Situation awareness-based business workflow methods, systems, terminals, and storage media
By screening and detecting servers in device groups, identifying abnormal devices, and selecting backup devices based on group tag information, the problem of poor business transfer adaptability in existing technologies is solved, achieving efficient and adaptable business flow and improving system resource utilization.
Patent Information
- Application Number
- CN202411576448.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-06
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-11-06
AI Technical Summary
In existing technologies, the service transfer method involves randomly selecting a device from the normal devices to receive the services from the abnormal device. While this ensures rapid service transfer, it is difficult to guarantee the compatibility between the selected device and the transferred services.
By filtering out the detection server from the device group, the collected data of each device is obtained to identify abnormal devices, and backup devices are determined based on the group label information. The group label information is generated based on the operating condition information and business information, and the business flow of the abnormal device is transferred to the backup device.
It improves system resource utilization, ensures equipment compatibility during business processes, guarantees smooth business operation, and adjusts workflow strategies through real-time monitoring and evaluation to adapt to changes in the risk of abnormal equipment.
Smart Images

Figure CN119676061B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to a business flow method, system, terminal, and storage medium based on situational awareness. Background Technology
[0002] Situational awareness involves perceiving environmental elements within a specific time and space, understanding the meaning of these elements, and ultimately predicting their future development. Utilizing big data analytics, situational awareness can classify, statistically analyze, and comprehensively examine attack events, threat alerts, and attack sources, thereby enhancing the ability to detect, identify, analyze, and respond to security threats from a global perspective.
[0003] Current situational awareness methods primarily involve setting up a dedicated detection server to identify anomalous devices by analyzing data collected from various equipment. To ensure the normal operation of all system services, once a potentially vulnerable anomalous device is identified, its services need to be promptly transferred. Current service transfer methods mainly involve randomly selecting a device from the normal equipment pool to receive services from the anomalous device. While this ensures rapid service transfer, it's difficult to guarantee compatibility between the selected device and the transferred services.
[0004] Therefore, existing technologies still need improvement and development. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide a service transfer method, system, terminal and storage medium based on situational awareness, in order to address the above-mentioned defects of the prior art. The aim is to solve the problem that the service transfer method in the prior art is to randomly select a device from normal devices to receive the service from the abnormal device. Although this can ensure the rapid transfer of services, it is difficult to guarantee the compatibility between the selected device and the transferred service.
[0006] The technical solution adopted by this invention to solve the problem is as follows:
[0007] In a first aspect, embodiments of the present invention provide a service flow method based on situational awareness, the method comprising:
[0008] The detection server is selected from the device group, and the collected data of the remaining devices is obtained through the detection server. The abnormal devices in the device group are identified based on the collected data.
[0009] Obtain the group tag information of each device, and determine the backup device corresponding to the abnormal device based on the group tag information of each device; wherein, the group tag information is generated based on operating condition information and service information;
[0010] The service flow of the faulty device is transferred to the backup device.
[0011] In one implementation, identifying abnormal devices in the device group based on the collected data includes:
[0012] The collected data are classified to obtain several data groups; each data group corresponds to a different data type.
[0013] For each data group, all data contained in the data group are compared, and similar deviation data are identified through the comparison results to obtain cross-sectional analysis data;
[0014] For the collected data of each device, all data contained in the collected data are compared, and the data that deviates from the same device is identified by the comparison results to obtain longitudinal analysis data.
[0015] Abnormal devices in the device group are identified based on the horizontal analysis data and the vertical analysis data.
[0016] In one embodiment, the method for generating the group label information includes:
[0017] Obtain the operating status information and service information corresponding to each device in the device group;
[0018] Input the operating condition information and business information of each device into a pre-established device grouping algorithm;
[0019] The device grouping algorithm groups devices according to their operating conditions and business information, and generates grouping tag information for each device based on the grouping results.
[0020] In one implementation, determining the backup device corresponding to the abnormal device based on the group tag information of each device includes:
[0021] Based on the grouping tag information, devices located in the same group as the abnormal device are selected to obtain several candidate backup devices;
[0022] Based on the service information of the abnormal equipment, determine the number of backup devices;
[0023] For each candidate device, the device idleness is calculated based on the working condition information of the candidate device, the service similarity is calculated based on the service information of the candidate device and the abnormal device, and a comprehensive score is calculated based on the device idleness and the service similarity.
