Comprehensive online monitoring system for operation state of local area network equipment

The integrated online monitoring system for the operating status of local area network (LAN) devices has solved the problem of inaccurate fault and degradation location in multi-vendor mixed LANs. It has achieved accurate location and timely identification under a unified time base and business path perspective, thereby improving the reliability of operation and maintenance decisions.

CN121940262APending Publication Date: 2026-04-28HANGZHOU QINGLIN TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HANGZHOU QINGLIN TECHNOLOGY CO LTD
Filing Date
2026-01-27
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

In multi-vendor hybrid LANs, existing monitoring technologies struggle to continuously and structurally characterize the operational status of critical business links from a unified time base and business path perspective, and to accurately converge end-to-end anomalies to operable path segments or device ports, resulting in inaccurate and untimely fault and degradation localization.

Method used

A comprehensive online monitoring system for the operating status of local area network devices is adopted, including an operation slice control module, a topology and service path modeling module, a status acquisition and fingerprint construction module, a constraint reasoning and localization module, and a degradation trend identification module. The system divides the monitoring period by using unified time information, constructs the network topology, collects device status, generates path status fingerprints and local status fingerprints, and performs anomaly localization and trend identification based on combined constraint relationships.

Benefits of technology

It enables precise location of degradation sources in multi-vendor hybrid LANs, distinguishes between link degradation and single-point device anomalies, exposes hidden performance risks in advance, improves the accuracy and timeliness of fault location, reduces the dependence of operation and maintenance personnel, and forms an auditable and closed-loop hierarchical early warning system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121940262A_ABST
    Figure CN121940262A_ABST
Patent Text Reader

Abstract

The invention discloses a comprehensive online monitoring system for the operation state of local area network equipment, and particularly relates to the technical field of local area network operation state monitoring. The method is used for solving the problems that in an existing multi-manufacturer local area network, monitoring data time calibers are not uniform, a state modeling and degradation recognition mechanism based on a service path is lacked, and key service link hidden performance degradation is difficult to find and accurately locate in time. A unified time service and slicing monitoring period is established by running a slicing control module, a key service path and a path segment sequence are generated by cooperating with a topology and service path modeling module, and path state fingerprints and local state fingerprints are formed by a state acquisition and fingerprint construction module. And the constraint inference positioning module converges the end-to-end anomaly into a small number of suspected degradation path segments, so that a degradation source is accurately identified according to a service path in a multi-manufacturer local area network, link degradation and equipment anomaly are distinguished, performance risks are exposed, and the problem that key service path degradation is difficult to timely and accurately position in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of local area network (LAN) operation status monitoring technology, specifically to a comprehensive online monitoring system for the operation status of LAN devices. Background Technology

[0002] Current LAN operation monitoring largely relies on network management systems to poll the status and collect alarms from devices from various vendors. Common methods include periodic queries based on management information, port counting statistics, simple connectivity probes, and log alarm summaries. These solutions typically record operational status at the device or port level, with different devices often using their own time bases. Monitoring platforms often perform rough archiving based on the collection time, lacking strict unified time synchronization and stable monitoring period division mechanisms, leading to discrepancies in time-series comparisons across devices and paths. Furthermore, while existing systems can obtain partial link relationships through topology discovery, this remains largely at the display level, failing to continuously maintain a path link sequence consistent with actual forwarding behavior from the perspective of the complete business path from key terminals to key service nodes.

[0003] In complex multi-vendor hybrid LANs, critical services often span multiple layers, including core, aggregation, and access, with issues such as link redundancy, route convergence, and dynamic adjustments. When end-to-end latency jitter, increased packet loss, or degraded service access quality occur, existing monitoring methods typically only detect abnormal port counts on certain devices or single-point alarms. Operations personnel need to rely on experience to manually compare counts and logs from multiple devices. It is difficult to establish a stable correspondence between end-to-end anomalies in the service path and the local states of each segment of the path under a unified time benchmark. Often, it is impossible to converge anomalies to a small number of operable path segments or device ports in a short period of time, and it is also difficult to identify early degradation that only manifests as slight metric deviations but has a potential impact on critical services in a timely manner.

[0004] Therefore, existing technologies for operational monitoring of critical business communications in multi-vendor LAN environments still lack a comprehensive solution that, under unified time synchronization constraints, manages the monitoring process in a segmented manner, combines dynamic topology and business path structure to fingerprint the end-to-end and local link states within each monitoring cycle, and automatically maps business path anomalies to a small number of suspected degradation path segments through explicit combination constraints, thereby achieving precise location and trend identification at the business path level. The core technical challenge can be summarized as: how to continuously, structurally, and traceably characterize the operational status of critical business links in a multi-vendor hybrid LAN, under a unified time reference and business path perspective, and reliably converge end-to-end anomalies to operable path segments or device ports to improve the accuracy and timeliness of fault and degradation location. Summary of the Invention

[0005] To address the shortcomings of existing technologies, this invention provides a comprehensive online monitoring system for the operating status of local area network (LAN) devices, thereby resolving the problems mentioned in the background section.

[0006] To achieve the above objectives, the present invention provides the following technical solution: a comprehensive online monitoring system for the operating status of local area network devices, comprising: S1, the slice control module, is used to divide the monitoring cycle based on unified time information, generate slices with slice identifiers, and align the time of each monitoring data. S2, Topology and Service Path Modeling Module, is used to obtain the connectivity relationships of devices within the local area network, construct the network topology, and determine the service path identifiers and path segment sequences from key terminals to key service nodes. S3, Status Acquisition and Fingerprint Construction Module, is used to collect device port statistics, device resource status and active detection results within the running slice, and generate path status fingerprints for each service path and local status fingerprints for each path segment based on the fingerprint template. S4, Constraint Reasoning and Localization Module, is used to obtain the set of path segments that can explain the path state anomalies based on the combined constraints between the path state fingerprint and the local state fingerprint within the running slice, and to calculate the path segment degradation impact degree. S5, Degradation Trend Identification Module, is used to determine the degradation level of device ports and path segments based on the changes in degradation impact within continuously running slices, and generate early warning information; S6, Display and Linkage Module, is used to present early warning information in the topology view and business path view, and outputs structured data containing device identifier, path identifier and degradation level through external interface for operation and maintenance system to call.

[0007] Furthermore, S1 includes: The slice control module obtains reference time from the time source to generate unified time information, which is then distributed to the acquisition agent and key equipment via a dedicated management network. Each data acquisition agent records the local time offset, and when forming a monitoring record, it carries the slice number and the local time offset and sends it to the monitoring platform.

[0008] Furthermore, the slice control module summarizes the monitoring records by slice number at the end of each slice and determines the validity of the records based on the local time offset and the allowable time synchronization deviation range. Records that exceed the allowed time synchronization deviation range are marked as incomplete records, records that arrive after the corresponding running slice has finished are marked as late records, and the slice number, time synchronization configuration version number and merging status are registered in the slice record table; A version-locking strategy is used to generate configuration change records for slice length, timing accuracy, and allowable timing deviation range. These records are then indexed with the slice record table, monitoring records, fingerprint records, and early warning records to form a chain of evidence.

[0009] Furthermore, S2 includes: The topology and service path modeling module collects adjacency information, port connection information and forwarding relationships of LAN devices, constructs a connectivity graph with device identifiers as nodes and port connection information as edges, and assigns path segment identifiers to the physical links in the connectivity graph; When maintenance personnel register the address information, service type, and region of key terminals and key service nodes on the monitoring platform interface, the topology and service path modeling module searches for available paths that meet the service type constraints and region constraints in the connectivity graph, generates service path identifiers and corresponding path segment sequences, and registers the service path identifiers, path segment sequences, and the temporarily unreachable status of the service path in the path record table according to the topology configuration version.

[0010] Furthermore, S3 includes: The status acquisition and fingerprint construction module receives raw status records carrying device identifiers, port identifiers, and time information from the acquisition agent based on the running slice number, business path identifier, and path segment identifier. On the monitoring platform side, the status information is processed according to the field set and quantization rules in the fingerprint template to generate local status fingerprints and path status fingerprints; Write the local state fingerprint into the fingerprint record table using the running slice number and path segment identifier as indexes, write the path state fingerprint into the fingerprint record table using the running slice number and business path identifier as indexes, and register the fingerprint template version number.

[0011] Furthermore, S4 includes: At the end of each running slice, the constraint reasoning localization module reads the path state fingerprint and local state fingerprint within that running slice from the fingerprint record table using the running slice number as an index. Based on the business path identifier and path segment sequence in the path record table, abnormal paths are marked by comparing them with the health fingerprint set according to the anomaly judgment rules. Based on the index offset results and local offset thresholds involved in the abnormal path, the path segments with explanatory power are determined; The degradation impact of each path segment is calculated according to the degradation impact calculation rules and recorded in the degradation record table.

[0012] Furthermore, when the local state fingerprint is missing or the running slice is marked as an incomplete slice by the running slice control module, the constraint reasoning localization module uses the path segment and path state combination relationship template established in the healthy running slice and the complete running slice to perform combination constraints. The explanatory power weight of the path segment corresponding to the missing local state is reduced, the reasoning result of the running slice is marked as incomplete evidence, and the anomaly judgment rule version number and the degradation impact calculation rule version number are registered in the degradation record table.

