Network health management system and method based on multi-source data fusion feedback
The network health management system, which integrates and feeds back multi-source data, monitors network latency, jitter, and delay in real time, solving the problem of enterprises having difficulty understanding the network health status and enabling comprehensive network health management and anomaly detection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-19
- Publication Date
- 2026-03-31
AI Technical Summary
Enterprises often struggle to understand the health and operational efficiency of their networks, leading to network failures that impact IT system management and maintenance.
A network health management system based on multi-source data fusion feedback is adopted. Through latency presentation, jitter detection and delay detection units, the system monitors network transmission latency, jitter and delay in real time, generates health management signals and sends them to the network health management center.
It provides a multi-angle view of network health status, supports various monitoring views, and serves as a network management tool to assist in network health management, providing comprehensive coverage and timely detection of abnormal areas.
Smart Images

Figure CN121771073A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network health management technology, specifically to a network health management system and method based on multi-source data fusion feedback. Background Technology
[0002] As the internet becomes increasingly integrated with traditional industries, a large number of new business models have emerged explosively. As the foundation for the operation of various businesses, the network has become an infrastructure as important as water and electricity. More and more enterprises and institutions are finding it difficult to withstand the impact of network failures. However, most enterprises currently have no way of knowing the health and operational efficiency of their own networks, which is obviously detrimental to network operation and maintenance and further affects the support and management of the entire IT system.
[0003] In existing technologies, when jitter is too large or unstable, the services carried on the network will exhibit inconsistent speeds and inexplicable behavior. How can jitter detection help users understand network congestion, and how can the display provide users with a more accurate grasp of the network transmission quality between two points?
[0004] To address the aforementioned technical shortcomings, a solution is proposed. Summary of the Invention
[0005] The purpose of this invention is to solve the problems mentioned above by proposing a network health management system and method based on multi-source data fusion feedback.
[0006] The objective of this invention can be achieved through the following technical solution: a network health management system based on multi-source data fusion feedback, and a network health management center, wherein the network health management center has the following communication connections: The delay display unit collects and detects data transmission delay; The jitter detection unit detects and statistically analyzes changes in network data packet latency. The delay detection unit tracks and detects data transmission between regions.
[0007] Furthermore, the process of delaying the rendering of the unit is as follows: The system determines the data transmission time points and detects the data transmission time at each time point. Based on the detection records at each time point, it obtains the total round-trip delay of the data packets at each time point. The system then analyzes the total round-trip delay of the data packets: it collects the total round-trip delay of the data packets at each time point and compares it with a set delay threshold. If the total round-trip delay of the data packets exceeds the set delay threshold, the corresponding time point is marked as a high-latency moment; conversely, if the total round-trip delay of the data packets does not exceed the set delay threshold, the corresponding time point is marked as a low-latency moment.
[0008] Furthermore, if the ratio of the number of consecutive high-latency moments to the number of consecutive low-latency moments exceeds a set threshold during data transmission, it is inferred that the network transmission latency is abnormal. When the latency is too high, the services carried on the network will exhibit slow response speeds and stuttering. A latency signal is generated and sent to the network health management center. If the ratio of the number of consecutive high-latency moments to the number of consecutive low-latency moments does not exceed the set threshold during data transmission, it is inferred that the network transmission latency is normal. A timeliness signal is generated and sent to the network health management center.
[0009] Furthermore, the process of the jitter detection unit is as follows: Delay fluctuation detection is performed based on the fluctuation of network data packet latency. The network data packet latency at adjacent time points is recorded and a curve is constructed and set as a jitter curve. The peak network data packet latency at adjacent time points within the jitter curve is obtained. At the same time, the network data packet latency fluctuation frequency corresponding to consecutive time points within the jitter curve is collected. The peak network data packet latency at adjacent time points within the jitter curve and the network data packet latency fluctuation frequency corresponding to consecutive time points within the jitter curve are compared with the latency peak threshold and the latency fluctuation frequency threshold, respectively.
[0010] Furthermore, if the peak latency of network data packets at adjacent moments within the jitter curve exceeds the peak latency threshold, or if the frequency of network data packet latency fluctuation at consecutive moments within the jitter curve exceeds the frequency of latency fluctuation threshold, an abnormal jitter detection signal is generated and sent to the network health management center. Upon receiving the signal, the network health management center monitors network data transmission. If the peak latency of network data packets at adjacent moments within the jitter curve does not exceed the peak latency threshold, and the frequency of network data packet latency fluctuation at consecutive moments within the jitter curve does not exceed the frequency of latency fluctuation threshold, a normal jitter detection signal is generated and sent to the network health management center.
