Video and audio signal monitoring method of switch node port mirror image

By creating dynamic mirror points, collecting multi-dimensional data, and adaptive control, the problem of static mirror point settings in traditional methods has been solved, enabling efficient fault location and resource optimization, and improving the level of intelligent network operation and maintenance.

CN121907668APending Publication Date: 2026-04-21ZHONGYI INSTECH TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZHONGYI INSTECH TECH CO LTD
Filing Date
2025-12-25
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Traditional methods for monitoring video and audio signals mirrored on switch node ports cannot flexibly adjust mirroring points in complex network environments, leading to missed monitoring of critical nodes or wasted resources. Data collection is limited in scope and lacks high-precision time synchronization. Mirroring traffic conflicts affect service transmission, and fault analysis accuracy is low.

Method used

By employing dynamic mirror point creation, multi-dimensional data association and collection, fault propagation path modeling, and adaptive mirror traffic control, the mirror strategy is dynamically adjusted through network topology, troubleshooting scoring, and time synchronization to achieve efficient fault location and resource optimization.

Benefits of technology

It improves the timeliness and accuracy of fault detection, reduces reliance on manual intervention, achieves efficient resource utilization and stable service transmission, and enhances the intelligence level of network operation and maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121907668A_ABST
    Figure CN121907668A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of video and audio signal monitoring, in particular to a switch node port mirroring video and audio signal monitoring method, which comprises the following steps of: creating a dynamic mirroring point: creating a mirroring point at each node in a target node group based on a network topology structure, a traffic limit and a fault removal score of a candidate node; multi-dimensional data association collection: collecting mirror image flow data through the created mirror image point, collecting network equipment performance index data at the same time, and adding a synchronization timestamp mark to all the collected data; fault propagation path modeling: constructing a real-time fault propagation path model based on the network topology data and the collected fault data; and fault source automatic positioning: analyzing the fault propagation path model, and determining the initial occurrence position and time of the fault. The device can dynamically construct the mirror image, accurately determine the fault, adaptively control the flow and visualize, and efficiently improve the operation and maintenance of the video and audio network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of audio and video signal monitoring technology, and more specifically, to a method for monitoring audio and video signals mirrored on a switch node port. Background Technology

[0002] Against the backdrop of rapid development in modern communication technology, audio and video services have become deeply integrated into various production and daily life scenarios, becoming an indispensable and important component in areas such as information transmission, entertainment consumption, and remote collaboration. The stable transmission and efficient monitoring of audio and video signals are directly related to service experience and quality, and the completeness of its technical support system is receiving increasing attention from the industry. However, with the continuous expansion of network scale, increasingly complex network topologies, and a growing number of nodes, the operating environment of audio and video transmission networks has become more complex and volatile, leading to a simultaneous increase in the probability of fault occurrence and the difficulty of troubleshooting.

[0003] Traditional methods for monitoring audio and video signals mirrored on switch node ports have increasingly revealed numerous limitations when dealing with complex network environments. Firstly, traditional methods often employ static mirror point settings, making it difficult to flexibly adjust mirror point locations once determined. This fails to dynamically adapt to changes in network topology, service priority distribution, and differences in node failure risk. Consequently, some high-risk, high-value critical nodes may not be included in the monitoring scope, while low-value nodes consume significant monitoring resources, resulting in wasted resources and reduced timeliness of fault detection.

[0004] Secondly, in the data acquisition stage, traditional methods often suffer from problems such as limited data dimensions and insufficient synchronization. In most cases, only mirrored traffic data is collected, lacking effective capture of the network device's own performance indicators, making it difficult to comprehensively reflect the network's operating status and fault-related factors. At the same time, due to the lack of a high-precision time synchronization mechanism, data from different sources often have significantly different time stamps, weakening the correlation between data and failing to provide accurate time-series basis for fault analysis, thus affecting the accuracy of fault diagnosis.

