CN109714202A - A kind of client off-line reason method of discrimination and concentrating type safety management system - Google Patents

A kind of client off-line reason method of discrimination and concentrating type safety management system Download PDF

Info

Publication number
CN109714202A
CN109714202A CN201811579056.1A CN201811579056A CN109714202A CN 109714202 A CN109714202 A CN 109714202A CN 201811579056 A CN201811579056 A CN 201811579056A CN 109714202 A CN109714202 A CN 109714202A
Authority
CN
China
Prior art keywords
client
host process
management platform
reason
message
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201811579056.1A
Other languages
Chinese (zh)
Other versions
CN109714202B (en
Inventor
徐冠群
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Zhengzhou Yunhai Information Technology Co Ltd
Original Assignee
Zhengzhou Yunhai Information Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Zhengzhou Yunhai Information Technology Co Ltd filed Critical Zhengzhou Yunhai Information Technology Co Ltd
Priority to CN201811579056.1A priority Critical patent/CN109714202B/en
Publication of CN109714202A publication Critical patent/CN109714202A/en
Application granted granted Critical
Publication of CN109714202B publication Critical patent/CN109714202B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Landscapes

  • Debugging And Monitoring (AREA)

Abstract

This application discloses a kind of client off-line reason method of discrimination and concentrating type safety management systems, this method comprises: judging whether to receive heartbeat message within the heart time period;It if not, determining client off-line, and is network failure or forced shutdown by offline reason preliminary judgement;Monitoring process circulation reads heart time file, and judges at the time of heart time file record and whether the difference at current time is greater than a heart beat cycle;If so, determining that not receiving heartbeat successfully replys;Monitoring process collects host process information and is sent to management platform;According to host process information update client off-line reason.Concentrating type safety management system includes management platform and multiple client, and management platform includes database, communication part, Web server and main program module, and client includes host process module and monitoring process module.It can be improved the investigation efficiency of client off-line reason by the application, improve the communication stability between management platform and client.

