the above implementation, in order to generate device monitoring results, an input feature vector is generated through the input layer based on the intrinsic deviation feature matrix and the population deviation feature matrix. Then, a feature extraction vector is generated through the hidden layer based on the input feature vector. Finally, an output matrix is ​​generated through the output layer based on the feature extraction vector. The output matrix has a dimension of 2×0. The first row of the output matrix is ​​used to represent abnormal network devices, and the second row of the output matrix is ​​used to represent the abnormality score of the abnormal network devices. 0 is the number of abnormal network devices. Then, a network evaluation result is generated based on the output matrix.

[0089] As a further implementation of the method, the hidden layer includes a first hidden layer, a second hidden layer, and a third hidden layer, with a neuron ratio of 64:16:1 among the first, second, and third hidden layers. The step of generating a feature extraction vector based on the input feature vector through the hidden layers includes:

[0090] Step S61: Based on the first hidden layer and according to the input feature vector, generate the first intermediate feature vector.

[0091] Step S62: Based on the second hidden layer and according to the first intermediate feature vector, generate the second intermediate feature vector.

[0092] Step S63: Based on the third hidden layer and according to the second intermediate feature vector, generate the feature extraction vector.

[0093] In the above implementation, in order to generate the feature extraction vector, a first intermediate feature vector is first generated based on the first hidden layer and the input feature vector, then a second intermediate feature vector is generated based on the second hidden layer and the first intermediate feature vector, and finally a feature extraction vector is generated based on the third hidden layer and the second intermediate feature vector.

[0094] As a further implementation of the method, the step of generating the equipment condition assessment model includes:

[0095] Step S71: Obtain model training data and divide the model training data into training set and test set according to preset ratio. The model training data includes historical intrinsic deviation feature data and population deviation feature data.

[0096] Step S72: Set the hyperparameters of the pre-built neural network model according to the random network search algorithm, and use the root mean square error (RMSE) and coefficient of determination (R²) as evaluation indicators.

[0097] Step S73: Train the pre-built neural network model according to the training set to obtain the trained neural network model.

[0098] Step S74: Test the trained neural network model according to the test set, and determine whether the corresponding error is within the preset range according to the evaluation index. If so, use the trained neural network model as the device status evaluation model.

[0099] In the above embodiments, in order to generate an equipment condition assessment model, model training data is obtained and divided into a training set and a test set according to a preset ratio. The model training data includes historical intrinsic deviation feature data and population deviation feature data. Then, the hyperparameters of the pre-built neural network model are set according to a random network search algorithm, and the root mean square error (RMSE) and coefficient of determination (R²) are used as evaluation indicators. The pre-built neural network model is then trained according to the training set to obtain a trained neural network model. The trained neural network model is then tested according to the test set, and the corresponding error is judged according to the evaluation indicators to determine whether it is within a preset range. If the error is within the preset range, the trained neural network model is used as the equipment condition assessment model.

[0100] This application also discloses a network device monitoring system based on the Industrial Internet of Things.

[0101] refer to Figure 2 The network device monitoring system based on the Industrial Internet of Things includes a management platform, a sensor network platform, and an object platform that are connected in sequence. The management platform is configured with:

[0102] The performance fluctuation matrix generation module is used to obtain the time series data of the performance parameters of each network device in the i, i+1, ..., i+k monitoring periods, and to determine the performance fluctuation matrix of each network device in each monitoring period based on the time series data of the performance parameters. The performance fluctuation matrix is ​​used to represent the performance fluctuation status of a single network device.

[0103] The feature matrix generation module is used to determine the intrinsic deviation feature matrix corresponding to a single network device based on the performance fluctuation matrix for each network device, and to determine the group deviation feature matrix corresponding to a single network device based on the performance fluctuation matrix. The intrinsic deviation feature matrix is ​​used to represent the difference between the performance fluctuation of a single network device in the (i+k)th monitoring period and the average performance fluctuation level of the previous k monitoring periods. The group deviation feature matrix is ​​used to represent the difference between the performance fluctuation of a single network device in the (i+k)th monitoring period and the average performance fluctuation level of the same type of network devices in the (i), (i+1), ..., (i+k-1)th monitoring periods, respectively.