[0013] Furthermore, S5 includes: After each running slice ends, the degradation trend identification module aggregates the degradation impact sequence of each device port and each path segment within the observation window from the degradation record table, based on the observation window length and the running slice number. The degradation level of each device port and each path segment is determined based on the health threshold, the moderate threshold, the severe threshold, and the classification rules. Generate warning information that includes device identifier, port identifier, path segment identifier, operating slice range covered by the observation window, degradation level, degradation threshold version number, and observation window configuration version number, and write the warning information to the warning record table.

[0014] Furthermore, S6 includes: The display and linkage module reads the early warning information from the early warning record table in chronological order within the monitoring platform; In the topology view, the degradation level of a path segment is marked based on the device identifier and the path segment identifier. In the business path view, the associated business paths are displayed based on the business path identifier. The external interface returns structured data containing device identifier, path identifier, operating slice range, degradation level, warning number and configuration version number based on the request identifier, and registers the request identifier and return result in the interface access log.

[0015] Compared with the prior art, the present invention has the following beneficial effects: 1. By establishing a unified time synchronization and sliced ​​monitoring cycle through the slice control module, and in conjunction with the topology and business path modeling module, stable business paths and path segment sequences are generated between key terminals and key service nodes. The status acquisition and fingerprint construction module forms path status fingerprints and local status fingerprints at the slice granularity. Then, the constraint reasoning and localization module automatically converges end-to-end anomalies to a small number of suspected degradation path segments based on combined constraints. This achieves the technical effect of accurately identifying degradation sources, distinguishing link degradation from single-point device anomalies, and exposing hidden performance risks in advance in multi-vendor hybrid LANs at the business path dimension. This solves the technical problem in existing technologies that rely solely on single-device alarms or simple threshold statistics, making it difficult to accurately locate the problem from a unified time base and business path perspective.

[0016] 2. By using the degradation trend identification module to perform time series analysis on degradation records in continuously running slices and forming traceable degradation levels and early warning information according to preset rules, combined with the display and linkage module, the structured early warning records in the topology view and business path view provide idempotent and reusable linkage interfaces to external operation and maintenance systems. At the same time, version locking and evidence chain traceability management are implemented on the entire link of time synchronization configuration, fingerprint template, judgment rules and threshold configuration. This achieves the technical effect of upgrading scattered instantaneous anomalies into an auditable and closed-loop handling hierarchical early warning system, reducing reliance on manual troubleshooting and improving the stability of critical business operations and the reliability of operation and maintenance decisions. Attached Figure Description

[0017] Figure 1 This is a schematic diagram of the structure of a comprehensive online monitoring system for the operating status of local area network devices according to the present invention. Detailed Implementation

[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0019] Example: Figure 1 A flowchart of a comprehensive online monitoring system for the operating status of local area network (LAN) devices according to the present invention is provided. The comprehensive online monitoring system for the operating status of LAN devices includes: S1. The slice control module is used to divide the monitoring period based on unified time synchronization information, generate slices with slice identifiers, and align the time of each monitoring data point. Specifically, it is implemented as follows: The slice control module in this system acts as a time management and rhythm control unit. It relies on the monitoring platform to establish and maintain a unified time reference. The monitoring platform refers to an integrated computing and storage device deployed in the local area network management center, used to centrally execute monitoring strategies and store monitoring results. The time source refers to a device or service that can provide a reliable time reference, which can be a time server that accesses external time signals or a standard clock service provided to the superior management network. The unified time information refers to the time configuration adopted by the monitoring platform in a certain stage, which includes at least the current reference time, time representation format, time accuracy requirements, and allowable deviation range. The time configuration version refers to the version identifier corresponding to a certain set of unified time information, used to distinguish the combination of time parameters used in different stages.

[0020] To ensure that monitoring records generated by various devices within a multi-vendor LAN can be correlated under a unified timeline, the slice control module distributes unified timing information and slice parameters to each acquisition agent and key device through a dedicated management network. This dedicated management network refers to a communication channel logically isolated from the service-bearing network, which can be implemented through an independent virtual LAN or a separate physical management network. Acquisition agents are software or hardware units deployed within the LAN, responsible for acquiring status information from devices and uploading it to the monitoring platform. These can be agent programs installed on servers or acquisition functions integrated into dedicated monitoring devices. Key devices refer to network devices designated for mandatory timing control and monitoring recording in LAN monitoring, including core switching devices, aggregation switching devices, access switching devices, and boundary devices directly connected to critical business servers.

[0021] During the initialization phase, the slice control module obtains the reference time from the time synchronization source, generates the current time synchronization configuration version, and encapsulates the reference time, slice length parameters, slice start and end times, and allowable time synchronization deviation range into unified time synchronization information. This information is then sent to each acquisition agent and key device via a dedicated management network. Upon receiving the unified time synchronization information, each acquisition agent registers the difference between its local time and the reference time. This difference is recorded as the local time offset and is included with subsequent monitoring records. The local time offset refers to the difference between the internal clock of the terminal or acquisition agent and the reference time in the unified time synchronization information, and is used to restore the unified time stamp at the time of record formation on the monitoring platform side.

[0022] The running slice control module uses a running slice to refer to a time segment formed by dividing the monitoring time axis into equal lengths under the constraint of unified timing information. Each running slice corresponds to a unique slice number. The slice length parameter refers to the time span of the running slice, which is used to control the monitoring rhythm and the granularity of status aggregation. The slice start and end times refer to the reference time points corresponding to the start and end of a certain running slice. The allowable timing deviation range refers to the upper limit of the acceptable time deviation for each acquisition agent within a running slice.

[0023] To adapt to the differences in service characteristics within campus networks, factory networks, and multi-vendor LANs in data centers, maintenance personnel can adjust the slice length parameters and allowable time synchronization deviation range according to the site scale and the service's sensitivity to latency. This makes the module suitable for scenarios that require minute-level or second-level tracking of equipment operating status and maintaining time consistency among multiple monitoring modules.

[0024] During continuous operation, the slice control module divides the entire monitoring period into continuous slices based on unified time information and broadcasts the current slice number and the corresponding slice start and end times to each acquisition agent. The monitoring records formed by each acquisition agent in each slice carry the slice number and local time offset. The monitoring records refer to the status records formed by the acquisition agent around the target device within a certain period of time, which include at least the device identifier, the monitoring object identifier, status fields and values, and the corresponding time information.

[0025] When a certain operational slice ends, the operational slice control module aggregates monitoring records from different acquisition agents and key devices on the monitoring platform side according to the slice number. Based on the local time offset and the allowable time synchronization deviation range, it determines whether each monitoring record meets the current time synchronization configuration requirements. For time alignment, it preferably uses the reference time in the unified time synchronization information as the benchmark, adds the local time carried by the monitoring record to the corresponding local time offset to obtain the unified time mark of the record, and determines the operational slice to which the record should belong based on this. Records with deviations not exceeding the allowable range are mapped to the corresponding time positions on the unified time axis. Records exceeding the allowable time synchronization deviation range are marked as incomplete records. Incomplete records refer to monitoring records that do not meet the unified time synchronization requirements in terms of time accuracy or time deviation but still have certain reference value. For monitoring records that arrive at the monitoring platform after the corresponding operational slice ends, it is preferable to retain their original slice number and additionally mark them as late records. Late records will no longer participate in the time merging and status statistics within the slice, but will only be stored as diagnostic information to avoid affecting the overall judgment of the slice.

[0026] To facilitate subsequent modules' access to monitoring content from a slice perspective, the slice control module registers the slice number, corresponding timing configuration version number, and merging status of each running slice in the slice record table. Preferably, the slice record table records at least the running slice number, corresponding timing configuration version number, merging status, and the start and end reference times of the running slice, and can be stored in the persistent storage device of the monitoring platform. The status acquisition and fingerprint construction module, constraint reasoning and positioning module, and degradation trend identification module all obtain the available running slice range, the timing configuration version used, and the merging status from the slice record table when performing their respective functions, and access the monitoring records in slice number order to ensure consistency in the time dimension.

[0027] To avoid confusion caused by configuration adjustments at different stages, the slice control module adopts a version locking strategy for tuning key parameters such as slice length, timing accuracy, and deviation limit. The version locking strategy means that a unique configuration version number is assigned to each effective configuration within the monitoring platform, and the original configuration version and its association with the monitoring records are retained after configuration changes. Each time the configuration is adjusted, the monitoring platform generates a configuration change record. The configuration change record includes at least the original configuration version, the adjusted configuration version, the adjustment time, and a summary of the adjustment reason. An index relationship is established between the configuration change record and the slice record table, monitoring records, fingerprint records, and early warning records to form a chain of evidence. The chain of evidence refers to a record system that can show the correspondence between a certain monitoring result and the effective configuration at that time, which makes it easy for those skilled in the art to trace the time standard and configuration boundaries used for each running slice during subsequent operation and maintenance analysis or compliance audit.

