Abnormality detection method and device of business system, electronic equipment and storage medium

Through the combination of time series model and image classification model, the confidence interval is dynamically adjusted, and the shortcomings of static thresholds and traditional machine learning models in business system anomaly detection are solved, achieving efficient and accurate anomaly detection and prediction.

CN120295866APending Publication Date: 2025-07-11BEIJING YOUTEJIE INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510438631.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the prior art, the static threshold setting cannot adapt to data fluctuations and periodic changes, resulting in frequent false alarms or missed reports in abnormal detection of business systems. Traditional machine learning models require a large amount of data annotation, and the detection efficiency is low.

Method used

The time series model is used to obtain the fitting curve and confidence interval, combine the image classification model to identify abnormal behavior, predict abnormal moments through the time series model and issue operation and maintenance prompts, and dynamically adjust the confidence interval to adapt to data changes.

Benefits of technology

It improves the accuracy and efficiency of abnormal detection, avoids false alarms and missed alarms, and enhances the accuracy and prediction capabilities of operation and maintenance management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120295866A_ABST
    Figure CN120295866A_ABST
Patent Text Reader

Abstract

The invention discloses an anomaly detection method and device for a service system, electronic equipment and a storage medium, and relates to the field of operation and maintenance monitoring, and the method comprises the steps: obtaining a first quantity curve reflecting a mapping relation between a detection moment and an abnormal data quantity in a first time period; obtaining a first fitting curve matched with the first quantity curve and a first confidence interval through a time sequence model; according to the first confidence interval and the first quantity curve, determining quantity abnormal moments in the first time period; and obtaining an anomaly detection result of the business system in the first time period according to the actual anomaly number, the fitting anomaly number, the fitting anomaly upper limit and the fitting anomaly lower limit at the number anomaly moment. According to the technical scheme of the embodiment of the invention, the anomaly detection result not only adapts to data fluctuation and data periodical change, but also avoids missing report and false report of the abnormal state of the service system, improves the accuracy of the anomaly detection result, and improves the anomaly detection efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of operation and maintenance monitoring, and particularly to an abnormal detection method, device, electronic device and storage medium for a business system. Background Art

[0002] In the operation and maintenance monitoring of a business system, usually by monitoring log data, abnormal data in the business system is obtained, and then the abnormal state of the system is detected according to the number of abnormal data at each moment.

[0003] In the prior art, the number of abnormal data can be compared with a pre-set static threshold to determine whether there is an abnormal state in the business system, or the number distribution of abnormal data can be identified through a traditional machine learning model or statistical model to detect the abnormal state existing in the operation process of the business system.

[0004] However, the setting of the static threshold cannot adapt to data fluctuations and periodic changes, resulting in false alarms or missed alarms; traditional statistical models are less sensitive to non-normal distribution data, and the error of abnormal detection results is large; traditional machine learning models require a large amount of data annotation, and the efficiency of abnormal detection is low. Summary of the Invention

[0005] The present invention provides an abnormal detection method, device, electronic device and storage medium for a business system to solve the problems of large error of abnormal detection results and low detection efficiency.

[0006] According to one aspect of the present invention, an abnormal detection method for a business system is provided, including:

[0007] Obtain a first quantity curve of the business system within a first time period; wherein, the first quantity curve reflects the mapping relationship between the detection moment and the number of abnormal data;

[0008] Obtain a first fitting curve and a first confidence interval matching the first quantity curve through a time series model;

[0009] Determine the quantity abnormal moment within the first time period according to the first confidence interval and the first quantity curve;

[0010] Obtain the abnormal detection result of the business system within the first time period according to the actual abnormal quantity, fitting abnormal quantity, fitting abnormal upper limit and fitting abnormal lower limit at the quantity abnormal moment.

[0011] After determining the abnormal quantity moments within the first time period, the method further includes: obtaining an abnormal data waveform graph according to the abnormal data quantities at each abnormal quantity moment; classifying and identifying the abnormal data waveform graph through a pre-trained image classification model to obtain the types of abnormal behaviors in the service system within the first time period; wherein the types of abnormal behaviors include at least one of system failure behaviors, external attack behaviors, and resource limitation behaviors.

[0012] After obtaining the first quantity curve of the service system within the first time period, the method further includes: obtaining a first prediction curve that matches the first quantity curve within a second time period through the time series model; wherein the second time period is a downstream time period of the first time period; obtaining the prediction abnormal moments in the first prediction curve according to the first confidence interval, and sending an operation and maintenance prompt message according to the prediction abnormal moments.

[0013] After obtaining a first prediction curve that matches the first quantity curve within a second time period through the time series model, the method further includes: obtaining a second quantity curve within the second time period, and obtaining a second fitting curve and a second confidence interval that match the second quantity curve through the time series model; comparing the first prediction curve with the second confidence interval to obtain the prediction deviation moments in the first prediction curve that are outside the second confidence interval.

