SNMP-based network device early warning evaluation method and system

By using an SNMP-based network device early warning and assessment method, and leveraging an improved grey clustering algorithm and an early warning filter pool, real-time early warning and status assessment of network devices are achieved. This solves the problem of the lack of real-time early warning and assessment in existing technologies, improves the accuracy of assessment and operational efficiency, and provides support for preventive maintenance.

CN122116599APending Publication Date: 2026-05-29CHINESE PEOPLES LIBERATION ARMY UNIT 63636

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINESE PEOPLES LIBERATION ARMY UNIT 63636
Filing Date
2026-02-28
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing network device management software lacks real-time early warning and accurate assessment functions, making it impossible to detect potential faults in advance. Maintenance personnel need to frequently log in to the devices to check their status, and there is no hierarchical early warning mechanism, making it impossible to effectively integrate data, resulting in insufficient support for preventive maintenance.

Method used

A network device early warning and assessment method based on SNMP is adopted. Key status information is obtained through the SNMP protocol, and an improved gray clustering algorithm is used for real-time early warning and status assessment. By combining the early warning assessment model and the gray clustering algorithm, the organic linkage between early warning and assessment is realized, and an early warning filter pool and a gray clustering assessment model are constructed.

Benefits of technology

It achieves deep integration of real-time early warning and assessment of network devices, improves the accuracy and timeliness of assessment, provides reliable data support for preventive maintenance, simplifies operation and maintenance processes, and improves the efficiency and accuracy of equipment status monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122116599A_ABST
    Figure CN122116599A_ABST
Patent Text Reader

Abstract

The application discloses a kind of network equipment early warning evaluation method and system based on SNMP, belong to network equipment state monitoring early warning evaluation technical field, method includes: using SNMP protocol and equipment OID information acquisition network equipment's key state information and store to database;Real-time early warning is carried out to key state information based on early warning filter pool, and real-time early warning result is obtained;Current data, historical data are recalled and combined with real-time early warning result, and state evaluation is carried out using improved grey clustering algorithm, with early warning result as the determination reference of index abnormal degree and the basis for grey class correction, the state evaluation result associated with early warning result is output by calculating clustering coefficient and determining grey class.The application realizes the deep fusion of early warning and evaluation, improves the accuracy and timeliness of network equipment state evaluation, provides strong support for preventive maintenance, and can be widely applied to the operation and maintenance of various network equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network device status monitoring, early warning and evaluation technology, and specifically relates to a network device early warning and evaluation method and system based on SNMP. Background Technology

[0002] As the core carrier of information transmission and exchange, the reliability of network equipment directly affects the successful completion of critical tasks such as aerospace launches, large data center operations, and government network transmission. Therefore, extremely high demands are placed on the status monitoring, anomaly early warning, and operational evaluation of network equipment. Currently, there are many software programs for monitoring network equipment status, such as NCE and eSight. While these network management software programs can perform basic network equipment status monitoring and display, and their functional coverage is relatively broad, many unresolved technical problems still exist. Firstly, it only achieves simple monitoring and display of equipment status, lacks real-time abnormal early warning function for key operating indicators of equipment, cannot detect potential equipment failures in advance, and can only passively deal with equipment failures after they occur. Secondly, there is no systematic method for assessing the operational status of network equipment. Maintenance personnel can only make subjective judgments about the equipment status, which makes it impossible to quantitatively and accurately determine the health level of the equipment and makes it difficult to carry out preventive maintenance. Third, the monitoring and display operation process is complex, the equipment instances are scattered, and maintenance personnel need to frequently log in to different devices to check their status, resulting in extremely low work efficiency. Fourth, even if some software has a simple anomaly alert function, it lacks a graded early warning mechanism, making it impossible to accurately distinguish the severity of anomalies. Furthermore, there is no linkage mechanism between early warning and assessment, and relevant data cannot be effectively integrated and utilized.

[0003] The aforementioned problems make it difficult for existing network management software to meet the actual operation and maintenance needs of network management positions, and it cannot provide effective support for preventive maintenance of network equipment. There is an urgent need for an integrated technical solution that can realize real-time early warning and accurate assessment of network equipment.

[0004] Simple Network Management Protocol (SNMP) is a standard protocol specifically designed for managing network nodes such as switches and routers in IP networks. Its main function is to help network administrators manage network devices more effectively, identify and resolve network problems, and plan for future network development. Using the SNMP protocol, key operating parameters of network devices can be obtained through OIDs, enabling the establishment of network device status monitoring systems. Furthermore, it allows for the construction of general network device early warning models and evaluation algorithms, achieving real-time early warning and evaluation of network device operating status, predicting and alerting to potential network device failures, and providing strong support for preventative maintenance of network devices. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to provide a network device early warning and assessment method and system based on SNMP to address the shortcomings of the prior art, thereby solving the technical problem of the lack of early warning and assessment means for network devices and providing support for preventive maintenance of network devices.