[0024] The candidate devices are sorted according to their comprehensive scores, and backup devices are determined from the candidate devices based on the sorting results and the number of backup devices.
[0025] In one implementation, transferring the service traffic of the faulty device to the backup device includes:
[0026] Based on the service information of the abnormal device, the services are classified to obtain several service sets of different categories;
[0027] Assess the risk level of the abnormal device and the security level corresponding to each of the service sets;
[0028] Based on the risk level of the abnormal device and the security level of each service set, several first service sets to be transferred are determined.
[0029] All of the first service sets are transferred to the backup equipment.
[0030] In one implementation, determining the plurality of first service sets to be transferred based on the risk level of the abnormal device and the security level of each service set includes:
[0031] For each of the aforementioned service sets, determine whether the security level of the service set matches the risk level of the abnormal device;
[0032] If there is no match, then this set of services will be used as the first set of services to be transferred.
[0033] In one embodiment, the method further includes:
[0034] The risk level of the abnormal device is updated in real time;
[0035] If the updated risk level is greater than the original risk level, then based on the updated risk level and the remaining untransferred service set, continue to execute the step of determining several first service sets to be transferred based on the risk level of the abnormal device and the security level of each service set;
[0036] If the updated risk level is lower than the original risk level, then based on the updated risk level and the already transferred service sets, determine several second service sets to be restored; and transfer all second service sets back to the abnormal device.
[0037] Secondly, embodiments of the present invention also provide a situational awareness-based business flow system, the system comprising:
[0038] The threat perception module is used to filter out the detection server from the device group, obtain the collected data of the other devices through the detection server, and identify the abnormal devices in the device group based on the collected data.
[0039] The device selection module is used to obtain the group tag information of each device and determine the backup device corresponding to the abnormal device based on the group tag information of each device; wherein, the group tag information is generated based on operating condition information and business information;
[0040] The service flow module is used to transfer the service flow of the faulty device to the backup device.
[0041] Thirdly, embodiments of the present invention also provide a terminal, the terminal including a memory and at least one processor; the memory stores a program; the program includes instructions for executing the situational awareness-based service flow method as described above; the processor is used to execute the program.
[0042] Fourthly, embodiments of the present invention also provide a computer-readable storage medium having stored thereon a plurality of instructions adapted to be loaded and executed by a processor to implement the steps of the situation-aware-based service flow method as described above.
[0043] The beneficial effects of this invention are as follows: In this embodiment, a detection server is selected from a group of devices. This detection server acquires data from the remaining devices and identifies abnormal devices within the group based on this data. Group tag information for each device is obtained, and a backup device corresponding to the abnormal device is determined based on this group tag information. The group tag information is generated based on operating condition information and service information. The service flow of the abnormal device is then transferred to the backup device. This invention selects a detection server from the group of devices, eliminating the need for a dedicated detection server and improving system resource utilization. The detection server identifies abnormal devices based on the data acquired from the remaining devices and selects devices in the same group that are more compatible with the abnormal device's service as backup devices based on the group tag information of each device. This allows for timely transfer of services from the abnormal device and ensures smooth service operation. Attached Figure Description
[0044] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0045] Figure 1 This is a flowchart illustrating the business flow method based on situational awareness provided in an embodiment of the present invention.
[0046] Figure 2 This is a schematic diagram of data integration provided in an embodiment of the present invention.
[0047] Figure 3 This is a schematic diagram of data distribution provided in an embodiment of the present invention.
[0048] Figure 4 This is a schematic diagram of the functional modules of the detection server and the agent provided in the embodiment of the present invention.
[0049] Figure 5 This is a schematic diagram of the internal modules of the situation-aware business flow system provided in an embodiment of the present invention.
[0050] Figure 6 This is a schematic diagram of the terminal provided in the embodiment of the present invention. Detailed Implementation
[0051] This invention discloses a service flow method, system, terminal, and storage medium based on situational awareness. To make the objectives, technical solutions, and effects of this invention clearer and more explicit, the invention is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only for explaining the invention and are not intended to limit the invention.
