Charging service real-time monitoring method and device based on service probe

By building a multi-layer data analysis mechanism and anomaly recognition strategy based on multi-dimensional feature fusion, combining hardware state and scenario characteristics, a neural network classifier is established for abnormal analysis, which solves the insufficient data analysis, feature analysis and real-time monitoring in traditional paid business monitoring, and achieves efficient business exception recognition and early warning.

CN120416093AActive Publication Date: 2025-08-01BEIJING INTERNET ZHILIAN TECH CO LTD

Patent Information

Application Number
CN202510920312.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-04
Publication Date
2025-08-01
Estimated Expiration
2045-07-04

AI Technical Summary

Technical Problem

The existing charging business monitoring methods have shortcomings in data analysis, feature analysis and real-time monitoring, lacking systematicity and real-time nature, making it difficult to effectively integrate multi-dimensional data, resulting in insufficient early warnings.

Method used

By deploying network traffic acquisition devices for multi-layer analysis, building a business event chain, combining hardware state characteristics and scenario characteristics, using neural network classifiers for abnormal identification, and introducing a real-time monitoring engine for dynamic early warning.

Benefits of technology

It significantly improves the intelligence level and early warning effect of paid business monitoring, and achieves accurate identification and timely warning of business abnormalities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120416093A_ABST
    Figure CN120416093A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a charging service real-time monitoring method and device based on a service probe, and the method and device achieve the precise construction of a service event chain through constructing a multi-layer data analysis mechanism and integrating the data of an application layer, a session layer and a network layer. And designing an exception recognition strategy based on multi-dimensional feature fusion, and establishing a neural network classifier to perform exception event analysis in combination with hardware state features and scene features. A real-time monitoring engine is introduced, and dynamic early warning is carried out on business abnormity through hierarchical analysis and correlation analysis. According to the method, the defects of the traditional technology in the aspects of data analysis, feature analysis, real-time monitoring and the like are effectively overcome, and the intelligent level and the early warning effect of charging service monitoring are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing, and specifically to a real-time monitoring method and device for toll collection services based on business probes. Background Art

[0002] Existing toll collection service monitoring methods have obvious deficiencies. Traditional systems lack systematicness and real-time performance in data parsing, making it difficult to effectively integrate multi-dimensional data at the application layer, transport layer, network layer, and link layer, which affects the comprehensiveness of monitoring.

[0003] In addition, there are bottlenecks in feature analysis in the existing technology. Most systems fail to comprehensively consider hardware status and scenario features, and lack an anomaly recognition mechanism based on multi-dimensional feature fusion, resulting in inaccurate early warnings.

[0004] Existing systems have technical shortcomings in real-time monitoring. They lack the ability to dynamically analyze the business event chain and are difficult to detect anomalies in a timely manner through inter-layer data mapping, which affects the monitoring effect. Solving these problems is of great significance for improving the business monitoring level. Summary of the Invention

[0005] In view of the problems in the existing technology, this application provides a real-time monitoring method and device for toll collection services based on business probes, which can effectively solve the deficiencies of traditional technologies in data parsing, feature analysis, and real-time monitoring, and significantly improve the intelligent level and early warning effect of toll collection service monitoring.

[0006] To solve at least one of the above problems, this application provides the following technical solutions: In a first aspect, this application provides a real-time monitoring method for toll collection services based on business probes, including: Deploy a network traffic collection device, and obtain the network data stream of the data link layer from the core switch of the toll station through the network traffic collection device. Layer-by-layer parse the network data stream according to the application layer and the transport layer, extract transaction flow information and business management information from the application layer, extract device interaction information and vehicle identification information from the transport layer, extract business data transmission status information from the application layer, perform temporal correlation on the extracted multi-layer data based on the inter-layer data mapping relationship, generate a business event chain, and construct a toll collection service portrait model from the business event chain; Obtain the operation data and real-time business data of toll station equipment, extract the hardware status features from the equipment operation data, extract the scene features of traffic flow distribution, peak charging rules, and toll collection business indicators from the business data, perform feature fusion on the hardware status features and scene features to obtain a multi-dimensional feature vector, use the multi-dimensional feature vector to train a neural network classifier to obtain a business anomaly recognition model, and analyze the abnormal events in the business event chain based on the business anomaly recognition model to generate an abnormal event description vector; Build a business real-time monitoring engine, use the business real-time monitoring engine to perform hierarchical parsing and correlation analysis on newly collected network data streams, extract hardware status features and scene features for feature fusion, input the fused feature vector into the business anomaly recognition model for anomaly analysis, and generate business anomaly warning information when an abnormal event is identified.

[0007] Further, it also includes: establishing a physical connection between the network traffic collection device and the mirror port of the toll station core switch, configuring the data cache size and sampling time interval of the network traffic collection device, starting the data collection process of the network traffic collection device, writing the collected real-time network data stream into the data cache area, performing packet fragmentation and recombination on the network data stream in the data cache area to construct a complete network data stream; Build an application layer parsing unit to extract transaction flow information and business management information, build a transport layer parsing unit to extract device interaction information and vehicle identification information, build a network layer parsing unit to extract packet transmission status information, and based on the network layer parsing unit, connect the application layer parsing unit, transport layer parsing unit, and network layer parsing unit in series to form a protocol parsing processing chain, input the network data stream into each layer parsing unit in the protocol parsing processing chain in sequence to obtain hierarchical parsing results, and write the hierarchical parsing results into the data storage area according to a preset data format.

[0008] Further, it also includes: building a mapping matrix from the application layer to the transport layer and a mapping matrix from the transport layer to the network layer, calculating the correlation degree between data at different levels based on the mapping matrix, establishing a time series correlation relationship for data with a correlation degree higher than a preset threshold, combining multi-layer data with a time series correlation relationship to form a data link, sorting and merging the data link according to the timestamp, and generating a business event chain containing a complete business process; Extract four types of characteristic parameters, namely business type identifier, business operation sequence, business processing duration, and business status change, from the business event chain, input the characteristic parameters into a pre-trained deep learning model for feature vector conversion, construct a business portrait feature space based on the feature vector, calculate business similarity clustering in the feature space, generate a business portrait clustering model, and store the business portrait clustering model in the model library.

[0009] Further, it also includes: connecting the monitoring probe to the toll station equipment system, obtaining the processor utilization rate, memory occupancy rate, disk read / write rate, and network traffic data in the equipment, parsing and normalizing the data, constructing hardware status characteristic indicators, constructing the hardware status characteristic indicators into a characteristic matrix, and performing dimensionality reduction processing on the characteristic matrix to generate a hardware status characteristic vector; Reading the business transaction table data from the real-time business database, calculating the time distribution density and space distribution density of the traffic volume, identifying the rules of peak and trough periods of toll collection, extracting the ETC transaction success rate, ETC transaction time consumption, vehicle passing time, lane service incapability, billing accuracy rate, entrance information accuracy rate, license plate recognition accuracy rate, vehicle type recognition accuracy rate, and data transmission integrity rate, standardizing the traffic volume distribution data, toll collection peak rule data, and toll collection business index data, and using the feature weighting method to fuse the hardware status characteristic vector with the standardized scenario characteristic data to generate a multi-dimensional characteristic vector.

[0010] Further, it also includes: constructing a three-layer neural network structure, inputting the multi-dimensional characteristic vector into the input layer of the neural network, setting multiple convolutional kernels in the hidden layer to extract feature combinations, setting a softmax classifier in the output layer, using the backpropagation algorithm to iteratively optimize the neural network weights, calculating the classification accuracy rate based on the validation data set, and saving the trained neural network classifier as a business anomaly recognition model; Reading the business data in the business event chain, extracting the multi-dimensional characteristic vector and inputting it into the business anomaly recognition model, obtaining the type identifier and confidence score of the abnormal event, combining the type identifier and confidence score with the timestamp, device identifier, and operation sequence of the business event to generate an abnormal event description vector, sorting the abnormal event description vector according to the confidence score, and writing the sorting result into the abnormal event data table.

[0011] Further, it also includes: creating a data collection thread pool, a parsing and processing thread pool, and an analysis and processing thread pool, starting a network data stream collection task in the data collection thread pool, allocating the collected network data stream to the parsing and processing thread pool, calling the protocol parsing and processing chain to perform hierarchical parsing on the network data stream, writing the parsing result into the shared memory area, and reading the parsing result in the analysis and processing thread pool to perform data correlation analysis; Reading the parsed business data from the shared memory area, extracting the processor utilization rate, memory occupancy rate, disk read / write rate, and network traffic data in the equipment to construct a hardware status characteristic vector, extracting the traffic volume distribution data, toll collection peak rule data, and toll collection business index data to construct a scenario characteristic vector, and using the feature weighting method to fuse the hardware status characteristic vector with the scenario characteristic vector to generate a multi-dimensional characteristic vector for real-time monitoring.

[0012] Further, it further includes: inputting the fused feature vectors into the service anomaly recognition model batch by batch, obtaining the type identifier and confidence score of the anomaly event, performing normalization processing on the confidence score, comparing the normalized score with a preset anomaly threshold, marking the event higher than the anomaly threshold as an anomaly event, and writing the feature vector, type identifier, and confidence score of the anomaly event into the anomaly event buffer; Reading the anomaly event data from the anomaly event buffer, extracting the attribute information such as the occurrence time, device identifier, anomaly type, and anomaly degree of the anomaly event, matching the attribute information with a preset anomaly event description template, generating a standardized anomaly event description text, constructing a service anomaly warning message containing the anomaly event description text, and pushing the service anomaly warning message to the warning information processing module.