[0104] The device status assessment module is used to generate device monitoring results based on the device status assessment model and according to the intrinsic deviation feature matrix and the group deviation feature matrix. The device monitoring results include abnormal network devices and abnormality scores of abnormal network devices.

[0105] The overall framework of another application scenario of the network device monitoring system based on the Industrial Internet of Things in this application is as follows: Figure 3As shown, the system can include a user platform, a service platform, a management platform, a sensor network platform, and an object platform that interact sequentially, forming a five-platform architecture based on the Industrial Internet of Things (IIoT). The management platform includes a performance fluctuation matrix generation module, a feature matrix generation module, and a device status assessment module. The service platform includes a main service database, n service sub-platforms, and n service sub-databases. Each service sub-platform can communicate with its corresponding service sub-database, and each service sub-database can communicate with the main service database. The sensor network platform includes a main sensor database and n sensor network sub-platforms. Each sensor network sub-platform has its own sensor sub-database, and each sensor network sub-platform can communicate with the main sensor database.

[0106] Specifically, in the aforementioned application scenario, the network device monitoring system based on the Industrial Internet of Things (IIoT) includes a management platform. The management platform is configured to: acquire time-series data of performance parameters for each network device within the i-th, i+1-th, ..., i+k-th monitoring periods; determine the performance fluctuation matrix for each network device within each monitoring period based on the time-series data of performance parameters, where the performance fluctuation matrix represents the performance fluctuation status of a single network device; for each network device, determine the intrinsic deviation feature matrix corresponding to the single network device based on the performance fluctuation matrix, and determine the group deviation feature matrix corresponding to the single network device based on the performance fluctuation matrix, where the intrinsic deviation feature matrix represents the difference between the performance fluctuation of a single network device in the i+k-th monitoring period and the average performance fluctuation level of the previous k monitoring periods, and the group deviation feature matrix represents the difference between the performance fluctuation of a single network device in the i+k-th monitoring period and the average performance fluctuation level of similar network devices within the i-th, i+1-th, ..., i+k-1-th monitoring periods; and generate device monitoring results based on a device status assessment model and according to the intrinsic deviation feature matrix and the group deviation feature matrix, where the device monitoring results include abnormal network devices and anomaly scores for the abnormal network devices.

[0107] By establishing a complete closed-loop information operation logic through the interaction between various functional platforms of the industrial IoT-based network equipment monitoring system based on the aforementioned three or five platforms, the orderly operation of sensing and control information is ensured, thereby realizing intelligent equipment management.

[0108] The network device monitoring system based on the Industrial Internet of Things of the present invention can implement any of the methods in the network device monitoring method based on the Industrial Internet of Things, and the specific working process of the network device monitoring system based on the Industrial Internet of Things of the present invention can refer to the corresponding process in the above-mentioned network device monitoring method based on the Industrial Internet of Things.

[0109] This application also discloses a computer device.

[0110] refer to Figure 4 A computer device includes a memory and a processor, wherein the memory stores a computer program that can run on the processor, and the processor executes the computer program to implement any of the above-described methods for monitoring network devices based on the Industrial Internet of Things.

[0111] This application also discloses a computer-readable storage medium.

[0112] A computer-readable storage medium storing a computer program that can be loaded by a processor and executed by any of the above-described methods for monitoring network devices based on the Industrial Internet of Things.

[0113] The computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device; the program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0114] The above are all preferred embodiments of this application and are not intended to limit the scope of protection of this application. Any feature disclosed in this specification (including the abstract and drawings) may be replaced by other equivalent or similar features unless specifically stated otherwise. That is, unless specifically stated otherwise, each feature is only one example of a series of equivalent or similar features.