Description

A kind of client off-line reason method of discrimination and concentrating type safety management system
Technical field
This application involves safety management technology fields, more particularly to a kind of client off-line reason method of discrimination and cluster Formula safety management system.
Background technique
In safety management system, information security increasingly attracts people's attention.Traditional security software is generally installed In separate unit resource, such as on single computer, server or intelligent terminal, security strategy is configured in single computer and is looked into See executive condition.With the development of big data and cloud computing, security software gradually develops to clustering direction, the safety of clustering Software mainly includes management platform and client, and management platform is used for management client, and client is for being responsible for specific safe plan The feedback of execution slightly and policy execution result.
In the security software of clustering, client can normal operation and be connected to management platform on, for system Stable operation is very important.Under general application scenarios, it is reliable for managing the network between platform and client, but It is the communication network for certain specific application scenarios, such as between farther away distributed terminal, client and management platform Network is sometimes insecure.When communication network is unreliable, it may appear that client off-line judges the offline original of client Cause, and then continued with according to offline reason, it is an important problem.
In current clustering security software, after management platform discovery client off-line, just management of the pause to client, Malfunction elimination is carried out in client, management of the restarting management platform to client after troubleshooting.
However, at present in the investigation method of client off-line reason, due to need interrupt management platform and client it Between communication, carry out line under check, check low efficiency, influence the normal operation of security software, be unfavorable for the peace to whole system Full guard.
Summary of the invention
It is existing to solve this application provides a kind of client off-line reason method of discrimination and concentrating type safety management system The investigation low efficiency of client off-line reason, influence security software are operated normally and are unfavorable in technology the peace of whole system The problem of full guard.
In order to solve the above-mentioned technical problem, the embodiment of the present application discloses following technical solution:
A kind of client off-line reason method of discrimination is applied in concentrating type safety management system, the concentrating type safety It include that management platform and multiple client, the client are installed on the computer for needing to carry out safeguard protection in management system On, the management stage+module passes through messaging bus between management platform and the client on an independent computer It connects, is provided with host process and monitoring process in the client, which comprises
Judge to manage the heartbeat message whether platform receives client within the period 1, the period 1 is primary The normal heartbeat period;
It if not, determining client off-line, and is network failure or forced shutdown by client off-line reason preliminary judgement;
Monitoring process circulation reads the heart time file being stored in host process, and judges in the heart time file At the time of record and whether the difference at current time is greater than the period 1, and the heart time file is replied for record management platform At the time of client heartbeat success;
If so, the heartbeat that judgement client does not receive management platform is successfully replied;
Monitoring process collects host process information every second round, and the host process information is sent to management platform, The second round is that monitoring process carries out the adjacent time interval monitored twice to host process, and the host process information includes: The occupied CPU size of host process, host process memory size, the Thread Count of host process, the handle count of host process and host process Whether have that the generation moment of dump file and the dump file records in the heart time file under software catalog when After quarter;
According to the host process information update client off-line reason.
Optionally, before judging to manage the heartbeat message whether platform receives client within the period 1, the side Method further include:
Client sends heartbeat message to management platform by messaging bus;
When management platform receives the heartbeat message by messaging bus, a heartbeat is returned to client and is successfully replied;
Client receives the heartbeat by messaging bus when successfully replying, and the heart is written at the time of heartbeat is successfully replied Jump time file.
Optionally, the method that the host process information is sent to management platform by monitoring process, specifically:
The host process information is sent to management platform by messaging bus by monitoring process in the specific format, described specific Format includes: message queue title or command word.
It is optionally, described according to the host process information update client off-line reason, comprising:
Judge whether host process is running;
If host process is out of service, the generation of dump file is judged whether there is;
If there is dump file, offline reason is updated to software crash;
If there is no dump file, offline reason is updated to other reasons and is closed;
If host process is being run, judge the parameter in the host process information whether in normal parameters;
If so, offline reason is updated to other reasons;
If not, offline reason is updated to software anomaly.
Optionally, the method also includes:
When FTP client FTP actively shuts down, client sends first message to management platform by messaging bus, described It include: that system is closed or restarted in first message;
When client stops client main program by management tool manually, client is flat to management by messaging bus Platform sends second message, includes: that software is turned off manually in the second message.
Optionally, before according to the host process information update client off-line reason, the method also includes:
Judge to manage whether platform receives first message transmitted by client;
If so, offline reason is updated to system closing or is restarted;
If not, judging to manage whether platform receives second message transmitted by client;
If management platform receives second message transmitted by client, offline reason is updated to software and is turned off manually.
A kind of concentrating type safety management system includes management platform and multiple clients in the concentrating type safety management system End, the client are installed on the computer for needing to carry out safeguard protection, and the management stage+module is in an independent meter It on calculation machine, is connected between management platform and the client by messaging bus, the management platform includes: database, communication Component, Web server and main program module include host process module and monitoring process module in the client;
The main program module, the heartbeat letter for whether receiving within the period 1 client for judging to manage platform Breath, and, when management platform does not receive the heartbeat message of client within the period 1, determine client off-line, and It is network failure or forced shutdown by client off-line reason preliminary judgement, the period 1 is a normal heartbeat period;
The host process module, for running all business functions of client or logic;
The monitoring process module for recycling the heart time file for reading and being stored in host process module, and judges At the time of record in the heart time file and whether the difference at current time is greater than the period 1, and, when the heartbeat Between when being greater than the period 1 with the difference at current time at the time of record in file, determine that client does not receive the heartbeat for managing platform Success is replied, at the time of the heart time file replys client heartbeat success for record management platform;
The monitoring process module is also used to, and the host process information of host process module is collected every second round, and by institute It states host process information and is sent to management platform, the second round is that monitoring process module is carried out continuously twice host process module The time interval of monitoring;
The main program module is also used to, according to the host process information update client off-line reason.
Optionally, the main program module includes:
Judging unit, the heartbeat message for whether receiving within the period 1 client for judging to manage platform;
Offline reason preliminary judgement unit, for not receiving the heartbeat of client within the period 1 when management platform When information, client off-line is determined, and be network failure or forced shutdown by client off-line reason preliminary judgement;
Offline reason updating unit, for according to the host process information update client off-line reason.
Optionally, the offline reason updating unit includes:
First judgment sub-unit, for judging whether host process is carrying out;
Second judgment sub-unit, for when host process is out of service, judging whether there is the generation of dump file;
Third judgment sub-unit, for when host process at runtime, judge parameter in the host process information whether In normal parameters;