[0013] In a second aspect, the present application provides a real-time monitoring device for toll collection services based on a service probe, including: A model construction module, configured to deploy a network traffic collection device, obtain data link layer network data streams from the toll station core switch through the network traffic collection device, perform hierarchical parsing on the network data streams according to the application layer and the transport layer, extract transaction flow information and service management information from the application layer, extract device interaction information and vehicle identification information from the transport layer, extract service data transmission status information from the application layer, perform temporal association on the extracted multi-layer data based on the inter-layer data mapping relationship, generate a service event chain, and construct a toll collection service portrait model from the service event chain; An anomaly description module, configured to obtain toll station device operation data and real-time service data, extract hardware status features from the device operation data, extract scenario features such as traffic flow distribution, toll collection peak rules, and toll collection service indicators from the service data, perform feature fusion on the hardware status features and the scenario features to obtain a multi-dimensional feature vector, train a neural network classifier using the multi-dimensional feature vector to obtain a service anomaly recognition model, and analyze the anomaly events in the service event chain based on the service anomaly recognition model to generate an anomaly event description vector; A service detection module, configured to construct a service real-time monitoring engine, perform hierarchical parsing and correlation analysis on newly collected network data streams using the service real-time monitoring engine, extract hardware status features and scenario features for feature fusion, input the fused feature vectors into the service anomaly recognition model for anomaly analysis, and generate a service anomaly warning message when an anomaly event is recognized.

[0014] In a third aspect, the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the real-time monitoring method for charging services based on service probes are implemented.

[0015] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the real-time monitoring method for charging services based on service probes are implemented.

[0016] In a fifth aspect, the present application provides a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, the steps of the real-time monitoring method for charging services based on service probes are implemented.

[0017] As can be seen from the above technical solutions, the present application provides a real-time monitoring method and device for charging services based on service probes. By constructing a multi-layer data parsing mechanism and integrating data from the application layer, session layer, and network layer, an accurate construction of the service event chain is achieved. Design an anomaly recognition strategy based on multi-dimensional feature fusion, combine hardware status features and scenario features, and establish a neural network classifier for anomaly event analysis. Introduce a real-time monitoring engine to dynamically warn of service anomalies through hierarchical parsing and correlation analysis. This method effectively solves the deficiencies of traditional technologies in aspects such as data parsing, feature analysis, and real-time monitoring, and significantly improves the intelligent level and warning effect of charging service monitoring. Description of the Drawings

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0019] Figure 1 It is a schematic flowchart of the real-time monitoring method for charging services based on service probes in the embodiments of the present application; Figure 2 It is a structural diagram of the real-time monitoring device for charging services based on service probes in the embodiments of the present application; Figure 3 It is a schematic structural diagram of the electronic device in the embodiments of the present application.

[0020] Reference Signs: Electronic device 9600, central processing unit 9100, memory 9140, communication module 9110, input unit 9120, audio processor 9130, display 9160, power supply 9170, buffer memory 9141, application / function storage unit 9142, data storage unit 9143, driver program storage unit 9144, antenna 9111, speaker 9131, microphone 9132. Detailed implementation manners

[0021] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Apparently, the described embodiments are some but not all of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0022] In the technical solutions of the present application, the acquisition, storage, use, processing, etc. of data all comply with the relevant provisions of national laws and regulations.

[0023] Considering the problems existing in the prior art, the present application provides a real-time monitoring method and device for toll collection services based on a service probe. By constructing a multi-layer data parsing mechanism and integrating data from the application layer, transport layer, and network layer, an accurate construction of the service event chain is achieved. An anomaly recognition strategy based on multi-dimensional feature fusion is designed, and combined with hardware status features and scenario features, a neural network classifier is established for anomaly event analysis. A real-time monitoring engine is introduced to dynamically warn of service anomalies through hierarchical parsing and correlation analysis. This method effectively solves the deficiencies of traditional technologies in aspects such as data parsing, feature analysis, and real-time monitoring, and significantly improves the intelligent level and warning effect of toll collection service monitoring.

[0024] To effectively solve the deficiencies of traditional technologies in aspects such as data parsing, feature analysis, and real-time monitoring, and significantly improve the intelligent level and warning effect of toll collection service monitoring, the present application provides an embodiment of a real-time monitoring method for toll collection services based on a service probe. Refer to Figure 1 The real-time monitoring method for toll collection services based on a service probe specifically includes the following content: Step S101: Deploy a network traffic collection device. Obtain the data link layer network data stream from the toll station core switch through the network traffic collection device, perform hierarchical parsing on the network data stream according to the application layer and the transport layer, extract transaction flow information and business management information from the application layer, extract device interaction information and vehicle identification information from the transport layer, extract business data transmission status information from the application layer, perform temporal association on the extracted multi-layer data based on the inter-layer data mapping relationship, generate a business event chain, and construct a toll business portrait model from the business event chain; Optionally, in view of the problems existing in traditional toll business monitoring, such as incomplete data collection, insufficient protocol parsing, and insufficient business relevance analysis, this embodiment innovatively designs a set of business monitoring solutions based on multi-layer protocol analysis. In this embodiment, a high-performance network traffic collection device is first deployed on the toll station core switch, and professional network adapters and large-capacity data caches are used to ensure stable collection of network data streams in high-concurrency scenarios. The device establishes a physical connection with the switch through a mirror port and uses zero-packet-loss technology to capture network data packets in real time.

[0025] This embodiment deeply optimizes the protocol parsing mechanism. A hierarchical parsing strategy is adopted to process the network data stream: Protocol(data) = {App_layer, Session_layer, Network_layer}, where each layer represents the application layer, session layer, and network layer protocols respectively. The protocol type of each layer is accurately identified through a protocol recognition engine, and protocol parsing rules are customized for the toll business scenario. Especially for encrypted communication, the system realizes data decryption through a certificate management and key negotiation mechanism.

[0026] This embodiment innovatively realizes the application layer data extraction strategy. For the transaction flow information, the system parses the HTTP / HTTPS request and response packets and extracts business fields such as transaction amount, vehicle type category, and payment method. For the business management information, by analyzing the application layer command words and status codes, the business operation type and processing result are identified. The system pays special attention to abnormal status codes and timeout requests, which are of great value for discovering business anomalies.

[0027] This embodiment optimizes the session layer data analysis mechanism. By parsing the TCP / UDP session data, the communication mode and interaction sequence between devices are extracted. The system records the complete process of session establishment, data transmission, and session termination, and constructs a device interaction relationship diagram. For the vehicle identification information, license plate numbers, ETC card numbers and other identity identifiers are extracted by analyzing the session data, and a vehicle passing record is established.

[0028] In this embodiment, a network layer monitoring scheme is innovatively designed. The system analyzes the transmission status of IP data packets, including network performance indicators such as packet size, transmission delay, and packet loss rate: Performance = Statistics(packet_size, delay, loss_rate), where each parameter represents packet size, transmission delay, and packet loss rate respectively. Through these indicators, the system can timely detect network congestion and transmission anomalies.

[0029] In this embodiment, the data association mechanism is deeply optimized. The inter-layer data mapping relationship is constructed, and the association relationship of data at different levels is established through key fields such as session identifier, timestamp, and service identifier. The system uses the sliding window method to process data timeliness to ensure the integrity and continuity of business events. For complex multi-device interaction scenarios, a global data association view is established through graph model analysis.

[0030] In this embodiment, a business portrait modeling strategy is innovatively implemented. Based on the association analysis results, a business event chain is constructed to record the complete business processing flow. Through the deep learning model, the business characteristics in the event chain are analyzed, including processing timeliness, operation mode, state transition, etc. The system establishes a multi-dimensional business portrait feature space and identifies typical business models through clustering analysis.

[0031] In this embodiment, accurate portraits of toll collection services are achieved through deep learning technology. Especially when dealing with complex business scenarios, it shows strong analysis capabilities. Through multi-level data collection and in-depth protocol parsing, the system can accurately restore the business processing process and provide a reliable data basis for anomaly monitoring. This monitoring scheme based on multi-level analysis significantly improves the accuracy and real-time performance of business monitoring.

[0032] The innovative design of this embodiment not only solves the problems of data collection and analysis in traditional methods but also establishes a sustainable optimization monitoring framework. Through continuous data accumulation and dynamic optimization of the model, the system can continuously improve its analysis capabilities for various business scenarios and provide strong support for toll collection service management. This intelligent monitoring mechanism ensures that the system always maintains high monitoring capabilities and reliable analysis effects when facing complex and changeable business scenarios.

[0033] Step S102: Obtain the operation data of toll station devices and real-time business data, extract the hardware status features from the device operation data, extract the scene features of traffic flow distribution, toll collection peak rules, and toll collection service indicators from the business data, perform feature fusion on the hardware status features and the scene features to obtain a multi-dimensional feature vector, use the multi-dimensional feature vector to train a neural network classifier to obtain a business anomaly recognition model, and analyze the abnormal events in the business event chain based on the business anomaly recognition model to generate an abnormal event description vector; Optionally, in view of the problems existing in the monitoring of traditional toll collection services, such as incomplete feature extraction, insufficient scenario analysis, inaccurate anomaly identification, etc., this embodiment innovatively designs an anomaly identification solution based on multi-dimensional feature fusion. First, this embodiment accesses various key devices at the toll station through monitoring probes, including toll collection terminals, servers, network devices, etc., and collects device operation status data in real time. At the same time, real-time business records are extracted from the business database to ensure the integrity and timeliness of the data.

[0034] This embodiment deeply optimizes the hardware status feature extraction mechanism. Key performance indicators are extracted from the device operation data: Performance = Monitor(CPU, Memory, Disk, Network), where each parameter represents the processor utilization rate, memory occupancy rate, disk read / write rate, and network traffic respectively. By establishing a performance baseline, the system can detect device status anomalies in a timely manner. Especially for high-load scenarios, by analyzing the change trend of performance indicators, potential device failures can be predicted.

[0035] This embodiment innovatively implements a scenario feature analysis strategy. Regarding the traffic flow distribution characteristics, the system uses time series analysis methods to identify the traffic flow change rules at different times and on different sections of the road. By statistical modeling, the toll collection peak rules are found, including typical scenarios such as morning and evening peaks, and holiday peaks. For the toll collection service index factors, the system analyzes the impact of parameters such as precipitation, visibility, and temperature on the service: Impact = Analysis(weather, visibility, temperature), where each parameter represents the degree of influence of meteorological conditions on the toll collection service.

