Network equipment management method and device, electronic equipment and storage medium

By developing differentiated data collection strategies and dynamic threshold models for different network devices, and combining them with Bayesian network analysis, the problem of resource waste in heterogeneous device management is solved, and more efficient anomaly detection and management are achieved.

CN121814560APending Publication Date: 2026-04-07BEIJING ZHUOYIDA TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-27
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing network monitoring methods manage heterogeneous devices based on the smallest-sized device, resulting in a waste of resources for high-sized devices.

Method used

Differentiated data collection strategies are developed for different network devices. The status thresholds of the operating status indicators are calculated through a dynamic threshold model. The causes of anomalies are analyzed by combining a Bayesian network model, and a multi-dimensional visualization page is generated.

Benefits of technology

It improves resource utilization and management precision, enabling more accurate detection of equipment anomalies and rapid location of the source of failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121814560A_ABST
    Figure CN121814560A_ABST
Patent Text Reader

Abstract

The invention provides a network equipment management method and device, electronic equipment and a storage medium, and the network equipment management method comprises the steps: collecting equipment parameters of each network equipment based on a collection strategy corresponding to each network equipment; calculating operation state indexes of the network devices based on the device parameters, and calculating state thresholds of the operation state indexes based on a dynamic threshold model; and detecting whether the network equipment is abnormal or not based on the operation state index and the state threshold, obtaining a detection result, and managing the network equipment based on the detection result. According to the invention, the resource utilization rate and the management precision are improved through dynamic acquisition of the dynamic threshold strategy and the equipment parameters.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network management, and in particular to a network device management method and device, electronic equipment and a storage medium. BACKGROUND

[0002] The existing network monitoring method usually assumes that devices of the same type (such as switches and servers) have uniform resource specifications. When the specifications of the devices are heterogeneous (such as differences in port rates and cache capacities of different models of switches), the minimum specification device is usually taken as the benchmark for monitoring and management, resulting in waste of resources of high-specification devices. SUMMARY

[0003] The present application provides a network device management method, device, electronic equipment and storage medium to solve the defects in the prior art.

[0004] The present application provides a network device management method, comprising: Collecting device parameters of each network device based on a collection strategy corresponding to each network device; Calculating an operating state indicator of each network device based on the device parameters, and calculating a state threshold of each operating state indicator based on a dynamic threshold model; Detecting whether the network device is abnormal based on the operating state indicator and the state threshold, obtaining a detection result, and managing the network device based on the detection result.

[0005] According to the network device management method provided by the present application, the state threshold of each operating state indicator is calculated based on a dynamic threshold model, comprising: Obtaining historical operating state indicators of the network device within a historical time range; Inputting the historical operating state indicators into the dynamic threshold model to obtain the state threshold.

[0006] According to the network device management method provided by the present application, the network device is managed based on the detection result, comprising: If the number of times that the operating state indicator of the network device is greater than or equal to the state threshold reaches a threshold value, analyzing the abnormal reason of the network device.

[0007] According to the network device management method provided by the present application, the abnormal reason of the network device is analyzed, comprising: Obtaining a device topology structure of the network device; Based on the device topology structure, a Bayesian network model is used to infer the abnormal reason of the network device and determine an abnormal influence range.

[0008] According to a network device management method provided by the present invention, the step of managing the network device based on the detection result includes: Based on the detection results, a multi-dimensional visualization page is generated; wherein, the multi-dimensional aspects include device type, data center location, and indicator type, and the visualization page displays the trend curves of the operating status indicators and the real-time traffic topology diagram and alarm diagram of the network devices.

[0009] According to a network device management method provided by the present invention, the step of collecting device parameters of each network device based on the collection strategy corresponding to each network device includes: An independent thread is created for each of the network devices, and based on the independent thread and the acquisition strategy, the device parameters of each network device are acquired. If the device parameters cannot be acquired, the acquisition is repeated by retrying using the Simple Network Management Protocol (SMMP).

[0010] According to a network device management method provided by the present invention, before collecting the device parameters of each network device based on the collection strategy corresponding to each network device, the method further includes: The fluctuation indicators of various device parameters are obtained, and the acquisition strategy for each device parameter is determined based on the fluctuation indicators.