[0006] The present invention adopts the following technical solution: A network device early warning assessment method based on SNMP includes the following steps: S1. Collect key status information of network devices using Simple Network Management Protocol (SNMP) and device OID information, and store the key status information in a database; perform data comparison and analysis based on the key status information in the database, and combine it with a preset early warning evaluation model to perform real-time early warning operation on the operating status of network devices to obtain real-time early warning results; S2. Retrieve the current key status data and historical key status data of the network devices from the database, and combine them with the real-time warning results obtained in step S1. Use an improved gray clustering algorithm to perform status assessment. The improved gray clustering algorithm uses the real-time warning results as a reference for judging the degree of indicator anomaly and as a basis for gray class correction. By calculating the clustering coefficient and determining the gray class, it outputs the network device status assessment results associated with the real-time warning results.

[0007] Preferably, in step S1, the key status information includes: the operating temperature of the network device, CPU utilization, memory utilization, transmit and receive power, and uplink port traffic; the real-time early warning result includes the early warning level and indicator sampling value, periodic change rate, and degradation or growth rate data corresponding to each key status information.

[0008] Preferably, in step S1, the early warning assessment model is constructed in the following way: Based on expert experience and equipment indicator system, a network equipment early warning filter pool was established, and the early warning levels were divided into four categories: alert, general, severe, and emergency. Early warning rules were set for each of the four early warning levels for each key status information.

[0009] Preferably, the early warning rules are set by combining the sampled values ​​of the corresponding key status information, the rate of change within the period, or the degree of deterioration, the rate of increase, or the degree of threshold deviation. The system periodically collects the key operating information of the network devices and calculates the rate of change of each indicator, and matches the early warning rules to obtain real-time early warning results.

[0010] Preferably, the obtained real-time warning results are stored and displayed by distinguishing between current warnings and historical warnings, and different warning levels are distinguished by different colors. Furthermore, the current warning supports one-click clearing and single-selection clearing operations.

[0011] Preferably, in step S2, the network device status is divided into four levels: good, normal, attention, and alarm, corresponding to gray class I, gray class II, gray class III, and gray class IV, respectively. The output network device status assessment result includes the device health level, clustering coefficient matrix, and threshold distribution curve. A PDF network device status assessment report can be generated based on the status assessment result, and the corresponding real-time warning results are displayed in the assessment report. The execution process of the improved gray clustering algorithm includes: S201. Based on expert experience, determine the evaluation index system and index threshold standards. Determine the whitening weight function for different gray classes based on the threshold standards and form the whitening weight function index. Standardize the temperature and light power indexes. S202. Calculate the whitening weight function weight value of each index for different gray categories, and use it as the first weight value for evaluation; S203. Use principal component analysis to process historical data of equipment indicators and calculate the importance weight of the indicators themselves. S204. Combining the first weight value and its own importance weight value, the comprehensive weight value of different gray categories of the indicator is obtained; S205. Calculate the clustering coefficients of different gray categories of the equipment based on the comprehensive weights, determine the worst clustering coefficients in combination with the real-time early warning results, and calculate the gray category correction coefficients. Determine the final gray category to which the network equipment belongs based on the gray category correction coefficients.

[0012] Preferably, in step S201, the standardization process uses the value of the index deviation center, the center of the operating temperature is the middle value of its preset range, and the optical power index is selected from the optical power value under the worst condition for standardization processing.

[0013] Preferably, in step S204, when solving the comprehensive weight value, the weight coefficient is set to 0.5, taking into account both expert experience preferences and the distinguishability of the indicator attributes themselves.

[0014] Preferably, in step S205, if the gray class correction coefficient is greater than 1.5, the network device belongs to the first gray class selected according to the principle of maximum membership degree; otherwise, it belongs to the gray class corresponding to the worst clustering coefficient.

[0015] Secondly, embodiments of the present invention provide a network device early warning and assessment system based on SNMP, comprising: The data module is used to collect key status information of network devices using the Simple Network Management Protocol (SNMP) and device OID information, and store the key status information in the database; The early warning module is communicatively connected to the data module and is used to perform data comparison and analysis based on key status information in the database, and to perform real-time early warning operations in conjunction with a preset early warning evaluation model to obtain real-time early warning results. The evaluation module, which is communicatively connected to both the data module and the early warning module, is used to retrieve the current and historical key status data of network devices from the database. Combined with the real-time early warning results, it uses an improved gray clustering algorithm to perform status evaluation. The real-time early warning results serve as a reference for determining the degree of indicator anomaly and as a basis for gray class correction. By calculating the clustering coefficient and determining the gray class, the network device status evaluation results associated with the real-time early warning results are output.

[0016] Thirdly, a computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described SNMP-based network device early warning assessment method.