[0036] This embodiment optimizes the feature fusion mechanism. The attention mechanism is used to adaptively weight and fuse the hardware status features and scenario features. The fusion process takes into account the importance and timeliness of different features, and ensures the accuracy of feature representation through dynamic weight adjustment. The system particularly focuses on the correlation between features, such as the relationship between device load and traffic flow, and the association between environmental factors and device performance. This multi-dimensional feature fusion provides comprehensive data support for anomaly identification.

[0037] This embodiment innovatively designs an anomaly identification model training scheme. A deep neural network classifier is constructed, and a multi-layer perceptron structure is used to process high-dimensional feature data. The network structure includes a feature extraction layer, an attention layer, and a classification layer, and the automatic learning of anomaly patterns is achieved through end-to-end training. During the training process, the cross-validation method is used to evaluate the model performance, and the recognition accuracy is improved by adjusting the network parameters.

[0038] This embodiment deeply optimizes the abnormal event analysis mechanism. The data in the business event chain is input into the trained abnormal recognition model, which identifies potential abnormal situations by analyzing the characteristic patterns of the event sequence. The system pays attention to various types of abnormalities, including equipment failures, network anomalies, service interruptions, etc. For the detected abnormalities, the system generates a detailed description vector and records key information such as the type of abnormality, occurrence time, and scope of influence.

[0039] This embodiment innovatively implements an abnormal early warning strategy. An early warning mechanism is constructed based on the abnormal event description vector, and different levels of early warning information are generated according to the severity and scope of influence of the abnormality. The system establishes an early warning rule library and can flexibly adjust the early warning threshold according to specific scenarios. For emergency abnormal situations, the system pushes early warning messages through multiple channels to ensure that operation and maintenance personnel can respond in a timely manner.

[0040] This embodiment realizes the accurate recognition of business abnormalities through deep learning technology. Especially when dealing with complex scenarios, it shows strong analysis capabilities. Through multi-dimensional feature extraction and deep feature fusion, the system can accurately detect various abnormal situations, providing reliable guarantee for the stable operation of the charging business. This recognition scheme based on deep learning significantly improves the accuracy and real-time performance of abnormal detection.

[0041] The innovative design of this embodiment not only solves the problem of abnormal recognition in traditional methods, but also establishes a continuously optimizable monitoring framework. Through continuous data accumulation and dynamic model optimization, the system can continuously improve its recognition ability for various abnormal scenarios, providing strong support for the management of the charging business. This intelligent monitoring mechanism ensures that the system always maintains high monitoring capabilities and reliable early warning effects in the face of complex and changing business scenarios.

[0042] Step S103: Construct a business real-time monitoring engine, use the business real-time monitoring engine to perform hierarchical parsing and correlation analysis on newly collected network data streams, extract hardware status features and scenario features for feature fusion, input the fused feature vector into the business abnormal recognition model for abnormal analysis, and generate business abnormal early warning information when an abnormal event is recognized.

[0043] Optionally, this embodiment innovatively designs a real-time monitoring solution based on multi-threading to address the problems of poor real-time performance, low analysis efficiency, and untimely early warning in traditional charging business monitoring. This embodiment first constructs a high-performance business monitoring engine, adopting a multi-threaded parallel processing architecture, including a data collection thread pool, a parsing and processing thread pool, and an analysis and processing thread pool. Each thread pool dynamically adjusts the number of threads according to the number of CPU cores and business load to ensure the optimal utilization of resources.

[0044] This embodiment deeply optimizes the data processing mechanism. The zero-copy technology is adopted to achieve efficient collection of network data streams: Data_Flow = Capture(network, buffer), where network is the network interface and buffer is the data buffer. Data transfer between threads is realized through shared memory to minimize data replication overhead. The system adopts a batch processing mode to organize continuously collected data packets into data batches, improving the processing throughput.

[0045] This embodiment innovatively implements the protocol parsing strategy. Multiple-layer protocol parsing tasks, including application layer, session layer, and network layer data extraction, are executed in parallel in the parsing processing thread pool. For different protocol types, the system dynamically loads the corresponding parsing modules to improve the parsing efficiency. Especially for encrypted traffic, the system reduces the decryption overhead through the session key caching mechanism. For abnormal data packets, fault tolerance processing is adopted to ensure the stability of the parsing process.

[0046] This embodiment optimizes the feature extraction mechanism. Device operation data and scenario data are collected in parallel, and the hardware status features are calculated in real time: Hardware = Status(CPU, Memory, Disk, Network), where each parameter represents the CPU usage rate, memory occupancy rate, disk read / write rate, and network traffic respectively. The system smooths the performance metrics through the sliding window method to reduce the impact of instantaneous fluctuations. At the same time, the vehicle flow changes and environmental conditions are continuously monitored to update the scenario feature information.

[0047] This embodiment innovatively designs a feature fusion scheme. An adaptive weight mechanism is used to fuse the hardware status features and scenario features, and the weight coefficients are dynamically adjusted according to the importance of the features. The system considers the correlation between features and optimizes the feature combination through association analysis. For different types of abnormal patterns, differentiated feature weight configurations are adopted to improve the accuracy of abnormal identification.

[0048] This embodiment deeply optimizes the anomaly analysis mechanism. The fused feature vectors are batch-input into a pre-trained anomaly recognition model, and fast inference is achieved through GPU acceleration. The model outputs the anomaly type and confidence score, and the system filters out low-confidence anomaly events through the dynamic threshold mechanism. For continuously occurring similar anomalies, an event aggregation strategy is adopted to reduce redundant warnings.

[0049] This embodiment innovatively implements the warning generation strategy. The system generates a standardized warning text according to the attribute information of the anomaly event and the preset template, including the event occurrence time, device location, anomaly type, and processing suggestions. The warning message is reliably delivered through the message queue mechanism to ensure that critical warnings are not lost. The system supports dynamic adjustment of the warning level, and different warning priorities are set according to the impact range and urgency of the anomaly event.

[0050] In this embodiment, real-time monitoring of toll collection services is achieved through multi-thread parallel technology. Especially in dealing with high-concurrency service scenarios, it demonstrates powerful processing capabilities. Through efficient data processing and real-time anomaly analysis, the system can quickly detect and alert business anomalies, providing timely decision-making support for toll collection service management. This monitoring solution based on parallel processing significantly improves the real-time performance and reliability of business monitoring.

[0051] The innovative design of this embodiment not only solves the real-time processing problem in traditional methods but also establishes an extensible monitoring framework. Through the optimization of the multi-thread architecture and the improvement of the processing flow, the system can adapt to the growing business scale, providing reliable guarantee for the stable operation of toll collection services. This intelligent monitoring mechanism ensures that the system always maintains efficient monitoring capabilities and fast response effects in the face of complex and changing business scenarios. Especially through parallel processing and real-time warning, the system can issue warnings in the early stage of anomalies, effectively reducing business risks.

[0052] As can be seen from the above description, the real-time monitoring method for toll collection services based on business probes provided by the embodiments of this application can achieve the precise construction of business event chains by constructing a multi-layer data parsing mechanism and integrating data from the application layer, session layer, and network layer. Design an anomaly recognition strategy based on multi-dimensional feature fusion, combine hardware status features and scenario features, and establish a neural network classifier for anomaly event analysis. Introduce a real-time monitoring engine to dynamically warn of business anomalies through hierarchical parsing and correlation analysis. This method effectively solves the deficiencies of traditional technologies in data parsing, feature analysis, and real-time monitoring, significantly improving the intelligent level and warning effect of toll collection service monitoring.

[0053] In an embodiment of the real-time monitoring method for toll collection services based on business probes of this application, the following content may also be specifically included: Step S201: Establish a physical connection between the network traffic collection device and the mirror port of the toll station core switch, configure the data cache size and sampling time interval of the network traffic collection device, start the data collection process of the network traffic collection device, write the collected real-time network data stream into the data cache area, and perform packet fragmentation and recombination on the network data stream in the data cache area to construct a complete network data stream; Step S202: Construct an application layer parsing unit to extract transaction flow information and business management information, construct a transport layer parsing unit to extract device interaction information and vehicle identification information, construct a network layer parsing unit to extract packet transmission status information, connect the application layer parsing unit, the transport layer parsing unit, and the network layer parsing unit in series to form a protocol parsing processing chain, input the network data stream into each layer parsing unit in the protocol parsing processing chain in sequence to obtain a hierarchical parsing result, and write the hierarchical parsing result into the data storage area according to a preset data format.

[0054] Optionally, in view of the problems existing in the traditional toll business monitoring, such as unstable data collection, incomplete data parsing, and insufficient protocol analysis, this embodiment innovatively designs a data collection and parsing scheme based on multi-layer protocols. First, a high-performance network traffic collection device is deployed at the toll station, and a professional network adapter is used to support high-speed data collection of 10 Gbps. A physical connection is established between the collection device and the mirror port of the core switch through an optical fiber cable to ensure the stability and reliability of data transmission.

[0055] This embodiment deeply optimizes the data caching mechanism. Dynamically adjust the data cache size based on the real-time traffic monitoring results: Buffer_Size = Base_Size (1 + α Flow_Rate), where Base_Size is the base cache size, α is the adjustment coefficient, and Flow_Rate is the current traffic ratio. The sampling time interval is adaptively adjusted according to the business peak and valley characteristics, shortening the sampling interval during the business peak period and appropriately extending the interval during the valley period to ensure both data integrity and optimized storage efficiency.

[0056] This embodiment innovatively implements a data fragmentation and reassembly strategy. For large-scale network data streams, a multi-level cache structure is adopted, and independent receive buffers and processing buffers are set. The system identifies fragmented packets through the packet header information and establishes a fragmentation mapping table to record the fragmentation sequence number and offset: Fragment_Map = {Packet_ID, Offset, Length, Flag}, where each field represents the packet identifier, offset, length, and integrity flag respectively. Accurate fragmentation reassembly is performed based on the mapping table information.

[0057] This embodiment optimizes the application layer parsing mechanism. An application layer parsing unit is constructed to specifically process the application layer protocols related to the toll business. The content of the data packet is analyzed through a protocol recognition engine to extract business information such as transaction amount, vehicle type category, and payment method. For encrypted communication, the system realizes data decryption through a certificate management and key negotiation mechanism. The parsing unit can also identify business command words and status codes and analyze the business processing results.