[0052] Those skilled in the art will understand that, unless specifically stated otherwise, the singular forms “a,” “an,” “the,” and “the” used herein may also include the plural forms. It should be further understood that the term “comprising” as used in this specification means the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. It should be understood that when we say an element is “connected” or “coupled” to another element, it can be directly connected or coupled to the other element, or there may be intermediate elements. Furthermore, “connected” or “coupled” as used herein can include wireless connections or wireless coupling. The term “and / or” as used herein includes all or any units and all combinations of one or more associated listed items.
[0053] It will be understood by those skilled in the art that, unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. It should also be understood that terms such as those defined in general dictionaries should be understood to have the same meaning as in the context of the prior art, and should not be interpreted in an idealized or overly formal sense unless specifically defined as herein.
[0054] Current situational awareness methods primarily involve setting up a dedicated detection server to identify anomalous devices by analyzing data collected from various equipment. To ensure the normal operation of all system services, once a potentially vulnerable anomalous device is identified, its services need to be promptly transferred. Current service transfer methods mainly involve randomly selecting a device from the normal equipment pool to receive services from the anomalous device. While this ensures rapid service transfer, it's difficult to guarantee compatibility between the selected device and the transferred services.
[0055] To address the aforementioned shortcomings of existing technologies, this invention provides a situational awareness-based service flow method. This method involves selecting a detection server from a device group, acquiring data from the remaining devices through the detection server, and identifying abnormal devices within the device group based on the acquired data. It then acquires group tag information for each device and determines a backup device corresponding to the abnormal device based on this group tag information. The group tag information is generated based on operational and service information. Finally, the service flow of the abnormal device is transferred to the backup device. This invention selects a detection server from the device group, eliminating the need for a dedicated detection server and improving system resource utilization. By having the detection server identify abnormal devices based on the acquired data from the remaining devices and selecting devices in the same group that are more compatible with the abnormal device's services as backup devices based on the group tag information, the service flow on the abnormal device can be transferred in a timely manner, ensuring smooth service operation.
[0056] like Figure 1 As shown, the method includes:
[0057] Step S100: Select the detection server from the device group, obtain the collected data of the other devices through the detection server, and identify the abnormal devices in the device group based on the collected data.
[0058] Specifically, a network requiring situational awareness or monitoring is pre-defined, and all or key devices within this network are selected to form a specific device group. To improve system resource utilization, this embodiment does not set up an additional device as a detection server. Instead, by analyzing the status and / or service priority of each device in the device group, one or more idle devices are selected as the detection server. The remaining devices act as proxies, performing local data acquisition tasks. The detection server is responsible for managing and coordinating the data acquisition process of the remaining devices. The detection server first orchestrates and issues acquisition instructions to each device. In the initial stage, pre-set basic acquisition instructions can be issued, or acquisition instructions can be orchestrated and issued based on specific computing tasks. After receiving the acquisition instruction, each device executes the corresponding data acquisition task according to the instruction and reports the acquired data to the detection server. By comparing and analyzing the acquired data from each device, the detection server can identify devices with abnormal status. Abnormal devices pose certain security risks and need to be monitored and handled promptly.
[0059] In one implementation, identifying abnormal devices in the device group based on the collected data includes:
[0060] The collected data are classified to obtain several data groups; each data group corresponds to a different data type.
[0061] For each data group, all data contained in the data group are compared, and similar deviation data are identified through the comparison results to obtain cross-sectional analysis data;
[0062] For the collected data of each device, all data contained in the collected data are compared, and the data that deviates from the same device is identified by the comparison results to obtain longitudinal analysis data.
[0063] Abnormal devices in the device group are identified based on the horizontal analysis data and the vertical analysis data.
[0064] Specifically, this embodiment will perform data analysis tasks from two dimensions: horizontal analysis and vertical analysis. Horizontal analysis refers to comparing and analyzing the same type of data collected from multiple devices, while vertical analysis refers to comparing and analyzing multiple types of data collected from the same device.