[0011] The present invention also provides a network device management apparatus, comprising: The acquisition module is configured to acquire device parameters of each network device based on the acquisition strategy corresponding to each network device; The calculation module is configured to calculate the operating status indicators of each of the network devices based on the device parameters, and to calculate the status threshold of each of the operating status indicators based on a dynamic threshold model. The management module is configured to detect whether the network device is abnormal based on the operating status indicators and the status threshold, obtain the detection results, and manage the network device based on the detection results.

[0012] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the network device management method described above.

[0013] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the network device management method as described above.

[0014] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the network device management method as described above.

[0015] The network device management method, apparatus, electronic device, and storage medium provided by this invention formulate differentiated data acquisition strategies for different network devices. These strategies collect device parameters and calculate operational status indicators based on these parameters. A corresponding dynamic threshold model is constructed for each operational status indicator, and the dynamic threshold model determines the status threshold for each indicator. By automatically adjusting the thresholds, more accurate anomaly detection is achieved, and network devices are managed based on the detection results. This invention improves resource utilization and management accuracy through dynamic threshold strategies and dynamic acquisition of device parameters. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0017] Figure 1 This is a flowchart illustrating the network device management method provided by the present invention.

[0018] Figure 2 This is a schematic diagram of the network device management device provided by the present invention.

[0019] Figure 3 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0020] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0021] Figure 1 This is a flowchart illustrating a network device management method according to an exemplary embodiment. Figure 1 As shown in an exemplary embodiment, the network device management method includes steps 110 to 130, which are described in detail below.

[0022] Step 110: Collect the device parameters of each network device based on the collection strategy corresponding to each network device.

[0023] In this embodiment of the invention, various device parameter acquisition strategies are pre-set, and device parameters of each network device are acquired based on the acquisition strategies, with network devices as the target.

[0024] Step 120: Calculate the operating status indicators of each network device based on the device parameters, and calculate the status threshold of each operating status indicator based on the dynamic threshold model.

[0025] In this embodiment of the invention, from the collected device parameters, the device parameters of the indicator type are subjected to unit conversion and smoothing filtering to eliminate instantaneous fluctuation interference. Specifically, this includes outlier removal and unit unification. Furthermore, based on the corresponding data collection result processing algorithm, the operating status indicators of the device parameters are calculated, such as algorithms for calculating port inflow and outflow rates, bandwidth utilization, packet loss rate, CPU utilization, etc. Dynamic threshold models are pre-constructed for various operating status indicators, and the corresponding state thresholds for each operating status indicator are calculated based on these dynamic threshold models.

[0026] Step 130: Detect whether the network device is abnormal based on the operating status indicators and the status threshold, obtain the detection results, and manage the network device based on the detection results.

[0027] In this embodiment of the invention, operational status indicators are compared with corresponding status thresholds. Based on the comparison result, it is determined whether the network device is abnormal, and thus whether an early warning needs to be triggered. The comparison result is used as the detection result, and network devices are managed based on the detection result.

[0028] In this embodiment of the invention, differentiated data collection strategies can be formulated for different network devices. Device parameters are collected through these strategies, and operational status indicators are calculated based on these parameters. A corresponding dynamic threshold model is constructed for each operational status indicator. The dynamic threshold model determines the status threshold for each indicator, and automatic adjustment of the thresholds enables more accurate anomaly detection. Finally, network devices are managed based on the detection results. This invention improves resource utilization and management accuracy through dynamic threshold strategies and dynamic collection of device parameters.

[0029] In an exemplary embodiment of the present invention, the step of calculating the state thresholds of each of the operating state indicators based on the dynamic threshold model includes: Obtain the historical operating status indicators of the network device within a historical time range; The historical operating status indicators are input into the dynamic threshold model to obtain the status threshold.

[0030] In this embodiment of the invention, raw device parameters of network devices are pre-collected. These parameters are then subjected to unit conversion and smoothing filtering to eliminate transient fluctuations, specifically including outlier removal and unit standardization. Based on the processed raw device parameters, raw operational status indicators are calculated, ultimately generating a standardized result set that meets analytical requirements. Then, by learning historical patterns of the raw operational status indicators, a dynamic threshold model is constructed to automatically adjust the status thresholds to adapt to normal fluctuations, finding the optimal solution between accuracy, real-time performance, and computational cost.