[0058] In this embodiment, an innovative session layer analysis scheme is designed. The transport layer parsing unit establishes a complete view of device interaction by tracking the TCP / UDP session status. The system records the processes of session establishment, data transmission, and session termination, and extracts key information such as device identification, communication timing, and interaction patterns. For vehicle identification information, license plate numbers, ETC card numbers, and other identity identifiers are extracted through specialized parsing rules.

[0059] In this embodiment, the network layer monitoring mechanism is deeply optimized. The network layer parsing unit is responsible for analyzing the transmission status of IP data packets, including performance metrics such as packet size, transmission delay, and packet loss rate. The system monitors changes in the network status in real time by establishing a performance baseline model. Special attention is paid to abnormal situations such as network congestion and transmission interruption, providing a reference for the upper-layer service analysis of the network environment.

[0060] In this embodiment, an innovative protocol parsing chain design is implemented. The three-layer parsing units are connected in series according to the protocol levels to construct a complete parsing processing pipeline. The data stream passes through the network layer, session layer, and application layer parsing in sequence, and the parsing results of each layer save necessary context information for subsequent correlation analysis. The system adopts a multi-thread parallel processing mechanism to improve the parsing efficiency.

[0061] In this embodiment, accurate extraction of service data is achieved through hierarchical parsing technology. Especially in dealing with complex service scenarios, it shows strong parsing capabilities. Through multi-level protocol analysis and data correlation, the system can accurately restore the service processing process, providing a reliable data basis for anomaly monitoring. This monitoring scheme based on multi-level parsing significantly improves the integrity of data collection and the accuracy of parsing.

[0062] The innovative design of this embodiment not only solves the problems of data collection and parsing in traditional methods but also establishes a sustainable optimization processing framework. Through continuous data accumulation and dynamic optimization of parsing rules, the system can continuously improve its analysis capabilities for various service scenarios, providing strong support for toll business management. This intelligent parsing mechanism ensures that the system always maintains high-efficiency collection capabilities and reliable parsing effects in the face of complex and changing service scenarios. At the same time, the preset data format specifications ensure the standardized storage of parsing results, facilitating subsequent data analysis and applications.

[0063] In an embodiment of the real-time monitoring method for toll business based on service probes in this application, the following content may also be specifically included: Step S301: Construct a mapping matrix from the application layer to the session layer and a mapping matrix from the session layer to the network layer. Calculate the correlation degree between data at different levels based on the mapping matrix, establish a temporal correlation relationship for data with a correlation degree higher than a preset threshold, combine multi-layer data with a temporal correlation relationship to form a data link, sort and merge the data link according to timestamps, and generate a business event chain containing a complete business process; Step S302: Extract four types of characteristic parameters, namely, business type identifier, business operation sequence, business processing duration, and business status change, from the business event chain. Input the characteristic parameters into a pre-trained deep learning model for feature vector conversion, construct a business portrait feature space based on the feature vectors, calculate business similarity clustering in the feature space, generate a business portrait clustering model, and store the business portrait clustering model in the model library.

[0064] Optionally, in view of the problems existing in the traditional toll business monitoring, such as poor data correlation, incomplete extraction of business characteristics, and inaccurate portrait modeling, this embodiment innovatively designs a business portrait construction scheme based on multi-layer mapping. This embodiment first establishes a mapping relationship of multi-layer protocol data and constructs an inter-layer mapping matrix using the sparse matrix representation method: M(i,j) = Correlation(Layer_i, Layer_j), where Layer_i and Layer_j respectively represent data items of adjacent protocol layers, and Correlation represents the correlation strength between data items.

[0065] This embodiment deeply optimizes the correlation degree calculation mechanism. By analyzing the temporal dependence, content association, and business logic between data items, a multi-dimensional relevance evaluation model is established. The model takes into account multiple factors such as business field mapping, session identifier association, and packet sequence relationship. For example, when analyzing transaction records, the system associates the transaction information in the application layer with the device interaction records in the session layer through the session identifier, and then incorporates the relevant network layer transmission status data into the association link through timestamps.

[0066] This embodiment innovatively implements a temporal correlation strategy. The sliding window method is used to process the temporality of data, and the window size is dynamically adjusted according to the business processing delay. The system aligns data at different levels through timestamps to establish an accurate temporal relationship. For data items with a correlation degree exceeding the preset threshold, the system establishes a temporal correlation link to form a complete data processing link. This temporal-based correlation method can accurately restore the complete process of business processing.

[0067] This embodiment optimizes the business event chain generation mechanism. The associated data links are sorted according to timestamps, and a merging algorithm is used to process data in overlapping time windows. The system tracks the business processing flow through a state machine model to ensure the continuity and integrity of the event chain. Especially for complex business scenarios such as distributed processing or asynchronous operations, the system ensures the accuracy of the event chain through context association.

[0068] This embodiment innovatively designs a feature parameter extraction scheme. Four types of key feature parameters are extracted from the business event chain: the business type identifier reflects the nature of the business, the operation sequence records the processing steps, the processing duration represents the execution efficiency, and the state change shows the processing result. The system standardizes these parameters through a feature extractor to construct a standardized feature representation. Especially for abnormal business processes, abnormal patterns are identified by analyzing the state change sequence.

[0069] This embodiment deeply optimizes the feature vector conversion mechanism. A pre-trained deep learning model is used to convert the feature parameters into feature vectors with a fixed dimension. The model learns the internal representation of the features through a multi-layer neural network to capture the key patterns of business processing. The conversion process takes into account the correlation between features and highlights the influence of important features through an attention mechanism. For example, a higher attention weight is given to the state change of key business steps.

[0070] This embodiment innovatively implements a business portrait modeling strategy. An improved clustering algorithm is used in the feature space for business pattern analysis to identify typical business processing patterns. The system clusters similar business processes by calculating the similarity between feature vectors. The clustering results reflect the main patterns and variant forms of business processing, providing a benchmark reference for anomaly detection.

[0071] This embodiment realizes a precise portrait of the business process through deep learning technology. Especially when dealing with complex business scenarios, it shows strong feature extraction and pattern recognition capabilities. Through multi-level data association and deep feature learning, the system can accurately capture the key features of business processing, providing reliable model support for anomaly monitoring. This portrait scheme based on deep learning significantly improves the accuracy and efficiency of business analysis.

[0072] The innovative design of this embodiment not only solves the problems of feature extraction and modeling in traditional methods but also establishes a sustainable optimization portrait framework. Through continuous data accumulation and dynamic optimization of the model, the system can continuously improve its analysis ability for various business scenarios, providing strong support for toll business management. This intelligent portrait mechanism ensures that the system always maintains high analysis ability and reliable modeling effect when facing complex and changing business scenarios.

[0073] In an embodiment of the real-time monitoring method for toll collection services based on business probes in the present application, the following specific content may also be included: Step S401: Connect the monitoring probe to the toll station device system, obtain the device processor utilization rate, memory occupancy rate, disk read / write rate, and network traffic data in real time, construct hardware status characteristic indicators, construct the hardware status characteristic indicators into a characteristic matrix, and perform dimensionality reduction processing on the characteristic matrix to generate a hardware status characteristic vector; Step S402: Read the business transaction table data from the real-time business database, calculate the time distribution density and spatial distribution density of vehicle flow, identify the rules of peak and off-peak toll collection periods, extract precipitation, visibility, and temperature data from the meteorological monitoring data, perform standardization processing on the vehicle flow distribution data, peak toll collection period rule data, and toll collection service index data, and use the feature weighting method to fuse the hardware status characteristic vector with the standardized scenario characteristic data to generate a multi-dimensional characteristic vector.

[0074] Optionally, in view of the problems existing in traditional toll collection service monitoring, such as incomplete feature extraction, irregular data processing, and insufficient scenario analysis, this embodiment innovatively designs a data processing solution based on multi-dimensional feature fusion. This embodiment first connects various key devices in the toll station through a dedicated monitoring probe, including toll collection terminals, servers, network devices, etc. The probe adopts a lightweight design to minimize the impact on the business system and collects device operation data in real time through a standard interface.

[0075] This embodiment deeply optimizes the hardware status monitoring mechanism. It adopts a multi-dimensional performance index collection strategy: Performance = Monitor(CPU, Memory, Disk, Network), where each parameter represents the processor utilization rate, memory occupancy rate, disk read / write rate, and network traffic respectively. The system smooths the performance data through the sliding window method to eliminate the influence of instantaneous fluctuations. For sudden performance fluctuations, they are identified and processed through the outlier detection algorithm.

[0076] This embodiment innovatively implements a data normalization strategy. In view of the data differences of different devices and different indicators, it adopts an adaptive normalization method: Normalized = (Raw - Min) / (Max - Min), where Raw is the original data, and Min and Max are the real-time minimum and maximum values of the indicator respectively. By establishing a dynamic baseline, the system can accurately reflect the relative level of device performance. Especially for newly deployed devices, the performance baseline is gradually established through incremental learning.

[0077] This embodiment optimizes the feature matrix construction mechanism. The normalized hardware state indicators are organized into a multi-dimensional feature matrix. Each row of the matrix represents a state snapshot at a time point, and each column corresponds to a performance indicator. The dimensionality of the feature matrix is reduced by the principal component analysis method to retain the main feature information and reduce data redundancy. The system pays particular attention to the correlation between indicators and optimizes feature selection through correlation analysis.

[0078] This embodiment innovatively designs a scenario feature analysis scheme. The traffic flow distribution features are extracted from real-time business data, and the spatio-temporal distribution law of traffic flow is identified through time series analysis methods. The system uses a density clustering algorithm to analyze the spatial distribution features of traffic flow and identify dense and sparse traffic flow areas. For the peak charging rules, the traffic flow characteristics at different times are discovered through periodic analysis methods.