Claims

1. A network device monitoring method based on the Industrial Internet of Things, characterized in that, Applied to an industrial Internet of Things (IIoT) system, the IIoT system includes a management platform, a sensor network platform, and an object platform that are sequentially and communicatively connected. The method is executed by the management platform and includes: Obtain the time-series data of performance parameters of each network device in the i-th, i+1, ..., i+k-th monitoring periods, and determine the performance fluctuation matrix of each network device in each monitoring period based on the time-series data of performance parameters, wherein the performance fluctuation matrix is ​​used to represent the performance fluctuation status of a single network device. For each network device, an intrinsic deviation feature matrix corresponding to a single network device is determined based on the performance fluctuation matrix, and a group deviation feature matrix corresponding to a single network device is determined based on the performance fluctuation matrix. The intrinsic deviation feature matrix is ​​used to represent the difference between the performance fluctuation of a single network device in the (i+k)th monitoring period and the average performance fluctuation level of the previous k monitoring periods. The group deviation feature matrix is ​​used to represent the difference between the performance fluctuation of a single network device in the (i+k)th monitoring period and the average performance fluctuation level of the same type of network devices in the i, i+1, ..., i+k-1th monitoring periods, respectively. Based on the device status assessment model, and according to the intrinsic deviation feature matrix and the population deviation feature matrix, device monitoring results are generated, wherein the device monitoring results include abnormal network devices and the abnormality score of the abnormal network devices; The step of determining the performance fluctuation matrix of each network device in each monitoring period based on the time-series data of the performance parameters includes: For each network device in the i-th, i+1-th, ..., i+k-th monitoring period, the corresponding performance parameter time series data is matrixed to obtain the corresponding performance parameter matrix, wherein the rows of the performance parameter matrix are used to represent the various performance parameters of the network device; Obtain the importance weights of each performance parameter, and perform a weighted transformation on the performance parameter matrix according to the importance weights to obtain the corresponding weighted matrix; The weighted matrix is ​​subjected to row differencing to obtain the corresponding performance fluctuation matrix.

2. The network device monitoring method based on the Industrial Internet of Things according to claim 1, characterized in that, The step of determining the intrinsic deviation feature matrix corresponding to a single network device based on the performance fluctuation matrix includes: For each network device, the performance fluctuation matrix of the same network device in the i, i+1, ..., i+k-1 monitoring periods is averaged to obtain n first performance fluctuation average matrices, where the first performance fluctuation average matrix is ​​used to represent the average performance fluctuation level of the same network device in the first k monitoring periods, and n is the total number of network devices. The performance fluctuation matrix of the same network device in the (i+k)th monitoring period is subtracted from the corresponding first performance fluctuation average matrix to obtain n intrinsic deviation feature matrices.

3. The network device monitoring method based on the Industrial Internet of Things according to claim 2, characterized in that, The step of determining the group deviation feature matrix corresponding to a single network device based on the performance fluctuation matrix includes: For each monitoring period in the i, i+1, ..., i+k-1th monitoring period, the performance fluctuation matrix corresponding to the same type of network devices is obtained, and the performance fluctuation matrix corresponding to the same type of network devices is subjected to matrix averaging to obtain the second performance fluctuation average matrix corresponding to the same type of network devices, wherein the second performance fluctuation average matrix is ​​used to represent the average performance fluctuation level of the same type of network devices. For the (i+k)th monitoring period, matrix subtraction is performed on the performance fluctuation matrix corresponding to each network device and the second average performance fluctuation matrix corresponding to the same type of network device to obtain k*m*n group deviation feature matrices, where m is the number of categories of the network devices.

4. The network device monitoring method based on the Industrial Internet of Things according to claim 2, characterized in that, The equipment condition assessment model includes an input layer, a hidden layer, and an output layer. The step of generating equipment monitoring results based on the equipment condition assessment model and according to the intrinsic deviation feature matrix and the population deviation feature matrix includes: Through the input layer, an input feature vector is generated based on the intrinsic deviation feature matrix and the population deviation feature matrix; Through the hidden layer, a feature extraction vector is generated based on the input feature vector; Through the output layer, an output matrix is ​​generated based on the feature extraction vector, wherein the dimension of the output matrix is ​​2×o, the first row of the output matrix is ​​used to represent abnormal network devices, the second row of the output matrix is ​​used to represent the abnormality score of the abnormal network devices, and o is the number of abnormal network devices; Based on the output matrix, network evaluation results are generated.