[0031] In one embodiment of the present invention, the dynamic threshold model can be constructed based on 3-sigma (3 times the standard deviation), which is based on the normal distribution theory: under normal operating conditions, approximately 99.7% of the data points should fall within the range of the mean plus or minus 3 times the standard deviation. The dynamic threshold model calculates a state threshold in real time based on historical operating state indicators over a recent historical time range. Through the dynamic threshold model, a smaller state threshold can be obtained when the network device load is stable, allowing even minor anomalies to be detected; when the network device load fluctuates drastically, a larger state threshold can be obtained, avoiding false alarms caused by normal fluctuations.

[0032] When calculating the state threshold, the collected historical operating state indicators are determined. The quantity N is set, and the sensitivity coefficient (k) is set, which is a multiple of Sigma. The standard value is 3, but it can be set to 2 in a strict environment and 4 in a lenient environment.

[0033] Calculate the moving average value based on the collected historical operational status indicators. The moving average can be either a simple moving average (SMA) or an exponentially weighted moving average (EWMA). The simple moving average (SMA) and the exponentially weighted moving average (EWMA) can be calculated using the following formulas: ; ; in, Indicates weight, This refers to the most recent historical operating status indicator from the current time t. Indicates based on The simple moving average (SMA) is calculated from other historical performance indicators besides those mentioned above.

[0034] The standard deviation is calculated based on the collected historical operational status indicators. The standard deviation reflects the degree of fluctuation in operational status indicators, and is calculated based on the following formula: .

[0035] Generate the current state threshold z according to the 3-sigma rule: .

[0036] In another embodiment of the invention, the median absolute deviation (MAD) can be used instead of the aforementioned large standard deviation. Specifically, the median M of the historical operating status indicators is calculated, the absolute value of each historical operating status indicator relative to the median is calculated, and the median m of the absolute values ​​is determined. The obtained median m is used as the median absolute deviation (MAD). The state threshold obtained by the median absolute deviation (MAD) is not affected by individual peak values, thus enabling more accurate capture of true persistent anomalies.

[0037] In another embodiment of the invention, a dynamic threshold model can be constructed based on a lightweight time series algorithm (such as Holt-Winters or a simplified version of LSTM).

[0038] Specifically, to achieve high-precision dynamic thresholding, a multi-dimensional feature vector is constructed. This multi-dimensional feature vector includes at least two of the following: a time-series feature vector, a business load vector, and an environmental state vector.

[0039] Taking historical CPU utilization as an example of historical operating status indicators, the time-series feature vector includes historical data from the same period and time encoding. Historical data from the same period is the historical CPU utilization at the same time in the past N days; the time encoding is the number of minutes (0-1439), day of the week (0-6), and whether it is a holiday (0 / 1) of the historical operating status indicators in a day. The load vector includes throughput, bandwidth utilization, and concurrent connections. Throughput is the current packet forwarding rate (Packets Per Second, PPS) of the network device; bandwidth utilization is the total bandwidth utilization of the current interface of the network device (Bits Per Second, BPS); and concurrent connections are the number of active TCP / UDP sessions of the network device. The environment state vector includes the recent trend and volatility. The recent trend represents the CPU moving average over the first past time range (e.g., 5 minutes); the volatility represents the CPU standard deviation over the second past time range (e.g., 15 minutes).

[0040] The state threshold is obtained by processing the constructed multidimensional feature vector based on the dynamic threshold model.

[0041] In an exemplary embodiment of the present invention, managing the network device based on the detection result includes: If the number of times the detection results indicate that the operating status index of the network device is greater than or equal to the status threshold reaches a threshold, the cause of the network device's abnormality is analyzed.

[0042] In this embodiment of the invention, if the number of times a network device's operating status indicator is greater than or equal to the corresponding status threshold reaches a threshold, such as 3 times, an early warning event is generated and its level is marked (warning / serious / urgent). For network devices that exceed the status threshold multiple times consecutively, a deep diagnostic process is automatically triggered to analyze the cause of the anomaly.