[0005] In addition, traditional methods lack an effective mirror traffic control mechanism. When network traffic peaks, mirror traffic may consume a large amount of bandwidth resources, conflicting with normal audio and video service traffic and causing problems such as lag and delay in normal service transmission. At the same time, the display of troubleshooting results is relatively simple, mostly in the form of text or simple tables, lacking intuitive graphical displays. It is difficult for technicians to quickly grasp the overall situation of the fault, which is not conducive to efficient collaborative fault handling. Summary of the Invention

[0006] This invention provides a method for monitoring video and audio signals mirrored on a switch node port, comprising the following steps:

[0007] S1. Dynamic mirror point creation: Based on the network topology, preset traffic quota and troubleshooting scores of candidate nodes, determine and create a target mirror point group, wherein the troubleshooting scores are generated by comprehensively considering the historical failure frequency of the nodes, the criticality of the network topology and the service importance of the audio and video services they carry.

[0008] S2. Multi-dimensional data association and collection: Collect mirror traffic data through the target mirror point group, synchronously collect network device performance index data, and use a time synchronization mechanism to add a synchronization timestamp to all collected data;

[0009] S3. Fault propagation path modeling: Based on the network topology data and the collected data with the synchronization timestamp, a real-time fault propagation path model describing the spatiotemporal correlation of fault events is constructed.

[0010] S4. Automatic fault root cause location: Analyze the real-time fault propagation path model to determine the initial occurrence node and time of the fault;

[0011] S5. Mirrored Traffic Adaptive Control: Monitor the bandwidth utilization of the mirrored port, and based on the bandwidth utilization and the troubleshooting score, dynamically adjust the mirroring strategy to prioritize the integrity of data collection for nodes with high troubleshooting value.

[0012] Further, in step S1, the creation of dynamic mirror points specifically involves: under the premise of meeting the preset traffic quota constraint, selecting nodes with the highest troubleshooting score from the candidate nodes to form a target mirror point group, and the total traffic usage of the target mirror point group does not exceed the preset traffic quota.

[0013] Furthermore, the troubleshooting score is calculated based on a weighted average of the node's historical failure frequency, network topology criticality, and service importance. The weighting formula used for the troubleshooting score is as follows:

[0014] .

[0015] in, This is a normalized value for historical fault frequencies; Topological criticality is calculated based on node betweenness centrality; The importance of the node is determined based on the level of audio and video services it carries; , , These are the weighting coefficients.

[0016] Furthermore, the mirrored traffic data includes data packet characteristic information of the audio and video streams, and the network device performance index data includes one or more of the following: port utilization, error frame count, buffer overflow event, link bandwidth utilization, and data packet forwarding delay.

[0017] Furthermore, in step S3, the fault propagation path modeling specifically includes:

[0018] S31. Construct a network topology diagram that combines physical and logical elements based on network topology data;

[0019] S32. Based on the collected data with synchronization timestamps, mark the fault-related events of each node in the network topology diagram in chronological order;

[0020] S33. Generate a preliminary fault propagation path based on the event occurrence sequence and node association relationships;

[0021] S34. By verifying whether the time delay of each node failure event on the path is within a preset reasonable range, optimize and determine the final real-time fault propagation path model.

[0022] Furthermore, in step S4, the automatic fault root cause location specifically includes:

[0023] S41. In the real-time fault propagation path model, trace the starting trigger point of the fault event as a candidate for the initial occurrence node of the fault.

[0024] S42. Verify the causal relationship between candidate nodes and subsequent associated node failure events, and eliminate interference from secondary failure nodes;

[0025] S43. By combining the troubleshooting score of the node and the timestamp of the fault event, the initial node and the exact time of occurrence of the fault are finally determined.

[0026] Furthermore, it also includes a fault delimitation result visualization step: the initial occurrence node of the fault, the fault propagation path, the scope of influence and the fault type information are displayed to the user in the form of a graphical interface, supporting fault timeline playback and scope of influence simulation.

[0027] Furthermore, in step S5, dynamically adjusting the mirroring strategy specifically includes:

[0028] S51. When the bandwidth utilization rate is higher than the preset threshold, the traffic of nodes with low troubleshooting scores is collected using a 1 / N sampling method, only the specific protocol header data is mirrored, or its bandwidth allocation priority is reduced.

[0029] When the bandwidth utilization rate is lower than the preset threshold, S52 improves the data collection integrity of high troubleshooting scoring nodes, including the full collection of mirror traffic data.