[0014] The step of obtaining a first fitting curve and a first confidence interval that match the first quantity curve through the time series model further includes: obtaining a first fitting curve that matches the first quantity curve through the time series model, and an initial first confidence interval; obtaining the floating coefficients at each detection moment according to the abnormal data quantities at each detection moment in the first fitting curve; updating the initial first confidence interval according to the first fitting curve and the floating coefficients at each detection moment to obtain the updated first confidence interval.

[0015] The step of obtaining a first fitting curve and a first confidence interval that match the first quantity curve through the time series model further includes: obtaining alternative confidence intervals that match the first quantity curve respectively under multiple confidence interval widths through the time series model; obtaining the target alternative confidence intervals corresponding to each of the detection moments according to the abnormal data quantities at each detection moment in the first quantity curve; wherein the quantity interval where the abnormal data quantity at the detection moment is located has a positive correlation with the confidence interval width; obtaining the target intervals that match the corresponding detection moments among the target alternative confidence intervals, and sequentially combining the target intervals according to the time series of the corresponding detection moments to obtain a first confidence interval that matches the first quantity curve.

[0016] According to another aspect of the present invention, there is provided an abnormality detection device for a service system, comprising:

[0017] A quantity curve acquisition module, configured to acquire a first quantity curve of the service system within a first time period; wherein, the first quantity curve reflects the mapping relationship between the detection time and the quantity of abnormal data;

[0018] A fitting curve acquisition module, configured to obtain a first fitting curve and a first confidence interval matching the first quantity curve through a time series model;

[0019] An abnormal time acquisition module, configured to determine the quantity abnormal time within the first time period according to the first confidence interval and the first quantity curve;

[0020] A detection result acquisition module, configured to obtain the abnormality detection result of the service system within the first time period according to the actual abnormal quantity, the fitting abnormal quantity, the fitting abnormal upper limit, and the fitting abnormal lower limit of the quantity abnormal time.

[0021] According to another aspect of the present invention, there is provided an electronic device, the electronic device comprising:

[0022] At least one processor; and

[0023] A memory communicatively connected to the at least one processor; wherein,

[0024] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the abnormality detection method of the service system according to any embodiment of the present invention.

[0025] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to implement the abnormality detection method of the service system according to any embodiment of the present invention when executed.

[0026] According to another aspect of the present invention, there is provided a computer program product comprising a computer program which, when executed by a processor, implements the abnormality detection method of the service system according to any embodiment of the present invention.

[0027] In the technical solution of the embodiment of the present invention, a first quantity curve reflecting the mapping relationship between the detection time and the number of abnormal data within a first time period is obtained; a first fitting curve and a first confidence interval matching the first quantity curve are obtained through a time series model; according to the first confidence interval and the first quantity curve, the quantity abnormal time within the first time period is determined; according to the actual abnormal quantity, the fitted abnormal quantity, the upper limit of the fitted abnormality, and the lower limit of the fitted abnormality at the quantity abnormal time, the abnormal detection result of the business system within the first time period is obtained. Thus, the abnormal detection result not only adapts to the data fluctuation and the change of data periodicity, but also avoids the missed report and false report of the abnormal state of the business system, improves the accuracy of the abnormal detection result, and improves the abnormal detection efficiency.

[0028] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0030] Figure 1 is a flowchart of an abnormal detection method for a business system according to Embodiment 1 of the present invention;

[0031] Figure 2 is a schematic diagram of a first quantity curve, a first fitting curve, and a first confidence interval according to Embodiment 2 of the present invention;

[0032] Figure 3 is a flowchart of another abnormal detection method for a business system according to Embodiment 2 of the present invention;

[0033] Figure 4 is a flowchart of yet another abnormal detection method for a business system according to Embodiment 3 of the present invention;

[0034] Figure 5 is a schematic structural diagram of an abnormal detection device for a business system according to Embodiment 4 of the present invention;

[0035] Figure 6 is a schematic structural diagram of an electronic device for implementing the abnormal detection method of the business system in the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0037] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned accompanying drawings are used to distinguish similar objects and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0038] Embodiment 1

[0039] Figure 1 It is a flowchart of an abnormal detection method for a service system provided in Embodiment 1 of the present invention. This embodiment is applicable to obtaining the abnormal detection result of the service system through a time series model according to the first quantity curve of the service system. This method can be executed by the abnormal detection device of the service system in any embodiment of the present invention. The abnormal detection device of the service system can be implemented in the form of hardware and / or software, and the abnormal detection device of the service system can be configured in an electronic device such as a server, as Figure 1 shown, the method includes:

[0040] S101. Obtain the first quantity curve of the service system within the first time period; wherein, the first quantity curve reflects the mapping relationship between the detection time and the quantity of abnormal data.

[0041] The server monitors the abnormal data in its own carried business system or a specified business system, and obtains the number of abnormal data obtained within the current detection period at each detection moment; wherein, the detection period can be preset as needed. For example, taking 10 minutes as the detection period, that is, every 10 minutes, the cumulative number of abnormal data in the business system within the current 10 minutes is obtained; the abnormal data can include abnormal log data, which records the error information that appears during the operation of the business system or the application program in the business system. Optionally, in the embodiments of the present invention, neither the type nor the acquisition method of the abnormal data is specifically limited.