[0079] This embodiment deeply optimizes the meteorological data processing mechanism. The system analyzes the impact of environmental factors such as precipitation, visibility, and temperature on toll collection operations. By establishing a meteorological impact model, the impact degree of different meteorological conditions on business processing efficiency is quantified. Especially for adverse weather conditions, the system improves the reliability of environmental features through multi-source data fusion.

[0080] This embodiment innovatively implements a feature fusion strategy. An adaptive weight mechanism is used to fuse hardware state features and scenario features: Fusion = w1 Hardware + w2 Scene, where w1 and w2 are dynamic weight coefficients, Hardware is the hardware state feature vector, and Scene is the scenario feature vector. The weight coefficients are automatically adjusted through machine learning methods to ensure that the fused features can accurately reflect the overall state of the business scenario.

[0081] This embodiment realizes precise modeling of business scenarios through deep learning technology. Especially when dealing with complex scenarios, it shows strong feature expression ability. Through multi-dimensional feature extraction and deep feature fusion, the system can accurately depict the business operation state and provide a reliable data basis for anomaly monitoring. This analysis scheme based on multi-dimensional features significantly improves the accuracy and comprehensiveness of business monitoring.

[0082] The innovative design of this embodiment not only solves the problems of feature extraction and fusion in traditional methods but also establishes a feature analysis framework that can be continuously optimized. Through continuous data accumulation and dynamic feature optimization, the system can continuously improve its expression ability for various business scenarios and provide strong support for toll collection business management. This intelligent feature processing mechanism ensures that the system always maintains efficient feature extraction and reliable fusion effects when facing complex and changing business scenarios.

[0083] In an embodiment of the real-time monitoring method for charging services based on business probes in the present application, the following specific content may also be included: Step S501: Construct a three-layer neural network structure. Input the multi-dimensional feature vector into the input layer of the neural network. Set multiple convolutional kernels in the hidden layer to extract feature combinations. Set a softmax classifier in the output layer. Use the backpropagation algorithm to iteratively optimize the neural network weights. Calculate the classification accuracy based on the validation data set. Save the trained neural network classifier as a business anomaly recognition model. Step S502: Read the business data in the business event chain. Extract the multi-dimensional feature vector and input it into the business anomaly recognition model. Obtain the type identifier and confidence score of the abnormal event. Combine the type identifier and confidence score with the timestamp, device identifier, and operation sequence of the business event to generate an abnormal event description vector. Sort the abnormal event description vector according to the confidence score. Write the sorting result into the abnormal event data table.

[0084] Optionally, in view of the problems existing in traditional charging service monitoring, such as incomplete feature extraction, inaccurate anomaly recognition, and untimely warning, this embodiment innovatively designs a set of anomaly recognition solutions based on deep learning. This embodiment first constructs a three-layer neural network structure. The dimension of the input layer matches the dimension of the feature vector. The hidden layer adopts a multi-channel convolutional structure, and the output layer uses a softmax classifier. The network structure design follows the characteristics of anomaly recognition, and improves the recognition accuracy through deep feature extraction.

[0085] This embodiment deeply optimizes the feature learning mechanism. Set multi-scale convolutional kernels in the hidden layer: Conv(x) = σ(W x + b), where W is the convolutional kernel weight, b is the bias term, σ is the activation function, and x is the input feature. Capture the local correlation of features through convolutional kernels of different sizes to achieve multi-granularity feature extraction. For example, small-sized convolutional kernels focus on the instantaneous changes in the hardware state, and large-sized convolutional kernels capture the long-term trends of business traffic.

[0086] This embodiment innovatively implements a classifier optimization strategy. Use a softmax classifier in the output layer to calculate the probability distribution of various anomalies, and guide the model training through the cross-entropy loss function. Adopt an adaptive learning rate adjustment strategy during the backpropagation process, and dynamically adjust the parameter update step size according to the loss change. The system accelerates the training convergence through batch normalization technology, and at the same time uses the dropout mechanism to prevent overfitting.

[0087] This embodiment optimizes the model verification mechanism. The K-fold cross-validation method is used to evaluate the model performance, and the recognition effects of different types of anomalies are analyzed through the confusion matrix. The system pays special attention to the recognition accuracy of high-risk anomalies and improves the recognition performance of key anomalies by adjusting the class weights. For newly emerging anomaly patterns, the model parameters are updated through the incremental learning method.

[0088] This embodiment innovatively designs an abnormal event description scheme. The type identifier and confidence score output by the model are combined with the context information of the business event to construct a structured abnormal event description. The description vector contains complete information in the time dimension, space dimension, and business dimension, facilitating subsequent analysis and processing. The system determines the processing priority of anomalies through confidence ranking.

[0089] This embodiment deeply optimizes the feature extraction mechanism. The hardware status indicators are monitored in real time, including the processor utilization rate, memory occupancy rate, disk read / write speed, and network traffic. Through data cleaning and normalization processing, a standardized hardware status feature matrix is constructed. The system uses the principal component analysis method for dimensionality reduction, reducing redundant information while retaining the key feature dimensions.

[0090] This embodiment innovatively realizes scenario feature analysis. The distribution law of vehicle flow is mined from real-time data to identify peak and off-peak toll collection periods. Combining the analysis of toll collection business indicator data on the influence of external factors, the comparability of features in different dimensions is ensured through standardization processing. The system uses a weighted fusion method to integrate the hardware status and scenario features to generate a comprehensive feature representation.

[0091] This embodiment realizes the accurate recognition of business anomalies through deep learning technology. Especially when dealing with complex scenarios, it shows strong feature learning and pattern recognition capabilities. Through multi-level feature extraction and deep neural network learning, the system can accurately identify various abnormal situations, providing reliable decision-making support for toll collection business management. This recognition scheme based on deep learning significantly improves the accuracy and real-time performance of anomaly detection.

[0092] The innovative design of this embodiment not only solves the problems of feature extraction and anomaly recognition in traditional methods but also establishes a continuously optimizable monitoring framework. Through the continuous accumulation of data and the dynamic optimization of the model, the system can continuously improve its recognition ability for various abnormal scenarios, providing reliable guarantees for the stable operation of the toll collection business. This intelligent monitoring mechanism ensures that the system always maintains high recognition ability and reliable warning effects when facing complex and changeable business scenarios.

[0093] In an embodiment of the real-time toll collection business monitoring method based on business probes of this application, the following content may also be specifically included: Step S601: Create a data collection thread pool, a parsing and processing thread pool, and an analysis and processing thread pool. Start a network data stream collection task in the data collection thread pool, allocate the collected network data stream to the parsing and processing thread pool, call the protocol parsing and processing chain to perform hierarchical parsing on the network data stream, write the parsing result into the shared memory area, and read the parsing result in the analysis and processing thread pool for data correlation analysis; Step S602: Read the parsed service data from the shared memory area, extract the processor utilization rate, memory occupancy rate, disk read and write speed, and network traffic data in the device to construct a hardware status feature vector, extract the traffic flow distribution data, peak charging pattern data, and toll collection service index data to construct a scenario feature vector, and use the feature weighting method to fuse the hardware status feature vector and the scenario feature vector to generate a multi-dimensional feature vector for real-time monitoring.

[0094] Optionally, this embodiment innovatively designs a real-time processing solution based on multi-threading for the problems existing in traditional toll collection service monitoring, such as low processing efficiency, unreasonable resource utilization, and untimely feature extraction. This embodiment first constructs an efficient thread pool management architecture, including three independent thread pools for data collection, parsing and processing, and analysis and processing. The thread pool size is dynamically configured according to the number of CPU cores of the server: Pool_Size = CPU_Cores (1 + Load_Factor), where CPU_Cores is the number of processor cores and Load_Factor is the load factor.

[0095] This embodiment deeply optimizes the data collection mechanism. Implement a zero-copy data collection strategy in the data collection thread pool to minimize data transmission overhead through direct memory access technology. The collection thread monitors the network interface in a polling manner and immediately triggers the collection operation when new data is detected. The system manages the collection requests through a task queue to ensure the stability of data collection in high-concurrency scenarios. Especially for bursty data traffic, dynamically adjust the number of collection threads to adapt to load changes.

[0096] This embodiment innovatively implements a parsing and processing strategy. The parsing and processing thread pool is responsible for executing the protocol parsing task, and uses a pipeline design to improve processing efficiency. Each parsing thread is equipped with an independent parsing context, and concurrent parsing requests are processed through the context switching mechanism. The system uses the task sharding technology to decompose the large-scale data stream into data blocks of appropriate size for parallel parsing. For complex protocol parsing, the parsing speed is increased by caching the parsing rules.

[0097] This embodiment optimizes the memory management mechanism. It uses a shared memory area to store the parsing results and realizes efficient data sharing through memory mapping technology: Memory_Map = Map(Shared_Memory, Access_Mode), where Shared_Memory is the shared memory area and Access_Mode is the access mode. The system adopts a read-write lock mechanism to protect the shared data and ensure the thread safety of data access. Especially for frequently accessed data, the dynamic allocation overhead is reduced through the memory pre-allocation strategy.

[0098] This embodiment innovatively designs a data analysis solution. The analysis processing thread pool is responsible for executing data correlation analysis tasks and optimizes the data access efficiency through a multi-level cache. The system extracts hardware status features in real time, including performance metrics such as processor utilization rate, memory occupancy rate, disk read-write speed, and network traffic. The performance data is aggregated in real time through a sliding window method to generate a feature vector reflecting the device status.

[0099] This embodiment deeply optimizes the scenario feature construction mechanism. The system processes traffic flow distribution data, peak charging pattern data, and toll business metric data in parallel and identifies business features through time series analysis methods. For traffic flow data, a density estimation algorithm is used to calculate spatio-temporal distribution features. The system pays special attention to the impact of environmental factors and improves the reliability of scenario features through multi-source data fusion.

[0100] This embodiment innovatively implements a feature fusion strategy. It uses an adaptive weight mechanism to fuse hardware status features and scenario features, and the weight coefficients are dynamically adjusted through real-time performance evaluation. The system considers the timeliness of features and assigns greater weights to features with high real-time requirements. The feature fusion process adopts a parallel computing method to ensure real-time performance in large-scale data processing scenarios.