[0017] Fourthly, embodiments of the present invention provide a computer-readable storage medium including a computer program, which, when executed by a processor, implements the steps of the above-described SNMP-based network device early warning and assessment method.

[0018] Fifthly, a chip includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described SNMP-based network device early warning assessment method.

[0019] In a sixth aspect, embodiments of the present invention provide an electronic device including a computer program, which, when executed by the electronic device, implements the steps of the above-described SNMP-based network device early warning and assessment method.

[0020] Compared with the prior art, the present invention has at least the following beneficial effects: A network device early warning and assessment method based on SNMP collects and stores key status information through SNMP, and generates early warning results in real time based on an early warning assessment model. Then, it retrieves current and historical data and combines them with the early warning results, employing an improved grey clustering algorithm for assessment. The early warning results serve as a reference for the degree of anomaly and as a basis for grey cluster correction, outputting a status assessment result correlated with the early warning results. This method achieves organic linkage between early warning and assessment, using the anomaly information obtained from real-time early warning as an important input for assessment, overcoming the shortcomings of traditional methods where early warning and assessment are independent. The improved grey clustering algorithm uses early warning results to correct grey clusters, making the assessment results more reflective of the actual operating status of the equipment and improving the accuracy of the assessment. Furthermore, the entire process is based on the SNMP protocol for data collection, does not affect the normal operation of the equipment, is applicable to various network devices, and provides reliable data support for preventive maintenance.

[0021] Furthermore, the core indicators for collection were clearly defined, covering the main health dimensions of network equipment operation, ensuring the comprehensiveness of early warning and assessment; the early warning results contain multi-dimensional quantitative data, providing rich feature information for subsequent gray clustering assessment, enabling the assessment model to more precisely characterize subtle changes in equipment status, thereby improving the accuracy and reliability of the assessment.

[0022] Furthermore, the construction of the early warning filter pool incorporates expert experience, giving the early warning rules clear physical meaning and industry applicability; the four-level classification enables hierarchical management of early warnings, distinguishing anomalies of different severity levels and facilitating maintenance personnel to prioritize urgent issues; rules are set separately for different indicators, fully considering the characteristics of each indicator, thus improving the pertinence and accuracy of early warnings.

[0023] Furthermore, the early warning rules not only focus on the current sampled values ​​but also on the changing trends, which can effectively capture sudden anomalies and slow deterioration trends, and discover potential risks in advance; periodic data collection and real-time matching ensure the timeliness of early warnings, enabling maintenance personnel to know about equipment anomalies as soon as possible, and providing support for rapid response.

[0024] Furthermore, color-coding the warning levels makes the monitoring interface intuitive and clear, allowing maintenance personnel to quickly identify high-risk emergency warnings; differentiating between current and historical warnings helps track changes in equipment status and analyze fault modes; the clearing function simplifies interface management, improves user experience, and facilitates flexible handling of alarms already processed in actual maintenance.

[0025] Furthermore, a correlation is established between assessment levels and warning levels, facilitating maintenance personnel's understanding of equipment health status. The improved grey clustering algorithm integrates expert experience weights and the importance of the data itself, and incorporates warning results as a correction basis. By calculating the grey class correction coefficient, the grey class to which the equipment belongs is ultimately determined. Comparative experiments in the disclosure document show that this method is more accurate than traditional methods, can reasonably adjust some samples from good to normal or watch out, better reflects actual operating data, and significantly improves the accuracy and practicality of the assessment.

[0026] Furthermore, for operating temperatures with a defined range, using deviation from the center can eliminate the influence of dimensions and intuitively reflect the degree to which the temperature deviates from the ideal value; for ports with multiple optical powers, selecting the worst value as a representative can highlight the weak points of the equipment, avoid averaging to mask serious local problems, and make the assessment results closer to the real risks.

[0027] Furthermore, the coefficient of 0.5 balances subjective and objective weights, preserving the guiding role of domain knowledge while making full use of the inherent patterns of historical data. This avoids the bias of a single weight source, making the comprehensive weight more reasonable and robust, thereby improving the generalization ability and credibility of the evaluation model.

[0028] Furthermore, a fine-grained correction of the initial gray class was achieved through specific thresholds. Experimental data in the disclosure document show that this correction strategy can correct misjudgments that may be caused by simply relying on the maximum membership degree, making the evaluation results highly consistent with the actual operating conditions of the equipment, and enhancing the robustness and engineering applicability of the method.

[0029] It is understood that the beneficial effects of the second to sixth aspects mentioned above can be found in the relevant descriptions in the first aspect mentioned above, and will not be repeated here.

[0030] In summary, this invention collects key parameters through SNMP, constructs an early warning filter pool to achieve hierarchical real-time early warning, and uses the early warning results as a basis for improving gray clustering evaluation. This achieves deep integration of early warning and evaluation, significantly improves the accuracy and timeliness of network device status evaluation, provides quantitative and qualitative support for preventive maintenance, and has strong engineering applicability.