[0042] The server obtains the number of abnormal data actually detected at each detection moment, and after connecting the number of abnormal data at each detection moment in sequence, a first quantity curve reflecting the mapping relationship between the detection moment and the number of abnormal data is formed; as Figure 2 shown, the abscissa is the detection time, and each detection moment is arranged in sequence based on the time series, the ordinate is the number of abnormal data, and the purple curve therein is the first quantity curve, which reflects the change trend of the number of abnormal data actually detected at each detection moment during the time period from detection moment A to detection moment N (i.e., the first time period).

[0043] S102. Obtain a first fitting curve and a first confidence interval that match the first quantity curve through a time series model.

[0044] A time series model (Time Series Model) is a mathematical model used to analyze and predict data arranged in chronological order, and the input time series data has data characteristics such as trend, seasonality, and noise; wherein, the trend indicates that the data shows a long-term upward or downward trend; the seasonality indicates that the data has periodic fluctuations; the noise indicates the random fluctuations of the data under the interference of external factors. Optionally, in the embodiments of the present invention, the time series model includes the Prophet model.

[0045] The Prophet model is an open-source time series prediction tool, which builds models for trends, seasonality, and holidays internally, reducing the manual parameter adjustment process. At the same time, it provides trend decomposition and parameter visualization functions; among them, the trend component includes a piecewise linear trend suitable for a trend with obvious inflection points and a logistic growth trend suitable for a saturated upper limit; the seasonal component includes annual seasonality, monthly seasonality, and weekly seasonality; the holiday component includes a list of holidays specified by the user.

[0046] If the Prophet model is used as a time series model, first complete the parameter configuration of the Prophet model, including setting the confidence interval width (for example, setting the confidence interval width to 0.95), enabling annual periodicity (i.e., setting the annual cycle to "True"), enabling weekly periodicity (i.e., setting the weekly cycle to "True"), setting the trend change sensitivity (for example, setting the trend change sensitivity to 0.05), seasonal superposition mode (for example, setting the seasonal superposition mode to "additive", indicating that the seasonal fluctuation amplitude does not change with the trend), and starting the monthly cycle (for example, customizing the monthly cycle to 30.5).

[0047] Before inputting the abnormal data quantity at each detection moment in the first quantity curve into the Prophet model, the millisecond-level timestamp data can be first converted into a timezone-naive Datetime format in the Asia / Shanghai timezone to make the input data meet the data processing requirements of the Prophet model; for example, first convert the millisecond timestamp to a second value, then create a datetime object of UTC time through the "utcfromtimestamp" function, then explicitly set the timezone information for the UTC time, then use the "astimezone" method to convert it to the Asia / Shanghai timezone, and finally remove the timezone information to obtain a timezone-naive Datetime object.

[0048] In addition, force the abnormal data quantity in the first fitting curve to be of numerical type to avoid the Prophet model being unable to recognize due to other data types; at the same time, for the missing points in the first quantity curve, they can be filled based on the abnormal data quantity at adjacent detection moments, for example, filled according to the change trend of the abnormal data quantity at the front and back detection moments, or filled according to the average value of the abnormal data quantity at adjacent front and back detection moments to ensure the accuracy of the data input into the Prophet model; thus, after inputting the abnormal data quantity at each detection moment in the first quantity curve into the Prophet model, the Prophet model fits the above input data to obtain the first fitting curve; among them, Figure 2 the blue curve in

[0049] The confidence interval is composed of an upper boundary curve representing the upper threshold value and a lower boundary curve representing the lower threshold value, with the fitting curve as the middle value. Specifically, it refers to the estimation interval of the population parameter constructed by the sample statistic, indicating how likely (i.e., the confidence level) the true value of the input parameter falls within this interval, and also indicating how many sampling points fall within this interval; after completing the configuration of the confidence interval width, the Prophet model can obtain the matching first confidence interval according to the first fitting curve; among them,Figure 2 The green curve in it is the upper boundary of the first confidence interval, and the red curve is the lower boundary of the first confidence interval.

[0050] S103. Determine the moment of quantity anomaly in the first time period according to the first confidence interval and the first quantity curve.

[0051] The detection moments in the first quantity curve that are outside the first confidence interval are all moments of quantity anomaly; among them, if the number of abnormal data is higher than the upper boundary of the first confidence interval, it means that the number of abnormal data obtained at this sampling moment has increased significantly. At this time, it may be due to a business system failure or an attack on the business system resulting in an increase in abnormal data; if the number of abnormal data is lower than the lower boundary of the first confidence interval, it means that the number of abnormal data obtained at this sampling moment is significantly too small. At this time, it may be due to the business system crashing or suspending business processing, resulting in a reduction in overall business data, and the corresponding abnormal data will also decrease, rather than the abnormal data value under normal operating conditions.

[0052] S104. Obtain the anomaly detection result of the business system in the first time period according to the actual anomaly quantity, fitted anomaly quantity, fitted anomaly upper limit, and fitted anomaly lower limit at the moment of quantity anomaly.