[0101] This embodiment realizes the real-time processing of business data through multi-thread parallel technology. Especially in processing high-concurrency business scenarios, it shows strong processing capabilities. Through efficient thread management and data processing, the system can quickly extract and fuse various features, providing real-time data support for anomaly monitoring. This monitoring scheme based on parallel processing significantly improves the real-time performance and accuracy of business monitoring.

[0102] The innovative design of this embodiment not only solves the processing efficiency problem in traditional methods but also establishes an extensible real-time processing framework. Through the optimization of the multi-thread architecture and the improvement of the processing flow, the system can adapt to the growing business scale and provide reliable guarantee for the real-time monitoring of toll business. This intelligent processing mechanism ensures that the system always maintains high processing capabilities and reliable analysis effects in the face of complex and changing business scenarios.

[0103] In an embodiment of the real-time monitoring method for charging services based on business probes in this application, the following specific contents may further be included: Step S701: Input the fused feature vectors into the service anomaly recognition model batch by batch, obtain the type identification and confidence score of the anomaly event, perform normalization processing on the confidence score, compare the normalized score with a preset anomaly threshold, mark the events with scores higher than the anomaly threshold as anomaly events, and write the feature vectors, type identification, and confidence scores of the anomaly events into the anomaly event buffer; Step S702: Read the anomaly event data from the anomaly event buffer, extract the attribute information such as the occurrence time, device identification, anomaly type, and anomaly degree of the anomaly event, match the attribute information with a preset anomaly event description template, generate a standardized anomaly event description text, construct a service anomaly warning message containing the anomaly event description text, and push the service anomaly warning message to the warning information processing module.

[0104] Optionally, in view of the problems existing in traditional charging service monitoring, such as low anomaly recognition efficiency, non-standard warning descriptions, and untimely responses, this embodiment innovatively designs a set of batch-based anomaly warning solutions. This embodiment first performs batch processing on the fused feature vectors, adopts an efficient data batch processing mechanism, and realizes fast model inference through GPU acceleration. The batch size is dynamically adjusted according to the real-time service load, optimizing the utilization of computing resources while ensuring real-time performance.

[0105] This embodiment deeply optimizes the confidence evaluation mechanism. The confidence score is mapped to a unified interval through normalization processing: Score_norm = (Score - Min_score) / (Max_score - Min_score), where Score is the original confidence score, and Min_score and Max_score are the real-time minimum and maximum scores respectively. The system adopts an adaptive threshold strategy and dynamically adjusts the anomaly determination criteria according to the characteristics of the business scenario. For example, the threshold is appropriately increased during the business peak period to reduce false alarms, and the threshold is decreased during the off-peak period to improve sensitivity.

[0106] This embodiment innovatively realizes the anomaly event caching strategy. A hierarchical storage structure is adopted to manage the anomaly event data. High-priority events are stored in the fast access area to ensure fast response to critical anomalies. The buffer adopts a circular buffer design, and the life cycle of event data is managed through a sliding window method. The system optimizes the utilization of storage space through data compression technology and archives the real-time event data regularly.

[0107] This embodiment optimizes the event attribute extraction mechanism. Multidimensional attribute information is extracted from abnormal event data, including time dimension (occurrence time, duration), space dimension (device location, affected range), business dimension (abnormal type, severity), etc. The system discovers the causal relationships between events through attribute correlation analysis and identifies chain failures and potential risks.

[0108] This embodiment innovatively designs an event description generation scheme. A multi-level abnormal event description template is constructed, and the description format is customized for different types of abnormalities. The template contains fixed fields and variable fields, and accurate and standardized description text is generated through parameter substitution: Description = Template(Time, Device, Type, Level), where each parameter represents the abnormal occurrence time, device identifier, abnormal type, and severity respectively.

[0109] This embodiment deeply optimizes the warning message construction mechanism. The event description text is integrated with relevant context information to form a structured warning message. The warning message contains multiple information levels, from the summary to the details, which is convenient for recipients of different roles to quickly understand the abnormal situation. The system sets the message priority according to the abnormal severity to ensure that important warnings can be processed first.

[0110] This embodiment innovatively implements a warning push strategy. Based on the message queue mechanism, reliable warning delivery is achieved, and multi-level caching is used to ensure that messages are not lost. The system supports multi-channel pushing, including internal system notifications, text messages, emails, etc., and selects the appropriate pushing method according to the role and scenario of the recipient. For urgent abnormalities, the system ensures the timely delivery of warning information through backup channels.

[0111] This embodiment realizes the efficient processing of abnormal events through pipeline processing technology. Especially when dealing with high-concurrency abnormalities, it shows strong processing capabilities. Through multi-stage data processing and intelligent warning generation, the system can quickly respond to various abnormal situations and provide timely warning support for toll business management. This pipeline-based processing solution significantly improves the real-time performance and reliability of abnormal warnings.

[0112] The innovative design of this embodiment not only solves the warning processing problems in traditional methods but also establishes an extensible warning framework. Through the continuous optimization of warning templates and the improvement of the push mechanism, the system can continuously improve its response ability to various abnormal scenarios and provide reliable guarantees for the stable operation of the toll business. This intelligent warning mechanism ensures that the system always maintains high processing capabilities and reliable warning effects when facing complex and changeable business scenarios.

[0113] In order to effectively solve the deficiencies of traditional technologies in aspects such as data parsing, feature analysis, and real-time monitoring, and significantly improve the intelligent level and early warning effect of toll business monitoring, this application provides an embodiment of a real-time toll business monitoring device based on business probes for implementing all or part of the above-mentioned real-time toll business monitoring method based on business probes. Refer to Figure 2 The real-time toll business monitoring device based on business probes specifically includes the following components: A model construction module 10, which is used to deploy a network traffic collection device, obtain data link layer network data streams from the core switch of the toll station through the network traffic collection device, perform hierarchical parsing on the network data streams according to the application layer and the transport layer, extract transaction flow information and business management information from the application layer, extract device interaction information and vehicle identification information from the transport layer, extract business data transmission status information from the application layer, perform temporal association on the extracted multi-layer data based on the inter-layer data mapping relationship, generate a business event chain, and construct a toll business portrait model from the business event chain; An anomaly description module 20, which is used to obtain toll station device operation data and real-time business data, extract hardware status features from the device operation data, extract scenario features such as traffic flow distribution, toll peak rules, and toll business indicators from the business data, fuse the hardware status features and the scenario features to obtain a multi-dimensional feature vector, train a neural network classifier using the multi-dimensional feature vector to obtain a business anomaly recognition model, and analyze the anomaly events in the business event chain based on the business anomaly recognition model to generate an anomaly event description vector; A business detection module 30, which is used to construct a business real-time monitoring engine, perform hierarchical parsing and correlation analysis on newly collected network data streams using the business real-time monitoring engine, extract and fuse hardware status features and scenario features, input the fused feature vector into the business anomaly recognition model for anomaly analysis, and generate a business anomaly early warning message when an anomaly event is identified.

[0114] As can be seen from the above description, the real-time toll business monitoring device based on business probes provided by the embodiments of this application can accurately construct a business event chain by building a multi-layer data parsing mechanism and integrating data from the application layer, session layer, and network layer. Design an anomaly recognition strategy based on multi-dimensional feature fusion, combine hardware status features and scenario features, and establish a neural network classifier for anomaly event analysis. Introduce a real-time monitoring engine to dynamically warn of business anomalies through hierarchical parsing and correlation analysis. This method effectively solves the deficiencies of traditional technologies in aspects such as data parsing, feature analysis, and real-time monitoring, and significantly improves the intelligent level and early warning effect of toll business monitoring.

[0115] From a hardware perspective, in order to effectively address the deficiencies of traditional technologies in aspects such as data parsing, feature analysis, and real-time monitoring, and significantly improve the intelligent level and early warning effect of toll business monitoring, this application provides an embodiment of an electronic device for implementing all or part of the real-time toll business monitoring method based on business probes. The electronic device specifically includes the following: A processor, a memory, a communications interface, and a bus; wherein, the processor, the memory, and the communications interface complete communication with each other through the bus; the communications interface is used to realize information transmission between the real-time toll business monitoring device based on business probes and related devices such as the core business system, user terminals, and relevant databases. The logic controller can be a desktop computer, a tablet computer, a mobile terminal, etc., and this embodiment is not limited thereto. In this embodiment, the logic controller can be implemented with reference to the embodiments of the real-time toll business monitoring method based on business probes and the embodiments of the real-time toll business monitoring device based on business probes, and the content is incorporated herein, and the repeated parts will not be elaborated.

[0116] It can be understood that the user terminal may include a smart phone, a tablet electronic device, a network set-top box, a portable computer, a desktop computer, a personal digital assistant (PDA), a vehicle-mounted device, a smart wearable device, etc. Among them, the smart wearable device may include smart glasses, a smart watch, a smart bracelet, etc.

[0117] In actual applications, part of the real-time toll business monitoring method based on business probes can be executed on the electronic device side as described above, or all operations can be completed in the client device. Specifically, it can be selected according to the processing capacity of the client device and the limitations of the user usage scenario, etc. This application does not make any limitations in this regard. If all operations are completed in the client device, the client device may further include a processor.

[0118] The above-mentioned client device may have a communication module (i.e., a communication unit) and can communicate with a remote server to realize data transmission with the server. The server may include a server on the task scheduling center side, and in other implementation scenarios, it may also include a server on the intermediate platform, such as a server on a third-party server platform with a communication link to the task scheduling center server. The server may include a single computer device, or a server cluster composed of multiple servers, or a server structure of a distributed device.

[0119] Figure 3 This is a schematic block diagram of the system composition of the electronic device 9600 according to the embodiment of this application. AsFigure 3 As shown, the electronic device 9600 may include a central processing unit 9100 and a memory 9140; the memory 9140 is coupled to the central processing unit 9100. It should be noted that this Figure 3 is exemplary; other types of structures may also be used to supplement or replace this structure to implement telecommunication functions or other functions.