Subelement is updated, for when the second judgment sub-unit is determined with dump file, offline reason to be updated to software Offline reason is updated to other reasons and closed, when third is sentenced by collapse when the second judgment sub-unit determines no dump file When disconnected subelement determines that the parameter in the host process information is in normal parameters, offline reason is updated to other originals Cause, and, it, will be offline when third judgment sub-unit determines the parameter in the host process information not in normal parameters Reason is updated to software anomaly.
Optionally, in the client further include:
First message sending module, for being sent out to management platform by messaging bus when FTP client FTP actively shuts down First message is sent, includes: that system is closed or restarted in the first message;
Second message sending module, for passing through when client stops client main program by management tool manually Messaging bus sends second message to management platform, includes: that software is turned off manually in the second message.
The technical solution that embodiments herein provides can include the following benefits:
The application provides a kind of client off-line reason method of discrimination, and this method is applied to concentrating type safety management system In, this method first determines whether management platform receives the heartbeat message of client within a normal heartbeat period, if It is no, client off-line is determined, and be network failure or forced shutdown by client off-line reason preliminary judgement, secondly by client End monitoring process circulation read heart time file, and judge in heart time file record at the time of and current time difference Whether the period 1 is greater than, if so, the heartbeat that judgement client does not receive management platform is successfully replied, that is, last After subnormal heartbeat, client host process is abnormal.Then monitoring process collects host process every the time of second round Information, and the host process information collected is sent to management platform, management platform according to host process information update client from Line reason.The application is monitored host process by the monitoring process run in client, can be in time by host process Exception is uploaded to management platform, and management platform judges automatically client off-line original according to the information that client control process is uploaded Cause can greatly improve the investigation efficiency of client off-line reason.And the method in the application can carry out online, therefore not The normal operation for influencing security software is conducive to improve the communication stability between management platform and client.Management platform is adopted The mode of offline reason is tentatively judged and updated with offline reason, it is final to determine client off-line reason, client can be combined Host process information carries out more accurately judgement, is conducive to the accuracy and reliability for improving offline reason judgement.In addition, this Shen Please in run on the monitoring process of client and belong to Lightweight Process, service logic is few, stable, is conducive to quasi- in time Host process information really is sent to management platform by messaging bus, the standard of client off-line reason judgement can be further increased True property.
The application also provides a kind of concentrating type safety management system, which mainly includes management platform and multiple clients End, wherein being connected between management platform and client by messaging bus, management platform includes: database, communication part, Web Server and main program module include host process module and monitoring process module in client.Concentrating type in the present embodiment Safety management system is capable of deciding whether other than it can carry out normal logic business to client by main program module The heartbeat message of client is received within a normal heartbeat period, to judge whether client is offline, as judgement visitor It is network failure or forced shutdown by client off-line reason preliminary judgement when family end is offline.Secondly, monitoring process Module cycle At the time of reading the heart time file that is stored in host process module, and judge to record in heart time file and current time Difference whether be greater than the period 1, if it is determine client do not receive management platform heartbeat successfully reply, monitoring process is every Host process information is collected every the time of second round, and host process information is sent to management platform.Host process module is also used to According to host process information update client off-line reason.The application, can by the way that a monitoring process module is arranged in the client The host process module of client is monitored in time, and management platform will be uploaded to extremely, manages platform according to monitoring process The information that module is uploaded carries out preliminary judgement and update to client off-line reason respectively, to more accurately determine client The offline reason at end, and then improve the communication stability between management platform and client.In addition, monitoring process mould in the application What block was carried out is a kind of Lightweight Process, and occupied system resource is few, and its own service logic is few, so that monitoring process The reliability of module is higher, is conducive to send host process information to management platform by messaging bus in time and accurately, can Further increase the accuracy of client off-line reason judgement.
It should be understood that above general description and following detailed description be only it is exemplary and explanatory, not The application can be limited.
Detailed description of the invention
The drawings herein are incorporated into the specification and forms part of this specification, and shows the implementation for meeting the application Example, and together with specification it is used to explain the principle of the application.
In order to illustrate the technical solutions in the embodiments of the present application or in the prior art more clearly, to embodiment or will show below There is attached drawing needed in technical description to be briefly described, it should be apparent that, for those of ordinary skill in the art Speech, without creative efforts, is also possible to obtain other drawings based on these drawings.
Fig. 1 is a kind of flow diagram of client off-line reason method of discrimination provided by the embodiment of the present application;
Fig. 2 is the realization process schematic of step S14 in the embodiment of the present application;
Fig. 3 is the information transfering relation schematic diagram managed between platform and client in the embodiment of the present application;
Fig. 4 is a kind of structural schematic diagram of concentrating type safety management system provided by the embodiment of the present application.
Specific embodiment
In order to make those skilled in the art better understand the technical solutions in the application, below in conjunction with the application reality The attached drawing in example is applied, the technical scheme in the embodiment of the application is clearly and completely described, it is clear that described implementation Example is merely a part but not all of the embodiments of the present application.Based on the embodiment in the application, this field is common The application protection all should belong in technical staff's every other embodiment obtained without making creative work Range.
Client off-line reason method of discrimination is mainly used in concentrating type safety management system in the present embodiment.Usual one It include management platform and two subsystem of client in a concentrating type safety management system.Management platform has one, general to install In on individual machine, for being managed collectively client;Client has multiple, is separately mounted to the meter for needing to carry out safeguard protection On calculation machine, it is responsible for the execution of specific security strategy and the feedback of policy execution result.Same luck in the client of the present embodiment Go host process and monitoring process, host process runs all business functions of client or logic, full-featured but stability Relatively low, monitoring process is the process of a lightweight for being monitored to host process, and service logic is few, stability and Reliability comparotive is high.
Client in the present embodiment is connect by messaging bus with management platform, that is, passes through network and management platform Communication connection.Client needs to be registered to when in use on management platform, and after the completion of registration, management platform passes through web interface Mode shows the list of all chartered clients, administrator by web interface to client configure security strategy and It audits.The client come up is registered for each, manages its presence of platform maintenance, client presence includes It is online or offline, when offline, offline reason is tentatively understood from management platform end using the method in the application, to facilitate positioning to ask Topic diagnoses rapidly.
In the present embodiment, client sends the very short heartbeat message of a content, pipe to management platform at regular intervals After platform receives heartbeat message, it is believed that the client is online;Platform is managed within a period of time does not receive certain When the heartbeat message of client, then it is assumed that when the client offline.Meanwhile the message that client is sent to management platform, pipe Platform can provide the very short response of content, and when client can not receive response message, client determines it itself is offline 's.In the present embodiment default management platform and messaging bus stable operation always, be not in collapse, network disconnect etc. feelings Condition.And the channel between default management platform and messaging bus is stable operation, is not in disconnection or the feelings for losing data Condition.