[0065] For cross-sectional analysis: First, the collected data from each device is categorized. The purpose of categorization is to group data of the same or similar types together for easier subsequent processing and analysis. The categorization criteria can be determined based on one or more characteristics such as data source, type, format, and purpose. Each group of data obtained after categorization becomes a data set, and each data set contains data of the same type from different devices. Different data sets correspond to different data types, such as temperature data, functional data, CPU data, memory data, etc. (e.g., ...) Figure 2 (As shown). For each data set, all data within that set are compared. The purpose of this comparison is to identify data that is significantly different from the other data and define these deviations as similar deviations. The cross-sectional analysis results are then obtained based on all similar deviations. In practical applications, the cross-sectional analysis comparison process can employ one or more comparison methods, such as statistical analysis methods or machine learning algorithms. For example, using statistical analysis methods, the mean and / or standard deviation can be used to identify data that deviates from the normal range.
[0066] For longitudinal analysis: Data collected from each device is analyzed independently, rather than by combining data from multiple devices. For each device, all collected data is internally compared to identify data whose generation / change trends significantly differ from other data from that device. This deviation is defined as "device-specific deviation data." The longitudinal analysis results are obtained based on all device-specific deviation data. In practical applications, the longitudinal analysis comparison process can employ one or more comparison methods, such as statistical analysis methods, time series analysis methods, and machine learning algorithms.
[0067] In one implementation, when there is only one detection server, it indicates that a single-device detection mode is currently being used, meaning all data sets are sent to one device for data analysis (e.g., ...). Figure 2 (As shown); When multiple detection servers exist, it indicates that a distributed detection mode is currently being used, meaning that multiple data sets can be sent to multiple devices for data analysis. Devices with more computing resources are allocated more data sets, and devices with fewer computing resources are allocated fewer data sets (e.g., ...). Figure 3 (As shown). In practical applications, one detection server can be selected first, and then the detection module of that server can further determine whether more detection servers are needed to collaborate on data analysis.
[0068] Step S200: Obtain the group tag information of each device, and determine the backup device corresponding to the abnormal device based on the group tag information of each device; wherein, the group tag information is generated based on operating condition information and service information.
[0069] Specifically, operating condition information refers to the equipment's working conditions and / or operating environment, which may include factors such as equipment uptime, load status, and ambient temperature and humidity. Business information refers to the business processes or application scenarios supported by the equipment. For example, some equipment may be specifically used for R&D testing, while others may be used for customer service; different types of business may have different performance requirements for the equipment. In practical applications, all equipment in the equipment group is first grouped according to operating condition information and business information, and group label information for each device is determined based on the grouping results. This group label information is stored in each device, but it is only used by devices acting as analysis servers. After identifying abnormal devices, backup devices can be selected from the same group first.
[0070] In one implementation, the method for generating the group label information includes:
[0071] Obtain the operating status information and service information corresponding to each device in the device group;
[0072] Input the operating condition information and business information of each device into a pre-established device grouping algorithm;
[0073] The device grouping algorithm groups devices according to their operating conditions and business information, and generates grouping tag information for each device based on the grouping results.
[0074] Specifically, such as Figure 4 As shown, the detection server includes a data grouping module and a detection module. The data grouping module generates and / or stores grouping tag information for each device, while the detection module analyzes the collected data from each device to identify abnormal devices. In practical applications, to facilitate rapid device grouping, a device grouping algorithm can be pre-built. This algorithm automatically calculates the operational similarity and business similarity between pairs of devices and groups devices based on these similarities. This ensures that devices with similar operational conditions and business types are grouped together, while devices with different operational conditions and business types are grouped into different groups, resulting in multiple device groups.
[0075] In one implementation, the functional modules within the detection server include, but are not limited to: a detection module, a data management module, an orchestration module, an instruction management module, and a communication module. The orchestration module primarily handles task parsing, instruction orchestration, and instruction invocation; the instruction management module primarily handles instruction generation and instruction issuance; the detection module primarily determines the currently used detection mode; and the data management module primarily handles device grouping (grouping devices according to their operating conditions, functions, and services for better data comparison and analysis), data routing, and instruction issuance.
[0076] In one implementation, the functional modules within the agent (devices other than the detection server) include, but are not limited to: a communication module, an instruction module, a response module, a data acquisition probe module, and a management module. The instruction module is primarily used for instruction parsing and distribution / execution; the data acquisition probe module is primarily used for data acquisition. Data probe types include, but are not limited to: system information probes, used to collect information about the current system operating environment; performance probes, used to collect information related to system resource utilization, such as CPU, memory, and disk information; and network probes, used to collect network packet information. Since each device may have a different operating system, the data probes supported by each device may also differ.