[0120] In one embodiment, the function of the real-time monitoring method for toll services based on service probes may be integrated into the central processing unit 9100. Among them, the central processing unit 9100 may be configured to perform the following controls: Step S101: Deploy a network traffic collection device, obtain data link layer network data streams from the core switch of the toll station through the network traffic collection device, perform hierarchical parsing on the network data streams according to the application layer and the transport layer, extract transaction flow information and service management information from the application layer, extract device interaction information and vehicle identification information from the transport layer, extract service data transmission status information from the application layer, perform temporal correlation on the extracted multi-layer data based on the inter-layer data mapping relationship, generate a service event chain, and construct a toll service portrait model from the service event chain; Step S102: Obtain the operation data and real-time service data of the toll station devices, extract the hardware state features from the device operation data, extract the scenario features of traffic flow distribution, toll peak rules, and toll service indicators from the service data, perform feature fusion on the hardware state features and the scenario features to obtain a multi-dimensional feature vector, use the multi-dimensional feature vector to train a neural network classifier to obtain a service anomaly recognition model, and analyze the abnormal events in the service event chain based on the service anomaly recognition model to generate an abnormal event description vector; Step S103: Construct a service real-time monitoring engine, use the service real-time monitoring engine to perform hierarchical parsing and correlation analysis on the newly collected network data streams, extract the hardware state features and the scenario features for feature fusion, input the fused feature vector into the service anomaly recognition model for anomaly analysis, and generate a service anomaly warning message when an abnormal event is recognized.

[0121] As can be seen from the above description, the electronic device provided by the embodiment of the present application realizes the accurate construction of the service event chain by constructing a multi-layer data parsing mechanism and integrating the data of the application layer, session layer, and network layer. Design an anomaly recognition strategy based on multi-dimensional feature fusion, combine the hardware state features and the scenario features, and establish a neural network classifier for abnormal event analysis. Introduce a real-time monitoring engine to dynamically warn of service anomalies through hierarchical parsing and correlation analysis. This method effectively solves the deficiencies of traditional technologies in data parsing, feature analysis, and real-time monitoring, and significantly improves the intelligent level and warning effect of toll service monitoring.

[0122] In another embodiment, the real-time monitoring device for toll services based on service probes can be separately configured from the central processing unit 9100. For example, the real-time monitoring device for toll services based on service probes can be configured as a chip connected to the central processing unit 9100, and the functions of the real-time monitoring method for toll services based on service probes are implemented through the control of the central processing unit.

[0123] As Figure 3 shown, the electronic device 9600 may further include: a communication module 9110, an input unit 9120, an audio processor 9130, a display 9160, and a power supply 9170. It should be noted that the electronic device 9600 does not necessarily have to include Figure 3 all the components shown in Figure 3 ; in addition, the electronic device 9600 may further include

[0124] As Figure 3 shown, the central processing unit 9100, sometimes also referred to as a controller or operation control, may include a microprocessor or other processor devices and / or logic devices. The central processing unit 9100 receives inputs and controls the operations of the various components of the electronic device 9600.

[0125] Among them, the memory 9140, for example, may be one or more of a buffer, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory, or other suitable devices. The above information related to failures can be stored, and in addition, programs for executing relevant information can also be stored. And the central processing unit 9100 can execute the programs stored in the memory 9140 to implement information storage or processing, etc.

[0126] The input unit 9120 provides inputs to the central processing unit 9100. The input unit 9120 is, for example, a key or a touch input device. The power supply 9170 is used to supply power to the electronic device 9600. The display 9160 is used to display display objects such as images and texts. The display may be, for example, an LCD display, but is not limited thereto.

[0127] The memory 9140 may be a solid-state memory. For example, a read-only memory (ROM), a random access memory (RAM), a SIM card, etc. It may also be such a memory that stores information even when powered off, can be selectively erased and has more data. Examples of such a memory are sometimes referred to as EPROMs, etc. The memory 9140 may also be some other type of device. The memory 9140 includes a buffer memory 9141 (sometimes referred to as a buffer). The memory 9140 may include an application / function storage unit 9142, and the application / function storage unit 9142 is used to store application programs and function programs or the processes for operating the electronic device 9600 through the central processing unit 9100.

[0128] The memory 9140 may further include a data storage unit 9143 for storing data such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 9144 of the memory 9140 may include various drivers for the communication functions of the electronic device and / or for performing other functions of the electronic device (such as a messaging application, an address book application, etc.).

[0129] The communication module 9110 is a transmitter / receiver that transmits and receives signals via the antenna 9111. The communication module 9110 (transmitter / receiver) is coupled to the central processor 9100 to provide input signals and receive output signals, which may be the same as in the case of a conventional mobile communication terminal.

[0130] Based on different communication technologies, multiple communication modules 9110 may be provided in the same electronic device, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module, etc. The communication module 9110 (transmitter / receiver) is also coupled to the speaker 9131 and the microphone 9132 via the audio processor 9130 to provide an audio output via the speaker 9131 and receive an audio input from the microphone 9132, so as to implement normal telecommunication functions. The audio processor 9130 may include any suitable buffers, decoders, amplifiers, etc. In addition, the audio processor 9130 is also coupled to the central processor 9100, so that it is possible to record on the local machine through the microphone 9132 and play the sound stored on the local machine through the speaker 9131.

[0131] An embodiment of the present application also provides a computer-readable storage medium capable of implementing all steps in the real-time monitoring method for charging services based on service probes, where the execution subject in the above embodiments is a server or a client. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, it implements all steps of the real-time monitoring method for charging services based on service probes, where the execution subject in the above embodiments is a server or a client. For example, when the processor executes the computer program, the following steps are implemented: Step S101: Deploy a network traffic collection device, obtain data link layer network data streams from the toll station core switch through the network traffic collection device, perform hierarchical parsing on the network data streams according to the application layer and the transport layer, extract transaction flow information and service management information from the application layer, extract device interaction information and vehicle identification information from the transport layer, extract service data transmission status information from the application layer, perform temporal association on the extracted multi-layer data based on the inter-layer data mapping relationship, generate a service event chain, and construct a charging service portrait model from the service event chain; Step S102: Obtain the toll station equipment operation data and real-time service data, extract the hardware status features from the equipment operation data, extract the scenario features of traffic flow distribution, toll collection peak rules, and toll collection service indicators from the service data, perform feature fusion on the hardware status features and scenario features to obtain a multi-dimensional feature vector, use the multi-dimensional feature vector to train a neural network classifier to obtain a service anomaly recognition model, analyze the anomaly events in the service event chain based on the service anomaly recognition model, and generate an anomaly event description vector; Step S103: Construct a service real-time monitoring engine, use the service real-time monitoring engine to perform hierarchical parsing and correlation analysis on newly collected network data streams, extract hardware status features and scenario features for feature fusion, input the fused feature vector into the service anomaly recognition model for anomaly analysis, and generate a service anomaly warning message when an anomaly event is recognized.

[0132] As can be seen from the above description, the computer-readable storage medium provided by the embodiments of the present application realizes the precise construction of the service event chain by constructing a multi-layer data parsing mechanism and integrating the data of the application layer, session layer, and network layer. Design an anomaly recognition strategy based on multi-dimensional feature fusion, combine hardware status features and scenario features, and establish a neural network classifier for anomaly event analysis. Introduce a real-time monitoring engine to dynamically warn of service anomalies through hierarchical parsing and correlation analysis. This method effectively solves the deficiencies of traditional technologies in data parsing, feature analysis, and real-time monitoring, and significantly improves the intelligent level and warning effect of toll collection service monitoring.

[0133] The embodiments of the present application also provide a computer program product capable of implementing all the steps in the service probe-based toll collection service real-time monitoring method whose execution subject in the above embodiments is a server or a client. When the computer program / instructions are executed by a processor, the steps of the service probe-based toll collection service real-time monitoring method are implemented. For example, the computer program / instructions implement the following steps: Step S101: Deploy a network traffic collection device, obtain the data link layer network data stream from the toll station core switch through the network traffic collection device, perform hierarchical parsing on the network data stream according to the application layer and transport layer, extract transaction flow information and service management information from the application layer, extract device interaction information and vehicle identification information from the transport layer, extract service data transmission status information from the application layer, perform temporal correlation on the extracted multi-layer data based on the inter-layer data mapping relationship, generate a service event chain, and construct a toll collection service portrait model from the service event chain; Step S102: Obtain the toll station equipment operation data and real-time business data, extract the hardware status features from the equipment operation data, extract the scenario features of traffic flow distribution, peak charging rules, and toll business indicators from the business data, perform feature fusion on the hardware status features and scenario features to obtain a multi-dimensional feature vector, train a neural network classifier using the multi-dimensional feature vector to obtain a business anomaly recognition model, and analyze the abnormal events in the business event chain based on the business anomaly recognition model to generate an abnormal event description vector; Step S103: Construct a business real-time monitoring engine, use the business real-time monitoring engine to perform hierarchical parsing and correlation analysis on newly collected network data streams, extract hardware status features and scenario features for feature fusion, input the fused feature vector into the business anomaly recognition model for anomaly analysis, and generate a business anomaly warning message when an abnormal event is recognized.

[0134] As can be seen from the above description, the computer program product provided by the embodiments of the present application realizes the accurate construction of the business event chain by constructing a multi-layer data parsing mechanism and integrating the data of the application layer, session layer, and network layer. Design an anomaly recognition strategy based on multi-dimensional feature fusion, combine the hardware status features and scenario features, and establish a neural network classifier for abnormal event analysis. Introduce a real-time monitoring engine to dynamically warn of business anomalies through hierarchical parsing and correlation analysis. This method effectively solves the deficiencies of traditional technologies in data parsing, feature analysis, and real-time monitoring, and significantly improves the intelligent level and warning effect of toll business monitoring.

[0135] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, apparatus, or computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0136] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (apparatus), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing device generate for realizing in the process Figure 1 one process or multiple processes and / or blocks Figure 1means for the functions specified in one or more boxes.

[0137] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction means that implements the functions specified in one Figure 1 process or more processes and / or boxes Figure 1 or more boxes.

[0138] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus, such that a series of operational steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one Figure 1 process or more processes and / or boxes Figure 1 or more boxes.