[0028] In practical applications, the unified time synchronization and alignment achieved through the slice control module allow monitoring records from different manufacturers and models of equipment to be aggregated and compared within the same slice according to a unified time base. The status acquisition and fingerprint construction module can select consecutive running slices to construct path status fingerprints based on the slice record table. The constraint reasoning and localization module can locate degradation sources using slice numbers as clues. The degradation trend identification module can analyze the changing trend of degradation impact around consecutive slice numbers. In a preferred embodiment, maintenance personnel can set the running slice length to approximately one minute, limiting the allowable time synchronization deviation range. With the time synchronization information refresh cycle set to once a day and the local time correction cycle of the data acquisition agent set to once every five minutes, multiple core devices and critical paths within the campus network are continuously monitored under this configuration. By viewing the slice number, time synchronization configuration version number, merging status, and corresponding start and end times recorded in the slice record table, individual running slices marked as incomplete or late records can be identified. The impact of these slices can be limited when analyzing path status fingerprints and degradation records, thereby ensuring that the time caliber of this system is stable, traceable, and easy to reproduce in the actual production environment.

[0029] S2, the topology and service path modeling module, is used to obtain the connectivity relationships of devices within the local area network, construct the network topology, and determine the service path identifiers and path segment sequences from key terminals to key service nodes. Specifically, it is implemented as follows: The topology and service path modeling module, serving as the structure identification and path modeling unit within the monitoring platform, relies on the unified time base provided by the operation slice control module to centrally organize the connection relationships between devices within the local area network (LAN), and provides a stable path view for the state acquisition and fingerprint construction module and the constraint reasoning and localization module. Adjacency information refers to the neighbor device identifiers, neighbor port identifiers, and local port identifiers maintained locally by the LAN devices, which can be obtained through the device's neighbor discovery mechanism. Port connection information refers to the port pair relationships summarized on the monitoring platform side based on adjacency information, used to characterize the physical connection between the two ports. Forwarding relationships refer to the prefix information and next-hop information maintained by the LAN devices during Layer 3 or multi-layer forwarding, used to infer the logical forwarding path. Device identifiers are unique identifiers that can identify the device's connection to the network. A device identifier is a code that identifies a local area network (LAN) device. This code can be the device management address or the device number registered in the monitoring platform. A port identifier is a unique code that identifies a device port. This code can be a combination of a port number and a slot number. A network topology is the overall connection structure built with device identifiers as nodes and port connection information as edges. A Layer 2 connection relationship is a link relationship obtained based on port connection information and adjacency information. A Layer 3 forwarding relationship is a logical connectivity relationship derived from device forwarding relationships. A connectivity graph is a graphical structure obtained by modeling Layer 2 connection relationships and Layer 3 forwarding relationships in a unified way. A physical link is a link unit in the connectivity graph that is jointly determined by a pair of port identifiers. A path segment identifier is a unique number assigned to each physical link by the monitoring platform and used for reference in the path segment sequence.

[0030] The topology and service path modeling module collects adjacency information, port connection information, and forwarding relationships from various LAN devices in the monitoring platform according to a preset rhythm. The collected records are organized according to device identifiers and port identifiers, and duplicate adjacency pairs and self-loop connections are removed. When there are inconsistencies in adjacency information from different devices, a set of adjacency information can be selected as the currently effective record by configuring priority or time recentity rules. On this basis, the module constructs the network topology with device identifiers as nodes and port connection information as edges, unifies the Layer 2 connection relationships and the Layer 3 forwarding relationships derived from forwarding relationships into the connectivity graph, maps each physical link to a unique path segment identifier, and records the local device identifier, local port identifier, peer device identifier, and peer port identifier associated with the path segment identifier.

[0031] Critical terminals refer to terminal nodes marked as critical by operations and maintenance personnel in a local area network, including critical production terminals, office terminals, or monitoring terminals. Critical service nodes refer to server or gateway nodes that carry critical business, including application servers, database servers, or egress gateways. Address information refers to the address identifiers used to identify critical terminals and critical service nodes in the network, which can be Layer 2 addresses, Layer 3 addresses, or a combination of both. Business type refers to the business category to which the communication between critical terminals and critical service nodes belongs, such as production control, office access, or operations and maintenance management. Region refers to the physical or logical region to which critical terminals and critical service nodes belong, used to limit the candidate range during path search.

[0032] After maintenance personnel register the address information, service type, and region of key terminals and key service nodes on the monitoring platform interface, the topology and service path modeling module, referring to the current connectivity graph, searches for available paths between key terminals and key service nodes in the graph, provided that the constraints of service type and region are met. An available path refers to a simple path, under the current connectivity graph and routing configuration, that has an end-to-end connectivity from the node corresponding to the key terminal to the node corresponding to the key service node, and does not repeatedly pass through the same device node, and where every path segment is available. Preferably, the module considers each pair of key terminals and key service nodes as an example. The service node selects a priority path from the available path set as the business path based on the number of hops, path level, or preset strategy. It can also record several backup paths for switching use when the topology changes, provided that resources allow. When an available path cannot be found for a pair of key terminals and key service nodes under the current connectivity graph, the module marks the corresponding business path as temporarily unreachable in the path record table. Temporarily unreachable means that there is no available path between the key terminal and the key service node that meets the above conditions under the current topology configuration version. This allows the module to identify such situations when analyzing the path status fingerprint and avoid mistaking the unreachable state for performance degradation.

[0033] A business path refers to an ordered path in the connectivity graph consisting of key terminal nodes, key service nodes, and several path segments. A business path identifier is a unique code assigned to each business path by the monitoring platform, used to mark the path status fingerprint record together with the running slice number. A path segment sequence refers to the set of path segment identifiers that the business path passes through in the connectivity graph, arranged in the direction from the key terminal to the key service node. It is used to guide the status acquisition and fingerprint construction module to select the local status fingerprint of the corresponding path segment when constructing the path status fingerprint, and to guide the constraint reasoning and localization module to execute combined constraints when disassembling the path status fingerprint.

[0034] The topology and service path modeling module periodically refreshes topology information during operation. The topology refresh cycle refers to the time interval at which the module re-collects adjacency information, port connection information, and forwarding relationships and updates the connectivity graph. During each topology refresh, the module compares the old and new connectivity graphs to identify device online / offline status, link additions, and link removals. When changes affecting the connectivity of critical terminals or critical service nodes are detected, service path reconstruction is triggered. Service path reconstruction refers to re-executing the search for available paths and selection of preferred paths between critical terminals and critical service nodes on the new connectivity graph. The topology configuration version refers to the version identifier generated after each topology refresh and service path reconstruction, used to indicate the currently effective connectivity graph and service path set.

[0035] After each business path reconstruction, the topology and business path modeling module registers the current topology configuration version, the business path identifier for each business path, the corresponding path segment sequence, the effective time of the business path, and whether it is temporarily unreachable in the path record table. The path record table is a collection of records used to store business path definitions in the monitoring platform, and can be indexed by business path identifier and topology configuration version. When generating path status fingerprints, the status acquisition and fingerprint construction module queries the path record table by business path identifier for the corresponding path segment sequence and the temporarily unreachable mark, and aggregates the local status fingerprints of each path segment in the running slice according to the path segment sequence to form the path status fingerprint. For temporarily unreachable business paths, no path status fingerprint is generated or they are marked as unreachable. When disassembling path status fingerprints, the constraint reasoning and positioning module obtains the path segment sequence by business path identifier and topology configuration version from the path record table, establishes a combination relationship between the path status fingerprint and the local status fingerprints on the path segment, and skips the degradation source reasoning of the business path when the path record table marks the business path as temporarily unreachable.

[0036] To ensure the traceability of topology changes, the topology and business path modeling module records the refresh range, the set of affected device identifiers, and the number of business paths that have undergone path reconstruction each time the topology is refreshed. This information is associated with the corresponding topology configuration version and stored to form a chain of evidence related to path changes. This chain is used to distinguish between path status changes caused by topology changes and path status changes caused by device degradation during the process of locating degradation sources.

[0037] In typical campus network conditions, the topology refresh cycle can be set to several minutes to tens of minutes, such as five or fifteen minutes. The number of service paths can cover dozens or hundreds of critical service paths. In a topology refresh, when it is detected that the aggregation layer has added an uplink and switched the forwarding path of some access devices to the new link, the module generates a new topology configuration version, recalculates the service paths from the affected critical terminals to the critical service nodes, updates the path segment sequence and temporarily unreachable marker in the path record table, and records the number of devices involved in this topology refresh and the number of service paths with path changes. If the path status fingerprint of the above service paths changes after the topology change, the constraint reasoning and localization module can combine the topology configuration version and path change records to determine whether the change is related to the structural adjustment, thereby improving the accuracy of degradation source localization results.

[0038] In this implementation, the topology and service path modeling module provides a clear, traceable, and reproducible path foundation for subsequent state modeling and degradation analysis based on running slices through the above-mentioned structure identification and path modeling process. This enables those skilled in the art to adjust the refresh cycle, priority path selection strategy, number of backup paths, and temporary unreachability handling method according to the actual equipment type, scale, and service requirements of the local area network, thereby maintaining the stability and adaptability of the service path view under different operating conditions.