[0030] Furthermore, it also includes: the troubleshooting score is generated using a machine learning-based scoring model, which is trained by inputting historical fault data, network topology data, and service importance labeling data. The model can dynamically update parameter weights or directly output the troubleshooting score of the node.

[0031] Furthermore, in step S3, a fault propagation path is constructed and verified by using association rule mining based on time windows or a probabilistic inference model based on Bayesian networks, thereby improving the accuracy and reliability of the fault propagation path model.

[0032] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0033] 1. This invention, through a dynamic mirror point creation mechanism, breaks through the limitations of traditional static mirror point settings. It can flexibly select target node groups with high troubleshooting value and create mirror points based on network topology, traffic quotas, and node troubleshooting scores, ensuring that monitoring resources are concentrated on critical aspects. This dynamic adaptation method effectively avoids the problems of missed monitoring of critical nodes or excessive resource consumption by low-value nodes in traditional methods, making audio and video signal monitoring more targeted and effective. This lays a solid foundation for rapid fault detection and accurate analysis, significantly improving the monitoring system's adaptability to complex network environments.

[0034] 2. In this invention, the combination of multi-dimensional data association and high-precision time synchronization technology enables comprehensive capture and efficient association of mirrored traffic data and network device performance index data, providing rich and accurate data support for fault analysis. The fault propagation path modeling step clearly reconstructs the fault propagation logic by sorting out node connection relationships and fault sequence, while the automatic fault root cause location step quickly locates the initial location and time of the fault based on this model, significantly improving the accuracy and efficiency of fault location. This process eliminates reliance on manual experience, reduces the time and manpower costs of fault diagnosis, helps technicians respond quickly to faults, reduces the adverse effects of audio and video service interruptions, and improves the intelligence level of network operation and maintenance.

[0035] 3. In this invention, the mirror traffic adaptive control mechanism can monitor the bandwidth utilization of the mirror port in real time. By dynamically adjusting the sampling frequency, it avoids interference with normal audio and video service transmission caused by mirror traffic overload while ensuring the integrity of data from high-troubleshooting value nodes, thus achieving a dynamic balance between monitoring needs and normal service needs. Simultaneously, the fault localization result visualization step adopts a graphical display method. Through color differentiation and timeline playback functions, complex fault information is transformed into an intuitive and easy-to-understand graphical interface, helping technicians quickly grasp the fault situation and improving the collaborative efficiency of fault handling. Overall, this invention forms a complete intelligent solution from data acquisition and fault analysis to result display, comprehensively optimizing the operation and maintenance management process of audio and video networks and improving the stability and reliability of network operation. Attached Figure Description

[0036] Figure 1 This is a schematic diagram of the overall steps of the present invention;

[0037] Figure 2 This is a schematic diagram of the dynamic mirror point creation process of the present invention;

[0038] Figure 3 This is a schematic diagram of the multi-dimensional data association and acquisition process of the present invention;

[0039] Figure 4 This is a schematic diagram of the fault propagation path modeling process of the present invention;

[0040] Figure 5 This is a schematic diagram of the automatic fault root cause location process of the present invention;

[0041] Figure 6 This is a schematic diagram of the adaptive control process for mirrored traffic in this invention;

[0042] Figure 7 This is a schematic diagram illustrating the visualization process of the fault delimitation results of this invention;

[0043] Figure 8 This is a schematic diagram illustrating the complete core steps of the monitoring method of the present invention. Detailed Implementation

[0044] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0045] This invention provides a method for monitoring audio and video signals mirrored on a switch node port, see [link to relevant documentation]. Figure 1 - Figure 8 As shown, it includes the following steps:

[0046] S1. Dynamic Mirror Point Creation: Based on the network topology, preset traffic quota, and troubleshooting scores of candidate nodes, a target mirror point group is determined and created. The troubleshooting score is generated by comprehensively considering the node's historical failure frequency, network topology criticality, and the service importance of the audio and video services it carries. In addition, the troubleshooting score is generated using a machine learning-based scoring model. The model is trained by inputting historical failure data, network topology data, and service importance annotation data. The model can dynamically update parameter weights or directly output the node's troubleshooting score. Furthermore, dynamic mirror point creation specifically involves: under the premise of meeting the preset traffic quota constraint, selecting nodes with the highest troubleshooting scores from the candidate nodes to form a target mirror point group, and the total traffic usage of the target mirror point group does not exceed the preset traffic quota.