[0011] Furthermore, the process of the delay detection unit is as follows: The system acquires the data transmission process between different regions and obtains the delay duration at each moment during the data transmission phase. If the delay duration exceeds the set threshold, the current region and the transmission region are marked as delayed transmission regions; otherwise, if the delay duration does not exceed the set threshold, the current region and the transmission region are marked as non-delayed transmission regions. The system then sends the corresponding type of region to the network health management center.
[0012] This invention also proposes a network health management method based on multi-source data fusion feedback, the specific method of which is as follows: First, data transmission latency is collected and detected. Then, changes in network data packet latency are detected and statistically analyzed. Finally, data transmission between regions is tracked and detected.
[0013] Compared with the prior art, the beneficial effects of the present invention are: the present invention assists users in obtaining a view of the health status of the network and lines from multiple perspectives such as topology, performance, and early warning. The system supports a variety of monitoring views and can be used as an auxiliary tool for network administrators to intuitively display various monitoring views. The health management is comprehensive and can support the health tracking and monitoring of any node through the flexible deployment of the coordinator. Attached Figure Description
[0014] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings.
[0015] Figure 1 This is a system principle block diagram of the present invention; Figure 2 This is a topology diagram showing the network health status in this invention. Detailed Implementation
[0016] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0017] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0018] 1. Supports the selection and combination of network protocols. The deployment is described in detail below (including but not limited to the monitoring methods below; the system has extended functions for multiple protocols): UDPEcho The UDPECHO job can test end-to-end response time or connectivity between a router and an IP device. UDP is a network layer (layer 3) protocol that can report errors and provide other information related to IP packet processing. The response time is calculated by combining the time difference between sending a UDPECHO message and receiving a UDPECHO response with the results of the previous round. Enabling the Responder function on the responder can improve the accuracy of UDPecho.
[0019] DNS DNS response time is calculated by determining the time difference between sending a DNS request and receiving a response. This operation can query an IP address using either a user-provided hostname or a user-provided IP address.
[0020] HTTP HTTP jobs can measure the round-trip time (RTT) for connecting to or accessing data from an HTTP server. This is primarily defined by a URL. The HTTP server response time metric consists of the following three parts: DNS lookup—Round-Trip Time (RTT) for domain name lookup; TCP connection — Round-trip time for TCP connection processing; HTTP processing time is the round-trip time from sending a request to receiving a response from the server.
[0021] 2. Supports selection of probe data packet payload. The payload is the actual size of the content carried by the packet. This value is different from the size of the packet itself. Depending on the protocol type, the length of the packet header also varies. When selecting the payload value, the influence of the maximum transmission unit (MTU) that controls packet fragmentation must be considered. By controlling the payload size related to the MTU, the number of packets sent for each sample can be controlled. This value should ideally be consistent with the actual number of packets in the network.
[0022] The average packet size on the Internet is 260 bytes, and this is the default packet size used by the system.
[0023] 3. Supports selection of the TOS bit in probe data packets. To provide more granular quality monitoring, users can implement TOS monitoring as needed to detect the service quality of data traffic at different data QoS levels.
[0024] 4. Supports flexible detection interval selection The frequency at which the system sends probe signaling samples depends on the network bandwidth requirements of the monitoring traffic itself. The sampling frequency can be considered based on the premise of obtaining the most accurate network service level conclusions, but unfortunately, this is generally unrealistic. On an expensive wide area link, users will not allow test data to consume too much bandwidth. When using low-end routers or when a large amount of traffic passes through the router, the impact of generating SLA traffic on the performance of the device itself must also be considered. In this case, it is necessary to reduce the sampling frequency or use a separate router to perform IPSLA operations.
[0025] 5. Select an appropriate threshold value The system's thresholds are mainly used for the early warning module. Users can adopt the system's recommended values based on the built-in expert system. For the service provider's transmission lines, users can also use the predefined performance thresholds provided in SLC as a reference. If the service provider's parameters are not clear, users can also decide for themselves what threshold value to choose.
