Supervision method and device for equipment to be supervised, electronic equipment and storage medium
By constructing a target fingerprint feature vector of the device and comparing its similarity with the fingerprint database, the problem of inaccurate supervision caused by changes in device information is solved, and real-time tracking and accurate supervision of device status are achieved.
Patent Information
- Application Number
- CN202511426685.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-01-23
AI Technical Summary
In existing technologies, frequent changes in equipment information make it impossible for maintenance personnel to track the final status of the equipment in real time, resulting in information omissions, record errors, and untimely updates, which affects the accuracy of the supervision of the equipment to be supervised.
By determining the device type of the device to be regulated, a target fingerprint feature vector is constructed and compared with the fingerprint feature vector in the pre-established target fingerprint database. A preset similarity threshold is used to determine whether the device is a known device. If the device is unknown, a manual review process is triggered to achieve automated regulation.
It enables real-time status tracking and accurate monitoring of the equipment under supervision, improving the accuracy of equipment supervision and operational efficiency.
Smart Images

Figure CN121387684A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information technology, and in particular to a method, apparatus, electronic device and storage medium for monitoring equipment to be monitored. Background Technology
[0002] With the development of the internet, the number of devices owned by enterprises and organizations has exploded, and the types of devices are becoming increasingly diverse. At the same time, with the widespread application of technologies such as cloud computing and virtualization, the dynamism of devices has been significantly enhanced, and information such as device IP addresses and operating status changes frequently, making the supervision of devices increasingly important.
[0003] In related technologies, existing methods for monitoring devices under supervision mainly rely on maintenance personnel manually registering device information. This approach is extremely inefficient and resource-intensive when dealing with large-scale, distributed deployments of devices. Furthermore, due to frequent changes in device information, maintenance personnel cannot track the final status of the devices in real time, leading to frequent issues such as information omissions, recording errors, and untimely updates, ultimately affecting the accuracy of monitoring the devices under supervision. Summary of the Invention
[0004] The purpose of this application is to provide a method, apparatus, electronic device, and storage medium for monitoring equipment under supervision, so as to automatically monitor the equipment under supervision. The specific technical solution is as follows: In a first aspect of this application, a method for monitoring a device to be monitored is provided, the method comprising: Determine the device type corresponding to the device to be monitored, and construct the target fingerprint feature vector corresponding to the device to be monitored based on the device type; Obtain the target fingerprint database corresponding to the device type, wherein the target fingerprint database contains M fingerprint feature vectors, where M is a positive integer; For any fingerprint feature vector in the target fingerprint database, determine the similarity between the target fingerprint feature vector corresponding to the device to be monitored and the fingerprint feature vector. The target similarity is determined from the M similarities, and the device to be monitored is monitored based on the comparison result between the target similarity and the preset similarity threshold.
[0005] In an optional implementation, constructing the target fingerprint feature vector corresponding to the device to be monitored based on the device type includes: Determine the acquisition protocol and feature extraction rules corresponding to the device type; The device information of the device to be monitored is collected through the aforementioned collection protocol; Based on the feature extraction rules and the device information, a target fingerprint feature vector corresponding to the device to be monitored is constructed.
[0006] In an optional implementation, constructing the target fingerprint feature vector corresponding to the device to be monitored based on the feature extraction rules and the device information includes: According to the feature extraction rules, N key features are extracted from the device information, where N is a positive integer; According to the preset splicing rules, the N key features are combined to generate the target fingerprint feature vector corresponding to the device to be monitored.
[0007] In an optional implementation, the step of monitoring the device to be monitored based on the comparison result between the target similarity and a preset similarity threshold includes: If the target similarity is greater than or equal to the preset similarity threshold, the device to be monitored is identified as a known device, and the device to be monitored is monitored. If the target similarity is less than the preset similarity threshold, the device to be monitored will be marked as an unknown device, and a manual review process will be triggered to detect the device to be monitored.
[0008] In an optional implementation, the monitoring of the device to be monitored includes: Determine the fingerprint feature vector corresponding to the target similarity in the target fingerprint database; Obtain device attribute information associated with the fingerprint feature vector from the target fingerprint database; The device attribute information is associated with the device to be monitored to generate monitoring information; The regulatory information is included in the equipment management list, and the equipment to be regulated is regulated through the equipment management list.
[0009] In an optional implementation, after the manual review process is triggered to inspect the device to be monitored, the method further includes: Obtain the equipment attribute information of the equipment to be monitored, as determined through the manual review process; After associating the target fingerprint feature vector corresponding to the device to be monitored with the device attribute information, the data is stored in the target fingerprint database.
[0010] In an optional implementation, the target fingerprint database is constructed through the following steps: For any given device type, collect device attribute information of at least one known device corresponding to that device type; For any of the known devices, a fingerprint feature vector corresponding to the known device is constructed based on the feature extraction rules corresponding to the device type and the device attribute information corresponding to the known device. The fingerprint feature vector is associated with and stored with the device attribute information corresponding to the known device to construct a target fingerprint database corresponding to the device type.
