Software analysis method and system based on penetration log, terminal and medium

Through the software analysis method based on penetrating logs, a service call chain diagram is built and the performance bottleneck positioning algorithm is used to solve the problem of distributed system performance analysis, achieving all-round and meticulous performance bottleneck positioning and optimization suggestions generation, and improving analysis and optimization efficiency.

CN120492260AInactive Publication Date: 2025-08-15QINGDAO PORT INT CO LTD +1
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510525534.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-08-15
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing distributed system performance analysis methods are difficult to fully capture and diagnose performance problems, resulting in difficulty in positioning, inefficient optimization, and may introduce new problems.

Method used

The software analysis method based on penetrating logs is adopted to collect, preprocess and store log information, and a service call chain diagram is built, and the performance bottleneck positioning algorithm is used to analyze the system's performance bottleneck points, including log-level configuration, log formatting, log cleaning and log sharding, combining cluster analysis, association rule mining and exception detection algorithms.

Benefits of technology

It realizes all-round and meticulous analysis of the performance of distributed systems, can accurately locate performance bottlenecks, improve optimization efficiency, generate optimization suggestions, and support large-scale log information processing and automated analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120492260A_ABST
    Figure CN120492260A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of software analysis, in particular to a penetrating log-based software analysis method and system, a terminal and a medium, and the method comprises the following steps: collecting log information of each level in a target application software system; the collected log information is preprocessed; storing the preprocessed log information; and outputting a service calling chain graph based on a calling chain construction algorithm, extracting performance data of each service node from the stored log information when the target application software system runs, and positioning performance bottleneck points in the target application software system based on the service calling chain graph and the performance data by adopting a performance bottleneck positioning algorithm. According to the method, the system performance can be analyzed more comprehensively and meticulously, and hidden performance bottleneck points or potential problems can be found easily.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software analysis, and in particular to a software analysis method, system, terminal and medium based on penetrating logs. Background Art

[0002] With the widespread adoption of distributed systems, application software performance issues are becoming increasingly complex. Due to the distributed nature of system architectures, performance issues can involve multiple service nodes, complex network interactions, and the coordinated operation of diverse heterogeneous resources. These factors make locating, analyzing, and resolving performance issues more difficult.

[0003] Traditional performance analysis methods, such as performance metric analysis based on monitoring tools and performance profiling based on code instrumentation, often struggle to fully capture and diagnose performance issues in distributed systems. These methods typically only provide limited information, such as CPU usage and memory utilization, but fail to provide a deep understanding of service call relationships and performance bottlenecks within the system.

[0004] Therefore, due to the lack of effective performance analysis methods, developers and operations personnel often struggle to accurately pinpoint the source of performance issues. This can lead to significant time and effort wasted troubleshooting, and they may even misjudge the cause, leading to incorrect optimization measures. Inaccurate performance problem location directly leads to inefficient optimization. Developers may blindly optimize without understanding the true cause of the problem, which not only fails to resolve the issue but may also introduce new performance issues. Furthermore, due to the complexity of distributed systems, even if the source of the problem is pinpointed, coordinated optimization across multiple service nodes may be required, further increasing the difficulty and cost of optimization. Summary of the Invention

[0005] In order to solve the technical problem that the existing performance analysis method of application software using distributed systems is difficult to comprehensively analyze system performance, the present invention provides a software analysis method based on penetrating logs on the one hand, and a software analysis system, a terminal and a medium based on penetrating logs on the other hand.

[0006] To achieve the above objectives, the technical solution adopted by the software analysis method based on penetrating logs in the present invention is: The software analysis method based on penetrating logs includes the following steps: Collect log information at all levels of the target application software system; Preprocess the collected log information; Store the preprocessed log information; Based on the call chain construction algorithm, a service call chain diagram is output, and the performance data of each service node when the target application software system is running is extracted from the stored log information. The performance bottleneck positioning algorithm is used to locate the performance bottleneck point in the target application software system based on the service call chain diagram and performance data.

[0007] This application collects log information from each level or module of the software, builds a service call chain diagram, and uses a performance bottleneck location algorithm to locate performance bottlenecks in the target application software system based on the service call chain diagram and performance data. It analyzes system performance more comprehensively and meticulously, which helps to discover hidden performance bottlenecks or potential problems.

[0008] As a preferred implementation of the software analysis method based on penetrating logs, before collecting log information at each level in the target application software system, the software analysis method based on penetrating logs includes the following steps: Configure the log level for each service node or functional module in the target application software system according to business needs; And / or, formulate a log format for the log information, which at least includes a timestamp, service name, request ID, call relationship, and response time.

[0009] As a preferred implementation of the software analysis method based on penetrating logs, the preprocessing includes log cleaning, log formatting and log segmentation.