[0039] S3, Status Acquisition and Fingerprint Construction Module, is used to collect device port statistics, device resource status, and active probing results within the running slice. Based on the fingerprint template, it generates path status fingerprints for each service path and local status fingerprints for each path segment. Specifically, it is implemented as follows: The status acquisition and fingerprint construction module works collaboratively between the monitoring platform and the acquisition agent. Based on the slice number provided by the operation slice control module and the business path identifier and path segment identifier provided by the topology and business path modeling module, it acquires device port statistics, device resource status, and active detection results within each operation slice. This status information is then constructed into path status fingerprints and local status fingerprints according to unified rules to support subsequent constraint reasoning for localization and degradation trend identification. Device port statistics refer to the cumulative packet count and quality information for each device port within an operation slice, including at least the number of received packets and the number of sent packets. The quantity, number of dropped packets, number of erroneous packets, and the proportion of broadcast and multicast packets in all packets are used to characterize the service load level and packet quality of the port within the current operating slice; Device resource status refers to indicators reflecting the processing capacity and storage capacity utilization of the device within an operating slice, including at least processor utilization and storage resource utilization, used to reflect the overall resource pressure of the device within the operating slice; Active probing results refer to the round-trip latency and latency statistically analyzed within an operating slice after the monitoring platform or collection agent sends lightweight probing packets to key terminals and key service nodes according to a pre-set probing rhythm. Fluctuation amplitude and probe loss ratio are used to reflect the end-to-end latency quality and reliability of the corresponding business path; fingerprint template refers to the set of fields and quantization rules pre-defined in the monitoring platform, used to uniformly convert state records from different devices, different acquisition rhythms, and different sources into fixed-length state vectors. The fingerprint template at least specifies the unit conversion method, value range, range clipping rules, and discrete level classification rules for each state indicator, so that the state fingerprints formed by different devices and different operating slices are comparable under the premise of using the same fingerprint template version; path state fingerprint refers to the fingerprint of a certain business path within an operating slice. The state vector formed by combining the local states of each path segment on the path is used to describe the end-to-end operating state of the service path within the operating slice. Preferably, the path state fingerprint may include discrete fields such as end-to-end latency level, latency fluctuation level, loss level, and overall load level. The local state fingerprint refers to the state vector formed for a certain path segment within an operating slice based on the port statistics at both ends of the path segment and the resource status of associated devices. It is used to describe the local operating state of the path segment within the operating slice. Preferably, the local state fingerprint may include fields such as port load level, error message level, and local resource pressure level.

[0040] In a real-world local area network deployment, the status acquisition and fingerprint construction module, based on the slice number provided by the running slice control module, issues a status acquisition plan to each acquisition agent for each running slice. The acquisition agent reads port counts and resource status from the managed devices according to a set rhythm, and initiates active probing at certain intervals within the running slice. The acquired raw status records carry at least the device identifier, port identifier, running slice number, and local time information.

[0041] To accommodate the differences in counting cycles and statistical calibers among different devices, the status acquisition and fingerprint construction module uniformly converts port counts into statistical values ​​on a standard time scale on the monitoring platform side. Preferably, various port counts can be converted into messages per second and bits per second in second-level time units. The error message ratio and broadcast / multicast ratio are uniformly converted into percentages. The processor utilization rate and storage resource utilization rate are uniformly expressed as percentages. The round-trip latency and latency fluctuation amplitude are uniformly expressed as milliseconds. The detection loss ratio is uniformly expressed as a ratio with a fixed base as the denominator, such as a fraction of ten thousand. Based on the range clipping rules in the fingerprint template, values ​​that obviously exceed the reasonable engineering range are clipped to preset upper and lower limits.

[0042] To ensure the robustness of fingerprint construction, if a short-term acquisition failure or a few missing fields occur in a certain running slice, the module can preferably refer to the stable value of the same port in the previous running slice or the median value of the same type of port under the same device in the current running slice to fill in the missing fields. After the completion is completed, a completion mark is attached to the corresponding status field. The completion mark indicates that the field was not directly acquired from this slice, thereby reducing the weight of the completed field in subsequent analysis.

[0043] After completing unit unification, range trimming, and missing data completion, the status acquisition and fingerprint construction module associates the status of each device port within each operating slice with the corresponding path segment identifier according to the path record table provided by the topology and business path modeling module. It combines the statistics of the two ends of the port belonging to the same path segment with the status of the associated device resources, and constructs a local status fingerprint according to the field order and quantification rules specified in the fingerprint template. The fingerprint is then registered in the fingerprint record table with the operating slice number and path segment identifier as indexes. The fingerprint record table refers to the set of records in the monitoring platform used to store local status fingerprints and path status fingerprints, and at least records the operating slice number, business path identifier or path segment identifier, fingerprint vector field, and fingerprint template version number.

[0044] Subsequently, for each business path, the module sequentially reads the local state fingerprints of each path segment involved in the business path according to the path segment sequence within the same running slice. Based on the aggregation rules specified in the fingerprint template, the local state fingerprints are combined in dimensions such as latency, loss, and load to form the path state fingerprint of the business path within the running slice. This fingerprint is also written into the fingerprint record table, indexed by the running slice number and the business path identifier. The fingerprint template version number used to construct the fingerprint is marked in the record. The fingerprint template version number refers to the identifier assigned when managing the fingerprint template version, which is used to ensure that the constraint reasoning localization module and the degradation trend recognition module can use the same template caliber when comparing fingerprints in different running slices.

[0045] When the field set or quantification rules of a fingerprint template change due to business needs, the monitoring platform generates a new fingerprint template version number before the new template takes effect, and registers the change description between the old and new versions in the configuration management record, so that each fingerprint record in the fingerprint record table can be traced back to the specific fields and quantification rules used at that time through the fingerprint template version number.

[0046] In field operations, to mitigate the impact on business traffic, the status acquisition and fingerprint construction module can adjust the acquisition rhythm and active detection frequency according to device performance and business sensitivity. For example, it is preferable to use a higher acquisition frequency and less detection load on key aggregation devices, a moderate acquisition frequency and lower detection frequency on access layer devices, arrange a denser active detection rhythm on key business paths, and a sparser detection rhythm on general business paths. The detection configuration version number for different path categories is recorded in the fingerprint template for traceability.

[0047] Under typical healthy operating conditions, the round-trip latency of a critical business path within a single operating slice can be in the range of several milliseconds to over ten milliseconds. The latency fluctuation is preferably within several milliseconds, and the detection loss ratio is preferably lower than a preset low failure rate threshold. The latency level and loss level in the corresponding path status fingerprint are classified into healthy levels. When the device port statistics show that the port load of a certain path segment is consistently high or the error packet ratio is consistently higher than the healthy threshold, the port load level and error packet level in the corresponding local status fingerprint will be classified into higher levels. This will then be reflected in the path status fingerprint as an increase in the overall load level or loss level, providing a basis for the subsequent constraint reasoning and localization module to identify degraded path segments.

[0048] Through the above-described processes of data collection, normalization, completion, and fingerprint construction, the status collection and fingerprint construction module, while ensuring controllable impact on existing network services, forms a structured status description around the operating slice and service path. This enables those skilled in the art to adjust the collection rhythm, detection frequency, range clipping rules, and completion strategy according to the actual scale of the local area network and equipment capabilities. With the support of fingerprint template version management and fingerprint record table, stable generation and traceable use of status fingerprints are achieved, thus providing a public, sufficient, and reproducible foundation for the subsequent degradation identification and localization of this system.

[0049] S4, the constraint reasoning and localization module, is used to determine the set of path segments that can explain path state anomalies within the running slice based on the combined constraints between the path state fingerprint and the local state fingerprint, and to calculate the path segment degradation impact degree. Specifically, it is implemented as follows: The constraint reasoning localization module operates in the monitoring platform based on the fingerprint record table and the path record table. Under the constraint of the slice number given by the slice control module, it performs combined reasoning on the path state fingerprint and local state fingerprint in each slice to determine the suspected degraded path segments and calculate the degradation impact, thereby providing degradation clues at the path segment level to the subsequent degradation trend identification module.

[0050] A path state fingerprint refers to the end-to-end state vector of a specific service path within an operational slice. A local state fingerprint refers to the local state vector of a specific path segment within an operational slice. Path state anomalies refer to a significant shift in the path state fingerprint of a specific service path within an operational slice compared to the healthy fingerprint set formed by that path in historical healthy operational slices. A healthy fingerprint set refers to the set of path state fingerprints marked as healthy during system initialization or long-term operation. A healthy level refers to a combination of levels corresponding to indicators such as latency, loss, and load within the expected normal range under the level classification specified by the fingerprint template. A path segment set refers to the set of identifiers of several path segments in the network topology. Degradation impact refers to the quantitative value obtained by combining the coverage and offset of the local state fingerprint of a specific path segment on multiple abnormal service paths within an operational slice, used to reflect the degree of contribution of that path segment to the overall performance degradation within the current operational slice.