[0011] In a second aspect of this application, a monitoring device for a device to be monitored is also provided, the device comprising: The vector construction module is used to determine the device type corresponding to the device to be monitored, and construct the target fingerprint feature vector corresponding to the device to be monitored based on the device type; The target fingerprint database acquisition module is used to acquire the target fingerprint database corresponding to the device type. The target fingerprint database contains M fingerprint feature vectors, where M is a positive integer. The similarity determination module is used to determine the similarity between the target fingerprint feature vector corresponding to the device to be monitored and the fingerprint feature vector for any fingerprint feature vector in the target fingerprint database. The equipment monitoring module is used to determine the target similarity from the M similarities, and to monitor the equipment to be monitored based on the comparison result between the target similarity and the preset similarity threshold.
[0012] In a third aspect of the embodiments of this application, an electronic device is also provided, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; Memory, used to store computer programs; When a processor executes a program stored in a memory, it implements the monitoring method for the device to be monitored as described in any of the first aspects above.
[0013] In a fourth aspect of the embodiments of this application, a storage medium is also provided, the storage medium storing instructions that, when run on a computer, cause the computer to execute the monitoring method for any of the monitored devices described in the first aspect above.
[0014] In a fifth aspect of the embodiments of this application, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to perform the monitoring method for the device to be monitored as described in any of the first aspects above.
[0015] The technical solution provided in this application determines the device type corresponding to the device to be monitored, and constructs a target fingerprint feature vector corresponding to the device to be monitored based on the device type. A target fingerprint database corresponding to the device type is obtained, containing M fingerprint feature vectors, where M is a positive integer. For any fingerprint feature vector in the target fingerprint database, the similarity between the target fingerprint feature vector corresponding to the device to be monitored and the fingerprint feature vector is determined. A target similarity is determined from the M similarities. Based on the comparison result of the target similarity and a preset similarity threshold, the device to be monitored is monitored. In this way, based on the similarity between the target fingerprint feature vector corresponding to the device to be monitored and each fingerprint feature vector in the target fingerprint database, the target similarity is determined. Therefore, based on the comparison result of the target similarity and the preset similarity threshold, the device to be monitored is monitored, which allows for real-time tracking of the status information of the device to be monitored and improves the accuracy of monitoring. Attached Figure Description
[0016] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0017] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] One or more embodiments are illustrated by way of example with reference numerals in the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Elements with the same reference numerals in the drawings are denoted as similar elements. Unless otherwise stated, the figures in the drawings are not to be limited by scale.
[0019] Figure 1 A schematic diagram illustrating the implementation process of a monitoring method for a device to be monitored, provided as an embodiment of this application; Figure 2 A schematic diagram illustrating the implementation process of another monitoring method for a device to be monitored, provided as an embodiment of this application; Figure 3 A schematic diagram illustrating the implementation process of a method for constructing a target fingerprint feature vector provided in this application embodiment; Figure 4 A schematic diagram illustrating the implementation process of a method for constructing a target fingerprint database, provided in an embodiment of this application; Figure 5 A schematic diagram illustrating the implementation process of a monitoring method for a device to be monitored, provided as an embodiment of this application; Figure 6A schematic diagram illustrating the implementation process of a method for updating a target fingerprint database, provided in an embodiment of this application; Figure 7 A schematic diagram of the structure of a monitoring device for a device to be monitored, provided in an embodiment of this application; Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0020] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0021] The following disclosure provides numerous different embodiments or examples for implementing various structures of this application. To simplify the disclosure, specific examples of components and arrangements are described below. These are merely examples and are not intended to limit the scope of this application. Furthermore, reference numerals and / or letters may be repeated in different examples. Such repetition is for simplification and clarity and does not in itself indicate a relationship between the various embodiments and / or arrangements discussed.
[0022] To address the technical problem in existing technologies where frequent changes in equipment information prevent maintenance personnel from tracking the final status of equipment in real time, leading to frequent issues such as information omissions, recording errors, and untimely updates, ultimately affecting the accuracy of monitoring the equipment under supervision, this application provides a monitoring method, apparatus, electronic device, and storage medium for equipment under supervision. This method determines the target similarity based on the similarity between the target fingerprint feature vector corresponding to the equipment under supervision and each fingerprint feature vector in the target fingerprint database. Then, based on the comparison result of the target similarity and a preset similarity threshold, the equipment under supervision is monitored, enabling real-time tracking of the status information of the equipment under supervision and improving the accuracy of monitoring.
[0023] like Figure 1 The diagram shown is a schematic representation of the implementation process of a monitoring method for equipment to be monitored according to an embodiment of this application. The method may specifically include the following steps: S101, determine the device type corresponding to the device to be regulated, and construct the target fingerprint feature vector corresponding to the device to be regulated based on the device type.
[0024] The aforementioned devices to be monitored refer to physical devices in the network that need to be identified, monitored, and managed, such as servers, workstations, network switches, routers, firewalls, storage devices, and various smart terminals. Different devices to be monitored correspond to different hardware configurations, operating systems, and management protocols.