[0047] It should be noted that the troubleshooting score is calculated based on a weighted average of the node's historical failure frequency, network topology criticality, and service importance. The weighting formula used for the troubleshooting score is as follows:

[0048] .

[0049] in, This is a normalized value for historical fault frequencies; Topological criticality is calculated based on node betweenness centrality; The importance of the node is determined based on the level of audio and video services it carries; , , These are the weighting coefficients.

[0050] S2. Multi-dimensional data association and collection: Mirror traffic data is collected through the target mirror point group, network device performance index data is collected synchronously, and a time synchronization mechanism is used to add a synchronization timestamp to all collected data. The mirror traffic data includes data packet characteristic information of audio and video streams. The network device performance index data includes one or more of the following: port utilization, error frame count, buffer overflow event, link bandwidth utilization, and data packet forwarding delay.

[0051] S3. Fault Propagation Path Modeling: Based on the network topology data and the collected data with the synchronization timestamps, a real-time fault propagation path model describing the spatiotemporal correlation of fault events is constructed. This involves using time-window-based association rule mining or a Bayesian network-based probabilistic inference model to construct and validate fault propagation paths, thereby improving the accuracy and reliability of the fault propagation path model. Specifically, fault propagation path modeling includes:

[0052] S31. Construct a network topology diagram that combines physical and logical elements based on network topology data;

[0053] S32. Based on the collected data with synchronization timestamps, mark the fault-related events of each node in the network topology diagram in chronological order;

[0054] S33. Generate a preliminary fault propagation path based on the event occurrence sequence and node association relationships;

[0055] S34. By verifying whether the time delay of each node failure event on the path is within a preset reasonable range, optimize and determine the final real-time fault propagation path model.

[0056] S4. Automatic fault root cause location: Analyze the real-time fault propagation path model to determine the initial occurrence node and time of the fault. Specifically, automatic fault root cause location includes:

[0057] S41. In the real-time fault propagation path model, trace the starting trigger point of the fault event as a candidate for the initial occurrence node of the fault.

[0058] S42. Verify the causal relationship between candidate nodes and subsequent associated node failure events, and eliminate interference from secondary failure nodes;

[0059] S43. By combining the troubleshooting score of the node and the timestamp of the fault event, the initial node and the exact time of occurrence of the fault are finally determined.

[0060] It also includes a fault delimitation result visualization step: displaying the initial occurrence node, fault propagation path, impact range, and fault type information to the user in a graphical interface, supporting fault timeline playback and impact range simulation.

[0061] S5. Mirrored Traffic Adaptive Control: Monitor the bandwidth utilization of the mirrored ports and dynamically adjust the mirroring strategy based on the bandwidth utilization and the troubleshooting score. Prioritize the integrity of data collection from high-troubleshooting-value nodes. Specifically, dynamically adjusting the mirroring strategy includes:

[0062] S51. When the bandwidth utilization rate is higher than the preset threshold, the traffic of nodes with low troubleshooting scores is collected using a 1 / N sampling method, only the specific protocol header data is mirrored, or its bandwidth allocation priority is reduced.

[0063] When the bandwidth utilization rate is lower than the preset threshold, S52 improves the data collection integrity of high troubleshooting scoring nodes, including the full collection of mirror traffic data.

[0064] Example

[0065] Regarding troubleshooting scoring, in addition to weighted summation, machine learning-based scoring models can also be used. These models are trained using historical data and dynamically updated with weights or directly output risk scores. For example, a random forest algorithm can be used, employing features such as the historical failure frequency of nodes, network topology criticality, and business importance. By training the model with a large amount of historical failure data, the model can automatically learn the weights of each feature's impact on node failure risk, thereby outputting a more accurate troubleshooting score.

[0066] For fault propagation modeling, time-window-based association rule mining or Bayesian network-based probabilistic inference models can be used to construct and verify propagation paths. Time-window-based association rule mining can set a fixed time window and analyze the correlation between fault events of each node within the time window to discover potential fault propagation rules. Bayesian network-based probabilistic inference models can construct a network of probabilistic relationships between node faults and use prior and posterior probabilities to infer the most likely path of fault propagation.