[0031] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0032] Figure 1 This is a flowchart of the network device status early warning process of the present invention; Figure 2 To improve the flowchart for network device status assessment using gray clustering; Figure 3 Screenshot of the real-time alert status display interface for network devices; Figure 4 This is a screenshot of the network device's current warning information display interface; Figure 5 Screenshot of the network device's historical warning information display interface; Figure 6 Screenshot of the network device status assessment display interface; Figure 7 A screenshot of the report generated from the network device status assessment results; Figure 8 A schematic diagram of a computer device provided in an embodiment of the present invention; Figure 9 This is a block diagram of a chip provided according to an embodiment of the present invention.

[0033] Among them, 60. Computer equipment; 61. Processor; 62. Memory; 63. Computer program; 600. Electronic device; 610. Processing unit; 620. Storage unit; 6201. Random access memory unit; 6202. Cache memory unit; 6203. Read-only memory unit; 6204. Program / utility; 6205. Program module; 630. Bus; 640. Display unit; 650. Input / output interface; 660. Network adapter; 700. External device. Detailed Implementation

[0034] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0035] In the description of this invention, it should be understood that the terms "comprising" and "including" indicate the presence of the described features, integrals, steps, operations, elements and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.

[0036] It should also be understood that the terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in this specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.

[0037] It should also be further understood that the term "and / or" as used in this specification and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes such combinations. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. Additionally, the character " / " in this invention generally indicates that the preceding and following objects have an "or" relationship.

[0038] It should be understood that although terms such as first, second, third, etc., may be used in the embodiments of the present invention to describe the preset range, these preset ranges should not be limited to these terms. These terms are only used to distinguish the preset ranges from one another. For example, without departing from the scope of the embodiments of the present invention, the first preset range may also be referred to as the second preset range, and similarly, the second preset range may also be referred to as the first preset range.

[0039] Depending on the context, the word "if" as used here can be interpreted as "when," "when," "in response to determination," or "in response to detection." Similarly, depending on the context, the phrase "if determination" or "if detection (of the stated condition or event)" can be interpreted as "when determination," "in response to determination," "when detection (of the stated condition or event)," or "in response to detection (of the stated condition or event)."

[0040] The accompanying drawings illustrate various structural schematic diagrams according to embodiments disclosed in this invention. These drawings are not to scale, and some details have been enlarged for clarity, and some details may have been omitted. The shapes of the various regions and layers shown in the drawings, as well as their relative sizes and positional relationships, are merely exemplary and may deviate from reality due to manufacturing tolerances or technical limitations. Furthermore, those skilled in the art can design regions / layers with different shapes, sizes, and relative positions as needed.

[0041] This invention provides a network device early warning and assessment method based on SNMP. It employs an early warning filter pool model to achieve real-time early warning of key network device indicators and uses an improved grey clustering algorithm for device status assessment. Without affecting normal device operation, it achieves real-time early warning of network device risks and assessment of operational status. Through practical application, it enriches the means of monitoring and early warning of network device status, fills the gap in network device status assessment, and provides key technical support for preventative maintenance of network devices from both quantitative and qualitative perspectives. This lays a solid foundation for ensuring the long-term stability and reliability of network devices, improves task execution efficiency, and demonstrates good practical application results.

[0042] Please see Figure 1The present invention provides a network device early warning assessment method based on SNMP, comprising the following steps: S1. Use SNMP protocol and device OID information to obtain key status information of network devices, including operating temperature, CPU utilization, memory utilization, transmit and receive power, uplink port traffic, etc., and store them in the database. Real-time early warning is given through data comparison analysis and early warning evaluation model. S101. Based on expert experience and equipment indicator system, establish a network equipment early warning filter pool as shown in Table 1, construct a network equipment status early warning model, and divide the early warning level into four categories: prompt, general, severe and emergency. Table 1 Network Device Status Early Warning Filter Pool

[0043] S102. The system periodically collects key operational information from network devices, calculates the rate of change of each indicator through comparative analysis, and issues real-time warnings based on the current sampled values ​​and rate of change. It distinguishes between current and historical warnings, using different colors to differentiate alarm levels. The current warning interface allows for one-click alarm clearing and single-selection clearing. The system interface is shown below. Figure 3 , Figure 4 , Figure 5 As shown.

[0044] S2. Based on the acquired current and historical data of the network devices, assess the network device status. Following the general device status classification method, classify the network device status into four levels: Good, Normal, Attention, and Alarm. Specifically: Good corresponds to category I (gray class), indicating that all network device indicators are within the good range, and the overall health level of the device is good; Normal corresponds to category II (gray class), indicating that all network device indicators are within the normal range, but some indicators may deviate from the standard values, and the device is generally healthy and can operate normally; Attention corresponds to category III (gray class), indicating that some network device indicators are high, but the operation is still acceptable, requiring close attention, but no immediate action is needed; Alarm corresponds to category IV (gray class), indicating that some or most network device indicators deviate significantly from normal levels, possibly indicating a fault, requiring timely intervention. S201. Based on expert experience, determine the evaluation index system and the threshold standards for the indicators (as shown in Table 2). Then, determine the whitening weight function for different gray levels based on the threshold standards, forming whitening weight function indices for different gray classes (as shown in Table 3). Among them, temperature and optical power indices need to be standardized by using the value of the index deviation from the center. For example, if the working temperature range is [0, 65], then the center temperature is 32.5℃, and the corresponding index is the value of deviation from 32.5℃. If there are multiple optical powers, the worst case is selected. Table 2 Standard Threshold Table

[0045] Table 3. Whitening weight function indices for different gray classes

[0046] S202. Calculate the whitening weight function weight value of each indicator for different gray categories according to formula (1). This weight value serves as the first weight value of the evaluation method, directly reflecting the expert's experience and preferences. express Indicators Gray class weights express Indicators Gray class inflection point value; (1) S203. Collect historical data of equipment indicators, and use principal component analysis to calculate the importance weight of the indicators according to formula (2), where, Indicates the first The weights of the original indicators, Indicates the first The eigenvalues ​​corresponding to each principal component Indicates the first The first indicator in the eigenvector elements on each principal component This indicates the number of principal components to be retained. Considering that we need to calculate the weights of all indicators, we take the number of principal components as the number of indicators. (2) S204. The final comprehensive weight of different gray classes of the index is obtained by using the whitening weight function weight and the principal component analysis weight. The formula is as shown in formula (3). Under the same consideration of expert censorship preference and the distinguishability of the attribute itself, the weight coefficient is selected as 0.5. (3) S205. Calculate the clustering coefficients of different gray classes of the equipment according to the gray clustering coefficient calculation method, select the first gray class according to the principle of maximum membership, and calculate the gray class correction coefficient according to formula (4), where... The worst clustering coefficient is used. If the correction coefficient is greater than 1.5, it belongs to the first gray class; otherwise, it belongs to the gray class corresponding to the worst clustering coefficient, thus completing the equipment condition assessment.

[0047] (4) The interface of the network device status assessment system is as follows: Figure 6As shown, first select the device to be evaluated, then enter parameters such as the device's operating temperature range, optical power range, and the number of historical data sets. Click "Start Evaluation" to obtain the evaluation results, including the network device's status evaluation results, clustering coefficient matrix, threshold distribution curve, and other information. After the evaluation is complete, clicking "Generate Evaluation Report" will produce a PDF format device status evaluation report. A screenshot of the generated report is shown below. Figure 7 As shown.

[0048] In another embodiment of the present invention, a network device early warning and evaluation system based on SNMP is provided. This system can be used to implement the above-mentioned network device early warning and evaluation method based on SNMP. Specifically, the network device early warning and evaluation system based on SNMP includes a data module, an early warning module, and an evaluation module.

[0049] The data module is used to collect key status information of network devices using the Simple Network Management Protocol (SNMP) and device OID information, and store the key status information in the database. The early warning module is communicatively connected to the data module and is used to perform data comparison and analysis based on key status information in the database, and to perform real-time early warning operations in conjunction with a preset early warning evaluation model to obtain real-time early warning results. The evaluation module, which is communicatively connected to both the data module and the early warning module, is used to retrieve the current and historical key status data of network devices from the database. Combined with the real-time early warning results, it uses an improved gray clustering algorithm to perform status evaluation. The real-time early warning results serve as a reference for determining the degree of indicator anomaly and as a basis for gray class correction. By calculating the clustering coefficient and determining the gray class, the network device status evaluation results associated with the real-time early warning results are output.

[0050] This invention provides a terminal device comprising a processor and a memory. The memory stores a computer program, which includes program instructions. The processor executes the program instructions stored in the computer storage medium. The processor may be a Central Processing Unit (CPU), or other general-purpose processors, graphics processing units (GPUs), tensor processing units (TPUs), digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing and control core of the terminal, suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions to achieve corresponding method flows or corresponding functions. The processor described in this embodiment can be used in the operation of a network device early warning and assessment method based on SNMP, including: Key status information of network devices is collected using Simple Network Management Protocol (SNMP) and device OID information, and stored in a database. Based on the key status information in the database, data comparison and analysis are performed, and a preset early warning assessment model is used to execute real-time early warning operations on the network device's operating status, obtaining real-time early warning results. Current and historical key status data of the network devices are retrieved from the database, and combined with the obtained real-time early warning results, an improved grey clustering algorithm is used for status assessment. The improved grey clustering algorithm uses the real-time early warning results as a reference for determining the degree of indicator anomaly and as a basis for grey class correction. By calculating clustering coefficients and determining grey classes, it outputs network device status assessment results associated with the real-time early warning results.

[0051] Please see Figure 8 The terminal device is a computer device. In this embodiment, the computer device 60 includes a processor 61, a memory 62, and a computer program 63 stored in the memory 62 and executable on the processor 61. When executed by the processor 61, the computer program 63 implements the SNMP-based network device early warning and evaluation method described in this embodiment. To avoid repetition, details are omitted here. Alternatively, when executed by the processor 61, the computer program 63 implements the functions of each model / unit in the SNMP-based network device early warning and evaluation system described in this embodiment. To avoid repetition, details are omitted here.

[0052] Computer device 60 can be a desktop computer, laptop, handheld computer, cloud server, or other computing device. Computer device 60 may include, but is not limited to, a processor 61 and a memory 62. Those skilled in the art will understand that... Figure 8 This is merely an example of computer device 60 and does not constitute a limitation on computer device 60. It may include more or fewer components than shown, or combine certain components, or different components. For example, computer device may also include input / output devices, network access devices, buses, etc.

[0053] The processor 61 may be a Central Processing Unit (CPU), or other general-purpose processors, graphics processing units (GPUs), tensor processing units (TPUs), digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.

[0054] The memory 62 can be an internal storage unit of the computer device 60, such as a hard disk or memory of the computer device 60. The memory 62 can also be an external storage device of the computer device 60, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc. equipped on the computer device 60.

[0055] Furthermore, the memory 62 may include both internal storage units of the computer device 60 and external storage devices. The memory 62 is used to store computer programs and other programs and data required by the computer device. The memory 62 can also be used to temporarily store data that has been output or will be output.

[0056] Please see Figure 9The terminal device is an electronic device 600, which is manifested in the form of a general-purpose computing device. The components of the electronic device may include, but are not limited to: at least one processing unit 610, at least one storage unit 620, a bus 630 connecting different platform components (including storage unit 620 and processing unit 610), a display unit 640, etc.

[0057] The storage unit stores program code, which can be executed by the processing unit 610 to perform the steps described in the method section of this specification according to various exemplary embodiments of the present invention. For example, the processing unit 610 can perform actions such as... Figure 1 The steps are shown in the figure.

[0058] Storage unit 620 may include a readable medium in the form of a volatile storage unit, such as random access memory (RAM) 6201 and / or cache memory 6202, and may further include a read-only memory (ROM) 6203.

[0059] Storage unit 620 may also include a program / utility 6204 having a set (at least one) program module 6205, such program module 6205 including but not limited to: operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.

[0060] Bus 630 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the multiple bus structures.

[0061] Electronic device 600 can also communicate with one or more external devices 700 (e.g., keyboard, pointing device, Bluetooth device, etc.), and with one or more devices that enable a user to interact with electronic device 600, and / or with any device that enables electronic device 600 to communicate with one or more other computing devices (e.g., router, modem). This communication can be performed via input / output interface 650. Furthermore, electronic device 600 can also communicate with one or more networks (e.g., local area network, wide area network, and / or public network, such as the Internet) via network adapter 660. Network adapter 660 can communicate with other modules of electronic device 600 via bus 630. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 600, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage platforms.

[0062] Example 3 This invention also provides a storage medium, specifically a computer-readable storage medium, which is a memory device in a terminal device for storing programs and data. It is understood that the computer-readable storage medium here can include both built-in storage media in the terminal device and extended storage media supported by the terminal device; it can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. The computer-readable storage medium provides storage space that stores the terminal's operating system. Furthermore, the storage space also stores one or more instructions suitable for loading and execution by a processor, which can be one or more computer programs (including program code). More specific examples of the computer-readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, random access memory, read-only memory, erasable programmable read-only memory, optical fiber, portable compact disk read-only memory, optical storage device, magnetic storage device, or any suitable combination thereof.

[0063] Computer-readable storage media also include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable storage medium can also be any readable medium other than a readable storage medium that can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium can be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, radio frequency, etc., or any suitable combination thereof.

[0064] Program code for performing the operations of this invention can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0065] One or more instructions stored in a computer-readable storage medium can be loaded and executed by a processor to implement the corresponding steps of the SNMP-based network device early warning assessment method in the above embodiments; one or more instructions in the computer-readable storage medium are loaded and executed by the processor to perform the following steps: Key status information of network devices is collected using Simple Network Management Protocol (SNMP) and device OID information, and stored in a database. Based on the key status information in the database, data comparison and analysis are performed, and a preset early warning assessment model is used to execute real-time early warning operations on the network device's operating status, obtaining real-time early warning results. Current and historical key status data of the network devices are retrieved from the database, and combined with the obtained real-time early warning results, an improved grey clustering algorithm is used for status assessment. The improved grey clustering algorithm uses the real-time early warning results as a reference for determining the degree of indicator anomaly and as a basis for grey class correction. By calculating clustering coefficients and determining grey classes, it outputs network device status assessment results associated with the real-time early warning results.

[0066] The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.

[0067] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.

[0068] Table 4 shows 14 sets of actual operating data collected from network equipment during routine maintenance.

[0069] The evaluation method based on the improved grey clustering algorithm proposed in this invention is used for evaluation and analysis. The method is compared with the method in the literature "Research on Network Equipment Health Management Based on Grey Theory" and analyzed in combination with the actual working status to verify the correctness of the method.

[0070] Table 4. Actual Equipment Operating Data

[0071] The clustering coefficients and evaluation results are shown in Table 5. The comparative literature only provides the evaluation results and does not include the clustering coefficients evaluated by the evaluation methods in the literature.

[0072] Table 5. Clustering coefficients and status assessment results of network devices in this invention.

[0073] As shown in Table 5, in the evaluation results obtained using the method of this invention, network devices 1, 10, 12, and 13 are in good condition, with their overall indicators generally good. Although some indicators deviate from the good range, the deviation is small, and the overall operation of the devices is good. Network devices 2, 3, 5, and 6 are in normal condition, with most of their indicators within the normal range. Although some indicators deviate from the normal range, the deviation is small, and the overall operation of the devices is normal. Network devices 4, 7, 11, and 14 are in a state of concern, with most of their indicators exceeding the normal range, but none exceeding the maximum threshold. They require attention from management personnel, but no action is needed at this time. Network devices 8 and 9 have most indicators reaching the alarm range, and several indicators are near the critical threshold, requiring timely action from management personnel.

[0074] Compared with the results in the literature, without correction, our method considers network devices 2 and 5 to be in a normal state, and network device 14 to be in a state of concern. Based on actual operating data, the operating temperature, memory utilization, and transmit / receive power of sample 2 all exceed the good range and are within the normal range, so it is more reasonable to determine it as a normal state. Similarly, the operating temperature, memory utilization, and transmit / receive power of sample 5 all exceed the good range, and one of the indicators (transmit / receive power) is within the range of concern, so it is more reasonable to determine it as a normal state. The memory utilization and uplink traffic of sample 14 both exceed the normal range and are within the range of concern, and one of the indicators (transmit / receive power) is within the normal range, so it is more reasonable to determine this sample as a state of concern rather than a good state. With corrections, this paper assesses Sample 3 as being in a normal state. Based on actual operating data, the operating temperature, memory utilization, and light and power of Sample 3 all exceed the good range and fall within the normal range. Therefore, it should also be determined as being in a normal state. However, compared to Sample 2, the deviation of the indicators of Sample 3 is smaller, indicating that the operating state of Sample 3 is better than that of Sample 2. In order to more accurately assess the operating state of the equipment, a correction strategy needs to be adopted, thereby improving the accuracy of the assessment.

[0075] The operation and maintenance of aerospace business network switches were carried out using the method and system developed in this invention. Through practical application, the means of monitoring and early warning of equipment status have been enriched, making the working status of key network equipment indicators clear at a glance, greatly reducing the number of times devices need to be logged in for queries, and improving the monitoring efficiency during mission preparation and implementation. The method has good engineering practicality. At the same time, the status assessment method proposed in this invention has high accuracy and adaptability, providing key technical support for preventive maintenance of equipment from both quantitative and qualitative aspects, thus laying a good foundation for ensuring the long-term stability and reliability of network equipment. It has been highly praised by on-site personnel and command decision-makers.

[0076] In summary, this invention provides a network device early warning and assessment method and system based on SNMP. Without affecting the existing network device's operational status, it acquires key indicator parameters of the network device based on the SNMP protocol. Then, by designing an early warning filter pool, it constructs a general network device early warning model to provide real-time early warnings for abnormal conditions of key network device indicators. Combined with data comparison and analysis, it predicts and alerts to potential network device faults, achieving early warning of possible network device risks. Simultaneously, it employs an improved grey clustering algorithm for device status assessment, resulting in higher accuracy and better reflecting the actual operating conditions of the network device. Through practical application to network device early warning and assessment, it significantly improves the ability of personnel to identify potential equipment problems in advance, providing strong support for preventative maintenance of network devices.

[0077] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0078] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0079] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this invention can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0080] In the embodiments provided by this invention, it should be understood that the disclosed devices / terminals and methods can be implemented in other ways. For example, the device / terminal embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0081] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0082] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0083] If the integrated module / unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random-access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.

[0084] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus, and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0085] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0086] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0087] The above content is only for illustrating the technical concept of the present invention and should not be construed as limiting the scope of protection of the present invention. Any modifications made to the technical solution based on the technical concept proposed in this invention shall fall within the scope of protection of the claims of this invention.