[0053] Classify and store the abnormal data quantities in the above-mentioned various curves (i.e., the first quantity curve, the first fitted curve, the upper boundary curve of the first confidence interval, and the lower boundary curve of the first confidence interval) at the moment of quantity anomaly, namely the actual anomaly quantity, the fitted anomaly quantity, the fitted anomaly upper limit, and the fitted anomaly lower limit. Then, according to the above-mentioned correlation parameters, obtain the anomaly detection result; for example, first obtain the difference between the maximum actual quantity and the corresponding predicted quantity at the moment of quantity anomaly, and then use the ratio of this difference to the maximum actual quantity as an evaluation index for the running stability of the current business system. The smaller this ratio is, the better the running stability of the current business system; the larger this ratio is, the worse the running stability of the current business system.

[0054] It is also possible to first obtain the differences between each actual quantity and the corresponding predicted quantity, and then use the largest ratio among the ratios of each difference to the corresponding actual quantity as an evaluation index for the running stability of the current business system. The smaller this ratio is, the better the running stability of the current business system; the larger this ratio is, the worse the running stability of the current business system; in addition, it is also possible to determine the running characteristics of the business system according to the distribution characteristics (continuous distribution or discrete distribution) of the moments of quantity anomaly.

[0055] For example, if the moments of abnormal quantity are continuously distributed, and there is a significant increase in the business quantity within this continuous time period, it is determined that the business system has an obvious business characteristic, that is, based on the increase in business quantity, a large number of abnormal data appear concentratedly in a specific continuous time period in the business system; if the moments of abnormal quantity are discretely distributed, and when the moments of abnormal quantity occur, there is no obvious change in the business quantity, it is determined that the business system does not have an obvious business characteristic, that is, based on the increase in business quantity, it will not cause a synchronous increase in the quantity of abnormal data.

[0056] Optionally, in an embodiment of the present invention, after determining the moments of abnormal quantity within the first time period, it further includes: obtaining an abnormal data waveform diagram according to the quantity of abnormal data at each moment of abnormal quantity; classifying and identifying the abnormal data waveform diagram through a pre-trained image classification model to obtain the types of abnormal behaviors in the business system within the first time period; where the types of abnormal behaviors include at least one of system failure behavior, external attack behavior, and resource limitation behavior.

[0057] Specifically, the abnormal data waveform diagram refers to a waveform diagram composed of the quantity of abnormal data corresponding to each moment of abnormal quantity, that is, a waveform diagram composed of the remaining curves after removing all the curves in the area of the first confidence interval. The abnormal data waveform diagram is input into the image classification model to obtain the type of abnormal behavior corresponding to this waveform through the image classification model; where the image classification model is an identification and classification model pre-trained based on deep learning or machine learning, and each training sample includes a combination of data waveforms, and the label of this training sample is marked with the corresponding type of abnormal behavior.

[0058] System failure behavior means that due to hardware or software failures of the business system, the server is unable to process one or more types of services, thereby causing the business system to generate abnormal data; external attack behavior means that due to external attacks on the business system, the business processing ability of the server itself is affected, thereby causing the business system to generate abnormal data; resource limitation behavior means that due to insufficient system resources (such as central processing unit resources and memory resources) of the business system, the business processing ability of the server itself is reduced, thereby causing the business system to generate abnormal data. Thus, by using the image classification model to identify the abnormal data waveform composed of the quantity of abnormal data at each moment of abnormal quantity, the detection and acquisition of the types of abnormal behaviors that generate abnormal data within the first time period are realized, providing an operation and maintenance analysis basis for the operation and maintenance management of the server.

[0059] Optionally, in the embodiments of the present invention, after obtaining the first quantity curve of the service system within the first time period, the method further includes: obtaining, through the time series model, a first prediction curve that matches the first quantity curve within a second time period; wherein the second time period is a downstream time period of the first time period; obtaining, according to the first confidence interval, prediction anomaly moments in the first prediction curve, and sending an operation and maintenance prompt message according to the prediction anomaly moments.

[0060] Specifically, according to the first quantity curve within the first time period, the time series model can predict the curve trend in the subsequent second time period, that is, obtain the first prediction curve within the second time period; wherein the second time period can be an adjacent downstream time period of the first time period, or a non-adjacent downstream time period of the first time period; after obtaining the first prediction curve, the first prediction curve can be compared with the first confidence interval to obtain the detection moments (i.e., prediction anomaly moments) outside the first confidence interval in the first prediction curve, and an operation and maintenance prompt message is sent based on the above prediction anomaly moments to prompt the operation and maintenance personnel to strengthen the prevention of abnormal behaviors at the corresponding time nodes to ensure the operation safety of the server.

[0061] Optionally, in the embodiments of the present invention, after obtaining, through the time series model, a first prediction curve that matches the first quantity curve within a second time period, the method further includes: obtaining a second quantity curve within the second time period, and obtaining, through the time series model, a second fitting curve and a second confidence interval that match the second quantity curve; comparing the first prediction curve with the second confidence interval to obtain prediction deviation moments outside the second confidence interval in the first prediction curve.