[0025] The term "device type" refers to the category categorized according to the function, operating system, or supported management protocol of the device to be regulated, including but not limited to devices supporting Simple Network Management Protocol, Windows system devices, Linux system devices, and network devices (such as switches and routers). This application example does not limit this category.
[0026] The aforementioned target fingerprint feature vector is used to represent the unique identifier of the device to be monitored. It can be composed of the device's hardware features (such as the model and capacity of the device's memory), software features (such as the operating system version), and network features (such as network address and open ports) after standardization. This application example does not limit this.
[0027] In this embodiment of the application, the device type corresponding to the device to be regulated is determined, and a target fingerprint feature vector corresponding to the device to be regulated is constructed based on the device type, thereby characterizing the device to be regulated through the target fingerprint feature vector.
[0028] S102, obtain the target fingerprint database corresponding to the device type. The target fingerprint database contains M fingerprint feature vectors, where M is a positive integer.
[0029] The aforementioned target fingerprint database refers to a pre-established set of known device fingerprint feature vectors associated with various device types, used to store the fingerprint feature vectors of known devices and their detailed information. The target fingerprint database can be stored in a relational database (such as a MySQL database), and includes, but is not limited to, related tables such as device fingerprint tables, device type tables, and manufacturer tables. This application example does not limit this.
[0030] The fingerprint feature vectors mentioned above are each feature vector stored in the target fingerprint database, and each fingerprint feature vector represents a standardized feature representation of a known device.
[0031] In this embodiment, a target fingerprint database corresponding to the device type can be obtained from the fingerprint database, which is a set of vectors of known devices that match the type of device to be monitored. The target fingerprint database contains M fingerprint feature vectors, where M is a positive integer (e.g., M is 1, 2, 3, etc.), and M is the total number of fingerprint feature vectors stored in the target fingerprint database. This embodiment does not limit the specific number of fingerprint feature vectors stored in the target fingerprint database.
[0032] For example, if the device to be monitored is a "Linux server", then the target fingerprint database with the device type "Linux server" is queried from the fingerprint database to obtain the fingerprint feature vectors of M known devices from the target fingerprint database.
[0033] S103, for any fingerprint feature vector in the target fingerprint database, determine the similarity between the target fingerprint feature vector and the fingerprint feature vector corresponding to the device to be monitored.
[0034] In this embodiment, for any fingerprint feature vector in the target fingerprint database, the similarity between the target fingerprint feature vector corresponding to the device to be monitored and the fingerprint feature vector is determined. The similarity is used to quantify the consistency or similarity between the target fingerprint feature vector of the device to be monitored and the known fingerprint feature vectors in the target fingerprint database. The similarity can be cosine similarity, and the value range of the similarity is [0,1]. This embodiment does not limit this.
[0035] Optionally, the target fingerprint feature vector and the fingerprint feature vector corresponding to the device to be monitored can be input into the cosine similarity calculation formula to calculate the similarity between the target fingerprint feature vector and the fingerprint feature vector corresponding to the device to be monitored.
[0036] The formula for calculating cosine similarity is: ; Where A is the target fingerprint feature vector corresponding to the device to be monitored, and B is the fingerprint feature vector. Let be the dot product of the target fingerprint feature vector and the fingerprint feature vector corresponding to the device to be monitored. Let be the magnitude of the target fingerprint feature vector corresponding to the device to be monitored. Let P be the magnitude of the fingerprint feature vector, and let P be the similarity between the target fingerprint feature vector and the fingerprint feature vector corresponding to the device to be monitored.
[0037] For example, if the target fingerprint feature vector corresponding to the device to be monitored is: A=[0.75,0.48,0,1,0,123456,0.2], and the fingerprint feature vector of a known device in the fingerprint database is: B=[0.80,0.50,0,1,0,123456,0.15], then using the cosine similarity calculation formula mentioned above, the similarity is calculated as 1.20 / (1.02×1.01)≈0.98.
[0038] S104, determine the target similarity from M similarities, and supervise the device to be supervised based on the comparison result between the target similarity and the preset similarity threshold.
[0039] The aforementioned target similarity can be the highest similarity value obtained by comparing the device to be monitored with known devices in the target fingerprint database.
[0040] The aforementioned preset similarity threshold refers to a pre-set similarity threshold used to determine whether the device to be monitored matches a known device in the target fingerprint database. The preset similarity threshold can be dynamically adjusted according to the device type; for example, the preset similarity threshold for server devices is 0.85, and the preset similarity threshold for network devices is 0.65. This application example does not limit this.
[0041] In this embodiment of the application, a target similarity is determined from M similarities, and the processing method for the device to be regulated is determined based on the comparison result between the target similarity and a preset similarity threshold, so as to regulate the device to be regulated.