[0051] After each running slice ends, the constraint reasoning and localization module reads the path status fingerprints of all business paths within that slice from the fingerprint record table, using the slice number as an index. Combining the business path identifiers and path segment sequences under the current topology configuration version in the path record table, it first compares the end-to-end latency level, latency fluctuation level, loss level, and overall load level in the path status fingerprints with the health fingerprint set of that business path according to the preset anomaly judgment rules. When the level of a certain indicator deviates from the health level by more than the preset anomaly level, and the duration of the deviation meets the minimum continuous slice requirement, the business path is marked as an abnormal path within that running slice, and the indicators involved in this anomaly, as well as their offset direction and offset magnitude, are recorded.

[0052] The anomaly detection rules are defined through configuration, including the minimum number of levels that each indicator needs to traverse from the healthy level to the abnormal level, the acceptable number of short-term fluctuations, and the upper limit of the cumulative number of anomalies within an observation window. When the module performs anomaly detection, it references the corresponding rule version number to form a subsequent chain of evidence.

[0053] For each business path marked as an abnormal path, the constraint reasoning localization module, based on the path segment sequence registered in the path record table, treats the path state as the result of superimposing local states along the path segment sequence. It reads the local state fingerprints of each path segment within the running slice from the fingerprint record table according to the running slice number and path segment identifier. It compares the indicators marked as offsets in the path state anomalies with the offsets of the same or related indicators in the local state fingerprints. When the offset direction of a path segment on this indicator is consistent with the path state anomaly and the offset magnitude exceeds the local offset threshold, it is considered that the path segment has explanatory power for this abnormal indicator. Explanatory power refers to the reasonable contribution of the local state offset to the end-to-end anomaly, which can be represented internally by Boolean labels, weighted coefficients, or combined scores.

[0054] The constraint reasoning localization module summarizes the explanatory relationships of all abnormal paths within the same running slice. For each path segment, it calculates the number of times it covers abnormal paths, the explanatory power score of each indicator, and the position of the path segment in the topology layer. The topology layer position can be divided into access layer, aggregation layer, or core layer according to the device type and connection relationship recorded by the topology and business path modeling module. Preferably, path segments in the aggregation layer and core layer can be assigned higher basic weights to reflect their potential impact on multiple business paths.

[0055] Based on this, the module estimates the degradation impact for each path segment that appears in at least one abnormal path in the current slice according to the preset degradation impact calculation rules. The degradation impact calculation rules can weight and superimpose the number of coverage times, local offset magnitude, topology level weight, and the number of types of abnormal indicators involved, and then normalize them to form a quantitative value that can directly correspond to the degradation level classification rules.

[0056] After calculating the degradation impact, the constraint reasoning localization module writes path segments with degradation impact exceeding a preset level threshold into the degradation record table. Path segments with degradation impact in the middle range are optionally marked as observed path segments, and path segments with degradation impact below the health threshold are marked as healthy path segments. The degradation record table records at least the running slice number, path segment identifier, degradation impact value, degradation level, number of abnormal paths involved, type of abnormal indicator involved, fingerprint template version number used, anomaly judgment rule version number used, and degradation impact calculation rule version number used. This information is used for cross-slice analysis by path segment dimension in the subsequent degradation trend identification module and serves as part of the evidence chain, providing complete context when maintenance personnel need to trace a degradation conclusion.

[0057] In cases where local state fingerprints are missing or a certain running slice is marked as an incomplete slice by the running slice control module, the constraint reasoning localization module prioritizes using the combined relationship template between path segments and path states that has been verified in healthy and complete running slices when executing combined constraints. Path segments with missing local states are not directly involved in the interpretation capability determination, or are given a lower weight, and the reasoning result of the running slice is marked as incomplete evidence, so as to avoid the decisive impact of a single abnormal collection or a short-term incomplete slice on the degradation impact result.

[0058] Based on typical operating conditions of campus networks, factory networks, or data center LANs, preferably, if within a single operating slice, multiple critical business paths are found to have end-to-end latency levels that are several levels higher than the healthy level, loss levels that are slightly higher, and overall load levels that are at a medium-to-high level, and the constraint reasoning localization module repeatedly searches the path segment sequences corresponding to these abnormal business paths and finds that a certain uplink path segment on the same aggregation switch is covered in multiple abnormal paths, and the port load level and error packet level in its local state fingerprint are consistently higher than the healthy level, and the explanatory power score for this path segment is significantly higher than other path segments, then under the action of the degradation impact calculation rules, the degradation impact of this path segment is rated as the highest level, and it is recorded as a candidate for severely degraded path segment in the corresponding degradation record table. The record also notes the operating slice number that triggered this judgment, the number of abnormal paths covered, and the types of indicators involved, providing a basis for the subsequent degradation trend identification module to further confirm the continuous degradation of this path segment in multiple slice dimensions.

[0059] Through the above-described process of identifying abnormal paths, interpreting local states, and calculating degradation impact based on operational slices, the constraint reasoning localization module, without relying on complex models, converges the abnormal information scattered in path state fingerprints and local state fingerprints into operable path segment degradation clues. This enables those skilled in the art to adjust the anomaly judgment threshold, interpretation capability weighting rules, and degradation impact level classification according to the local area network scale, business sensitivity, and fault tolerance strategy. With the support of degradation record tables and rule version management, the degradation localization process can be stably reproduced and audited.

[0060] S5, Degradation Trend Identification Module, is used to determine the degradation level of device ports and path segments based on the changes in degradation impact within continuously running slices, and generate early warning information. Specifically, it is implemented as follows: The degradation trend identification module operates on the degradation record table in the monitoring platform. Under the constraint of the slice number provided by the slice control module, it summarizes the degradation results of the path segments formed by the constraint reasoning and positioning module in the time dimension. This is used to identify the degradation development trend of device ports and path segments and form degradation levels and early warning information, thereby providing an actionable alarm basis for the display and linkage module and on-site operation and maintenance decisions.

[0061] The degradation record table refers to the set of degradation path segment records registered in the previous module according to the running slice number. It includes at least the running slice number, path segment identifier, degradation impact value, degradation level, number of involved abnormal paths, types of involved abnormal indicators, and the version numbers of the fingerprint template, anomaly judgment rules, and degradation impact calculation rules used. It can also be associated with the device identifier and port identifier of the device port where the path segment is located. The degradation level refers to the graded label given to a device port or path segment based on its degradation performance within a certain time range, used to reflect the severity of performance degradation of the object within that time range. Preferably... The degradation level can be divided into several levels: healthy, mild degradation, moderate degradation, and severe degradation. The warning information refers to the structured prompts formed around the degradation level, which includes at least the device identifier, port identifier or path segment identifier, current degradation level, a list of business paths associated in the most recent observation window, the range of operating slices covered by the observation window, and suggestions for subsequent operation and maintenance actions. The observation window length refers to the number of consecutive operating slices used by the degradation trend identification module to statistically analyze the degradation impact in the time dimension. It can be adjusted through the operating slice control module or the monitoring platform configuration interface to achieve a balance between response speed and stability.

[0062] In the field, the degradation trend identification module first determines an observation window that extends from the configured observation window length to several previous observation windows after each new observation window ends, based on the latest slice number provided by the operation slice control module and the configured observation window length. Then, it aggregates all path segment records involved in the degradation record table within the observation window according to the path segment identifier and device identifier, forming a degradation impact sequence and degradation level sequence for each device port and each path segment within the observation window. At the same time, it counts the number of abnormal business paths associated with the path segment in each operation slice within the observation window.

[0063] The health threshold refers to the boundary value of degradation impact used to distinguish between a healthy state and a deteriorating state. The moderate threshold and the severe threshold refer to the boundary values ​​of degradation impact used to distinguish between mild, moderate and severe degradation, respectively. All three are in the same numerical domain as the degradation impact. They can be tuned through configuration files or rule tables to form a degradation threshold version number. The degradation trend identification module references the corresponding degradation threshold version number when performing trend identification to ensure that the judgment criteria at different stages are traceable.

[0064] For each device port and path segment, the module determines the duration of degradation impact above the health threshold, the number of slices above the medium and severe thresholds, the trend of degradation impact with slice number, and the number of affected service paths within the observation window. The duration can be characterized by counting the number of slices with degradation impact not lower than the corresponding threshold in the continuously running slices within the observation window. The trend can be characterized by comparing the average degradation impact before and after the observation window or by using a simple monotonicity judgment without increasing complexity. The number of affected service paths can be obtained by summarizing the abnormal path count field associated with the path segment in the degradation record table.

[0065] Based on the above statistical results, the degradation trend identification module further classifies the status into healthy, mild degradation, moderate degradation, and severe degradation levels according to preset grading rules. These grading rules are given in the form of a rule table. For example, mild degradation can be defined as a situation where only a few slices within the observation window occasionally have a degradation impact slightly higher than the healthy threshold without a significant upward trend; moderate degradation can be defined as a situation where the degradation impact repeatedly exceeds the moderate threshold within the observation window but is not sustained and the number of affected business paths is small; severe degradation can be defined as a situation where the degradation impact exceeds the moderate threshold or even approaches or exceeds the severe threshold in several consecutive slices within the observation window, shows an overall upward trend, and the number of associated critical business paths reaches a preset number; and a healthy state is defined as a situation where all degradation impacts within the observation window are below the healthy threshold and the duration exceeds the number of times a degradation can be removed. The number of times a degradation can be removed threshold refers to the minimum number of healthy slices required to determine whether the degradation state can be removed, and can preferably be configured as a situation where the degradation impact of several consecutive slices within the observation window is below the healthy threshold.