[0026] 3.2 Deployment Method The network health management system consists of a controller and a coordinator. Depending on the user's different needs, it includes the following four deployment methods: vertical, horizontal, outward, and inward. Users can flexibly deploy one or a combination of multiple methods according to their needs. The vertical type is mainly used to monitor the connection between branch offices and headquarters, and to promptly detect network problems between the headquarters and branch offices. The horizontal type is mainly used to monitor the connection between branch offices or between buildings and data centers, and to promptly detect network problems between branch offices and data centers; The outward-facing probe detects the internet or external network connectivity at various locations, reflecting the network quality of each probe point and promptly identifying external network problems. The inward-facing type is mainly used to detect the connection status of external networks (Internet) to the internal network, reflect the network quality of each detection point to the internal network, and promptly detect external network problems; Please see Figure 1 As shown, the network health management system based on multi-source data fusion feedback includes a network health management center, which has communication connections to a delay presentation unit, a jitter detection unit, and a latency detection unit. The network health management center generates a delayed presentation signal and sends it to the delayed presentation unit; After receiving the delay presentation signal, the delay presentation unit collects and detects the data transmission delay. The data transmission time points are determined, and the data transmission time at each time point is detected. Based on the detection records at each time point, the total round-trip delay of the data packets at each time point is obtained; and the total round-trip delay of the data packets is analyzed. Collect the total round-trip latency of data packets at each time point and compare it with a set latency threshold. If the total round-trip latency of data packets exceeds the set latency threshold, the corresponding time point is marked as a high latency moment; otherwise, if the total round-trip latency of data packets does not exceed the set latency threshold, the corresponding time point is marked as a low latency moment. If the ratio of the number of consecutive high-latency moments to the number of consecutive low-latency moments during data transmission exceeds a set threshold, it is inferred that the network transmission latency is abnormal. When the latency is too high, the services carried on the network will exhibit slow response speed, stuttering, and other phenomena; a latency signal is generated and sent to the network health management center. If the ratio of the number of consecutive high-latency moments to the number of consecutive low-latency moments during data transmission does not exceed the set threshold, it is inferred that the network transmission latency is normal, and a timely signal is generated and sent to the network health management center. The network health management center performs targeted data transmission control based on the round-trip latency monitoring of data packets at various time points; The network health management center generates a jitter detection signal and sends it to the jitter detection unit; After receiving the jitter detection signal, the jitter detection unit detects and statistically analyzes the changes in network data packet latency; Delay fluctuation detection is performed based on the fluctuation of network data packet latency. The network data packet latency at adjacent time points is recorded, and a curve is constructed and set as a jitter curve. Obtain the peak network packet delay at adjacent times within the jitter curve, and simultaneously collect the network packet delay fluctuation frequency corresponding to consecutive times within the jitter curve. Compare the peak network packet delay at adjacent times within the jitter curve and the network packet delay fluctuation frequency corresponding to consecutive times within the jitter curve with the peak delay threshold and the delay fluctuation frequency threshold, respectively. If the peak latency of network data packets at adjacent moments within the jitter curve exceeds the peak latency threshold, or if the frequency of network data packet latency fluctuation at consecutive moments within the jitter curve exceeds the frequency of latency fluctuation threshold, it is inferred that the jitter of network data packets within the jitter curve is too large or unstable. When the jitter is too large or unstable, the services carried on the network will exhibit inconsistent speeds and incomprehensible behavior. For audio and video services, there will be intermittent connection and disconnection, generating a jitter detection anomaly signal and sending it to the network health management center. After receiving the signal, the network health management center will monitor the network data transmission. If the peak latency of network data packets at adjacent moments within the jitter curve does not exceed the peak latency threshold, and the frequency of network data packet latency fluctuation at consecutive moments within the jitter curve does not exceed the frequency of latency fluctuation threshold, then it is inferred that the network data packet transmission within the jitter curve is normal, a jitter detection normal signal is generated and sent to the network health management center, and after receiving it, the network health management center continuously monitors the network data transmission. The network health management center generates a delay detection signal and sends it to the delay detection unit; After receiving the delay detection signal, the delay detection unit tracks and detects the data transmission between regions. The data transmission process between different regions is obtained, and the delay duration at each moment during the data transmission phase is obtained. If the delay duration exceeds the set duration threshold, the current region and the transmission region are marked as delayed transmission regions; otherwise, if the delay duration does not exceed the set duration threshold, the current region and the transmission region are marked as non-delayed transmission regions. The corresponding regions are then sent to the Network Health Management Center. By comparing the data, the Network Health Management Center can promptly identify regions with abnormal network transmission, thus discovering network problems in abnormal regions before business operations are affected.
[0027] This invention also proposes a network health management method based on multi-source data fusion feedback, the specific method of which is as follows: First, data transmission latency is collected and detected. Then, changes in network data packet latency are detected and statistically analyzed. Finally, data transmission between regions is tracked and detected.