[0067] Adaptive control strategies can specifically include: 1 / N sampling of low-priority traffic, mirroring only specific protocol headers, and setting up differentiated guaranteed bandwidth queues. When sampling low-priority traffic at 1 / N, the sampling ratio N can be dynamically adjusted based on actual bandwidth usage; mirroring only specific protocol headers reduces the amount of mirrored data while retaining critical protocol information; setting up differentiated guaranteed bandwidth queues allocates dedicated bandwidth channels to mirrored traffic from high-troubleshooting-value nodes, ensuring their data transmission is not interfered with by other traffic.

[0068] Regarding visualization, the interface supports fault timeline playback, impact range simulation, and integration with the asset management system to locate physical devices. The fault timeline playback function can display the complete process of a fault from its occurrence to its propagation in chronological order; the impact range simulation can predict other nodes and services that the fault may affect based on the fault propagation path model; and the integration with the asset management system can quickly locate the physical device location, model, maintenance records, and other information corresponding to the root cause node of the fault, providing comprehensive support for fault handling.

[0069] Experimental verification and effect data

[0070] To verify the effectiveness of the present invention, a comparative test was conducted in a simulated audio-visual production network of a certain scale. The test group adopted the complete scheme of the present invention, control group A adopted a static key node mirroring scheme, and control group B adopted dynamic mirroring but without adaptive adjustment scheme.

[0071] Test metrics Control group A Control group B This invention test group Effect description Accuracy of root cause location 65% 78% 96% Collaborative analysis significantly improves accuracy Mean Time To Find Fault (MTTR) 45 minutes 22 minutes <8 minutes Automatic modeling and positioning are greatly accelerated. Peak business monitoring bandwidth ratio 15% (fixed) 15% (fixed) 5-12% (Dynamic) Adaptive regulation effectively saves bandwidth

[0072] Experiments show that the solution of the present invention has a significant effect of synergistic enhancement in terms of positioning accuracy, efficiency and intelligent resource scheduling.

[0073] The effects of the above steps can be achieved in the following ways:

[0074] The core structures involved in the dynamic mirror point creation process include a node detection module, a topology analysis unit, a scoring calculation unit, and a mirror point generation component. The node detection module's casing is made of high-strength aluminum alloy, which possesses excellent electromagnetic interference resistance and heat dissipation performance, enabling it to adapt to complex electromagnetic environments such as computer rooms. The internal circuit board uses FR-4 epoxy fiberglass board and is equipped with an industrial-grade detection chip to ensure accurate identification and stable monitoring of network node connection status. The core computing chip of the topology analysis unit uses a highly integrated dedicated processing chip, packaged in ceramic material, which enhances the chip's resistance to temperature variations and ensures operational stability during long-term operation.

[0075] The scoring calculation unit's circuit board employs high-density interconnect technology to reduce signal transmission loss, and all electronic components are selected to meet industry standards, ensuring the accuracy of the scoring calculation. The signal interface of the mirror point generation component uses a gold-plating process to reduce signal attenuation and improve the transmission efficiency of mirror point creation commands. The core functions of each structure are as follows: the node detection module acquires the network topology, traffic quota, and mirror traffic information of candidate nodes in the target network; the topology analysis unit parses the network topology and clarifies the connection relationships between nodes; the scoring calculation unit calculates the troubleshooting score of each candidate node based on the node's historical failure frequency, network topology criticality, and business importance using a weighted formula; and the mirror point generation component creates a mirror point for each node in the target node group.