[0077] In one implementation, determining the backup device corresponding to the abnormal device based on the group tag information of each device includes:
[0078] Based on the grouping tag information, devices located in the same group as the abnormal device are selected to obtain several candidate backup devices;
[0079] Based on the service information of the abnormal equipment, determine the number of backup devices;
[0080] For each candidate device, the device idleness is calculated based on the working condition information of the candidate device, the service similarity is calculated based on the service information of the candidate device and the abnormal device, and a comprehensive score is calculated based on the device idleness and the service similarity.
[0081] The candidate devices are sorted according to their comprehensive scores, and backup devices are determined from the candidate devices based on the sorting results and the number of backup devices.
[0082] Specifically, this embodiment involves two rounds of device screening when selecting backup devices for abnormal devices. One round is based on grouping, and the other is based on operating conditions and business needs. In practical applications, when a device is identified as abnormal, the first step is to check the group to which the device belongs. Then, other normal devices are selected from that group, and these selected devices are used as preliminary candidate devices. Next, the current business information of the abnormal device is analyzed, such as the current workload, the importance and / or urgency of the business. The analysis results determine how many backup devices are needed to take over the abnormal device's business to ensure that the business is not affected or the impact is minimized. For each candidate device, its current workload is examined through its operating condition information. The proportion of idle resources available for taking over new business is calculated, and the device idleness is used as a quantitative indicator of the calculation result. Secondly, the compatibility between the candidate device and the abnormal device and the business to be taken over is examined through their business information, such as the compatibility of business type, data format, and interface compatibility. The business similarity is used as a quantitative indicator of the comparison result. Finally, combining device idle time and service similarity, a comprehensive score is assigned to each candidate device. The top few candidate devices with the highest comprehensive scores are more suitable to be selected as backup devices to take over the services on the abnormal devices.
[0083] Step S300: Transfer the service flow of the faulty device to the backup device.
[0084] Specifically, to ensure data security and normal business operations, this embodiment requires suppressing or blocking abnormal devices, promptly transferring important services from the abnormal devices to backup devices with similar processing capabilities and available computing resources, and isolating the abnormal devices from other normal devices to ensure the secure and uninterrupted operation of the devices. Once the abnormal devices have recovered and the risk has been eliminated, the transferred services are then returned to the original devices.
[0085] In one implementation, transferring the service flow of the faulty device to the backup device includes:
[0086] Based on the service information of the abnormal device, the services are classified to obtain several service sets of different categories;
[0087] Assess the risk level of the abnormal device and the security level corresponding to each of the service sets;
[0088] Based on the risk level of the abnormal device and the security level of each service set, several first service sets to be transferred are determined.
[0089] All of the first service sets are transferred to the backup equipment.
[0090] Specifically, this embodiment requires first assessing the risk level of the malfunctioning device and the security level of each service set to accurately determine which services to transfer. For the malfunctioning device, a risk assessment model can be pre-built. This model accurately assesses the risk level of the malfunctioning device based on factors such as the degree of anomaly in the collected data, the current device status, and the frequency of failures. Risk levels can be divided into multiple levels, such as low risk, medium risk, and high risk, each corresponding to different handling strategies. For the service sets, maintenance personnel can pre-assess the security level of each service set, or a security assessment model can be pre-built. This model automatically assesses the security level of each service set based on the importance of the service, the confidentiality of the exchanged information, and the degree of impact on the system. Security levels can be divided into multiple levels, such as low security, medium security, and high security, each corresponding to different protection measures or transfer strategies. By comparing the risk level of the malfunctioning device and the security level of each service set, the service sets that need to be transferred in a timely manner can be correctly selected, thus obtaining the first service set. Backup equipment can take over these first service sets to ensure that the corresponding services can operate normally.
[0091] In one implementation, a specific workflow strategy can be determined based on all the first service sets to be workflowd, including but not limited to data migration and service switching strategies. Furthermore, automated tools can be used to execute the workflow process, reducing human error and improving workflow efficiency. In addition, during and / or after the workflow process, the operational status of each first service set and the performance of backup equipment can be monitored in real time, and a corresponding feedback mechanism can be established to promptly identify and address problems.