The application in order to better understand explains in detail presently filed embodiment with reference to the accompanying drawing.
Embodiment one
Referring to Fig. 1, Fig. 1 is a kind of process signal of client off-line reason method of discrimination provided by the embodiment of the present application Figure.As shown in Figure 1, client off-line reason method of discrimination mainly comprises the following processes in the present embodiment:
S04: judge to manage the heartbeat message whether platform receives client within the period 1.Wherein, the period 1 For a normal heartbeat period.
S05: if not, determining client off-line, and being network failure or pressure by client off-line reason preliminary judgement Shutdown.
If management platform receives the heartbeat message of client within a normal heartbeat period, determine that client exists Line.
By above step S04 and S05 it is found that first by determining whether management platform receives client within the period 1 The heartbeat message at end judges whether client is offline, starts to analyze offline reason when determining client off-line.It is flat due to managing Platform and client do not know mutually IP address, and the case where there may be subnet, when client off-line, for client For, it is that can not be distinguished because device network failure causes the reasons such as offline or unexpected power down to lead to forced shutdown, It therefore, is network failure or forced shutdown by client off-line reason preliminary judgement.
Further, the present embodiment is before step S04 further include:
S01: client sends heartbeat message to management platform by messaging bus.
It manages platform in the present embodiment to connect with client by messaging bus, that is, management platform and client connect It is connected on messaging bus, sends message to messaging bus and receives message from messaging bus, manage platform without normal direction client master It is dynamic to initiate request, it can only be replied according to the heartbeat message of client.
S02: when management platform receives heartbeat message by messaging bus, a heartbeat is returned to client and is successfully replied.
S03: client receives heartbeat by messaging bus when successfully replying, and the heart is written at the time of heartbeat is successfully replied Jump time file.
When client, which receives heartbeat, successfully replys, a heart time file is updated, this successful heartbeat is returned Heart time file is written in the multiple time, and primary normal heartbeat is completed.Wherein, heart time file is returned for record management platform At the time of multiple client heartbeat success.
With continued reference to Fig. 1 it is found that for network failure or forcing to close by client off-line reason preliminary judgement by step S05 After machine, when executing step S06: the heart time file that monitoring process circulation reading is stored in host process, and judging heartbeat Between at the time of record in file and whether the difference at current time is greater than the period 1.
S07: if so, the heartbeat that judgement client does not receive management platform is successfully replied.
As soon as if with the difference at current time greater than time normal heartbeat period at the time of record in heart time file, It is that playing the time that current time stops at the time of record from heart time file is more than a normal heartbeat period, illustrates visitor The heartbeat that family end does not receive management platform within a normal heartbeat period is successfully replied.If recorded in heart time file At the time of and current time difference be less than or equal to a normal heartbeat period, determine client can be normally received management platform Heartbeat successfully reply.
When the heartbeat that client does not receive management platform is successfully replied, execute step S08: monitoring process is every second week Phase collects host process information, and host process information is sent to management platform.Wherein, second round is monitoring process to host process Carry out the adjacent time interval monitored twice.
In the present embodiment client other than operating normally host process, also operation monitoring process, monitoring process will it is main into The method that journey information is sent to management platform, specifically:
Host process information is sent to management platform, specific format packet by messaging bus by monitoring process in the specific format It includes: message queue title or command word.Messaging bus can use message queue software, such as: RabbitMQ etc..It is communicating When, the message content on messaging bus has specific format, such as: can using the fields such as message queue title or command word come Distinguish different message categories.
The present embodiment carries out circularly monitoring to host process by the monitoring process of client, can be in time by the different of host process It often is uploaded to management platform, so as to greatly improve the investigation efficiency of client off-line reason.Moreover, running on client Monitoring process belongs to Lightweight Process, and service logic is few, stable, be conducive in time and accurately by messaging bus to It manages platform and sends host process information, the accuracy of client off-line reason judgement can be further increased.
Host process information includes: the occupied CPU size of host process, host process memory size, host process in the present embodiment Thread Count, host process handle count and host process software catalog under when whether having the generation of dump file and dump file After being engraved at the time of record in heart time file.It should be noted that judging whether there is dump under host process software catalog When file, the range that the dump file judged generates is: caused by after at the time of recorded in heart time file Dump file, it may be assumed that the dump file generated after at the time of recorded in heart time file indicates the normal heart of last time After jump, collapse or abnormal occurs for client host process.
The size of period 1 and second round in the present embodiment, are configured according to actual application scenarios, such as: it needs Frequent updating monitored results are wanted, what second round was arranged can be smaller.
S14: according to host process information update client off-line reason.
Managed in the present embodiment the client off-line reason that is determined of platform specifically include that network failure or forced shutdown, System is closed or is restarted, software is turned off manually, software crash, software anomaly, other reasons are closed and other reasons.
Referring to fig. 2 it is found that step S14 is comprised the following processes:
S141: judge whether host process is running;
If host process is out of service, step S142 is executed: judging whether there is the generation of dump file;
If there is dump file, executes step S143: offline reason is updated to software crash;
Otherwise, it if there is no dump file, executes step S144: offline reason being updated to other reasons and is closed;
If host process is being run, executes step S145: judging the parameter in host process information whether in normal parameter model In enclosing;
If the parameter in host process information in normal parameters, executes step S146: offline reason is updated to Other reasons;
If the parameter in host process information not in normal parameters, executes step S147: offline reason is updated For software anomaly.
When software anomaly, correlation performance parameters can exceed abnormal ranges, while sending and receiving for heartbeat can also generate Obstacle will lead to client off-line.
Further, in the client off-line reason method of discrimination of the present embodiment further include:
When FTP client FTP actively shuts down, client sends first message to management platform by messaging bus, wherein It include: that system is closed or restarted in first message.
When client stops client main program by management tool manually, client is flat to management by messaging bus Platform sends second message, includes: wherein that software is turned off manually in second message.
Client host process can capture the off signal of FTP client FTP in the present embodiment, when FTP client FTP actively closes When machine, host process sends first message to management platform by messaging bus, and illustrates client off-line original in first message Cause are as follows: system is closed or restarted;When user by client-side management tool stop client host process manually when, client master into Journey sends second message to management platform by messaging bus, and illustrates client off-line reason in second message are as follows: closes manually It closes.
Further, before step S14, client off-line reason method of discrimination further include:
S10: judge to manage whether platform receives first message transmitted by client;
If receiving first message transmitted by client, S11 is thened follow the steps: offline reason being updated to system and is closed Or restart;Otherwise, it executes step S12: judging to manage whether platform receives second message transmitted by client;If receiving visitor Second message transmitted by the end of family, thens follow the steps S13: offline reason being updated to software and is turned off manually.If do not received Second message transmitted by client, thens follow the steps S14.