[0010] As a preferred implementation of the software analysis method based on penetrating logs, the call chain construction algorithm includes the following steps: Call chain analysis: extract call information related to the call relationship from the stored log information; Dependency identification: organize call information into a chain structure in chronological order and build a service call chain diagram; Circular call detection: Detect and mark circular call paths during the construction of the service call chain graph; Topological sorting: topological sorting of the service call chain graph; Output call chain graph: Output the service call chain graph after topological sorting.

[0011] As a preferred implementation of the software analysis method based on penetrating logs, the performance bottleneck location algorithm includes the following steps: Cluster analysis: Extracts performance data for each service node during the target application system's runtime from stored log information. Performance data includes response time, throughput, and exception frequency. Uses the K-Means clustering algorithm or the DBSCAN algorithm to analyze service nodes whose response time exceeds the threshold and locate performance bottlenecks. Association rule mining: Use association rule mining algorithms to mine the performance correlation between service nodes in the target application software system from the stored log information, and locate performance bottlenecks based on the performance correlation; Bottleneck node detection: Combined with the topologically sorted service call chain graph, the path with the longest response time during the target application software system runtime is analyzed. The performance data of each service node on the path with the longest response time exceeding the threshold or the abnormal frequency exceeding the threshold is marked as a performance bottleneck point; Outlier detection: Calculates outliers in the performance data of each service node during the runtime of the target application software system using an anomaly detection algorithm, and locates performance bottlenecks based on the locations of the outliers. Combined with the dynamic threshold adjustment strategy, the location of performance bottlenecks obtained through cluster analysis, association rule mining, bottleneck detection and outlier detection is output.

[0012] As a preferred implementation of the software analysis method based on penetrating logs, after storing the pre-processed log information, the method further includes: The performance level of the target application software system is evaluated based on a performance data statistical analysis algorithm; the performance data statistical analysis algorithm includes: collecting performance data of each service node when the target application software system is running, performing statistical analysis on the collected performance data, and obtaining key performance indicators, which include average response time, maximum response time, throughput and error rate; and calculating the performance score of the target application software system based on weighted calculations of different key performance indicators.

[0013] As a preferred implementation of the software analysis method based on penetrating logs, a log collection tool is used to collect log information at various levels in the target application software system.

[0014] In a second aspect, the present application discloses a software analysis system based on penetrating logs, which adopts the following technical solutions: The software analysis system based on penetrating logs includes: The log collection module is configured to collect log information at all levels in the target application software system; and pre-process the collected log information; A log storage module, the log storage module is configured to store pre-processed log information; The log analysis module is configured to output a service call chain diagram based on a call chain construction algorithm, extract the performance data of each service node when the target application software system is running from the stored log information, and use a performance bottleneck location algorithm to locate the performance bottleneck point in the target application software system based on the service call chain diagram and performance data.

[0015] In a third aspect, the present application discloses a terminal that adopts the following technical solution: A terminal includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the steps of the software analysis method based on penetrating logs as described above are implemented.

[0016] In a fourth aspect, the present application discloses a medium, which adopts the following technical solution: The medium stores a computer program, which, when executed by a processor, implements the steps of the software analysis method based on penetrating logs as described above.

[0017] The beneficial effects of the present invention include: This application collects log information from each level or module of the software, builds a service call chain diagram, and uses a performance bottleneck location algorithm to locate performance bottlenecks in the target application software system based on the service call chain diagram and performance data. It analyzes system performance more comprehensively and meticulously, which helps to discover hidden performance bottlenecks or potential problems. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solution of the present invention, the following is a brief introduction to the drawings required for the description. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0019] Figure 1 Schematic flow chart of a software analysis method based on penetrating logs in a specific embodiment of the present invention; Figure 2 It is a schematic block diagram of a software analysis system based on penetrating logs in a specific embodiment of the present invention. DETAILED DESCRIPTION

[0020] Traditional performance analysis methods, such as performance metric analysis based on monitoring tools and performance profiling based on code instrumentation, often struggle to fully capture and diagnose performance issues in distributed systems. These methods typically only provide limited information, such as CPU usage and memory utilization, but fail to provide a deep understanding of service call relationships and performance bottlenecks within the system.

[0021] How to solve the technical problem that the existing performance analysis methods of application software using distributed systems are difficult to comprehensively analyze system performance has become a technical problem that needs to be solved urgently.

[0022] Based on this, this embodiment proposes a software analysis method based on penetrating logs, which can be used.

[0023] Before describing in detail the software analysis method based on penetrating logs involved in this embodiment, some existing professional terms involved in this embodiment are first explained to facilitate understanding of the solution described in this application: In a distributed system, "tier" typically refers to the system's logical structure or functional divisions, such as the access layer, logic layer, and data layer. A "service node" refers to the server or process that actually performs tasks like computing and storage. In a distributed system, there isn't a strict one-to-one correspondence between tiers and service nodes. A tier may contain multiple service nodes or share service nodes with other tiers.