[0092] In one implementation, determining the plurality of first service sets to be transferred based on the risk level of the abnormal device and the security level of each service set includes:
[0093] For each of the aforementioned service sets, determine whether the security level of the service set matches the risk level of the abnormal device;
[0094] If there is no match, then this set of services will be used as the first set of services to be transferred.
[0095] Specifically, a pre-defined mapping relationship can be established to match the risk level of abnormal devices with the security level of service sets. This mapping relationship covers the security levels of services that can guarantee normal operation under various risk levels. In practical applications, for each service set, based on the current risk level of the abnormal device and the pre-defined mapping relationship, it is determined whether the service set belongs to a security level that can guarantee normal operation under that risk level. If it does not belong, the service set is designated as the first service set. If the number of selected first service sets is too large, all first service sets can be prioritized to ensure that important service sets are transferred first.
[0096] In one implementation, the method further includes:
[0097] The risk level of the abnormal device is updated in real time;
[0098] If the updated risk level is greater than the original risk level, then based on the updated risk level and the remaining untransferred service set, continue to execute the step of determining several first service sets to be transferred based on the risk level of the abnormal device and the security level of each service set;
[0099] If the updated risk level is lower than the original risk level, then based on the updated risk level and the already transferred service sets, determine several second service sets to be restored; and transfer all second service sets back to the abnormal device.
[0100] Specifically, after the business process is completed, real-time risk monitoring and assessment of abnormal devices are required to ensure the timeliness of their risk levels, thereby ensuring that business process measures can respond promptly to new risk changes. In practical application scenarios, if the updated risk level is higher than the original risk level, it indicates that the potential threat from the abnormal device has increased. It is necessary to re-evaluate the security level of the remaining business sets on the local machine based on the updated risk level to determine whether the remaining business sets need to be transferred as soon as possible. If the updated risk level is lower than the original risk level, it indicates that the threat from the abnormal device has been mitigated. It is possible to re-evaluate the security level of the transferred business sets based on the updated risk level to determine if any of the transferred business sets are suitable for transfer back to the local machine, thereby reducing the business load on other devices. The technical solution of this embodiment can be used in conjunction with the HarmonyOS system.
[0101] Based on the above embodiments, the present invention also provides a situational awareness-based business flow system, such as... Figure 5 As shown, the system includes:
[0102] The threat perception module 01 is used to filter out the detection server from the device group, obtain the collected data of the other devices through the detection server, and identify the abnormal devices in the device group based on the collected data.
[0103] The device selection module 02 is used to obtain the group tag information of each device and determine the backup device corresponding to the abnormal device based on the group tag information of each device; wherein, the group tag information is generated based on operating condition information and business information;
[0104] The service transfer module 03 is used to transfer the service of the faulty device to the backup device.
[0105] In one implementation, the threat perception module 01 includes:
[0106] A data classification unit is used to classify the collected data to obtain several data groups; wherein each data group corresponds to a different data type.
[0107] The horizontal analysis unit is used to compare all the data contained in each data group, identify similar deviation data through the comparison results, and obtain horizontal analysis data.
[0108] The longitudinal analysis unit is used to compare all the data contained in the collected data for each device, identify the data that deviates from the same device through the comparison results, and obtain longitudinal analysis data.
[0109] The comprehensive analysis unit is used to identify abnormal devices in the device group based on the horizontal analysis data and the vertical analysis data.
[0110] In one implementation, the system further includes a tag generation module, which is used to:
[0111] Obtain the operating status information and service information corresponding to each device in the device group;
[0112] Input the operating condition information and business information of each device into a pre-established device grouping algorithm;
[0113] The device grouping algorithm groups devices according to their operating conditions and business information, and generates grouping tag information for each device based on the grouping results.
[0114] In one implementation, the device selection module 02 includes:
[0115] The equipment screening unit is used to screen out the equipment that is in the same group as the abnormal equipment according to the grouping label information, and obtain a number of candidate backup equipment.
[0116] A quantity determination unit is used to determine the number of backup devices based on the service information of the abnormal devices;
[0117] The equipment scoring unit is used to calculate the equipment idleness based on the working condition information of each candidate device, calculate the service similarity based on the service information of the candidate device and the abnormal device, and calculate a comprehensive score based on the equipment idleness and the service similarity.