Certainly, step S12 can also be first carried out in the present embodiment, disappeared if not receiving transmitted by client second Breath executes step S10, no to then follow the steps S14 if receiving first message transmitted by client thens follow the steps S11. That is: when not receiving first message transmitted by client and second message, execute step S14, first according to client it is direct on The offline reason passed updates client off-line reason, then according to client host process information update client off-line reason.
Below by taking a practical application scene as an example, the method in the present embodiment is described in detail.It, can by Fig. 3 referring to Fig. 3 Know, management platform is communicated with messaging bus, as shown in (1) in Fig. 3;Client host process and monitoring process and messaging bus Communication, as shown in (2) in Fig. 3.In communication, the message content in messaging bus has specific format, and client sends specific When the message of format, the only management specific module of platform can receive and process the information, conversely, disappearing transmitted by management platform Breath is also received and processed by the particular module of client.That is: the particular module for managing platform is matched with the corresponding module of client, Externally managing between platform and client has virtual channel.In Fig. 3, channel virtual in this way uses dotted arrow.
When normal work, the heartbeat sending module of client host process sends heartbeat to the heartbeat receiving module of management platform Information, as shown in (3) in Fig. 3;After the heartbeat receiving module of management platform receives heartbeat message, a success message is returned, As shown in (4) in Fig. 3, and the presence for updating client is " online ", if being presence, not more Newly.If not receiving heartbeat message for a period of time continuously, then it is assumed that the presence of client is " offline ", and fixes tentatively and recognize To be offline the reason is that " network failure or forced shutdown ".When client, which receives heartbeat, successfully replys, then a heartbeat is updated This document is written in this successful heartbeat turnaround time by time file, and primary normal heartbeat is completed.
In addition client runs monitoring process, and monitoring is run always and cycle detection heart time file, if heartbeat The difference of the time and current time that record inside time file have been more than certain threshold value, then it is assumed that client is not received for a long time Successful heartbeat to management platform is replied, and monitoring process will do it information search at this time, as shown in (5) in Fig. 3.Collect host process Whether CPU, memory size, Thread Count, the handle count of occupancy have newly generated dump file under host process software catalog, and new After range is the time recorded in heart time file at the time of the dump file of generation, that is, think the normal heart of last time After jump, client host process is collapsed or exception.
After having collected information, the information that the information collected is sent to management platform by monitoring process in the specific format is received Module, as shown in (6) in Fig. 3.After the information receiving module of management platform receives the information, it is analyzed and processed, after processing The reason of updating client off-line, specifically more new strategy are as follows:
A) the information uploaded first according to client judges whether it is because host process is turned off manually or restarts system/pass Caused by closing system, if it is directly updating reason is " system is closed or restarted " or " software is turned off manually ".
B) otherwise continue to check whether host process is running, if do not run, judge whether there is dump file, if Have, then updating offline reason is " software crash ", if not having dump file, updating offline reason is that " other reasons close It closes ";If host process software is being run, judge that CPU, memory, handle count, Thread Count of the host process for including in information etc. are joined Whether number is within normal range (NR), if having exceeded normal range (NR), updating offline reason is " software anomaly ";If these are joined For number within normal range (NR), then updating offline reason is " other reasons ".
Embodiment two
The application also provides a kind of concentrating type safety management system, include in concentrating type safety management system management platform and Multiple client, client are installed on the computer for needing to carry out safeguard protection, manage stage+module in an independent meter On calculation machine, manages and connected between platform and client by messaging bus.
On Fig. 1-embodiment illustrated in fig. 3 basis referring to fig. 4, Fig. 4 is a kind of collection provided by the embodiment of the present application The structural schematic diagram of group's formula safety management system.As shown in Figure 4, platform is managed in the present embodiment includes: database, communication group Part, Web server and main program module include host process module and monitoring process module in client.
Wherein, main program module is used to judge to manage the heartbeat letter whether platform receives client within the period 1 Breath, and, when management platform does not receive the heartbeat message of client within the period 1, determine client off-line, and It is network failure or forced shutdown by client off-line reason preliminary judgement, wherein the period 1 is a normal heartbeat period; Host process module is for running all business functions of client or logic;Monitoring process module for recycle read be stored in it is main into Heart time file in journey module, and judge at the time of record in heart time file and whether the difference at current time is greater than the One period, and, at the time of record in heart time file and when the difference at current time is greater than the period 1, determine client The heartbeat for not receiving management platform is successfully replied, and heart time file is successful for the reply client heartbeat of record management platform Moment;Monitoring process module is also used to, and the host process information of host process module is collected every second round, and by host process information It is sent to management platform, second round is that monitoring process module is carried out continuously the time interval monitored twice to host process module; Main program module is also used to according to host process information update client off-line reason.
Further, host process module includes: that judging unit, offline reason preliminary judgement unit and offline reason update list Member.Wherein, judging unit is used to judge whether management platform to receive the heartbeat message of client within the period 1, first week Phase is a normal heartbeat period;Offline reason preliminary judgement unit is used to not receive within the period 1 when management platform When the heartbeat message of client, client off-line is determined, and be network failure or pressure by client off-line reason preliminary judgement Shutdown;Offline reason updating unit, for according to host process information update client off-line reason.
Wherein, offline reason updating unit includes: the first judgment sub-unit, the second judgment sub-unit, third judgement again Unit and update subelement.Wherein, the first judgment sub-unit is for judging whether host process is carrying out;Second judgment sub-unit It is generated for when host process is out of service, judging whether there is dump file;Third judgment sub-unit is used to transport when host process When row, judge the parameter in host process information whether in normal parameters;Subelement is updated to be used for when the second judgement is single When member is determined with dump file, offline reason is updated to software crash, when the judgement of the second judgment sub-unit does not have dump file When, offline reason is updated to other reasons and is closed, when third judgment sub-unit determines the parameter in host process information normal When in parameter area, offline reason is updated to other reasons, and, when third judgment sub-unit determines in host process information When parameter is not in normal parameters, offline reason is updated to software anomaly.It is used for it is, updating subelement according to the The judging result of two judging units and third judging unit updates corresponding offline reason respectively.
It further, further include first message sending module and second message sending module in client, wherein first disappears Cease sending module be used for when FTP client FTP actively shut down, by messaging bus to manage platform transmission first message, first It include: that system is closed or restarted in message;Second message sending module is used to stop visitor manually by management tool when client When the main program of family end, second message is sent to management platform by messaging bus, includes: that software is turned off manually in second message.
The working principle and working method of concentrating type safety management system in the present embodiment, in Fig. 1-implementation shown in Fig. 3 It has been elaborated in example, the mutual reference of client between the two, details are not described herein.
The above is only the specific embodiment of the application, is made skilled artisans appreciate that or realizing this Shen Please.Various modifications to these embodiments will be apparent to one skilled in the art, as defined herein General Principle can be realized in other embodiments without departing from the spirit or scope of the application.Therefore, the application It is not intended to be limited to the embodiments shown herein, and is to fit to and the principles and novel features disclosed herein phase one The widest scope of cause.