[0042] Based on the above description of the technical solution provided in the embodiments of this application, the device type corresponding to the device to be monitored is determined, and a target fingerprint feature vector corresponding to the device to be monitored is constructed based on the device type. A target fingerprint database corresponding to the device type is obtained, containing M fingerprint feature vectors, where M is a positive integer. For any fingerprint feature vector in the target fingerprint database, the similarity between the target fingerprint feature vector corresponding to the device to be monitored and the fingerprint feature vector is determined. The target similarity is determined from the M similarities. Based on the comparison result of the target similarity and a preset similarity threshold, the device to be monitored is monitored. In this way, based on the similarity between the target fingerprint feature vector corresponding to the device to be monitored and each fingerprint feature vector in the target fingerprint database, the target similarity is determined. Thus, based on the comparison result of the target similarity and the preset similarity threshold, the device to be monitored is monitored, which can track the status information of the device to be monitored in real time and improve the monitoring accuracy of the device to be monitored.
[0043] like Figure 2 The diagram shown illustrates the implementation flow of another monitoring method for a device to be monitored, as provided in this application embodiment. Specifically, it may include the following: S201, determine the equipment type corresponding to the equipment to be monitored, and determine the collection protocol and feature extraction rules corresponding to the equipment type.
[0044] The aforementioned data collection protocol refers to the communication protocol used to collect device information of the device to be monitored. The data collection protocol includes, but is not limited to, Simple Network Management Protocol (SMAP), Windows Management Instrumentation (WMI), SSH (Secure Shell Protocol), Telnet, etc. The data collection protocol can be installed and configured on the network management server, but this application example does not limit this.
[0045] The aforementioned feature extraction rules refer to a set of rules used to extract, clean, and standardize key features from the original device information corresponding to the device to be regulated. This includes defined key fields for extraction and identification from the original device information corresponding to the device to be regulated (such as gateway, memory capacity, etc.), which are not limited in this application example.
[0046] In this embodiment, the device type corresponding to the device to be monitored is determined, and the collection protocol and feature extraction rules corresponding to the device type are also determined. Specifically, the device type (such as server, network device, storage device, smart terminal, etc.) of the device to be monitored can be identified based on network topology, device response, or user-preset policies.
[0047] Furthermore, the data acquisition protocol corresponding to a device type can be determined based on a pre-built device type-protocol mapping table. Specifically, for a device type corresponding to a Windows system, the corresponding data acquisition protocol can be WMI (Windows Management Specification); for a device type corresponding to a Linux system, the corresponding data acquisition protocol can be SSH (Secure Shell); for a device type corresponding to a network device (such as a switch or router), the corresponding data acquisition protocol can be Telnet; and for a device type corresponding to a device that supports SNMP (Simple Network Management Protocol) (such as some servers and network devices), the corresponding data acquisition protocol can be SNMP.
[0048] Similarly, feature extraction rules corresponding to device types can be determined based on a pre-built feature extraction mapping table. Specifically, for hardware features, the feature extraction rules cover extracting key information such as CPU model, memory capacity, hard drive serial number, and network card MAC address; for software features, the feature extraction rules cover extracting key information such as operating system type and version, names and versions of installed key software, and system patch information; for network features, the feature extraction rules cover extracting IP address ranges, open port numbers and corresponding services, and network traffic patterns of the devices to be monitored.
[0049] S202 collects equipment information of the equipment to be monitored through the collection protocol.
[0050] In this embodiment, device information of the device to be monitored is collected through a data acquisition protocol. Device information refers to the raw data set obtained from the device to be monitored through the data acquisition protocol, including but not limited to: hardware configuration information (CPU model and number of cores, memory capacity and type, hard drive specifications and serial number, network card MAC address, motherboard information, etc.), software environment information (operating system type and version, system installation time, list and version of installed software, system patch information, service running status, etc.), network configuration information (IP address and subnet mask, gateway address, DNS configuration, list of open ports, network connection status, routing table information, etc.), device operating status (CPU utilization, memory usage, disk I / O, network traffic statistics, device temperature, power status, etc.), and device identification information (device serial number, asset number, device model, manufacturer information, firmware version, etc.). This application example does not limit the specific details of this information.
[0051] S203, based on feature extraction rules and device information, construct the target fingerprint feature vector corresponding to the device to be monitored.
[0052] In this embodiment, a target fingerprint feature vector corresponding to the device to be monitored is constructed based on feature extraction rules and device information. The target fingerprint feature vector is used to identify the characteristics of the device to be monitored, serving as benchmark data for subsequent device matching and identification. The target fingerprint feature vector is a multi-dimensional numerical vector, where each dimension represents a standardized feature value of the device to be monitored. By transforming heterogeneous device information into a unified mathematical representation, similarity calculation and accurate identification between devices can be achieved. This embodiment does not limit this approach.
[0053] For example: [0.85 (CPU performance encoding), 0.25 (memory normalization value), 1 (Windows 11 one-hot encoding), 789456 (MAC hash value), 0.1 (port number normalization value)].
[0054] For details on how to construct the target fingerprint feature vector corresponding to the device to be monitored based on feature extraction rules and device information, please refer to [reference needed]. Figure 3 The method shown. (As illustrated) Figure 3 The diagram shown illustrates the implementation flow of a method for constructing a target fingerprint feature vector according to an embodiment of this application, which may specifically include the following steps: S301, according to the feature extraction rules, extract N key features from the device information, where N is a positive integer.