[0118] The equipment sorting unit is used to sort the candidate equipment according to the comprehensive score of each candidate equipment, and to determine the backup equipment from each candidate equipment according to the sorting result and the number of backup equipment.
[0119] In one implementation, the business flow module 03 includes:
[0120] A service classification unit is used to classify services according to the service information of the abnormal device to obtain several service sets of different categories.
[0121] The risk assessment unit is used to assess the risk level of the abnormal device and the security level corresponding to each of the service sets.
[0122] A service screening unit is used to determine several first service sets to be transferred based on the risk level of the abnormal device and the security level of each service set.
[0123] The service transfer unit is used to transfer all of the first service set to the backup device.
[0124] In one implementation, the business filtering unit is specifically used for:
[0125] For each of the aforementioned service sets, determine whether the security level of the service set matches the risk level of the abnormal device;
[0126] If there is no match, then this set of services will be used as the first set of services to be transferred.
[0127] In one implementation, the system further includes a service recovery module, which is used to:
[0128] The risk level of the abnormal device is updated in real time;
[0129] If the updated risk level is greater than the original risk level, then based on the updated risk level and the remaining untransferred service set, continue to execute the step of determining several first service sets to be transferred based on the risk level of the abnormal device and the security level of each service set;
[0130] If the updated risk level is lower than the original risk level, then based on the updated risk level and the already transferred service sets, determine several second service sets to be restored; and transfer all second service sets back to the abnormal device.
[0131] Based on the above embodiments, the present invention also provides a terminal, the principle block diagram of which can be as follows: Figure 6 As shown, the terminal includes a processor, memory, network interface, and display screen connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides the environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with external terminals via a network connection. When the computer program is executed by the processor, it implements a situational awareness-based business flow method.
[0132] The detection server is selected from the device group, and the collected data of the remaining devices is obtained through the detection server. The abnormal devices in the device group are identified based on the collected data.
[0133] Obtain the group tag information of each device, and determine the backup device corresponding to the abnormal device based on the group tag information of each device; wherein, the group tag information is generated based on operating condition information and service information;
[0134] The service flow of the faulty device is transferred to the backup device.
[0135] The terminal's display screen can be an LCD screen or an e-ink screen.
[0136] Those skilled in the art will understand that Figure 6 The schematic diagram shown is merely a partial structural diagram related to the present invention and does not constitute a limitation on the terminal to which the present invention is applied. A specific terminal may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0137] In one implementation, the terminal's memory stores one or more programs, and these programs are configured to be executed by one or more processors. The programs contain instructions for performing situational awareness-based service flow methods.
[0138] The detection server is selected from the device group, and the collected data of the remaining devices is obtained through the detection server. The abnormal devices in the device group are identified based on the collected data.
[0139] Obtain the group tag information of each device, and determine the backup device corresponding to the abnormal device based on the group tag information of each device; wherein, the group tag information is generated based on operating condition information and service information;
[0140] The service flow of the faulty device is transferred to the backup device.
[0141] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided by this invention can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM), etc.
[0142] In summary, this invention discloses a service flow method, system, terminal, and storage medium based on situational awareness. By selecting a detection server from a device group, acquiring data from the remaining devices, and identifying abnormal devices within the device group based on the acquired data, the invention obtains group tag information for each device and determines a backup device corresponding to the abnormal device based on this group tag information. The group tag information is generated based on operational and service information. The service flow of the abnormal device is then transferred to the backup device. This invention selects a detection server from the device group, eliminating the need for a dedicated detection server and improving system resource utilization. By using the detection server to identify abnormal devices based on the acquired data and selecting devices in the same group more compatible with the abnormal device's services as backup devices based on their group tag information, the invention facilitates timely transfer of services from the abnormal device and ensures smooth service operation.
[0143] It should be understood that the application of the present invention is not limited to the examples above. Those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims.