[0076] The multi-dimensional data association and acquisition process includes a mirror traffic acquisition module, a performance indicator acquisition sensor, a time synchronization module, and a data storage unit. The mirror traffic acquisition module's signal receiver features a shielded design with an aluminum alloy casing and an anti-interference internal circuitry to ensure accurate acquisition of audio and video stream data packet characteristics. The performance indicator acquisition sensor uses corrosion-resistant stainless steel for its casing, adapting to temperature and humidity changes in the computer room. Its sensor probes employ high-precision sensing elements to accurately capture device performance data such as port utilization, error frame counts, and buffer overflow events. The time synchronization module's core clock chip uses a high-precision temperature-compensated crystal oscillator, packaged in engineering plastic to ensure time signal stability. The module is equipped with an independent signal receiving antenna to enhance its ability to receive external high-precision time synchronization protocol signals. The data storage unit uses an industrial-grade solid-state drive, offering shock and vibration resistance, fast read and write speeds, and meeting the real-time storage needs of massive amounts of acquired data.

[0077] The functional division of each component is as follows: the mirror traffic acquisition module collects data packet characteristic information of audio and video streams through created mirror points; the performance index acquisition sensor synchronously collects various performance index data of network devices; the time synchronization module receives high-precision time synchronization protocol signals and adds a unified synchronization timestamp to all acquired data; the data storage unit temporarily stores the acquired multi-dimensional data to provide data support for subsequent processing. The control method adopts distributed control, with each acquisition unit controlled by an independent microcontroller. The microcontroller communicates with the central control unit via Ethernet to achieve real-time configuration of acquisition parameters and real-time uploading of acquired data. The time synchronization module ensures that the time base of all acquisition units is consistent through an automatic calibration mechanism.

[0078] The fault propagation path modeling process includes a topology modeling unit, a fault event annotation module, a path generation unit, and a delay verification component. The topology modeling unit utilizes an FPGA chip as its core, which features strong parallel computing capabilities and low power consumption. Its aluminum alloy heat dissipation casing enhances heat dissipation efficiency and ensures stability during prolonged high-load operation. The fault event annotation module uses an anti-glare LCD display panel for easy observation of annotation results by technicians. Its internal logic circuitry employs CMOS technology to reduce power consumption. The path generation unit uses a flexible circuit board design to adapt to different installation spaces. It uses an industrial-grade ARM chip with high computing speed, enabling rapid processing of node connection relationships and fault time series data. The delay verification component's core component is a high-precision timer encapsulated in ceramic, ensuring high timing accuracy and guaranteeing the accuracy of the propagation delay estimate.

[0079] The functions of each component are as follows: the topology modeling unit constructs a node connection graph based on network topology data; the fault event annotation module annotates fault events in the node connection graph based on collected fault data and timestamp sequences; the path generation unit generates fault propagation paths based on time sequences and node connections; and the delay verification component calculates the estimated fault propagation delay and verifies the rationality of the fault propagation path based on this estimate. A collaborative control architecture is adopted. The central control unit sends control commands to each unit via the CAN bus. After the topology modeling unit completes the construction of the node connection graph, it transmits the data to the fault event annotation module. The annotation module then feeds back the annotations to the path generation unit. After generating a preliminary path, the path generation unit verifies it using the delay verification component. If the verification result is unsatisfactory, the process is returned to the path generation unit for re-optimization. The entire process forms a closed-loop control.

[0080] The automatic fault propagation path localization process includes a path analysis module, a causal verification unit, a root cause determination component, and a result output interface. The core processor of the path analysis module uses an industrial-grade ARM chip, and its casing is made of insulated ABS plastic, providing excellent anti-static performance. The internal circuitry employs an anti-interference design to ensure accurate analysis of the fault propagation path model. The causal verification unit's logic operation chip uses a high-reliability CMOS chip, offering low power consumption and high processing speed, enabling rapid verification of causal relationships between fault events. The root cause determination component's storage chip uses non-volatile memory, permanently storing fault root cause determination rules to ensure the consistency of the determination logic. The result output interface uses a standardized RJ45 interface, offering strong compatibility and seamless integration with subsequent visualization modules.

[0081] The functions of each structure are as follows: the path analysis module analyzes the fault propagation path model and finds the starting point of the fault time series; the causal verification unit verifies the causal relationship between the starting point and subsequent fault events; the root cause determination component determines the initial location and time of the fault based on the verification results; and the result output interface transmits the fault root cause location results to the fault delimitation result visualization module.

[0082] The control method adopts a closed-loop control mechanism. The path analysis module transmits the analyzed starting point data to the causal verification unit. The verification unit verifies the causal relationship through preset logic rules. If the verification passes, the data is transmitted to the root cause determination component. If the verification fails, the data is returned to the path analysis module to find the starting point again until a valid root cause of the fault is obtained.