Claims (10)

1. a kind of client off-line reason method of discrimination is applied in concentrating type safety management system, the concentrating type bursting tube It include that management platform and multiple client, the client are installed on the computer for needing to carry out safeguard protection in reason system, The management stage+module is on an independent computer, which is characterized in that passes through between management platform and the client Messaging bus connects, and is provided with host process and monitoring process in the client, which comprises
Judge to manage the heartbeat message whether platform receives client within the period 1, the period 1 is one subnormal Heart beat cycle;
It if not, determining client off-line, and is network failure or forced shutdown by client off-line reason preliminary judgement;
Monitoring process circulation reads the heart time file being stored in host process, and judges to record in the heart time file At the time of and the difference at current time whether be greater than the period 1, the heart time file replys client for record management platform At the time of holding heartbeat success;
If so, the heartbeat that judgement client does not receive management platform is successfully replied;
Monitoring process collects host process information every second round, and the host process information is sent to management platform, described Second round is that monitoring process carries out the adjacent time interval monitored twice to host process, the host process information include: it is main into The occupied CPU size of journey, host process memory size, the Thread Count of host process, the handle count of host process and host process software At the time of whether thering is the generation moment of dump file and the dump file to record under catalogue in the heart time file it Afterwards;
According to the host process information update client off-line reason.
2. a kind of client off-line reason method of discrimination according to claim 1, which is characterized in that judgement, which manages platform, is Before the no heartbeat message for receiving client within the period 1, the method also includes:
Client sends heartbeat message to management platform by messaging bus;
When management platform receives the heartbeat message by messaging bus, a heartbeat is returned to client and is successfully replied;
Client receives the heartbeat by messaging bus when successfully replying, when heartbeat being written at the time of heartbeat is successfully replied Between file.
3. a kind of client off-line reason method of discrimination according to claim 1, which is characterized in that monitoring process will be described The method that host process information is sent to management platform, specifically:
The host process information is sent to management platform, the specific format by messaging bus by monitoring process in the specific format It include: message queue title or command word.
4. a kind of client off-line reason method of discrimination according to claim 1 to 3, which is characterized in that described According to the host process information update client off-line reason, comprising:
Judge whether host process is running;
If host process is out of service, the generation of dump file is judged whether there is;
If there is dump file, offline reason is updated to software crash;
If there is no dump file, offline reason is updated to other reasons and is closed;
If host process is being run, judge the parameter in the host process information whether in normal parameters;
If so, offline reason is updated to other reasons;
If not, offline reason is updated to software anomaly.
5. a kind of client off-line reason method of discrimination according to claim 1, which is characterized in that the method is also wrapped It includes:
When FTP client FTP actively shuts down, client by messaging bus to management platform send first message, described first It include: that system is closed or restarted in message;
When client stops client main program by management tool manually, client is sent out by messaging bus to management platform Second message is sent, includes: that software is turned off manually in the second message.
6. a kind of client off-line reason method of discrimination according to claim 5, which is characterized in that according to the host process Before information update client off-line reason, the method also includes:
Judge to manage whether platform receives first message transmitted by client;
If so, offline reason is updated to system closing or is restarted;
If not, judging to manage whether platform receives second message transmitted by client;
If management platform receives second message transmitted by client, offline reason is updated to software and is turned off manually.
It include management platform and multiple clients in the concentrating type safety management system 7. a kind of concentrating type safety management system End, the client are installed on the computer for needing to carry out safeguard protection, and the management stage+module is in an independent meter On calculation machine, which is characterized in that connected between management platform and the client by messaging bus, the management platform includes: Database, communication part, Web server and main program module include host process module and monitoring process in the client Module;
The main program module, the heartbeat message for whether receiving within the period 1 client for judging to manage platform, with And when managing platform and not receiving the heartbeat message of client within the period 1, judgement client off-line, and by client Holding offline reason preliminary judgement is network failure or forced shutdown, and the period 1 is a normal heartbeat period;
The host process module, for running all business functions of client or logic;
The monitoring process module, for recycling the heart time file for reading and being stored in host process module, and described in judgement At the time of record in heart time file and whether the difference at current time is greater than the period 1, and, when the heart time text At the time of record in part and when the difference at current time is greater than the period 1, determine that client does not receive the heartbeat success of management platform It replys, at the time of the heart time file replys client heartbeat success for record management platform;
The monitoring process module is also used to, and the host process information of host process module is collected every second round, and by the master Progress information is sent to management platform, and the second round is carried out continuously host process module for monitoring process module and monitors twice Time interval;
The main program module is also used to, according to the host process information update client off-line reason of host process module.
8. according to a kind of concentrating type safety management system according to claim 7, which is characterized in that the main program module Include:
Judging unit, the heartbeat message for whether receiving within the period 1 client for judging to manage platform;
Offline reason preliminary judgement unit, for not receiving the heartbeat message of client within the period 1 when management platform When, determine client off-line, and be network failure or forced shutdown by client off-line reason preliminary judgement;
Offline reason updating unit, for the host process information update client off-line reason according to the host process module.
9. a kind of concentrating type safety management system according to claim 8, which is characterized in that the offline reason updates single Member includes:
First judgment sub-unit, for judging whether host process is carrying out;
Second judgment sub-unit, for when host process is out of service, judging whether there is the generation of dump file;
Whether third judgment sub-unit judges the parameter in the host process information normal for working as host process at runtime In parameter area;
Subelement is updated, for when the second judgment sub-unit is determined with dump file, offline reason to be updated to software crash, When the second judgment sub-unit determines no dump file, offline reason is updated to other reasons and is closed, when third judges son When unit determines that the parameter in the host process information is in normal parameters, offline reason is updated to other reasons, with And when third judgment sub-unit determines the parameter in the host process information not in normal parameters, by offline reason It is updated to software anomaly.
10. according to a kind of concentrating type safety management system any in claim 7-9, which is characterized in that the client In end further include:
First message sending module, for when FTP client FTP actively shut down, by messaging bus to managing platform transmission the One message includes: that system is closed or restarted in the first message;
Second message sending module, for passing through message when client stops client main program by management tool manually Bus sends second message to management platform, includes: that software is turned off manually in the second message.
CN201811579056.1A 2018-12-21 2018-12-21 Client off-line reason distinguishing method and cluster type safety management system Active CN109714202B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201811579056.1A CN109714202B (en) 2018-12-21 2018-12-21 Client off-line reason distinguishing method and cluster type safety management system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201811579056.1A CN109714202B (en) 2018-12-21 2018-12-21 Client off-line reason distinguishing method and cluster type safety management system