[0062] Specifically, the second quantity curve also reflects the mapping relationship between the detection moment and the abnormal data quantity; after actually obtaining the quantity curve within the second time (i.e., the second quantity curve), as in the above technical solution, a second fitting curve and a second confidence interval that match the second quantity curve are obtained through the time series model, and then the first prediction curve is compared with the second confidence interval to obtain the prediction deviation moments outside the second confidence interval in the first prediction curve; wherein the prediction deviation moment indicates that there is a large error between the prediction result and the actual result of the abnormal data quantity by the time series model at this moment. Accordingly, the associated parameters of the prediction deviation moment, including the predicted abnormal quantity, the actual abnormal quantity, the fitted abnormal quantity, the upper limit of the fitted anomaly, and the lower limit of the fitted anomaly, are input to the time series model again as adjustment parameters to improve the prediction accuracy of the time series model and ensure the accurate prediction of abnormal faults in the service system.

[0063] In the technical solution of the embodiment of the present invention, a first quantity curve reflecting the mapping relationship between the detection time and the number of abnormal data within the first time period is obtained; a first fitting curve and a first confidence interval matching the first quantity curve are obtained through a time series model; according to the first confidence interval and the first quantity curve, the quantity abnormal time within the first time period is determined; according to the actual abnormal quantity, the fitting abnormal quantity, the fitting abnormal upper limit, and the fitting abnormal lower limit at the quantity abnormal time, the abnormal detection result of the business system within the first time period is obtained. Thus, the abnormal detection result not only adapts to the data fluctuation and the change of data periodicity, but also avoids the missed report and false report of the abnormal state of the business system, improves the accuracy of the abnormal detection result, and improves the abnormal detection efficiency.

[0064] Embodiment 2

[0065] Figure 3 It is a flowchart of an abnormal detection method for a business system provided in Embodiment 2 of the present invention. The relationship between this embodiment and the above embodiment is that the position of the first confidence interval is adjusted according to the floating coefficient at each detection time, as Figure 3 shown. The method includes:

[0066] S201. Obtain the first quantity curve of the business system within the first time period; wherein, the first quantity curve reflects the mapping relationship between the detection time and the number of abnormal data.

[0067] S202. Obtain a first fitting curve matching the first quantity curve and an initial first confidence interval through a time series model.

[0068] S203. Obtain the floating coefficient at each detection time according to the number of abnormal data at each detection time in the first fitting curve.

[0069] The average value of the number of abnormal data at each detection time can be used to jointly form an intermediate value interval with multiple values before and after the average value. The floating coefficient corresponding to the intermediate value interval is 1; other value intervals are set in sequence according to the value interval span. The larger the value of the value interval, the larger the floating coefficient, and the smaller the value of the value interval, the smaller the floating coefficient; thus, the floating coefficient at each detection time can be obtained according to the number of abnormal data at each detection time in the first fitting curve.

[0070] S204. Update the initial first confidence interval according to the first fitting curve and the floating coefficient at each detection time to obtain the updated first confidence interval.

[0071] In the embodiments of the present invention, the difference between the upper boundary and the lower boundary of each detection moment in the initial first confidence interval remains unchanged, and the floating coefficient affects the positions of the upper boundary and the lower boundary of the confidence interval; if the floating coefficient is greater than 1, that is, the upper boundary and the lower boundary of the confidence interval are both moved upward; if the floating coefficient is less than 1, the upper boundary and the lower boundary of the confidence interval are both moved downward; if the floating coefficient is equal to 1, the positions of the upper boundary and the lower boundary of the confidence interval remain unchanged. However, no matter how they are moved, the upper boundary of the confidence interval will not be lower than the corresponding point in the fitting curve, and the lower boundary of the confidence interval will not be higher than the corresponding point in the fitting curve.

[0072] For example, if the floating coefficient is greater than 1, the difference between the floating coefficient and the value 1 is multiplied by the actual number of anomalies corresponding to the current detection moment, and both the upper boundary and the lower boundary of the confidence interval are moved upward based on the result of the above multiplication operation. This means that if the number of anomaly data at the current moment is large, in order to avoid the configured width of the confidence interval being too small, resulting in the number of anomaly data at the current moment being significantly more than the number of anomaly data covered by the confidence interval, the confidence interval of this part is moved upward to reduce the difference in the number of anomaly data and the confidence interval, and improve the detection accuracy of the moment of abnormal quantity.

[0073] If the floating coefficient is less than 1, the difference between the value 1 and the floating coefficient is multiplied by the actual number of anomalies corresponding to the current detection moment, and both the upper boundary and the lower boundary of the confidence interval are moved downward based on the result of the above multiplication operation. This means that if the number of anomaly data at the current moment is small, in order to avoid the configured width of the confidence interval being too small, resulting in the number of anomaly data at the current moment being significantly less than the number of anomaly data covered by the confidence interval, the confidence interval of this part is moved downward to reduce the difference in the number of anomaly data and the confidence interval, and improve the detection accuracy of the moment of abnormal quantity.