[0043] In an exemplary embodiment of the present invention, analyzing the cause of the network device's anomaly includes: Obtain the device topology of the network device; Based on the device topology, a Bayesian network model is used to infer the cause of the network device's anomaly and determine the scope of its impact.

[0044] In this embodiment of the invention, each network device has a corresponding device topology, such as the topology of core network devices built based on the physical layer, service system layer, link layer, core access layer, and switching layer. Batch queries are performed on network devices that repeatedly exceed the state threshold. The scope of the anomaly is analyzed in conjunction with the topology relationship, and a Bayesian network model is used to infer the cause of the anomaly, such as abnormal port traffic possibly caused by link congestion or device hardware failure.

[0045] In this embodiment of the invention, when the Bayesian network model observes multiple anomalies, it can automatically and quickly calculate the posterior probability of all possible causes of failure and find the most likely root cause. This probabilistic output perfectly reflects the uncertainty of the cause of the anomaly, enabling decision-makers to assess risks and formulate corresponding investigation strategies (e.g., prioritizing the inspection of high-probability items while preparing alternative solutions for low-probability items).

[0046] In an exemplary embodiment of the present invention, managing the network device based on the detection result includes: Based on the detection results, a multi-dimensional visualization page is generated; wherein, the multi-dimensional aspects include device type, data center location, and indicator type, and the visualization page displays the trend curves of the operating status indicators and the real-time traffic topology diagram and alarm diagram of the network devices.

[0047] In this embodiment of the invention, multi-dimensional visualization pages are generated according to device type, data center location, and indicator type. These multi-dimensional visualizations support real-time traffic topology maps, trend curves, and alarm graphs, and can generate daily, weekly, and monthly reports. The real-time traffic topology map visually displays the physical / logical connections and real-time traffic status between network devices within a selected range. The selected range can be a chosen dimension or a selected date. The trend curve displays detailed trends in operational status indicators in a time-series format. The alarm graph centrally displays the most critical issues for the current network devices and can be a list, timeline, or aggregated chart (such as a bar chart of alarm counts).

[0048] In an exemplary embodiment of the present invention, the step of collecting device parameters of each network device based on the collection strategy corresponding to each network device includes: An independent thread is created for each of the network devices, and based on the independent thread and the acquisition strategy, the device parameters of each network device are acquired. If the device parameters cannot be acquired, the acquisition is repeated by retrying using the Simple Network Management Protocol (SMMP).

[0049] In this embodiment of the invention, an independent thread is created for each network device to avoid overall data collection delays caused by blockage of a single network device. Each independent thread initiates data collection requests simultaneously, making full use of the multi-core performance of the CPU and shortening the total processing time. When a network device fails to log in or collect data, multiple attempts to log in or collect data are made using SNMP (Simple Network Management Protocol) retries.

[0050] In an exemplary embodiment of the present invention, before collecting the device parameters of each network device based on the collection strategy corresponding to each network device, the method further includes: The fluctuation indicators of various device parameters are obtained, and the acquisition strategy for each device parameter is determined based on the fluctuation indicators.

[0051] In this embodiment of the invention, differentiated collection strategies are set for network devices, and the collected device parameters json_index={device_info,kpi_info} are returned. The collection strategies for the device parameters of each network device are set based on their corresponding fluctuation indicators. For example, CPU, memory, and port traffic are more affected by resource fluctuations, so they can be collected at shorter time intervals, such as once every 2 minutes; parameters such as device configuration, port status, and temperature have smaller fluctuations, so they can be collected at medium time intervals, such as once every 5 minutes; parameters that remain largely unchanged, such as interface aliases, interface physical addresses, and entity serial numbers, are collected at longer time intervals, such as once a week.

[0052] Before data collection, initialize the network device list list_devices=[device1,device2,...,device...]. n ]; each of these devices x Each of these is an instance object that includes: Device ID, Device Name, Device IP, Device Manufacturer, Device Type, Device Model, SNMP (Simple Network Management Protocol) Version, SNMP Port, SNMP Community Word, SNMP Username, SNMP Authentication Protocol, SNMP Authentication Password, SNMP Encryption Protocol, SNMP Encryption Password, SNMP Timeout, and SNMP Retry Count.