[0139] Specific embodiments are used in the present invention to elaborate on the principles and implementation manners of the present invention. The descriptions of the above embodiments are only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A real-time monitoring method for charging services based on business probes, characterized in that, The method includes: Deploying a network traffic collection device, obtaining data link layer network data streams from the toll station core switch through the network traffic collection device, hierarchically parsing the network data streams according to the application layer and the transport layer, extracting transaction flow information and business management information from the application layer, extracting device interaction information and vehicle identification information from the transport layer, extracting business data transmission status information from the application layer, performing temporal association on the extracted multi-layer data based on the inter-layer data mapping relationship to generate a business event chain, and constructing a toll business portrait model from the business event chain; Obtaining toll station device operation data and real-time business data, extracting hardware status features from the device operation data, extracting scenario features such as traffic flow distribution, toll peak rules, and toll business metrics from the business data, performing feature fusion on the hardware status features and the scenario features to obtain a multi-dimensional feature vector, training a neural network classifier using the multi-dimensional feature vector to obtain a business anomaly recognition model, and analyzing abnormal events in the business event chain based on the business anomaly recognition model to generate an abnormal event description vector; Constructing a business real-time monitoring engine, using the business real-time monitoring engine to perform hierarchical parsing and correlation analysis on newly collected network data streams, extracting hardware status features and scenario features for feature fusion, inputting the fused feature vector into the business anomaly recognition model for anomaly analysis, and generating business anomaly warning information when an abnormal event is identified.

2. The real-time monitoring method for charging services based on a service probe according to claim 1, wherein The deployment of the network traffic collection device, obtaining network data streams from the toll station core switch through the network traffic collection device, hierarchically parsing the network data streams according to the application layer and the transport layer, extracting transaction flow information and business management information from the application layer, extracting device interaction information and vehicle identification information from the transport layer, and extracting packet transmission status information from the network layer, includes: Establishing a physical connection between the network traffic collection device and the mirror port of the toll station core switch, configuring the data cache size and sampling time interval of the network traffic collection device, starting the data collection process of the network traffic collection device, writing the collected real-time network data streams into the data cache area, performing packet fragmentation and recombination on the network data streams in the data cache area, and constructing a complete network data stream; Constructing an application layer parsing unit to extract transaction flow information and business management information, constructing a transport layer parsing unit to extract device interaction information and vehicle identification information, constructing a network layer parsing unit to extract packet transmission status information, forming a protocol parsing processing chain by connecting the application layer parsing unit and the transport layer parsing unit in series, sequentially inputting the network data stream into each layer parsing unit in the protocol parsing processing chain to obtain a hierarchical parsing result, and writing the hierarchical parsing result into the data storage area according to a preset data format.

3. The real-time monitoring method for charging services based on service probes according to claim 1, characterized in that The temporal association of the extracted multi-layer data based on the inter-layer data mapping relationship to generate a business event chain and constructing a toll business portrait model from the business event chain includes: Construct a mapping matrix from the application layer to the transport layer and a mapping matrix from the transport layer to the network link layer. Calculate the correlation degree between data at different levels based on the mapping matrix, establish a time-series correlation relationship for data with a correlation degree higher than a preset threshold, combine multi-layer data with a time-series correlation relationship to form a data link, sort and merge the data link according to timestamps, and generate a business event chain containing a complete business process; Extract four types of characteristic parameters, namely business type identifier, business operation sequence, business processing duration, and business status change, from the business event chain. Input the characteristic parameters into a pre-trained deep learning model for feature vector conversion, construct a business portrait feature space based on the feature vectors, calculate business similarity clustering in the feature space, generate a business portrait clustering model, and store the business portrait clustering model in the model library.

4. The real-time monitoring method for charging services based on service probes according to claim 1, characterized in that, Obtain the toll station equipment operation data and real-time business data, extract the hardware status features from the equipment operation data, extract the scene features such as traffic flow distribution, toll collection peak pattern, and impact on toll collection business indicators from the real-time business data, and perform feature fusion on the hardware status features and scene features to obtain a multi-dimensional feature vector, including: Connect a monitoring probe to the toll station equipment system, obtain the processor usage rate, memory occupancy rate, disk read / write rate, and network traffic data in the equipment in real time, parse and normalize the operation data, construct hardware status feature indicators, construct the hardware status feature indicators into a feature matrix, and perform dimensionality reduction processing on the feature matrix to generate a hardware status feature vector; Read the business transaction table data from the real-time business database, calculate the time distribution density and space distribution density of the traffic flow, identify the rules of peak and trough toll collection periods, extract precipitation, visibility, and temperature data from the meteorological monitoring data, standardize the traffic flow distribution data, toll collection peak pattern data, and toll collection business indicator data, and use a feature weighting method to fuse the hardware status feature vector and the standardized scene feature data to generate a multi-dimensional feature vector.

5. The real-time monitoring method for charging services based on service probes according to claim 1, characterized in that, Use the multi-dimensional feature vector to train a neural network classifier to obtain a business anomaly recognition model, analyze the anomaly events in the business event chain based on the business anomaly recognition model, and generate an anomaly event description vector, including: Construct a three-layer neural network structure, input the multi-dimensional feature vector into the input layer of the neural network, set multiple convolutional kernels in the hidden layer to extract feature combinations, set a softmax classifier in the output layer, use the backpropagation algorithm to iteratively optimize the neural network weights, calculate the classification accuracy based on the validation data set, and save the trained neural network classifier as a business anomaly recognition model; Read the business data in the business event chain, extract the multi-dimensional feature vectors and input them into the business anomaly recognition model to obtain the type identifier and confidence score of the anomaly event. Combine the type identifier and confidence score with the timestamp, device identifier, and operation sequence of the business event to generate an anomaly event description vector. Sort the anomaly event description vector according to the confidence score and write the sorting result into the anomaly event data table.

6. The real-time monitoring method for charging services based on service probes according to claim 1, characterized in that The construction of the business real-time monitoring engine, using the business real-time monitoring engine to perform hierarchical parsing and correlation analysis on the newly collected network data stream, and extracting hardware status features and scenario features for feature fusion, including: Create a data collection thread pool, a parsing and processing thread pool, and an analysis and processing thread pool. Start the network data stream collection task in the data collection thread pool, allocate the collected network data stream to the parsing and processing thread pool, call the protocol parsing and processing chain to perform hierarchical parsing on the network data stream, write the parsing result into the shared memory area, and read the parsing result in the analysis and processing thread pool for data correlation analysis; Read the parsed business data from the shared memory area, extract the processor utilization rate, memory occupancy rate, disk read / write rate, and network traffic data in the device to construct a hardware status feature vector, extract the traffic flow distribution data, toll collection peak pattern data, and toll collection business indicator data to construct a scenario feature vector, and use the feature weighting method to fuse the hardware status feature vector and the scenario feature vector to generate a multi-dimensional feature vector for real-time monitoring.

7. The real-time monitoring method for charging services based on service probes according to claim 1, characterized in that Input the fused feature vector into the business anomaly recognition model for anomaly analysis. When an anomaly event is identified, generate a business anomaly warning message, including: Input the fused feature vector into the business anomaly recognition model in batches, obtain the type identifier and confidence score of the anomaly event, perform normalization processing on the confidence score, compare the normalized score with a preset anomaly threshold, mark the event higher than the anomaly threshold as an anomaly event, and write the feature vector, type identifier, and confidence score of the anomaly event into the anomaly event buffer; Read the anomaly event data from the anomaly event buffer, extract the attribute information such as the occurrence time, device identifier, anomaly type, and anomaly degree of the anomaly event, match the attribute information with a preset anomaly event description template to generate a standardized anomaly event description text, construct a business anomaly warning message containing the anomaly event description text, and push the business anomaly warning message to the warning information processing module.

8. A real-time monitoring device for charging services based on a service probe, characterized in that, The device includes: A model construction module, used to deploy a network traffic collection device, obtain the data link layer network data stream from the toll station core switch through the network traffic collection device, perform hierarchical parsing on the network data stream according to the application layer and the transport layer, extract transaction flow information and business management information from the application layer, extract device interaction information and vehicle identifier information from the transport layer, extract business data transmission status information from the application layer, perform temporal correlation on the extracted multi-layer data based on the inter-layer data mapping relationship to generate a business event chain, and construct a toll collection business portrait model from the business event chain; Anomaly description module, which is used to obtain the operation data and real-time business data of toll station equipment, extract hardware status features from the equipment operation data, extract scenario features such as traffic flow distribution, peak charging rules, and toll business indicators from the business data, perform feature fusion on the hardware status features and scenario features to obtain a multi-dimensional feature vector, train a neural network classifier using the multi-dimensional feature vector to obtain a business anomaly recognition model, and analyze abnormal events in the business event chain based on the business anomaly recognition model to generate an abnormal event description vector; Business detection module, which is used to build a business real-time monitoring engine, perform hierarchical parsing and correlation analysis on newly collected network data streams using the business real-time monitoring engine, extract hardware status features and scenario features for feature fusion, input the fused feature vector into the business anomaly recognition model for anomaly analysis, and generate a business anomaly warning message when an abnormal event is recognized.

9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the toll business real-time monitoring method based on a business probe according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the toll business real-time monitoring method based on a business probe according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Computer network service real-time monitoring system based on network probe technology

    CN107094101A

  • Business exception prediction method and device, storage medium and electronic device

    CN115859188A

  • Power transaction auxiliary decision-making system based on multi-data source fusion

    CN117853238A

  • Data management method and system for power spatial data

    CN119884610A

  • Deterministic network traffic identification method and system, computer equipment and medium

    CN120034396A

Cited By

  • Intelligent operation and maintenance monitoring method and system for data center

    CN120602308A

  • Intelligent operation and maintenance monitoring method and system of data center

    CN120602308B

  • Online service interaction anomaly analysis method based on AI server and big data

    CN121000773A

  • Function test method and device for Internet of Things platform, and medium

    CN121357051A

  • Road toll prediction method and system based on portal network spatial-temporal feature fusion

    CN121684213A