[0028] In addition, it also has the function of Internet detection and display, which mainly displays the service quality of the internal network to the external network (Internet). This detection is achieved by the coordinator simulating a complete HTTP process. The detection data indicators include TCP connection establishment time, HTML transmission time, DNS resolution time, total loading time, etc. Network health status topology display function, such as Figure 2 As shown, the system also supports network health topology display. Users can intuitively understand the real-time status of the entire network health through the network health topology display, and quickly locate the network parts with abnormal network health.
[0029] Thresholds, preset values, preset ranges, etc. are set for result comparison and analysis to determine whether they are good or bad. The value of these thresholds is determined by a combination of large-scale model analysis of sample data and human experience. They can also be adjusted appropriately based on seasonal or common-sense influences. The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to any specific implementation. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.
Claims
1. A network health management system based on multi-source data fusion feedback, characterized in that, The network health management center has the following communication connections: The delay display unit collects and detects data transmission delay; The jitter detection unit detects and statistically analyzes changes in network data packet latency. The delay detection unit tracks and detects data transmission between regions.
2. The network health management system based on multi-source data fusion feedback according to claim 1, characterized in that, The process of delaying the rendering of the unit is as follows: The system determines the data transmission time points and detects the data transmission time at each time point. Based on the detection records at each time point, it obtains the total round-trip delay of the data packets at each time point. The system then analyzes the total round-trip delay of the data packets: it collects the total round-trip delay of the data packets at each time point and compares it with a set delay threshold. If the total round-trip delay of the data packets exceeds the set delay threshold, the corresponding time point is marked as a high-latency moment; conversely, if the total round-trip delay of the data packets does not exceed the set delay threshold, the corresponding time point is marked as a low-latency moment.
3. The network health management system based on multi-source data fusion feedback according to claim 2, characterized in that, If the ratio of the number of consecutive high-latency moments to the number of consecutive low-latency moments exceeds a set threshold during data transmission, a delay signal is generated and sent to the network health management center. If the ratio of the number of consecutive high-latency moments to the number of consecutive low-latency moments does not exceed the set threshold, it is inferred that the network transmission delay is normal, and a timeliness signal is generated and sent to the network health management center.
4. The network health management system based on multi-source data fusion feedback according to claim 1, characterized in that, The process of the jitter detection unit is as follows: Delay fluctuation detection is performed based on the fluctuation of network data packet latency. The network data packet latency at adjacent time points is recorded and a curve is constructed and set as a jitter curve. The peak network data packet latency at adjacent time points within the jitter curve is obtained. At the same time, the network data packet latency fluctuation frequency corresponding to consecutive time points within the jitter curve is collected. The peak network data packet latency at adjacent time points within the jitter curve and the network data packet latency fluctuation frequency corresponding to consecutive time points within the jitter curve are compared with the latency peak threshold and the latency fluctuation frequency threshold, respectively.
5. The network health management system based on multi-source data fusion feedback according to claim 4, characterized in that, If the peak latency of network data packets at adjacent moments within the jitter curve exceeds the peak latency threshold, or if the frequency of network data packet latency fluctuation at consecutive moments within the jitter curve exceeds the frequency of latency fluctuation threshold, a jitter detection anomaly signal is generated and sent to the network health management center. Upon receiving the signal, the network health management center monitors network data transmission. If the peak latency of network data packets at adjacent moments within the jitter curve does not exceed the peak latency threshold, and the frequency of network data packet latency fluctuation at consecutive moments within the jitter curve does not exceed the frequency of latency fluctuation threshold, a jitter detection normal signal is generated and sent to the network health management center.
6. The network health management system based on multi-source data fusion feedback according to claim 1, characterized in that, The process of the delay detection unit is as follows: The data transmission process between different regions is obtained, and the delay duration at each moment during the data transmission phase is obtained. If the delay duration exceeds the set duration threshold, the current region and the transmission region are marked as delayed transmission regions; otherwise, if the delay duration does not exceed the set duration threshold, the current region and the transmission region are marked as non-delayed transmission regions. And send the corresponding type of region to the Network Health Management Center.
7. A network health management method based on multi-source data fusion feedback, employing the network health management system based on multi-source data fusion feedback as described in any one of claims 1-6, characterized in that, The specific method is as follows: First, data transmission latency is collected and detected. Then, changes in network data packet latency are detected and statistically analyzed. Finally, data transmission between regions is tracked and detected.