[0053] Initialize the SNMP collection parameters list_snmp_kpi=[kpi1,kpi2,...,kpi] according to the triggered collection policy. n ]; where each kpi x Each of these is an instance object and includes: the English name of the indicator, the Chinese name of the indicator, the manufacturer, the type, the model, the indicator type, the OID (object identifier) ​​value, the algorithm for processing the collected results, and the indicator description.

[0054] The technical solution provided by this invention employs high-frequency data collection for high real-time indicators such as CPU utilization, memory usage, and network throughput to ensure timely detection of abnormal fluctuations. For low-frequency data changes such as device configuration and firmware version, low-frequency data collection is used to reduce system overhead. Simultaneously, differentiated monitoring and management are implemented for different network device types: for core backbone devices, high-precision traffic analysis and deep packet inspection technologies are deployed to capture abnormal traffic in real time; for edge access devices, the focus is on basic status monitoring (such as port status and temperature alarms) and lightweight log collection. Furthermore, a multi-dimensional visualization page is generated, transforming massive device parameters into intuitive and actionable business insights to facilitate rational resource allocation and rapid fault location.

[0055] The network device management apparatus provided by the present invention will be described below. The network device management apparatus described below can be referred to in correspondence with the network device management method described above. It should be noted that the apparatus provided in the embodiments below and the method provided in the embodiments above belong to the same concept, and the specific way in which each module and unit performs operations has been described in detail in the method embodiments, and will not be repeated here.

[0056] In one exemplary embodiment of the present invention, please refer to Figure 2 , Figure 2 This is a network device management apparatus according to an exemplary embodiment, comprising the following modules.

[0057] The acquisition module 210 is configured to acquire device parameters of each network device based on the acquisition strategy corresponding to each network device; The calculation module 220 is configured to calculate the operating status indicators of each of the network devices based on the device parameters, and to calculate the status threshold of each of the operating status indicators based on a dynamic threshold model. The management module 230 is configured to detect whether the network device is abnormal based on the operating status indicators and the status threshold, obtain the detection results, and manage the network device based on the detection results.

[0058] In an exemplary embodiment of the present invention, the computing module 220 includes: The acquisition submodule is configured to acquire historical operating status indicators of the network device within a historical time range. The input submodule is configured to input the historical operating status indicators into the dynamic threshold model to obtain the status threshold.

[0059] In an exemplary embodiment of the present invention, the management module 230 includes: The analysis submodule is configured to analyze the cause of the network device's abnormality if the number of times the detection result indicates that the network device's operating status indicator is greater than or equal to the status threshold reaches a certain threshold.

[0060] In one exemplary embodiment of the present invention, the analysis submodule includes: The acquisition unit is configured to acquire the device topology of the network device; The inference unit is configured to infer the cause of the network device's anomaly based on the device topology using a Bayesian network model, and to determine the scope of the anomaly's impact.

[0061] In an exemplary embodiment of the present invention, the management module 230 includes: The generation submodule is configured to generate a multi-dimensional visualization page based on the detection results; wherein, the multi-dimensional aspects include device type, data center location, and indicator type, and the visualization page displays the trend curves of the operating status indicators and the real-time traffic topology diagram and alarm diagram of the network devices.

[0062] In an exemplary embodiment of the present invention, the acquisition module 210 includes: The acquisition submodule is configured to create an independent thread for each of the network devices, and to acquire device parameters of each network device based on the independent thread and the acquisition strategy, and to repeatedly acquire the parameters by retrying according to the Simple Network Management Protocol (SMMP) if the device parameters cannot be acquired.

[0063] In an exemplary embodiment of the present invention, the network device management apparatus further includes: The determination module is configured to acquire fluctuation indicators of various device parameters and determine the acquisition strategy for each device parameter based on the fluctuation indicators.