[0083] The mirrored traffic adaptive control process includes a bandwidth monitoring module, a traffic scheduling unit, a priority determination component, and a sampling frequency adjustment module. The bandwidth monitoring module uses a high-precision capacitive sensor with a polycarbonate housing, making it impact-resistant and wear-resistant, accurately monitoring the bandwidth utilization of the mirrored port. The traffic scheduling unit's relays use silver alloy contacts, offering good conductivity and low contact resistance, ensuring reliable execution of traffic scheduling commands. The priority determination component's core chip uses a low-power microprocessor, enabling rapid processing of node troubleshooting scoring data and determining the priority of mirrored traffic. The sampling frequency adjustment module uses a precision wire-wound potentiometer, offering high adjustment accuracy and precisely adjusting the sampling frequency of low-priority traffic.

[0084] The functions of each structure are as follows: the bandwidth monitoring module monitors the bandwidth utilization of the mirror port in real time; the traffic scheduling unit receives the bandwidth monitoring data and determines whether it exceeds the preset threshold; the priority determination component identifies high and low priority mirror traffic based on the node troubleshooting score; the sampling frequency adjustment module reduces the sampling frequency of low priority traffic according to the scheduling instruction, and prioritizes the integrity of mirror data of nodes with high troubleshooting value.

[0085] The control method adopts a feedback control mechanism. The bandwidth monitoring module transmits real-time monitoring data to the traffic scheduling unit. The scheduling unit makes a judgment based on a preset threshold. If the utilization rate exceeds the threshold, it sends an instruction to the priority determination component. After the priority determination component completes the priority determination, it feeds back to the traffic scheduling unit. The scheduling unit sends an adjustment instruction to the sampling frequency adjustment module. The entire control process responds quickly and ensures the real-time performance of traffic adjustment.

[0086] The fault localization result visualization process includes a graphics generation module, a display control unit, interactive operation components, and a data rendering engine. The graphics generation module's circuit board utilizes high-density interconnect technology, and the chip is a high-performance graphics processing chip, enabling rapid generation of the network topology map. The display control unit's circuit board uses a flexible circuit board, adaptable to different display device installation requirements, and the control chip uses a low-power microcontroller to ensure precise control of display parameters. The interactive operation components' buttons are made of silicone, offering a comfortable feel, high durability, and convenient user operation. The core GPU of the data rendering engine uses a professional graphics processing chip, and the heat sink is made of aluminum alloy, providing excellent heat dissipation performance and ensuring smooth graphics rendering.

[0087] The functions of each structure are as follows: the graphics generation module generates a network topology base map; the data rendering engine overlays the fault propagation path model and delimitation results onto the base map, and highlights the root node of the fault and the propagation path with different colors to distinguish the node's operating status; the display control unit controls the display mode, scaling ratio and other parameters of the graphics; the interactive operation component provides a timeline control to support the playback operation of the fault propagation process.

[0088] The control method adopts a graphical control interface. The GPU drives the data rendering engine to complete the graphics rendering. The display control unit receives the instructions issued by the user through the interactive operation component and adjusts the display effect. The playback control of the timeline is precisely controlled by the microcontroller to realize the forward and reverse playback of the fault propagation process.

[0089] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely preferred examples and are not intended to limit the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of the present invention is defined by the appended claims and their equivalents.

Claims

1. A method for monitoring video and audio signals mirrored on a switch node port, characterized in that: Includes the following steps: S1. Dynamic mirror point creation: Based on the network topology, preset traffic quota and troubleshooting scores of candidate nodes, determine and create a target mirror point group, wherein the troubleshooting scores are generated by comprehensively considering the historical failure frequency of the nodes, the criticality of the network topology and the service importance of the audio and video services they carry. S2. Multi-dimensional data association and collection: Collect mirror traffic data through the target mirror point group, synchronously collect network device performance index data, and use a time synchronization mechanism to add a synchronization timestamp to all collected data; S3. Fault propagation path modeling: Based on the network topology data and the collected data with the synchronization timestamp, a real-time fault propagation path model describing the spatiotemporal correlation of fault events is constructed. S4. Automatic fault root cause location: Analyze the real-time fault propagation path model to determine the initial occurrence node and time of the fault; S5. Mirrored Traffic Adaptive Control: Monitor the bandwidth utilization of the mirrored port, and based on the bandwidth utilization and the troubleshooting score, dynamically adjust the mirroring strategy to prioritize the integrity of data collection for nodes with high troubleshooting value.