Publications (2)

Publication Number Publication Date
CN109714202A true CN109714202A (en) 2019-05-03
CN109714202B CN109714202B (en) 2021-10-08

Family

ID=66257303

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201811579056.1A Active CN109714202B (en) 2018-12-21 2018-12-21 Client off-line reason distinguishing method and cluster type safety management system

Country Status (1)

Country Link
CN (1) CN109714202B (en)

Cited By (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110221928A (en) * 2019-06-11 2019-09-10 Oppo广东移动通信有限公司 Information recording method, device, terminal and storage medium
CN111162967A (en) * 2019-12-25 2020-05-15 北京东土科技股份有限公司 Offline court-opening processing method, device, terminal, server and storage medium
CN111596940A (en) * 2020-05-19 2020-08-28 杭州视联动力技术有限公司 Version upgrading method and device, electronic equipment and storage medium
CN112073265A (en) * 2020-08-31 2020-12-11 帷幄匠心科技(杭州)有限公司 Internet of things monitoring method and system based on distributed edge computing
CN112749142A (en) * 2019-10-31 2021-05-04 上海哔哩哔哩科技有限公司 Handle management method and system
WO2021128915A1 (en) * 2019-12-25 2021-07-01 苏宁云计算有限公司 Smart device monitoring method and apparatus
CN113296967A (en) * 2020-02-21 2021-08-24 西安诺瓦星云科技股份有限公司 Process management method, device and system based on embedded operating system
CN113301063A (en) * 2020-02-24 2021-08-24 中国移动通信集团上海有限公司 Method, device and equipment for determining equipment information of Internet of things and storage medium
CN115102887A (en) * 2022-07-15 2022-09-23 济南浪潮数据技术有限公司 Cluster node monitoring method and related equipment
CN115190160A (en) * 2022-05-25 2022-10-14 杭州脸脸会网络技术有限公司 Screen-off monitoring method and device for screen equipment, electronic device and storage medium
CN113296967B (en) * 2020-02-21 2024-06-04 西安诺瓦星云科技股份有限公司 Process management method, device and system based on embedded operating system

Citations (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101552740A (en) * 2009-05-14 2009-10-07 腾讯科技(北京)有限公司 Instant communication system, clients, server and method for judging on-line state
CN101777020A (en) * 2009-12-25 2010-07-14 北京讯鸟软件有限公司 Fault tolerance method and system used for distributed program
CN102647314A (en) * 2012-05-16 2012-08-22 深圳市乐唯科技开发有限公司 Client side on-line state judgment method and system
CN102937930A (en) * 2012-09-29 2013-02-20 重庆新媒农信科技有限公司 Application program monitoring system and method
US20130124607A1 (en) * 2011-11-15 2013-05-16 International Business Machines Corporation Diagnostic heartbeating in a distributed data processing environment
CN103607297A (en) * 2013-11-07 2014-02-26 上海爱数软件有限公司 Fault processing method of computer cluster system
CN104298567A (en) * 2014-10-31 2015-01-21 亚信科技(南京)有限公司 System and method for guaranteeing message processing consistency
CN105357038A (en) * 2015-10-26 2016-02-24 北京百度网讯科技有限公司 Method and system for monitoring virtual machine cluster
CN105959402A (en) * 2016-06-21 2016-09-21 上海卓易云汇智能技术有限公司 Method for solving network push
CN106209482A (en) * 2016-09-13 2016-12-07 郑州云海信息技术有限公司 A kind of data center monitoring method and system
US20170257226A1 (en) * 2016-03-04 2017-09-07 Wireless Input Technology, Inc. Method for Detecting the Status of a Home Automation Device
CN108566312A (en) * 2017-12-29 2018-09-21 美的集团股份有限公司 Off-line checking method, device and computer readable storage medium