[0066] The degradation trend identification module generates a warning message for each device port or path segment that reaches mild, moderate, or severe degradation, while simultaneously generating a degradation level. Each warning message is assigned a warning number, which is a unique identifier for a warning record and can be generated by combining time and object. The warning message includes the operating slice range used for this judgment, the degradation threshold version number, the observation window configuration version number, and the suggested follow-up actions. For example, for mild degradation, it is recommended to increase the status acquisition frequency of the path segment or shorten the observation window length; for moderate degradation, it is recommended to arrange remote review or increase the active detection frequency; and for severe degradation, it is recommended to conduct on-site inspection or perform traffic migration.

[0067] The warning information is written into the warning record table, which is a set of tables in the monitoring platform used to store degradation warning records. It records at least the warning number, device identifier, port identifier or path segment identifier, current degradation level, operating slice range covered by the observation window, list of associated business paths, degradation threshold version number, observation window configuration version number, and warning status. The warning status can indicate whether the warning is in effect, under observation, or has been lifted.

[0068] In subsequent operation slices, when the degradation trend identification module finds that the degradation impact of a certain object falls back to below the health threshold in a short period of time within multiple observation windows and stably exceeds the number of times it can be lifted, the module will automatically update the warning status of the object, mark it as lifted, and register the lifting time and a summary of the lifting reason in the warning record table. The summary of the lifting reason can be simply recorded as the degradation impact continuing to recover to the health level or the business path returning to normal, etc., for review during subsequent audits.

[0069] Based on the aforementioned typical operating conditions of the campus network, when the degradation trend identification module finds that the degradation impact of an uplink port of a certain aggregation switch is consistently higher than the moderate threshold and gradually increases in multiple observation windows within several dozen consecutive operating slices, and at the same time, the degradation record table shows that the number of critical business paths associated with the path segment corresponding to this port reaches several or more, the module assesses the port as severely degraded according to the classification rules, generates a warning message containing the device identifier and port identifier, a list of associated business path identifiers, the operating slice range covered by the observation window, and the severe degradation level, and marks the warning status as effective in the warning record table.

[0070] During subsequent operation, when maintenance personnel complete on-site rectification or traffic adjustment based on the early warning information, the degradation trend identification module will continuously observe in the new observation window that the degradation impact of the port has fallen back and remained below the health threshold, and the threshold condition for the number of times the warning is lifted is met. At this time, the warning will be automatically marked as lifted, providing clear degradation closed-loop information for the display and linkage module and the maintenance system.

[0071] Through the aforementioned time-series analysis and hierarchical early warning mechanism based on the degradation record table, the degradation trend identification module elevates degradation signs within a single slice to trend conclusions across slices. This enables those skilled in the art to adjust the observation window length, degradation threshold, hierarchical rules, and deactivation rules according to the local area network size, business importance, and fault tolerance strategy. Furthermore, with the cooperation of the degradation record table and the early warning record table, the degradation trend identification process can be stably reproduced and audited, providing a fully disclosed and implementable degradation early warning capability foundation for the overall monitoring system of this invention.

[0072] S6, the display and linkage module, is used to present warning information in the topology view and business path view. It outputs structured data containing device identifiers, path identifiers, and degradation levels through external interfaces for the operation and maintenance system to access. Specifically, it is implemented as follows: The display and linkage module serves as the interface presentation and external collaboration unit in the monitoring platform. It connects with the degradation trend identification module and the early warning record table to visually present early warning information in the topology view and business path view within the monitoring platform, and provides structured operational status information to the operation and maintenance system through external interfaces.

[0073] The topology view refers to the network schematic interface constructed on the monitoring platform side using device identifiers and path segment identifiers as nodes and connections. This interface overlays the current status of devices and the degradation level of path segments using colors, line types, or markers to reflect the overall structure of the local area network and the health status of critical links. The service path view refers to the interface that displays the status information and degradation level of each device node and path segment along the service path segment sequence, organized by service path identifiers, allowing maintenance personnel to quickly identify affected paths from a business perspective. The early warning record table refers to the set of records maintained in the monitoring platform by the degradation trend identification module when generating early warning information. It records at least the following fields: early warning number, device identifier, port identifier or path segment identifier, degradation level, operating slice range covered by the observation window, list of associated service paths, degradation threshold version number, observation window configuration version number, and early warning status.

[0074] The display and linkage module periodically reads the latest warning records in chronological order within the monitoring platform or when the warning record table is updated. It locates the specific device node and path segment corresponding to each warning in the topology view, and classifies and marks the nodes and links according to the degradation level field in the warning record. For example, severely degraded path segments can be rendered in a prominent color, and moderate and lightly degraded path segments can be distinguished by different colors or line types. At the same time, all affected key business paths are listed in the business path view according to the business path identifier, and the current degradation level of each path is attached to the path in the form of an icon or label. When the operation and maintenance personnel select a warning on the interface, the display and linkage module retrieves the path status fingerprint, local status fingerprint, and degradation impact record within the operating slice range associated with the warning from the fingerprint record table and degradation record table according to the warning number and associated fields. The key values ​​and configuration version number are displayed on the interface in the form of line, table, or detail panel, so that the operation and maintenance personnel can trace the formation process of the warning from the time dimension and verify the evidence chain.

[0075] External interfaces refer to the access channels that the monitoring platform opens to external operation and maintenance systems or other management systems. They are used to query early warning records and their associated upstream and downstream records according to a fixed set of fields and return them in the form of structured data. Structured data refers to records that are organized with fixed field names, uniform units and stable meanings for each early warning and query result. They must include at least the following fields: device identifier, path identifier, operating slice range, degradation level, early warning number, relevant configuration version number and timestamp.

[0076] External interfaces can be implemented via remote calls. Each call corresponds to a request identifier, which is a unique marker kept by the caller within a certain range. This identifier is used to identify a query request and support idempotency strategies. When initiating a request, the caller must include at least the query scope, device identifier or path identifier, time range, and a list of required fields in the request message. After receiving the request on the monitoring platform, the display and linkage module first checks for duplicates based on the request identifier. When the same request identifier is detected to appear repeatedly within a reasonable time window, the module directly returns the result record of the first query to ensure idempotency. During the first query, the module filters records that meet the conditions in the early warning record table based on the query scope and time range. It can also obtain necessary supplementary fields by combining the degradation record table and fingerprint record table. The query results are organized into a structured record according to the predefined field order and returned to the caller. At the same time, the call time, request identifier, caller identifier, query condition summary, and number of returned results are recorded in the interface access log to form an evidence chain for interface access.

[0077] To avoid order disorder caused by concurrent requests from the same caller on the same channel, the display and linkage module can require the caller to carry a sequence number in the request. The sequence number refers to the sequence number assigned in a monotonically increasing manner within the session period between a caller and the monitoring platform. When processing requests, the module uses the sequence number to determine whether there are out-of-order requests. For requests with a sequence number lower than the processed sequence number, the existing result can be returned directly according to the idempotent strategy. For cases where there is a significant jump in the sequence number, security auditing can be performed in conjunction with the caller identifier.

[0078] For potential call failure scenarios, the display and linkage module presets a small number of error codes and their corresponding meanings in the monitoring platform. The error codes are brief codes used to mark the reasons for the interface call failure, which may include types such as invalid query range, insufficient access permissions, non-existent warning records, and temporary insufficient system resources. When it is determined that the call conditions are not met or internal resources cannot complete the query within the specified time, the module returns the error code in a structured form and a brief explanation of the reason in natural language. The explanation of the reason can also provide suggested measures, such as prompting the caller to adjust the query time range or check the permission configuration.

[0079] External interfaces follow the access control policy of the monitoring platform. The access control policy refers to the set of rules that set the range of devices and paths that are allowed to be accessed by different callers. When generating query results, the display and linkage module only returns the device identifiers and path identifiers that are within the management scope of the caller. Device identifiers involving sensitive business can be presented in a de-identified form, such as retaining only some identifier fields or replacing the real identifier with a logical name. The de-identification rules are clearly stated in the interface protocol description to prevent the leakage of sensitive asset information when making cross-departmental or cross-system calls.

[0080] In a typical campus network scenario, when the aforementioned aggregation switch's uplink port is identified as severely degraded and an alert is generated by the degradation trend identification module, the display and linkage module marks the path segment corresponding to that port with a heavily degraded color in the topology view and marks all critical business paths passing through that path segment as affected paths in the service path view. Simultaneously, it provides the operation and maintenance system with a structured record containing the device identifier, path identifier, operating slice range, current degradation level, alert number, and relevant configuration version number through an external interface. Based on this, the operation and maintenance system generates a work order to arrange on-site replacement of optical modules or adjustment of links. Once the rectification is completed and the degradation impact of that path segment returns to a healthy level within a subsequent operating slice and meets the conditions for removal, the degradation trend identification module updates the alert status to "removed." The display and linkage module then returns the status and time of the alert record being removed in a subsequent remote call. The operation and maintenance system completes the closed loop by comparing the results of the two queries, further demonstrating the feasibility and auditability of the display and linkage capabilities provided by this module in actual field operations.