[0055] In this embodiment, N key features are extracted from the device information according to the feature extraction rules, where N is a positive integer. These key features may include hardware features, software features, and network features. Specifically, hardware features include CPU model (e.g., Intel i7-12700K), memory capacity (32GB), hard drive serial number (XYZ123), and network card MAC address (00:1B:44:11:3A:B7), etc.; software features include operating system type and version (Windows 11 Professional), installed critical software (Microsoft Office 2019), and system patch information (KB5012172), etc.; network features include IP address range (192.168.1.0 / 24), open port numbers (80, 443), and network traffic pattern (TCP / UDP protocol ratio), etc. This application example does not limit these features.
[0056] For example, when extracting the CPU model "Intel i7-12700K" from the device information, the "Intel" prefix needs to be removed, and only "i7-12700K" should be kept as the key feature; when extracting the memory capacity "32GB", the 32 should be directly used as the key feature.
[0057] S302, according to the preset splicing rules, combine N key features to generate the target fingerprint feature vector corresponding to the device to be monitored.
[0058] In this embodiment, N key features are combined according to a preset splicing rule to generate a target fingerprint feature vector corresponding to the device to be monitored. The preset splicing rule refers to the rule specifying the order of key feature combination and the numerical mapping method, such as splicing in the order of hardware features, software features, and network features. Numerical features are mapped to the [0,1] interval after Min-Max standardization, and coded features are encoded using one-hot encoding. This embodiment does not limit this specific approach.
[0059] Optionally, the N key features can be standardized and combined to generate a target fingerprint feature vector. For numerical key features (such as memory capacity), Min-Max standardization can be used; for coded key features (such as CPU architecture), one-hot encoding can be used to convert categorical variables into binary vectors. For textual key features (such as MAC addresses), a hash function can be used to convert them into fixed-length numerical values.
[0060] For example, a memory capacity of 64GB (range 4GB-128GB) is standardized to 0.48; the x86 CPU architecture encoding is converted to (1,0,0), and the ARM CPU architecture encoding is converted to (0,1,0); the MAC address "00:1B:44:11:3A:B7" is converted to 123456 using MD5 hash. Then, the fingerprint features are concatenated in the order of hardware features, software features, and network features to obtain the target fingerprint feature vector: [0.48 (memory), (0,1,0) (architecture encoding), 123456 (MAC address)].
[0061] In another embodiment of this application, multi-dimensional weights can be set, such as assigning higher weights to key features that are unique identifiers, like MAC addresses and hard drive serial numbers, while assigning lower weights to key features like open ports and traffic patterns. Each key feature is multiplied by its corresponding weight, and then combined according to a preset concatenation rule to generate a target fingerprint feature vector corresponding to the device to be monitored.
[0062] S204, Obtain the target fingerprint database corresponding to the device type. The target fingerprint database contains M fingerprint feature vectors, where M is a positive integer.
[0063] In this embodiment of the application, this step is similar to step S102 above, and will not be described in detail here.
[0064] For details on how to construct a target fingerprint database, please refer to [reference needed]. Figure 4 The method shown. (As illustrated) Figure 4 The diagram shown illustrates the implementation flow of a method for constructing a target fingerprint database according to an embodiment of this application, which may specifically include the following steps: S401, For any device type, collect device attribute information of at least one known device corresponding to the device type.
[0065] The aforementioned known devices refer to devices that are marked as trustworthy and have been included in management, whose identity (such as identification), configuration (such as hardware specifications), operating status (such as online / offline), and affiliation (such as the business to which they belong) are all clearly defined.
[0066] The aforementioned device attribute information refers to a set of metadata that can completely describe the identity, configuration, status, and ownership of a known device. This includes, but is not limited to, basic identification information, such as core identifiers used to uniquely identify the device (e.g., device name, device serial number, asset number, manufacturer, device model); hardware configuration information, used to describe the specifications of the components that constitute the physical entity of the device (e.g., CPU model and number of cores, memory capacity and specifications, number and capacity of hard drives, number and MAC addresses of network cards); software environment information, used to describe the composition of the software running on the device (e.g., operating system type and version, system installation time, installed key software and their versions); network configuration information, used to describe the device's interface and service configuration in the network (e.g., management IP address, VLAN, gateway address, DNS server, list of open ports); business attribute information, used to describe the device's business role and management affiliation within the organization (e.g., device purpose, department, responsible person, geographical location); and management information, referring to policies and agreements related to device operation and maintenance (e.g., maintenance window, service level agreement requirements, monitoring policies).
[0067] In this embodiment, for any device type, device attribute information of at least one known device corresponding to that device type is collected. This can be done through a collection protocol corresponding to the device type (such as SNMP, WMI, SSH, etc.), or by having maintenance personnel manually input the device's business attributes and management information into the management interface to supplement device-specific attributes that cannot be collected by the collection protocol. This embodiment does not limit this approach.