5. The network device monitoring method based on the Industrial Internet of Things according to claim 4, characterized in that, The hidden layer includes a first hidden layer, a second hidden layer, and a third hidden layer, with a neuron ratio of 64:16:1 among the first, second, and third hidden layers. The step of generating a feature extraction vector based on the input feature vector through the hidden layer includes: Based on the first hidden layer, and according to the input feature vector, a first intermediate feature vector is generated; Based on the second hidden layer, and according to the first intermediate feature vector, a second intermediate feature vector is generated; Based on the third hidden layer and according to the second intermediate feature vector, a feature extraction vector is generated.

6. The network device monitoring method based on the Industrial Internet of Things according to claim 1, characterized in that, The steps for generating the equipment condition assessment model include: Acquire model training data and divide the model training data according to a preset ratio to obtain a training set and a test set, wherein the model training data includes historical intrinsic deviation feature data and population deviation feature data; The hyperparameters of the pre-built neural network model are set according to the random network search algorithm, and the root mean square error (RMSE) and the coefficient of determination (R²) are used as evaluation indicators. The pre-built neural network model is trained based on the training set to obtain a trained neural network model; The trained neural network model is tested according to the test set, and the corresponding error is determined according to the evaluation index. If it is, the trained neural network model is used as the device status evaluation model.

7. A network device monitoring system based on the Industrial Internet of Things, characterized in that, It includes a management platform, a sensor network platform, and an object platform that are connected in sequence. The management platform is configured with: The performance fluctuation matrix generation module is used to obtain the time-series data of the performance parameters of each network device in the i, i+1, ..., i+k monitoring periods, and to determine the performance fluctuation matrix of each network device in each monitoring period based on the time-series data of the performance parameters, wherein the performance fluctuation matrix is ​​used to represent the performance fluctuation status of a single network device. The feature matrix generation module is used to determine, for each network device, the intrinsic deviation feature matrix corresponding to a single network device based on the performance fluctuation matrix, and to determine the group deviation feature matrix corresponding to a single network device based on the performance fluctuation matrix. The intrinsic deviation feature matrix is ​​used to represent the difference between the performance fluctuation of a single network device in the (i+k)th monitoring period and the average performance fluctuation level of the previous k monitoring periods. The group deviation feature matrix is ​​used to represent the difference between the performance fluctuation of a single network device in the (i+k)th monitoring period and the average performance fluctuation level of the same type of network devices in the (i), (i+1), ..., (i+k-1)th monitoring periods, respectively. The device status assessment module is used to generate device monitoring results based on the device status assessment model and according to the intrinsic deviation feature matrix and the population deviation feature matrix, wherein the device monitoring results include abnormal network devices and the abnormality score of the abnormal network devices; The step of determining the performance fluctuation matrix of each network device in each monitoring period based on the time-series data of the performance parameters includes: For each network device in the i-th, i+1-th, ..., i+k-th monitoring period, the corresponding performance parameter time series data is matrixed to obtain the corresponding performance parameter matrix, wherein the rows of the performance parameter matrix are used to represent the various performance parameters of the network device; Obtain the importance weights of each performance parameter, and perform a weighted transformation on the performance parameter matrix according to the importance weights to obtain the corresponding weighted matrix; The weighted matrix is ​​subjected to row differencing to obtain the corresponding performance fluctuation matrix.

8. A computer device, characterized in that, The method includes a memory and a processor, wherein the memory stores a computer program that can run on the processor, and the processor executes the computer program to implement the method of any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer program is stored that can be loaded by a processor and execute the method of any one of claims 1 to 6.

Citation Information

Patent Citations

  • Abnormal data identification method and device, equipment and storage medium

    CN120145286A

  • Performance monitoring method and device of network equipment and electronic equipment

    CN120856548A