[0081] In the operational scenario shown in this embodiment: In a campus LAN built with equipment from multiple vendors, the monitoring platform is deployed in the network management center's computer room. The slice control module, topology and service path modeling module, status acquisition and fingerprint construction module, constraint reasoning and location module, degradation trend identification module, and display and linkage module are all implemented in software on this monitoring platform. Several acquisition agents are deployed on servers next to the core switching equipment, aggregation switching equipment, and some access switching equipment to obtain port statistics and device resource status from the nearest location. Before the system goes live, maintenance personnel complete the access of the time synchronization source, the configuration of the topology acquisition strategy, and the registration of key terminals and key service nodes. Key terminals include production control terminals, monitoring terminals, and office terminals; key service nodes include production control servers, business application servers, and egress gateways. The slice control module obtains a reliable reference time from the time synchronization source, generates the first time synchronization configuration version, and distributes unified time synchronization information and slice parameters to each acquisition agent and key device through the dedicated management network. The slice length is configured in minutes, and the allowable time synchronization deviation range is configured in milliseconds. Each acquisition agent registers its local time offset and includes the slice number and local time offset in the subsequent monitoring records. As the network progresses, the slice control module divides the monitoring period into continuous slices according to the unified time synchronization information. At the end of each slice, it aggregates the monitoring records from different acquisition agents, marking records exceeding the allowable time synchronization deviation range as incomplete records, and separately marking and registering late records in the slice record table. This allows subsequent modules to select available slices for analysis within a unified timeline.

[0082] Under the premise of stable time dimension, the topology and service path modeling module periodically collects adjacency information, port connection information, and forwarding relationships from core switching devices, aggregation switching devices, and access switching devices according to the configured topology refresh cycle. It then constructs a connectivity graph on the monitoring platform side and assigns path segment identifiers to each physical link. On the monitoring platform interface, maintenance personnel mark the communication between several production control terminals and the production control server and database server as critical service paths, entering their address information, service type, and region. The module then searches the connectivity graph for available paths that meet the regional constraints and connectivity conditions, selecting a priority effective path for each pair of critical terminals and critical service nodes as the service path, generating a service path identifier, and registering the corresponding path segment sequence. Simultaneously, it records several backup paths to recalculate service paths when devices go offline or the link changes. The path record table stores the service path identifiers, path segment sequences, and temporarily unreachable markers for all service paths under each topology configuration version. These are used by the status acquisition and fingerprint construction module when constructing path status fingerprints, and also by the constraint reasoning and positioning module when disassembling path status fingerprints to establish the combination relationship between path status and path segment local status. When a topology refresh detects the addition of a new uplink in the aggregation layer or the switching of some access devices to new links in their forwarding paths, the module generates a new topology configuration version, recalculates the path segment sequence for the affected critical service paths, and records the path changes, providing evidence for later distinguishing between structural adjustments and performance degradation.

[0083] During continuous operation, before the start of each operating slice, the status acquisition and fingerprint construction module issues an acquisition plan to each acquisition agent based on the slice number and the business path identifier and path segment identifier in the path record table given by the operating slice control module. Each acquisition agent collects port counts and device resource status from the managed devices according to the set rhythm and sends the results to the monitoring platform. At the same time, within the operating slice, the monitoring platform or acquisition agents send lightweight probe messages to key terminals and key service nodes according to the pre-set probe rhythm, and statistically obtain round-trip latency, latency fluctuation and probe loss ratio. On the monitoring platform side, the status acquisition and fingerprint construction module uniformly converts the port counts reported by different devices into packets per second and bits per second under a standard time scale, unifies the error packet ratio and broadcast / multicast ratio as percentages, unifies the processor utilization rate and storage resource utilization rate as percentages, unifies the round-trip latency and fluctuation range as milliseconds, unifies the detection loss ratio as a ratio with a fixed base as the denominator, and cuts values ​​that obviously exceed the reasonable engineering range to preset upper and lower limits according to the range clipping rules in the fingerprint template. If a short-term acquisition failure or a few fields are found in a certain operating slice, the module refers to the stable value of the same port in the previous operating slice or the median value of the same type of port in the current slice in the same device to fill in the missing fields, and adds a completion mark to the field. After unifying units, trimming ranges, and filling in missing values, the module combines the port statistics at both ends of the same path segment and the resource status of associated devices according to the path segment sequence recorded in the path record table to generate a local state fingerprint. This fingerprint is then registered in the fingerprint record table using the running slice number and path segment identifier as indexes. Subsequently, for each business path, the local state fingerprints of each path segment are aggregated along the path segment sequence within the same running slice. Path state fingerprints are formed according to the aggregation rules in the fingerprint template in dimensions such as latency, loss, and load. These fingerprints are then registered in the fingerprint record table using the running slice number and business path identifier as indexes, while also noting the fingerprint template version number used to ensure consistent caliber for subsequent cross-slice comparisons.

[0084] After the monitoring platform accumulates operational slices over a period of time, the constraint reasoning and localization module, at the end of each operational slice, uses the operational slice number as an index to read the path status fingerprints of all business paths within that slice from the fingerprint record table. It then combines this with the path segment sequence under the current topology configuration version in the path record table, and compares the end-to-end latency level, latency fluctuation level, loss level, and overall load level with the health fingerprint set of that business path according to the configured anomaly judgment rules. When the levels of certain indicators deviate from the healthy level beyond the preset anomaly level and occur consecutively within the minimum continuous slice count requirement, the business path is marked as an abnormal path within that operational slice, and the offset indicator, direction, and magnitude are recorded. Subsequently, for each abnormal path, the module reads the local state fingerprints of each path segment in the corresponding path segment sequence within that operational slice. It searches for indicators in the local state fingerprints that are the same as or related to the offset indicators in the abnormal path state. If the offset direction of a path segment on this indicator is consistent with the end-to-end offset direction and the offset magnitude exceeds the local offset threshold, then the path segment is considered to have explanatory power for this abnormal indicator. Within the same running slice, the module summarizes the explanatory relationships of all abnormal paths. For each path segment, it calculates its coverage frequency in abnormal paths, the explanatory power score of each indicator, and its topological level position. Based on the degradation impact calculation rules, it comprehensively calculates the degradation impact by considering the coverage frequency, local offset magnitude, topological level weight, and the number of indicator types involved. Path segments with degradation impact exceeding a preset threshold are registered in the degradation record table and marked as candidates for degradation path segments in this running slice. In some running slices, if the proportion of missing local state fingerprints is high or the slice is marked as an incomplete slice in the slice record table, the module prioritizes using the combination relationship template between path segments and path states that has been verified in healthy and complete running slices when combining constraints. It reduces the weight of missing parts and marks the inference results of that slice as incomplete evidence, avoiding excessive influence of a single abnormal collection on the degradation impact.

[0085] As degradation records from different operating slices gradually accumulate in the degradation log table, the degradation trend identification module determines an observation window after each new operating slice ends, based on the configured observation window length. This observation window extends from the current operating slice forward, covering several operating slices. Records from the degradation log table within the observation window are aggregated by path segment identifier and device identifier, forming a degradation impact sequence and degradation level sequence for each device port and path segment within the observation window. The module also counts the number of abnormal business paths associated with that path segment within the observation window. Based on health, moderate, and severe thresholds, the module calculates the duration and number of slices where the degradation impact exceeds each threshold within the observation window. It determines the trend by comparing the average degradation impact before and after the observation window or by determining whether the degradation impact shows a monotonically increasing trend. Combined with the number of associated critical business paths within the observation window, the module classifies the status of the device port or path segment into healthy, mildly degraded, moderately degraded, or severely degraded categories according to grading rules. When a path segment consistently exhibits a degradation impact exceeding the moderate threshold and showing an upward trend across multiple adjacent observation windows, and the number of associated critical business paths reaches a preset number, the module classifies the corresponding port of that path segment as severely degraded and generates an early warning message. This message records the device identifier, port identifier, path segment identifier, current degradation level, the operating slice range covered by the observation window, a list of associated critical business paths, degradation threshold version number, observation window configuration version number, and suggested follow-up actions, and writes it to the early warning record table using the early warning number as an index. In subsequent operation, when the degradation impact of that path segment falls below the healthy threshold across multiple observation windows and the duration meets the required number of times to resolve the degradation, the degradation trend identification module automatically marks the corresponding early warning as resolved, registers the resolution time and a summary of the reason for resolution, providing clear degradation closed-loop information for the display and linkage module and the operation and maintenance system.