Claims
1. A business flow method based on situational awareness, characterized in that, The method includes: The detection server is selected from the device group, and the collected data of the remaining devices is obtained through the detection server. The abnormal devices in the device group are identified based on the collected data. The process involves obtaining group tag information for each device, determining the backup device corresponding to the abnormal device based on the group tag information, wherein the group tag information is generated based on operating condition information and service information, and includes: filtering devices located in the same group as the abnormal device based on the group tag information to obtain several candidate backup devices; determining the number of backup devices based on the service information of the abnormal device; for each candidate backup device, calculating the device idleness based on the operating condition information of the candidate backup device, calculating the service similarity based on the service information of the candidate backup device and the abnormal device, calculating a comprehensive score based on the device idleness and the service similarity; sorting the candidate backup devices according to the comprehensive score, and determining the backup device from the candidate backup devices based on the sorting result and the number of backup devices; The service flow of the faulty device is transferred to the backup device.
2. The business flow method based on situational awareness according to claim 1, characterized in that, The step of identifying abnormal devices in the device group based on the collected data includes: The collected data are classified to obtain several data groups; each data group corresponds to a different data type. For each data group, all data contained in the data group are compared, and similar deviation data are identified through the comparison results to obtain cross-sectional analysis data; For the collected data of each device, all data contained in the collected data are compared, and the data that deviates from the same device is identified by the comparison results to obtain longitudinal analysis data. Abnormal devices in the device group are identified based on the horizontal analysis data and the vertical analysis data.
3. The business flow method based on situational awareness according to claim 1, characterized in that, The method for generating the group label information includes: Obtain the operating status information and service information corresponding to each device in the device group; Input the operating condition information and business information of each device into a pre-established device grouping algorithm; The device grouping algorithm groups devices according to their operating conditions and business information, and generates grouping tag information for each device based on the grouping results.
4. The business flow method based on situational awareness according to claim 1, characterized in that, The step of transferring the service flow of the faulty device to the backup device includes: Based on the service information of the abnormal device, the services are classified to obtain several service sets of different categories; Assess the risk level of the abnormal device and the security level corresponding to each of the service sets; Based on the risk level of the abnormal device and the security level of each service set, several first service sets to be transferred are determined. All of the first service sets are transferred to the backup equipment.
5. The business flow method based on situational awareness according to claim 4, characterized in that, The step of determining several first service sets to be transferred based on the risk level of the abnormal device and the security level of each service set includes: For each of the aforementioned service sets, determine whether the security level of the service set matches the risk level of the abnormal device; If there is no match, then this set of services will be used as the first set of services to be transferred.
6. The business flow method based on situational awareness according to claim 4, characterized in that, The method further includes: The risk level of the abnormal device is updated in real time; If the updated risk level is greater than the original risk level, then based on the updated risk level and the remaining untransferred service set, continue to execute the step of determining several first service sets to be transferred based on the risk level of the abnormal device and the security level of each service set; If the updated risk level is lower than the original risk level, then based on the updated risk level and the already transferred service sets, determine several second service sets to be restored; and transfer all second service sets back to the abnormal device.
7. A business workflow system based on situational awareness, characterized in that, The system includes: The threat perception module is used to filter out the detection server from the device group, obtain the collected data of the other devices through the detection server, and identify the abnormal devices in the device group based on the collected data. The device selection module is used to acquire group label information of each device, and determine the backup device corresponding to the abnormal device based on the group label information of each device. The group label information is generated based on operating condition information and service information, including: filtering out devices located in the same group as the abnormal device based on the group label information to obtain several candidate backup devices; determining the number of backup devices based on the service information of the abnormal device; for each candidate backup device, calculating the device idle degree based on the operating condition information of the candidate backup device, calculating the service similarity based on the service information of the candidate backup device and the abnormal device, calculating a comprehensive score based on the device idle degree and the service similarity; sorting the candidate backup devices according to the comprehensive score of each candidate backup device, and determining the backup device from each candidate backup device according to the sorting result and the number of backup devices; The service flow module is used to transfer the service flow of the faulty device to the backup device.
8. A terminal, characterized in that, The terminal includes a memory and at least one processor; the memory stores a program; the program contains instructions for executing the situational awareness-based service flow method as described in any one of claims 1-6; the processor is used to execute the program.
9. A computer-readable storage medium storing a plurality of instructions thereon, characterized in that, The instructions are applicable to be loaded and executed by a processor to implement the steps of the situation-aware-based service flow method as described in any one of claims 1-6.
Citation Information
Patent Citations
Systems and methods for hierarchical failover groups
CN116802615A
Service processing method and device, computer equipment and storage medium
CN117714267A