Patent Citations (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101552740A (en) * 2009-05-14 2009-10-07 腾讯科技(北京)有限公司 Instant communication system, clients, server and method for judging on-line state
CN101777020A (en) * 2009-12-25 2010-07-14 北京讯鸟软件有限公司 Fault tolerance method and system used for distributed program
US20130124607A1 (en) * 2011-11-15 2013-05-16 International Business Machines Corporation Diagnostic heartbeating in a distributed data processing environment
CN102647314A (en) * 2012-05-16 2012-08-22 深圳市乐唯科技开发有限公司 Client side on-line state judgment method and system
CN102937930A (en) * 2012-09-29 2013-02-20 重庆新媒农信科技有限公司 Application program monitoring system and method
CN103607297A (en) * 2013-11-07 2014-02-26 上海爱数软件有限公司 Fault processing method of computer cluster system
CN104298567A (en) * 2014-10-31 2015-01-21 亚信科技(南京)有限公司 System and method for guaranteeing message processing consistency
CN105357038A (en) * 2015-10-26 2016-02-24 北京百度网讯科技有限公司 Method and system for monitoring virtual machine cluster
US20170257226A1 (en) * 2016-03-04 2017-09-07 Wireless Input Technology, Inc. Method for Detecting the Status of a Home Automation Device
CN105959402A (en) * 2016-06-21 2016-09-21 上海卓易云汇智能技术有限公司 Method for solving network push
CN106209482A (en) * 2016-09-13 2016-12-07 郑州云海信息技术有限公司 A kind of data center monitoring method and system
CN108566312A (en) * 2017-12-29 2018-09-21 美的集团股份有限公司 Off-line checking method, device and computer readable storage medium

Cited By (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110221928A (en) * 2019-06-11 2019-09-10 Oppo广东移动通信有限公司 Information recording method, device, terminal and storage medium
CN110221928B (en) * 2019-06-11 2021-06-04 Oppo广东移动通信有限公司 Information recording method, information recording apparatus, terminal, and storage medium
CN112749142A (en) * 2019-10-31 2021-05-04 上海哔哩哔哩科技有限公司 Handle management method and system
CN112749142B (en) * 2019-10-31 2023-09-01 上海哔哩哔哩科技有限公司 Handle management method and system
CN111162967A (en) * 2019-12-25 2020-05-15 北京东土科技股份有限公司 Offline court-opening processing method, device, terminal, server and storage medium
WO2021128915A1 (en) * 2019-12-25 2021-07-01 苏宁云计算有限公司 Smart device monitoring method and apparatus
CN113296967A (en) * 2020-02-21 2021-08-24 西安诺瓦星云科技股份有限公司 Process management method, device and system based on embedded operating system
CN113296967B (en) * 2020-02-21 2024-06-04 西安诺瓦星云科技股份有限公司 Process management method, device and system based on embedded operating system
CN113301063A (en) * 2020-02-24 2021-08-24 中国移动通信集团上海有限公司 Method, device and equipment for determining equipment information of Internet of things and storage medium
CN113301063B (en) * 2020-02-24 2023-02-28 中国移动通信集团上海有限公司 Method, device and equipment for determining equipment information of Internet of things and storage medium
CN111596940B (en) * 2020-05-19 2023-04-07 杭州视联动力技术有限公司 Version upgrading method and device, electronic equipment and storage medium
CN111596940A (en) * 2020-05-19 2020-08-28 杭州视联动力技术有限公司 Version upgrading method and device, electronic equipment and storage medium
CN112073265A (en) * 2020-08-31 2020-12-11 帷幄匠心科技(杭州)有限公司 Internet of things monitoring method and system based on distributed edge computing
CN115190160A (en) * 2022-05-25 2022-10-14 杭州脸脸会网络技术有限公司 Screen-off monitoring method and device for screen equipment, electronic device and storage medium
CN115102887A (en) * 2022-07-15 2022-09-23 济南浪潮数据技术有限公司 Cluster node monitoring method and related equipment

Also Published As

Publication number Publication date
CN109714202B (en) 2021-10-08

Similar Documents

Publication Publication Date Title
CN109714202A (en) A kind of client off-line reason method of discrimination and concentrating type safety management system
Lou et al. Mining dependency in distributed systems through unstructured logs analysis
US11706080B2 (en) Providing dynamic serviceability for software-defined data centers
WO2016188100A1 (en) Information system fault scenario information collection method and system
CN112506702B (en) Disaster recovery method, device, equipment and storage medium for data center
CN108429629A (en) Equipment fault restoration methods and device
CN103905247B (en) Two-unit standby method and system based on multi-client judgment
US7979744B2 (en) Fault model and rule based fault management apparatus in home network and method thereof
CN103812675A (en) Method and system for realizing allopatric disaster recovery switching of service delivery platform
US20130227568A1 (en) Systems and methods involving virtual machine host isolation over a network
CN104391777B (en) Cloud platform and its operation and monitoring method and device based on (SuSE) Linux OS
WO2022048671A1 (en) Method and apparatus for event categorization
CN106130763A (en) Server cluster and be applicable to the database resource group method for handover control of this cluster
KR100943213B1 (en) Fault model and rule based apparatus and its method in a home network
CN113765690A (en) Cluster switching method, system, device, terminal, server and storage medium
CN112231122A (en) APP management method based on heterogeneous communication model and oriented to terminal software platform
CN115378841B (en) Method and device for detecting state of equipment accessing cloud platform, storage medium and terminal
CN114500327B (en) Detection method and detection device for server cluster and computing equipment
WO2022238345A1 (en) Data synchronization in edge computing networks
CN115130112A (en) Quick start-stop method, device, equipment and storage medium
CN107590647A (en) The servo supervisory systems of ship-handling system
CN115037652A (en) Operation monitoring system for background module of sleeve protection system
CN110673710B (en) Server case resetting method, device, equipment and medium
CN113852984A (en) Wireless terminal access monitoring system and method, electronic equipment and readable storage device
CN112134727A (en) Network shutdown operation data exchange method based on container technology

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant