NVR Abnormality Detection via Keep-Alive Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing video surveillance systems cannot timely detect abnormalities in front-end devices, leading to instability and security risks due to the dual-network-interface-card dual-IP scheme, where the video server cannot actively acquire the running status of each IP camera, making it difficult to prevent hacking and spoofing.
Innovation Solution
An abnormality detection method where the NVR receives keep-alive information from front-end devices, generates and sends verification information to the video server, allowing the server to determine if an abnormality has occurred by comparing it with pre-stored normal process information, using hash operations based on sending time, device, and process features.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the dual-network-interface-card dual-IP scheme is adopted for NVR, then network security and isolation are improved, but the video server cannot actively acquire running status of front-end devices, leading to delayed abnormality detection
Solution Approach 1:
The NVR acts as an intermediary between the video server and front-end devices. It collects verification information from front-end devices and forwards it to the video server, enabling indirect status monitoring while preserving network isolation. The NVR receives keep-alive information from front-end devices, extracts verification information, and sends it to the video server for abnormality detection.
Solution Approach 2:
Verification information is pre-calculated and embedded in keep-alive messages before transmission. Front-end devices generate verification information based on their running status and include it in periodic keep-alive messages, allowing the server to detect abnormalities without actively querying device status.
2Loss of time
If the video server directly queries front-end devices for status information, then abnormality detection is improved, but network security and device exposure risks are worsened
Solution Approach 1:
The NVR serves as a protective intermediary that shields front-end devices from direct server access. The video server communicates only with the NVR, which then interacts with front-end devices. This maintains network security while enabling status monitoring, as the server receives verification information through the NVR without directly exposing front-end devices.
Solution Approach 2:
Front-end devices send periodic keep-alive messages with verification information to the NVR, which forwards them to the video server. The server compares verification information across messages to detect status changes or abnormalities, creating a continuous feedback loop for security monitoring without direct device exposure.
3Reliability
If manual security monitoring is performed, then security control is maintained, but operational complexity and manual intervention requirements increase
Solution Approach 1:
Front-end devices automatically generate and send keep-alive messages with verification information containing process IDs and other status data. The NVR automatically forwards these to the video server, which automatically compares verification information to detect abnormalities. This self-service mechanism eliminates manual security monitoring while maintaining reliable security control.
Solution Approach 2:
The system establishes automatic feedback loops where verification information flows continuously from front-end devices through the NVR to the video server. The server automatically analyzes this feedback stream to detect security issues, replacing manual monitoring with automated real-time detection.
Data Source
AI summary
Disclosed are an abnormality detection method, a network video recorder (NVR) and a video server. The method includes: an NVR receiving first keep-alive information from a front-end apparatus, the first keep-alive information carries first verification information, and the first verification information is generated according to a process run by the front-end apparatus while sending the first keep-alive information; the NVR carrying the first verification information in second keep-alive information, and sending the same to the video server; the video server determining, according to the first verification information and second verification information of the front-end apparatus, whether an abnormality has occurred in the front-end apparatus, the second verification information is generated according to a process run by the front-end apparatus in a normal operation status.