[0068] S402, For any known device, construct the fingerprint feature vector corresponding to the known device based on the feature extraction rules corresponding to the device type and the device attribute information corresponding to the known device.
[0069] In this embodiment of the application, for any known device, a fingerprint feature vector corresponding to the known device is constructed based on the feature extraction rules corresponding to the device type and the device attribute information corresponding to the known device.
[0070] Specifically, according to the feature extraction rules corresponding to the device type, at least one key feature for identifying a known device can be extracted from the device attribute information (e.g., extracting 10 key features). Each key feature is standardized, and the calibrated and processed key features are concatenated to generate a fingerprint feature vector corresponding to the known device. This process is similar to steps S201~S203 above.
[0071] S403, associate and store the fingerprint feature vector with the device attribute information corresponding to the known device to construct the target fingerprint database corresponding to the device type.
[0072] In this embodiment, fingerprint feature vectors are associated and stored with device attribute information corresponding to known devices to construct a target fingerprint database corresponding to the device type. The target fingerprint database may include a server fingerprint database and a network device fingerprint database. If the device type is a server type, the corresponding target fingerprint database is the server fingerprint database; if the device type is a network device type, the corresponding target fingerprint database is the network device fingerprint database. This application example does not limit this.
[0073] Specifically, a device fingerprint master table can be created to store fingerprint feature vectors, device IDs, device types, creation times, etc.; a device details table can be created to store complete device attribute information; a device type classification table can be established to manage the device type system; and relationships between tables can be established through primary key-foreign key associations to associate and store fingerprint feature vectors with unique device identifiers (such as device IDs), thereby constructing a target fingerprint database corresponding to the device type.
[0074] S205, for any fingerprint feature vector in the target fingerprint database, determine the similarity between the target fingerprint feature vector and the fingerprint feature vector corresponding to the device to be monitored.
[0075] In this embodiment of the application, this step is similar to step S103 above, and will not be described in detail here.
[0076] S206. Determine the target similarity from M similarities. If the target similarity is greater than or equal to the preset similarity threshold, then the device to be regulated is identified as a known device and regulated.
[0077] In this embodiment, a target similarity is determined from M similarities. If the target similarity is greater than or equal to a preset similarity threshold, the device to be monitored is identified as a known device, and monitoring is then implemented on the device. The preset similarity threshold is a value (e.g., 0.8, 0.6, etc.) pre-set according to different device types to identify the optimal matching degree between the device to be monitored and all known devices in the target fingerprint database. This embodiment does not limit this value.
[0078] Specifically, determining the target similarity from M similarities can be achieved by selecting the maximum similarity among the M similarities. This application does not limit this approach.
[0079] For example, if M is 3, and there are similarity scores 1 (0.75), 2 (0.92), and 3 (0.68), then the target similarity score is the maximum value among them, 0.92 (similarity score 2).
[0080] Optionally, for device types with stable and highly unique characteristics (such as most servers, whose hardware characteristics such as CPU model and MAC address usually remain unchanged), a high threshold (such as 0.9, 0.95, etc.) can be selected for the corresponding preset similarity threshold to strictly require matching accuracy and avoid misclassifying different devices as the same one. For device types whose characteristics are prone to reasonable fluctuations (such as DHCP clients with frequently changing IP addresses, or network devices with frequently adjusted configurations), a low threshold (such as 0.5, 0.6, etc.) can be selected for the corresponding preset similarity threshold to adapt to feature changes and avoid missed detections.
[0081] For details on how to regulate monitoring equipment, please refer to... Figure 5 The method shown. (As illustrated) Figure 5 The diagram shown is a schematic representation of the implementation process of a monitoring method for equipment to be monitored according to an embodiment of this application. Specifically, it may include the following steps: S501, Determine the fingerprint feature vector corresponding to the target similarity in the target fingerprint database.
[0082] In this embodiment, the fingerprint feature vector corresponding to the target similarity in the target fingerprint database is determined. That is, by reverse positioning, it is determined which known device in the target fingerprint database has its fingerprint feature vector calculated with the device to be monitored to obtain the target similarity. This located fingerprint feature vector is the fingerprint feature vector corresponding to the target similarity in the target fingerprint database.
[0083] For example, similarity 1 (0.2) corresponds to fingerprint feature vector 1, similarity 2 (0.8) corresponds to fingerprint feature vector 2, similarity 3 (0.5) corresponds to fingerprint feature vector 3, and the target similarity is similarity 2 (0.8). Then the fingerprint feature vector corresponding to the target similarity in the target fingerprint database is fingerprint feature vector 2.
[0084] S502, Obtain device attribute information associated with the fingerprint feature vector from the target fingerprint database.
[0085] In this embodiment, device attribute information associated with the fingerprint feature vector is obtained from the target fingerprint database. This device attribute information refers to a set of metadata that can completely describe the identity, configuration, status, and ownership of a known device, specifically including basic identification information, hardware configuration information, software environment information, network configuration information, service attribute information, and management information. This application example does not limit this specific information.