Claims

1. A network device early warning and assessment method based on SNMP, characterized in that, Includes the following steps: S1. Collect key status information of network devices using Simple Network Management Protocol (SNMP) and device OID information, and store the key status information in the database; Based on the key status information in the database, data comparison and analysis are performed, and combined with the preset early warning evaluation model, real-time early warning operations are performed on the operating status of network devices to obtain real-time early warning results. S2. Retrieve the current key status data and historical key status data of the network device from the database, and combine them with the real-time early warning results obtained in step S1 to perform status assessment using an improved gray clustering algorithm. The improved gray clustering algorithm uses the real-time warning results as a reference for judging the degree of indicator anomaly and as a basis for gray class correction. By calculating the clustering coefficient and determining the gray class, it outputs the network device status assessment results associated with the real-time warning results.

2. The SNMP-based network device early warning and assessment method according to claim 1, characterized in that, In step S1, the key status information includes: the operating temperature of the network device, CPU utilization, memory utilization, transmit and receive power, and uplink port traffic; the real-time early warning result includes the early warning level and indicator sampling value, periodic change rate, and degradation or growth rate data corresponding to each key status information.

3. The SNMP-based network device early warning and assessment method according to claim 1, characterized in that, In step S1, the early warning assessment model is constructed as follows: Based on expert experience and equipment indicator system, a network equipment early warning filter pool was established, and the early warning levels were divided into four categories: alert, general, severe, and emergency. Early warning rules were set for each of the four early warning levels for each key status information.

4. The SNMP-based network device early warning and assessment method according to claim 3, characterized in that, The warning rules are all set by combining the sampled values ​​of the corresponding key status information, the rate of change within the period, or the degree of deterioration, the rate of increase, or the degree of threshold deviation. The system periodically collects the key operating information of the network devices and calculates the rate of change of each indicator, and matches the warning rules to obtain real-time warning results.

5. The SNMP-based network device early warning and assessment method according to claim 3, characterized in that, The real-time warning results are stored and displayed by distinguishing between current warnings and historical warnings. Different warning levels are distinguished by different colors, and the current warning can be cleared with one click or by selecting a single warning to clear.

6. The SNMP-based network device early warning and assessment method according to claim 1, characterized in that, In step S2, the network device status is divided into four levels: good, normal, attention, and alarm, corresponding to gray class I, gray class II, gray class III, and gray class IV, respectively. The output network device status assessment results include device health level, clustering coefficient matrix, and threshold distribution curve. A network device status assessment report in PDF format can be generated based on the status assessment results. The assessment report displays the corresponding real-time warning results. The execution process of the improved grey clustering algorithm includes: S201. Based on expert experience, determine the evaluation index system and index threshold standards. Determine the whitening weight function for different gray classes based on the threshold standards and form the whitening weight function index. Standardize the temperature and light power indexes. S202. Calculate the whitening weight function weight value of each index for different gray categories, and use it as the first weight value for evaluation; S203. Use principal component analysis to process historical data of equipment indicators and calculate the importance weight of the indicators themselves. S204. Combining the first weight value and its own importance weight value, the comprehensive weight value of different gray categories of the indicator is obtained; S205. Calculate the clustering coefficients of different gray categories of the equipment based on the comprehensive weights, determine the worst clustering coefficients in combination with the real-time early warning results, and calculate the gray category correction coefficients. Determine the final gray category to which the network equipment belongs based on the gray category correction coefficients.

7. The SNMP-based network device early warning and assessment method according to claim 6, characterized in that, In step S201, the standardization process uses the value of the index deviation center, the center of the operating temperature is the middle value of its preset range, and the optical power index is selected from the optical power value under the worst condition for standardization processing.

8. The SNMP-based network device early warning and assessment method according to claim 6, characterized in that, In step S204, when solving for the comprehensive weight, the weight coefficient is set to 0.5, taking into account both expert experience preferences and the distinguishability of the indicator attributes themselves.

9. The SNMP-based network device early warning and assessment method according to claim 6, characterized in that, In step S205, if the gray class correction coefficient is greater than 1.5, the network device belongs to the first gray class selected according to the principle of maximum membership degree; otherwise, it belongs to the gray class corresponding to the worst clustering coefficient.

10. A network device early warning and assessment system based on SNMP, characterized in that, include: The data module is used to collect key status information of network devices using the Simple Network Management Protocol (SNMP) and device OID information, and store the key status information in the database; The early warning module is communicatively connected to the data module and is used to perform data comparison and analysis based on key status information in the database, and to perform real-time early warning operations in conjunction with a preset early warning evaluation model to obtain real-time early warning results. The evaluation module, which is communicatively connected to both the data module and the early warning module, is used to retrieve the current and historical key status data of network devices from the database. Combined with the real-time early warning results, it uses an improved gray clustering algorithm to perform status evaluation. The real-time early warning results serve as a reference for determining the degree of indicator anomaly and as a basis for gray class correction. By calculating the clustering coefficient and determining the gray class, the network device status evaluation results associated with the real-time early warning results are output.