2. The method for monitoring audio and video signals mirrored on switch node ports according to claim 1, characterized in that: In step S1, the creation of dynamic mirror points specifically involves: under the premise of meeting the preset traffic quota constraint, selecting nodes with the highest troubleshooting score from the candidate nodes to form a target mirror point group, and the total traffic usage of the target mirror point group does not exceed the preset traffic quota.

3. The method for monitoring audio and video signals mirrored on switch node ports according to claim 1, characterized in that: The troubleshooting score is calculated by weighting the node's historical failure frequency, network topology criticality, and service importance. The weighting formula used for the troubleshooting score is as follows: 。 in, This is a normalized value for historical fault frequencies; Topological criticality is calculated based on node betweenness centrality; The importance of the node is determined based on the level of audio and video services it carries; , , These are the weighting coefficients.

4. The method for monitoring audio and video signals mirrored on switch node ports according to claim 1, characterized in that: The mirrored traffic data includes data packet characteristic information of audio and video streams, and the network device performance index data includes one or more of the following: port utilization, error frame count, buffer overflow event, link bandwidth utilization, and data packet forwarding delay.

5. The method for monitoring audio and video signals mirrored on a switch node port according to claim 1, characterized in that: In step S3, fault propagation path modeling specifically includes: S31. Construct a network topology diagram that combines physical and logical elements based on network topology data; S32. Based on the collected data with synchronization timestamps, mark the fault-related events of each node in the network topology diagram in chronological order; S33. Generate a preliminary fault propagation path based on the event occurrence sequence and node association relationships; S34. By verifying whether the time delay of each node failure event on the path is within a preset reasonable range, optimize and determine the final real-time fault propagation path model.

6. The method for monitoring audio and video signals mirrored on a switch node port according to claim 1, characterized in that: In step S4, the automatic fault root cause location specifically includes: S41. In the real-time fault propagation path model, trace the starting trigger point of the fault event as a candidate for the initial occurrence node of the fault. S42. Verify the causal relationship between candidate nodes and subsequent associated node failure events, and eliminate interference from secondary failure nodes; S43. By combining the troubleshooting score of the node and the timestamp of the fault event, the initial node and the exact time of occurrence of the fault are finally determined.

7. The method for monitoring audio and video signals mirrored on a switch node port according to claim 6, characterized in that: It also includes a fault delimitation result visualization step: the initial occurrence node of the fault, the fault propagation path, the scope of impact and the fault type information are displayed to the user in the form of a graphical interface, supporting fault timeline playback and impact scope simulation.

8. The method for monitoring audio and video signals mirrored on a switch node port according to claim 1, characterized in that: In step S5, dynamically adjusting the mirroring strategy specifically includes: S51. When the bandwidth utilization rate is higher than the preset threshold, the traffic of nodes with low troubleshooting scores is collected using a 1 / N sampling method, only the specific protocol header data is mirrored, or its bandwidth allocation priority is reduced. When the bandwidth utilization rate is lower than the preset threshold, S52 improves the data collection integrity of high troubleshooting scoring nodes, including the full collection of mirror traffic data.

9. The method for monitoring audio and video signals mirrored on a switch node port according to claim 1, characterized in that: Also includes: The troubleshooting score is generated using a machine learning-based scoring model. The model is trained by inputting historical fault data, network topology data, and service importance labeling data. The model can dynamically update parameter weights or directly output the troubleshooting score of a node.

10. The method for monitoring audio and video signals mirrored on a switch node port according to claim 1, characterized in that: Also includes: In step S3, a fault propagation path is constructed and verified by using association rule mining based on time windows or a probabilistic inference model based on Bayesian networks, thereby improving the accuracy and reliability of the fault propagation path model.