[0086] S503 associates device attribute information with the device to be regulated and generates regulatory information.
[0087] In this embodiment, device attribute information is associated with the device to be monitored to generate monitoring information. This monitoring information integrates the network identifier of the device to be monitored and management attributes inherited from matched known devices (such as asset ownership, responsible person, and monitoring strategy), forming all the key attributes representing the device to be monitored.
[0088] S504 stipulates that regulatory information shall be incorporated into the equipment management list, and the equipment to be regulated shall be regulated through the equipment management list.
[0089] In this embodiment, regulatory information is incorporated into a device management list, and the devices to be regulated are regulated through this list. The device management list can be a configuration management database or a unified management list, containing all characteristic information of known devices (such as MAC address, IP address, model, manufacturer, etc.). This application example does not limit this specific type.
[0090] Specifically, the device management list can be used to identify devices to be monitored, and based on the policies in their monitoring information, the system can automatically perform comprehensive monitoring operations such as monitoring (e.g., performance monitoring, status checks), maintenance (e.g., patch management, configuration backup), compliance checks (e.g., security baseline scanning), and lifecycle management (e.g., maintenance expiration reminders). Ultimately, this achieves automated management of newly discovered devices, greatly improving operational efficiency and management accuracy.
[0091] S207 If the target similarity is less than the preset similarity threshold, the device to be monitored will be marked as an unknown device, and a manual review process will be triggered to detect the device to be monitored.
[0092] In this embodiment, if the target similarity is less than a preset similarity threshold, the device to be monitored is marked as an unknown device, and a manual review process is triggered to inspect the device. The manual review process refers to maintenance personnel inspecting the device using preset strategies. These preset strategies include, but are not limited to, remotely logging into the device for inspection, verifying procurement records, and contacting the person responsible for the device. This embodiment does not limit the scope of these strategies.
[0093] After the aforementioned manual review process is triggered and the monitored equipment is inspected, the target fingerprint database can also be updated. For details, please refer to... Figure 6 The method shown. (As illustrated) Figure 6 The diagram shown illustrates the implementation flow of a target fingerprint database update method provided in this application embodiment, which specifically includes the following steps: S601, Obtain the equipment attribute information of the equipment to be supervised, which has been determined through a manual review process.
[0094] In this embodiment, the device attribute information of the device to be monitored, determined through a manual review process, is obtained. Specifically, this can be the device attribute information of the device to be monitored manually entered by the maintenance personnel, or it can be obtained by importing the corresponding review report to identify the device attribute information of the device to be monitored. This application example does not limit this approach.
[0095] S602, after associating the target fingerprint feature vector corresponding to the device to be monitored with the device attribute information, it is stored in the target fingerprint database.
[0096] In this embodiment, the target fingerprint feature vector corresponding to the device to be monitored is associated with the device attribute information and then stored in the target fingerprint database. Specifically, the target fingerprint feature vector and device attribute information corresponding to the device to be monitored can be converted into a "fingerprint feature vector - device attribute information" pair and added to the target fingerprint database as a new record. This application example does not limit this.
[0097] For example, when a newly purchased server connects to the network for the first time, it is marked as an unknown device because its target fingerprint feature vector is not in the target fingerprint database. After manual verification of all its attributes, its target fingerprint feature vector and device attribute information are stored in the target fingerprint database. Thereafter, when a device of the same model or similar configuration comes online, automatic identification can be achieved.
[0098] Corresponding to the above method embodiments, this application also provides a monitoring device for the equipment to be monitored, such as... Figure 7 As shown, the device may include a vector construction module 701, a target fingerprint database acquisition module 702, a similarity determination module 703, and a device monitoring module 704.
[0099] The vector construction module 701 is used to determine the device type corresponding to the device to be monitored, and construct the target fingerprint feature vector corresponding to the device to be monitored based on the device type; The target fingerprint database acquisition module 702 is used to acquire the target fingerprint database corresponding to the device type. The target fingerprint database contains M fingerprint feature vectors, where M is a positive integer. The similarity determination module 703 is used to determine the similarity between the target fingerprint feature vector corresponding to the device to be monitored and the fingerprint feature vector for any fingerprint feature vector in the target fingerprint database. The equipment monitoring module 704 is used to determine the target similarity from the M similarities, and to monitor the equipment to be monitored based on the comparison result between the target similarity and the preset similarity threshold.
[0100] This application also provides an electronic device, such as... Figure 8 As shown, it includes a processor 801, a communication interface 802, a memory 803, and a communication bus 804. The processor 801, communication interface 802, and memory 803 communicate with each other via the communication bus 804. Memory 803 is used to store computer programs; In one embodiment of this application, when the processor 801 executes a program stored in the memory 803, it performs the following steps: The device type corresponding to the device to be regulated is determined, and based on the device type, a target fingerprint feature vector corresponding to the device to be regulated is constructed. The target fingerprint database corresponding to the device type is obtained. The target fingerprint database contains M fingerprint feature vectors, where M is a positive integer. For any fingerprint feature vector in the target fingerprint database, the similarity between the target fingerprint feature vector corresponding to the device to be regulated and the fingerprint feature vector is determined. The target similarity is determined from the M similarities. Based on the comparison result between the target similarity and the preset similarity threshold, the device to be regulated is regulated.