[0074] S205. Determine the moment of abnormal quantity in the first time period according to the updated first confidence interval and the first quantity curve.

[0075] S206. Obtain the anomaly detection result of the business system in the first time period according to the actual number of anomalies, the fitted number of anomalies, the upper limit of the fitted anomaly, and the lower limit of the fitted anomaly at the moment of abnormal quantity.

[0076] In the technical solution of the embodiment of the present invention, a first fitting curve and an initial first confidence interval that match the first quantity curve are obtained through a time series model; the floating coefficient of each detection time is obtained according to the number of abnormal data at each detection time in the first fitting curve; the initial first confidence interval is updated according to the first fitting curve and the floating coefficient of each detection time to obtain an updated first confidence interval. Thereby, the difference in the number between the abnormal data quantity and the confidence interval is reduced, and the detection accuracy of the quantity abnormal moment is improved.

[0077] Embodiment III

[0078] Figure 4 The flowchart of an abnormal detection method for a service system provided in Embodiment III of the present invention. The relationship between this embodiment and the above embodiments is that a first confidence interval is formed by splicing multiple alternative confidence intervals. As Figure 4 shown, the method includes:

[0079] S301. Obtain the first quantity curve of the service system within the first time period; wherein, the first quantity curve reflects the mapping relationship between the detection time and the number of abnormal data.

[0080] S302. Obtain alternative confidence intervals that respectively match the first quantity curve under various confidence interval widths through a time series model.

[0081] The confidence interval width usually can only be set in advance based on empirical values. However, setting a single confidence interval width often has a large prediction error. For example, in traditional technical solutions, the confidence interval width is usually set to 0.8 or 0.95. In the embodiment of the present invention, different confidence intervals (i.e., alternative confidence intervals) can be obtained by setting different confidence interval widths within the numerical range greater than or equal to 0.8 and less than or equal to 0.95.

[0082] S303. Obtain the target alternative confidence interval corresponding to each detection time according to the number of abnormal data at each detection time in the first quantity curve; wherein, the quantity interval where the number of abnormal data at the detection time is located has a positive correlation with the confidence interval width.

[0083] If the number of abnormal data at the current detection time is more, the corresponding confidence interval width is larger, that is, the span of the confidence interval is larger, so as to include the current detection time into the confidence interval as much as possible; if the number of abnormal data at the current detection time is less, the corresponding confidence interval width is smaller, that is, the span of the confidence interval is smaller, so as to improve the detection accuracy as much as possible.

[0084] For example, assume that according to the number of abnormal data at each detection time in the first quantity curve, the first quantity curve is successively divided into three curve segments, namely segment A, segment B, and segment C, and the numerical intervals where segment A, segment B, and segment C are located increase successively. Since the quantity interval where the number of abnormal data at the detection time is positively correlated with the confidence interval width, it can be determined that segment A, segment B, and segment C respectively correspond to confidence interval A, confidence interval B, and confidence interval C, and the widths of confidence interval A, confidence interval B, and confidence interval C increase successively; for example, the widths of confidence interval A, confidence interval B, and confidence interval C are 0.8, 0.88, and 0.95 respectively.

[0085] S304. In each target alternative confidence interval, obtain the target interval that matches the corresponding detection time, and combine the target intervals successively according to the time series of the corresponding detection time to obtain the first confidence interval that matches the first quantity curve.

[0086] In confidence interval A, the corresponding detection time is the detection time of segment A, and segment A is located at the front end, so the obtained target interval is the front-end interval of confidence interval A; in confidence interval B, the corresponding detection time is the detection time of segment B, and segment B is located in the middle, so the obtained target interval is the middle interval of confidence interval B; in confidence interval C, the corresponding detection time is the detection time of segment C, and segment C is located at the rear end, so the obtained target interval is the rear-end interval of confidence interval C.

[0087] According to the time series in which segment A, segment B, and segment C are arranged successively, combine the front-end interval of confidence interval A, the middle interval of confidence interval B, and the rear-end interval of confidence interval C successively. The combined result is the first confidence interval obtained that matches the first quantity curve; thus, according to the number of abnormal data at each detection time in the first quantity curve, multiple target alternative confidence intervals are selected, and then by combining different target intervals in each target alternative confidence interval successively, the combined first confidence interval is obtained, improving the accuracy of the calculation result of the first confidence interval, avoiding improper setting of the confidence interval width, resulting in too large or too small coverage area of the confidence interval, and enhancing the accuracy of the abnormal detection result.

[0088] S305. According to the first confidence interval and the first quantity curve, determine the quantity abnormal times within the first time period.

[0089] S306. According to the actual abnormal quantity, fitted abnormal quantity, fitted abnormal upper limit, and fitted abnormal lower limit of the quantity abnormal times, obtain the abnormal detection result of the business system within the first time period.