[0086] With the combined action of the above modules, the display and linkage module periodically reads the latest warning records from the warning record table on the monitoring platform side, locates the device nodes and path segments corresponding to the warnings on the topology view, marks severely degraded path segments with a prominent color, distinguishes moderate and mildly degraded path segments with different colors or line types, and marks all critical business paths passing through the path segment and their current degradation level in the business path view. Operation and maintenance personnel can select any warning on the interface to view the changes in the path status fingerprint, local status fingerprint, and degradation impact of the warning in different operating slices, and verify the timing configuration version, fingerprint template version, anomaly judgment rule version, and degradation threshold version used at that time. The display and linkage module simultaneously provides early warning information query capabilities to the operation and maintenance system through external interfaces. During a certain inspection cycle, the operation and maintenance system initiates a query to the monitoring platform via remote call. The request carries the target device identifier, time range, a list of required fields, and a request identifier. After detecting that this is the first appearance of the request identifier, the display and linkage module filters early warning records related to the uplink path segment of the device in the early warning record table according to the time range, and supplements the necessary fields according to the degradation record table and fingerprint record table. It returns a structured record containing device identifier, path identifier, operating slice range, degradation level, early warning number, configuration version number, and timestamp to the operation and maintenance system. At the same time, it records the call time, request identifier, caller identifier, query condition summary, and number of returned records in the access log. In a typical operational scenario, the performance of the optical module on the uplink port of a certain aggregation switch gradually degraded. This resulted in increased end-to-end latency and slightly higher loss rates for multiple critical service paths passing through this port in several adjacent operational slices. The constraint reasoning localization module repeatedly identified this uplink path segment as a candidate for a degraded path segment in these operational slices. The degradation trend identification module observed that the degradation impact of this path segment was consistently higher than the moderate threshold and showed an upward trend over several dozen consecutive operational slices. At the same time, the number of associated critical service paths reached a preset number. Therefore, the path segment was assessed as severely degraded and an early warning message was generated. The display and linkage module marked the path segment with a severe color in the topology view and pushed a record containing the device identifier, path identifier, operational slice range, and severe degradation level to the operation and maintenance system through the external interface. Based on this record, the operation and maintenance system generated a work order to arrange on-site replacement of the optical module. After the replacement is completed, the degradation impact of this path segment in subsequent operation slices will drop back to a healthy level. The degradation trend identification module will update the warning status to "resolved" after the resolution rules are met. The display and linkage module will present the status and time of the warning being resolved in the structured record returned by the next interface call. The operation and maintenance system will confirm that this degradation event has formed a closed loop by comparing the query results before and after.As can be seen from the above overall operation scenarios, the present invention can achieve a complete closed loop of unified time synchronization of operation slices, topology and business path modeling, status fingerprint construction, degradation source location, degradation trend identification, and early warning display linkage under typical campus network, factory network, and data center LAN operating conditions. Based on this, those skilled in the art can adjust the slice length, refresh cycle, collection rhythm, fingerprint template, judgment threshold, and early warning strategy to reproduce the comprehensive online monitoring capability of LAN device operation status provided by the present invention under different scales and business load conditions.

[0087] All calculations involved in the embodiments are dimensionless numerical calculations, and the preset parameters and thresholds in the calculations are set by those skilled in the art according to the actual situation.

[0088] It should be noted that this invention can be deployed on the device itself to realize embedded applications, or it can run on a PC or other terminal with a user interface, thereby meeting various hardware environments and usage requirements.

[0089] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wireless or wired transmission; wired transmission methods include optical fiber, twisted pair, coaxial cable, etc.; wireless transmission includes infrared, microwave, etc. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center containing one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.

[0090] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and modules described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0091] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or modules may be electrical, mechanical, or other forms.

[0092] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0093] In addition, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.

[0094] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0095] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0096] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A comprehensive online monitoring system for the operating status of local area network (LAN) devices, characterized in that, include: S1, the slice control module, is used to divide the monitoring cycle based on unified time information, generate slices with slice identifiers, and align the time of each monitoring data. S2, Topology and Service Path Modeling Module, is used to obtain the connectivity relationships of devices within the local area network, construct the network topology, and determine the service path identifiers and path segment sequences from key terminals to key service nodes. S3, Status Acquisition and Fingerprint Construction Module, is used to collect device port statistics, device resource status and active detection results within the running slice, and generate path status fingerprints for each service path and local status fingerprints for each path segment based on the fingerprint template. S4, Constraint Reasoning and Localization Module, is used to obtain the set of path segments that can explain the path state anomalies based on the combined constraints between the path state fingerprint and the local state fingerprint within the running slice, and to calculate the path segment degradation impact degree. S5, Degradation Trend Identification Module, is used to determine the degradation level of device ports and path segments based on the changes in degradation impact within continuously running slices, and generate early warning information; S6, Display and Linkage Module, is used to present early warning information in the topology view and business path view, and outputs structured data containing device identifier, path identifier and degradation level through external interface for operation and maintenance system to call.

2. The integrated online monitoring system for the operating status of local area network devices according to claim 1, characterized in that, S1 includes: The slice control module obtains reference time from the time source to generate unified time information, which is then distributed to the acquisition agent and key equipment via a dedicated management network. Each data acquisition agent records the local time offset, and when forming a monitoring record, it carries the slice number and the local time offset and sends it to the monitoring platform.

3. The integrated online monitoring system for the operating status of local area network devices according to claim 1, characterized in that: At the end of each running slice, the slice control module summarizes the monitoring records by slice number and determines the validity of the records based on the local time offset and the allowable time synchronization deviation range. Records that exceed the allowed time synchronization deviation range are marked as incomplete records, records that arrive after the corresponding running slice has finished are marked as late records, and the slice number, time synchronization configuration version number and merging status are registered in the slice record table; A version-locking strategy is used to generate configuration change records for slice length, timing accuracy, and allowable timing deviation range. These records are then indexed with the slice record table, monitoring records, fingerprint records, and early warning records to form a chain of evidence.

4. The integrated online monitoring system for the operating status of local area network devices according to claim 1, characterized in that, S2 include: The topology and service path modeling module collects adjacency information, port connection information and forwarding relationships of LAN devices, constructs a connectivity graph with device identifiers as nodes and port connection information as edges, and assigns path segment identifiers to the physical links in the connectivity graph; When maintenance personnel register the address information, service type, and region of key terminals and key service nodes on the monitoring platform interface, the topology and service path modeling module searches for available paths that meet the service type constraints and region constraints in the connectivity graph, generates service path identifiers and corresponding path segment sequences, and registers the service path identifiers, path segment sequences, and the temporarily unreachable status of the service path in the path record table according to the topology configuration version.

5. The integrated online monitoring system for the operating status of local area network devices according to claim 1, characterized in that, S3 includes: The status acquisition and fingerprint construction module receives raw status records carrying device identifiers, port identifiers, and time information from the acquisition agent based on the running slice number, business path identifier, and path segment identifier. On the monitoring platform side, the status information is processed according to the field set and quantization rules in the fingerprint template to generate local status fingerprints and path status fingerprints; Write the local state fingerprint into the fingerprint record table using the running slice number and path segment identifier as indexes, write the path state fingerprint into the fingerprint record table using the running slice number and business path identifier as indexes, and register the fingerprint template version number.

6. The integrated online monitoring system for the operating status of local area network devices according to claim 1, characterized in that, S4 includes: At the end of each running slice, the constraint reasoning localization module reads the path state fingerprint and local state fingerprint within that running slice from the fingerprint record table using the running slice number as an index. Based on the business path identifier and path segment sequence in the path record table, abnormal paths are marked by comparing them with the health fingerprint set according to the anomaly judgment rules. Based on the index offset results and local offset thresholds involved in the abnormal path, the path segments with explanatory power are determined; The degradation impact of each path segment is calculated according to the degradation impact calculation rules and recorded in the degradation record table.

7. The integrated online monitoring system for the operating status of local area network devices according to claim 1, characterized in that: When the local state fingerprint is missing or the running slice is marked as an incomplete slice by the running slice control module, the constraint reasoning localization module uses the path segment and path state combination relationship template established in the healthy running slice and the complete running slice to perform combination constraints. The explanatory power weight of the path segment corresponding to the missing local state is reduced, the reasoning result of the running slice is marked as incomplete evidence, and the anomaly judgment rule version number and the degradation impact calculation rule version number are registered in the degradation record table.

8. The integrated online monitoring system for the operating status of local area network devices according to claim 1, characterized in that, S5 include: After each running slice ends, the degradation trend identification module aggregates the degradation impact sequence of each device port and each path segment within the observation window from the degradation record table, based on the observation window length and the running slice number. The degradation level of each device port and each path segment is determined based on the health threshold, the moderate threshold, the severe threshold, and the classification rules. Generate warning information that includes device identifier, port identifier, path segment identifier, operating slice range covered by the observation window, degradation level, degradation threshold version number, and observation window configuration version number, and write the warning information to the warning record table.

9. A comprehensive online monitoring system for the operating status of local area network devices according to claim 1, characterized in that, S6 include: The display and linkage module reads the early warning information from the early warning record table in chronological order within the monitoring platform; In the topology view, the degradation level of a path segment is marked based on the device identifier and the path segment identifier. In the business path view, the associated business paths are displayed based on the business path identifier. The external interface returns structured data containing device identifier, path identifier, operating slice range, degradation level, warning number and configuration version number based on the request identifier, and registers the request identifier and return result in the interface access log.