[0064] Figure 3 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 3 As shown, the electronic device may include a processor 310, a communications interface 320, a memory 330, and a communication bus 340, wherein the processor 310, the communications interface 320, and the memory 330 communicate with each other via the communication bus 340. The processor 310 can call logical instructions in the memory 330 to execute a network device management method, which includes: collecting device parameters of each network device based on the acquisition strategy corresponding to each network device; The operating status indicators of each network device are calculated based on the device parameters, and the status thresholds of each operating status indicator are calculated based on the dynamic threshold model. The network device is detected as abnormal based on the operating status indicators and the status thresholds, and the detection results are obtained. The network device is then managed based on the detection results.

[0065] Furthermore, the logical instructions in the aforementioned memory 330 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0066] On the other hand, the present invention also provides a computer program product, the computer program product including a computer program, the computer program being stored on a non-transitory computer-readable storage medium, and when the computer program is executed by a processor, the computer is able to execute the network device management method provided by the above methods, the method including: collecting device parameters of each network device based on the collection strategy corresponding to each network device; The operating status indicators of each network device are calculated based on the device parameters, and the status thresholds of each operating status indicator are calculated based on the dynamic threshold model. The network device is detected as abnormal based on the operating status indicators and the status thresholds, and the detection results are obtained. The network device is then managed based on the detection results.

[0067] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the network device management method provided by the above methods, the method comprising: collecting device parameters of each network device based on a collection strategy corresponding to each network device; The operating status indicators of each network device are calculated based on the device parameters, and the status thresholds of each operating status indicator are calculated based on the dynamic threshold model. The network device is detected as abnormal based on the operating status indicators and the status thresholds, and the detection results are obtained. The network device is then managed based on the detection results.

[0068] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0069] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0070] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A network device management method, characterized in that, include: Based on the acquisition strategy corresponding to each network device, the device parameters of each network device are collected; The operating status indicators of each network device are calculated based on the device parameters, and the status thresholds of each operating status indicator are calculated based on the dynamic threshold model. The network device is detected as abnormal based on the operating status indicators and the status thresholds, and the detection results are obtained. The network device is then managed based on the detection results.

2. The network device management method according to claim 1, characterized in that, The calculation of the state thresholds for each of the aforementioned operating state indicators based on the dynamic threshold model includes: Obtain the historical operating status indicators of the network device within a historical time range; The historical operating status indicators are input into the dynamic threshold model to obtain the status threshold.

3. The network device management method according to claim 1, characterized in that, The management of the network device based on the detection results includes: If the number of times the detection results indicate that the operating status index of the network device is greater than or equal to the status threshold reaches a threshold, the cause of the network device's abnormality is analyzed.

4. The network device management method according to claim 3, characterized in that, The analysis of the causes of the network device's anomalies includes: Obtain the device topology of the network device; Based on the device topology, a Bayesian network model is used to infer the cause of the network device's anomaly and determine the scope of its impact.

5. The network device management method according to claim 1, characterized in that, The management of the network device based on the detection results includes: Based on the detection results, a multi-dimensional visualization page is generated; wherein, the multi-dimensional aspects include device type, data center location, and indicator type, and the visualization page displays the trend curves of the operating status indicators and the real-time traffic topology diagram and alarm diagram of the network devices.

6. The network device management method according to claim 1, characterized in that, The method of collecting device parameters for each network device based on the collection strategy corresponding to each network device includes: An independent thread is created for each of the network devices, and based on the independent thread and the acquisition strategy, the device parameters of each network device are acquired. If the device parameters cannot be acquired, the acquisition is repeated by retrying using the Simple Network Management Protocol (SMMP).

7. The network device management method according to any one of claims 1 to 6, characterized in that, Before collecting the device parameters of each network device based on the collection strategy corresponding to each network device, the method further includes: The fluctuation indicators of various device parameters are obtained, and the acquisition strategy for each device parameter is determined based on the fluctuation indicators.

8. A network device management device, characterized in that, include: The acquisition module is configured to acquire device parameters of each network device based on the acquisition strategy corresponding to each network device; The calculation module is configured to calculate the operating status indicators of each of the network devices based on the device parameters, and to calculate the status threshold of each of the operating status indicators based on a dynamic threshold model. The management module is configured to detect whether the network device is abnormal based on the operating status indicators and the status threshold, obtain the detection results, and manage the network device based on the detection results.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the network device management method as described in any one of claims 1 to 7.

10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the network device management method as described in any one of claims 1 to 7.