[0090] The technical solution of the embodiment of the present invention obtains alternative confidence intervals respectively matching the first quantity curve under various confidence interval widths through a time series model; obtains target alternative confidence intervals corresponding to each detection moment according to the number of abnormal data at each detection moment in the first quantity curve; in each target alternative confidence interval, obtains a target interval matching the corresponding detection moment, and combines each target interval in sequence according to the time series of the corresponding detection moment to obtain a first confidence interval matching the first quantity curve. Thereby, the accuracy of the calculation result of the first confidence interval is improved, and the situation that the coverage area of the confidence interval is too large or too small due to improper setting of the confidence interval width is avoided, and the accuracy of the abnormal detection result is improved.

[0091] Embodiment 4

[0092] Figure 5 FIG. 7 is a structural block diagram of an abnormal detection device for a service system provided in Embodiment 4 of the present invention, which specifically includes:

[0093] A quantity curve acquisition module 501 is configured to acquire a first quantity curve of the service system within a first time period; wherein, the first quantity curve reflects the mapping relationship between the detection moment and the number of abnormal data;

[0094] A fitting curve acquisition module 502 is configured to acquire a first fitting curve and a first confidence interval matching the first quantity curve through a time series model;

[0095] An abnormal moment acquisition module 503 is configured to determine the quantity abnormal moment within the first time period according to the first confidence interval and the first quantity curve;

[0096] A detection result acquisition module 504 is configured to acquire the abnormal detection result of the service system within the first time period according to the actual abnormal quantity, the fitting abnormal quantity, the fitting abnormal upper limit and the fitting abnormal lower limit at the quantity abnormal moment.

[0097] The technical solution of the embodiment of the present invention acquires a first quantity curve reflecting the mapping relationship between the detection moment and the number of abnormal data within a first time period; acquires a first fitting curve and a first confidence interval matching the first quantity curve through a time series model; determines the quantity abnormal moment within the first time period according to the first confidence interval and the first quantity curve; acquires the abnormal detection result of the service system within the first time period according to the actual abnormal quantity, the fitting abnormal quantity, the fitting abnormal upper limit and the fitting abnormal lower limit at the quantity abnormal moment. Thereby, the abnormal detection result not only adapts to the data fluctuation and the change of data periodicity, but also avoids the missed report and false report of the abnormal state of the service system, improves the accuracy of the abnormal detection result, and improves the abnormal detection efficiency.

[0098] Optionally, the exception detection device of the service system is further configured to obtain an abnormal data waveform graph according to the abnormal data quantities at each quantity abnormal moment; classify and identify the abnormal data waveform graph through a pre-trained image classification model to obtain the types of abnormal behaviors in the service system during the first time period; wherein, the types of abnormal behaviors include at least one of system failure behaviors, external attack behaviors, and resource limitation behaviors.

[0099] Optionally, the exception detection device of the service system is further configured to obtain a first prediction curve matching the first quantity curve during a second time period through the time series model; wherein, the second time period is a downstream time period of the first time period; obtain the predicted abnormal moments in the first prediction curve according to the first confidence interval, and send an operation and maintenance prompt message according to the predicted abnormal moments.

[0100] Optionally, the exception detection device of the service system is further configured to obtain a second quantity curve during the second time period, and obtain a second fitting curve and a second confidence interval matching the second quantity curve through the time series model; compare the first prediction curve with the second confidence interval to obtain the prediction offset moments in the first prediction curve that are outside the second confidence interval.

[0101] Optionally, the exception detection device of the service system is further configured to obtain a first fitting curve matching the first quantity curve and an initial first confidence interval through a time series model; obtain the floating coefficient at each detection moment according to the abnormal data quantity at each detection moment in the first fitting curve; update the initial first confidence interval according to the first fitting curve and the floating coefficients at each detection moment to obtain an updated first confidence interval.

[0102] Optionally, the exception detection device of the service system is further configured to obtain alternative confidence intervals respectively matching the first quantity curve under multiple confidence interval widths through a time series model; obtain the target alternative confidence interval corresponding to each detection moment according to the abnormal data quantity at each detection moment in the first quantity curve; wherein, the quantity interval where the abnormal data quantity at the detection moment is located has a positive correlation with the confidence interval width; obtain the target interval matching the corresponding detection moment in each target alternative confidence interval, and sequentially combine each target interval according to the time series of the corresponding detection moment to obtain a first confidence interval matching the first quantity curve.

[0103] The above device can execute the exception detection method of the service system provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method. For the technical details not described in detail in this embodiment, reference can be made to the exception detection method of the service system provided in any embodiment of the present invention.

[0104] Example 5

[0105] Figure 6 FIG. shows a schematic structural diagram of an electronic device 10 that can be used to implement the embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, electronic devices, blade electronic devices, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0106] As Figure 6 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. Among them, the memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.

[0107] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0108] The processor 11 can be various general-purpose and / or dedicated processing components with processing and computing capabilities. Some examples of the processor 11 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the anomaly detection method of the business system.

[0109] In some embodiments, the method for anomaly detection of a business system may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as a storage unit. In some embodiments, part or all of the computer program may be loaded and / or installed onto a heterogeneous hardware accelerator via a ROM and / or a communication unit. When the computer program is loaded into the RAM and executed by a processor, one or more steps of the above-described method for anomaly detection of the business system may be performed. Alternatively, in other embodiments, the processor may be configured to perform the method for anomaly detection of the business system by any other suitable means (e.g., by means of firmware).