[0101] The communication bus mentioned in the above electronic devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not indicate that there is only one bus or one type of bus.
[0102] The communication interface is used for communication between the aforementioned electronic devices and other devices.
[0103] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0104] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0105] In another embodiment provided in this application, a storage medium is also provided, which stores instructions that, when run on a computer, cause the computer to execute the monitoring method for the monitored device described in any of the above embodiments.
[0106] In another embodiment provided in this application, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to execute the monitoring method for the device to be monitored as described in any of the above embodiments.
[0107] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a storage medium or transmitted from one storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid state disk (SSD)).
[0108] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0109] The various embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0110] The above description is merely a specific embodiment of this application, enabling those skilled in the art to understand or implement this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application are included within the protection scope of this application.
Claims
1. A method for monitoring equipment to be monitored, characterized in that, The method includes: Determine the device type corresponding to the device to be monitored, and construct the target fingerprint feature vector corresponding to the device to be monitored based on the device type; Obtain the target fingerprint database corresponding to the device type, wherein the target fingerprint database contains M fingerprint feature vectors, where M is a positive integer; For any fingerprint feature vector in the target fingerprint database, determine the similarity between the target fingerprint feature vector corresponding to the device to be monitored and the fingerprint feature vector. The target similarity is determined from the M similarities, and the device to be monitored is monitored based on the comparison result between the target similarity and the preset similarity threshold.
2. The method according to claim 1, characterized in that, The step of constructing the target fingerprint feature vector corresponding to the device to be monitored based on the device type includes: Determine the acquisition protocol and feature extraction rules corresponding to the device type; The device information of the device to be monitored is collected through the aforementioned collection protocol; Based on the feature extraction rules and the device information, a target fingerprint feature vector corresponding to the device to be monitored is constructed.
3. The method according to claim 2, characterized in that, The step of constructing the target fingerprint feature vector corresponding to the device to be monitored based on the feature extraction rules and the device information includes: According to the feature extraction rules, N key features are extracted from the device information, where N is a positive integer; According to the preset splicing rules, the N key features are combined to generate the target fingerprint feature vector corresponding to the device to be monitored.
4. The method according to claim 1, characterized in that, The step of monitoring the device to be monitored based on the comparison result between the target similarity and a preset similarity threshold includes: If the target similarity is greater than or equal to the preset similarity threshold, the device to be monitored is identified as a known device, and the device to be monitored is monitored. If the target similarity is less than the preset similarity threshold, the device to be monitored will be marked as an unknown device, and a manual review process will be triggered to detect the device to be monitored.
5. The method according to claim 4, characterized in that, The monitoring of the device to be monitored includes: Determine the fingerprint feature vector corresponding to the target similarity in the target fingerprint database; Obtain device attribute information associated with the fingerprint feature vector from the target fingerprint database; The device attribute information is associated with the device to be monitored to generate monitoring information; The regulatory information is included in the equipment management list, and the equipment to be regulated is regulated through the equipment management list.
6. The method according to claim 4, characterized in that, After the manual review process is triggered to inspect the device under supervision, the following steps are also included: Obtain the equipment attribute information of the equipment to be monitored, as determined through the manual review process; After associating the target fingerprint feature vector corresponding to the device to be monitored with the device attribute information, the data is stored in the target fingerprint database.
7. The method according to claim 1, characterized in that, The target fingerprint database is constructed through the following steps: For any given device type, collect device attribute information of at least one known device corresponding to that device type; For any of the known devices, a fingerprint feature vector corresponding to the known device is constructed based on the feature extraction rules corresponding to the device type and the device attribute information corresponding to the known device. The fingerprint feature vector is associated with and stored with the device attribute information corresponding to the known device to construct a target fingerprint database corresponding to the device type.
8. A monitoring device for equipment to be monitored, characterized in that, The device includes: The vector construction module is used to determine the device type corresponding to the device to be monitored, and construct the target fingerprint feature vector corresponding to the device to be monitored based on the device type; The target fingerprint database acquisition module is used to acquire the target fingerprint database corresponding to the device type. The target fingerprint database contains M fingerprint feature vectors, where M is a positive integer. The similarity determination module is used to determine the similarity between the target fingerprint feature vector corresponding to the device to be monitored and the fingerprint feature vector for any fingerprint feature vector in the target fingerprint database. The equipment monitoring module is used to determine the target similarity from the M similarities, and to monitor the equipment to be monitored based on the comparison result between the target similarity and the preset similarity threshold.
9. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, when executing a program stored in memory, implements the method described in any one of claims 1-7.
10. A storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, implements the method described in any one of claims 1-7.
Citation Information
Cited By
Data processing method in device management and electronic device
CN122450778A