[0110] The various embodiments of the systems and techniques described above in this document may be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include: being implemented in one or more computer programs that may be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0111] The computer program for implementing the method of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer programs are executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer programs may be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine, or entirely on a remote machine or an electronic device.

[0112] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0113] To provide for interaction with a user, the systems and techniques described herein can be implemented on a heterogeneous hardware accelerator that has: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the heterogeneous hardware accelerator. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).

[0114] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data electronic device), or a computing system that includes middleware components (e.g., an application electronic device), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0115] A computing system may include a client and an electronic device. The client and the electronic device are generally far from each other and usually interact via a communication network. The relationship between the client and the electronic device is generated by computer programs running on respective computers and having a client-electronic device relationship with each other. The electronic device may be a cloud electronic device, also known as a cloud computing electronic device or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.

[0116] It should be understood that various forms of processes shown above can be used, with steps reordered, added or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.

[0117] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. An anomaly detection method for a business system, characterized in that, Including: Obtain the first quantity curve of the business system within the first time period; wherein, the first quantity curve reflects the mapping relationship between the detection time and the quantity of abnormal data; Obtain the first fitting curve and the first confidence interval that match the first quantity curve through a time series model; Determine the quantity abnormal moments within the first time period according to the first confidence interval and the first quantity curve; Obtain the anomaly detection result of the business system within the first time period according to the actual abnormal quantity, the fitted abnormal quantity, the upper limit of the fitted anomaly, and the lower limit of the fitted anomaly at the quantity abnormal moments.

2. The method according to claim 1, wherein After determining the quantity abnormal moments within the first time period, it further includes: Obtain an abnormal data waveform diagram according to the quantity of abnormal data at each quantity abnormal moment; Classify and identify the abnormal data waveform diagram through a pre-trained image classification model to obtain the types of abnormal behaviors in the business system within the first time period; wherein, the types of abnormal behaviors include at least one of system failure behaviors, external attack behaviors, and resource limitation behaviors.

3. The method according to claim 1, wherein After obtaining the first quantity curve of the business system within the first time period, it further includes: Obtain the first prediction curve that matches the first quantity curve within the second time period through the time series model; wherein, the second time period is the downstream time period of the first time period; Obtain the predicted abnormal moments in the first prediction curve according to the first confidence interval, and send an operation and maintenance prompt message according to the predicted abnormal moments.

4. The method according to claim 3, wherein After obtaining the first prediction curve that matches the first quantity curve within the second time period through the time series model, it further includes: Obtain the second quantity curve within the second time period, and obtain the second fitting curve and the second confidence interval that match the second quantity curve through the time series model; Compare the first prediction curve with the second confidence interval to obtain the predicted deviation moments in the first prediction curve that are outside the second confidence interval.

5. The method according to claim 1, characterized in that, The step of obtaining the first fitting curve and the first confidence interval that match the first quantity curve through the time series model further includes: Obtain the first fitting curve that matches the first quantity curve and the initial first confidence interval through the time series model; Obtain the floating coefficient at each detection moment according to the quantity of abnormal data at each detection moment in the first fitting curve; Update the initial first confidence interval according to the first fitting curve and the floating coefficients at each detection moment to obtain the updated first confidence interval.

6. The method according to claim 1, characterized in that, The step of obtaining the first fitting curve and the first confidence interval that match the first quantity curve through the time series model further includes: Obtain alternative confidence intervals that match the first quantity curve respectively under various confidence interval widths through the time series model; Obtain the target alternative confidence interval corresponding to each detection moment according to the quantity of abnormal data at each detection moment in the first quantity curve; wherein, the quantity interval where the quantity of abnormal data at the detection moment is located has a positive correlation with the confidence interval width. Among the respective target alternative confidence intervals, obtain the target intervals that match the corresponding detection times, and sequentially combine the respective target intervals according to the time series of the corresponding detection times, so as to obtain the first confidence interval that matches the first quantity curve.

7. An abnormal detection device for a service system, characterized in that, Including: A quantity curve acquisition module, configured to acquire a first quantity curve of a service system within a first time period; wherein, the first quantity curve reflects the mapping relationship between the detection time and the quantity of abnormal data; A fitting curve acquisition module, configured to acquire a first fitting curve and a first confidence interval that match the first quantity curve through a time series model; An abnormal time acquisition module, configured to determine the quantity abnormal times within the first time period according to the first confidence interval and the first quantity curve; A detection result acquisition module, configured to obtain the abnormal detection result of the service system within the first time period according to the actual abnormal quantity, the fitting abnormal quantity, the fitting abnormal upper limit, and the fitting abnormal lower limit of the quantity abnormal times.

8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor, so that the at least one processor can execute the abnormal detection method of the service system according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the abnormal detection method of the service system according to any one of claims 1-6 when executed by a processor.

10. A computer program product, including a computer program, where the computer program implements the abnormal detection method of the service system according to any one of claims 1-6 when executed by a processor.