[0024] The following describes in detail the software analysis method based on penetrating logs involved in this application. Specific details such as specific system structures and technologies are provided for illustration rather than limitation to facilitate a thorough understanding of the embodiments of this application. However, it should be clear to those skilled in the art that this application can also be implemented in other embodiments without these specific details.

[0025] The phrases "one embodiment" or "some embodiments" described in this application mean that the specific features, structures, or characteristics described in the embodiment are included in one or more embodiments of the application. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in other embodiments," etc. that appear in different places in this application do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized.

[0026] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0027] Reference Figure 1 , this application proposes a software analysis method based on penetrating logs, comprising the following steps: S1. Collect log information from each layer of the target application software system; pre-process the collected log information; the layers may include data access layer, business logic layer and web layer.

[0028] S2. Storing the pre-processed log information; S3. Output the service call chain diagram based on the call chain construction algorithm, extract the performance data of each service node when the target application software system is running from the stored log information, and use the performance bottleneck positioning algorithm to locate the performance bottleneck point in the target application software system based on the service call chain diagram and performance data.

[0029] Before step S1 , the software analysis method based on penetrating logs in this embodiment further includes: configuring a log level for each service node or functional module in the target application software system according to business requirements.

[0030] The business requirements of each service node or functional module in the target application software system include: (1) Criticality of the service: Some services may be critical to the operation of the entire system and require more detailed logging.

[0031] (2) Performance requirements: Some services may have strict performance requirements and need to reduce the amount of logs to reduce overhead.

[0032] (3) Troubleshooting needs: Some services may be more prone to failure and require more detailed logs to facilitate problem tracking.

[0033] (4) Security compliance requirements: Some services may involve sensitive data or be subject to specific regulations and need to meet specific logging requirements.

[0034] Log levels are typically used to distinguish the importance and urgency of log information. Common log levels, from low to high (i.e., the level of detail of log records, from high to low), include: TRACE: The most fine-grained information event, usually used for debugging; DEBUG: Events used for debugging, with more detailed information; INFO: Normal information during operation, used to record the current status of system operation; WARN: Warning message, indicating a possible problem, but the system can still continue to run; ERROR: Error message, indicating that an exception has occurred and requires attention; FATAL: A serious error may cause the system to stop running and requires immediate attention.

[0035] The log levels in this embodiment include but are not limited to the common log levels mentioned above.

[0036] In this embodiment, the log level can be dynamically adjusted through the log configuration tools of the Spring Cloud development framework (such as Logback, Log4j, etc.), avoiding the storage and processing burden caused by collecting too much redundant log data.

[0037] To facilitate unified processing of log information, this embodiment further includes: developing a log format for log information to ensure consistency and comparability of log information at all levels of the target application software system. The log format in this embodiment includes at least timestamp, service name, request ID, call relationship, and response time, where: Timestamp: Accurate to milliseconds, identifies the specific time of log recording and is used to locate the time when the event occurred; Service name: the name of the service node that records the log, which makes it easier to distinguish the source; Request ID: uniquely identifies a complete call chain, making it easier to associate the logs of each service node into a call chain graph; Call relationship: includes caller and callee information, used to show the dependency relationship between services; Response time: Records the response time of service calls to facilitate analysis of performance bottlenecks.

[0038] To ensure the conciseness of log information and the efficiency of analysis, in this embodiment, the preprocessing includes log cleaning, log formatting and log sharding to optimize storage and query efficiency and provide support for subsequent large-scale analysis. Among them, log cleaning means filtering advertising information, irrelevant logs and duplicate records through rules to ensure the purity and high quality of log data. Log formatting means uniformly formatting log information from different sources and converting it into a standardized JSON or CSV format to ensure that structured queries and comparisons can be easily performed during subsequent analysis. Log sharding means sharding log data by time (such as by day or by hour) or size (such as every 10MB) to ensure efficient storage and query in a large data volume environment and improve the response speed of the system.

[0039] In some embodiments, the call chain construction algorithm in step S3 includes the following steps: Call chain analysis: Extract call information related to the call relationship from the stored log information (such as request ID, caller and callee IDs, call time, response time, etc.); Dependency identification: Call information is organized into a chain structure in chronological order to build a service call chain graph. In the call chain graph, each node represents a service, and each edge represents a service call relationship. The edge weight can be expressed by response time or call frequency. Circular call detection: Detect and mark circular call paths during the construction of the service call chain graph; Topological sorting: topologically sort the service call chain graph; establish a hierarchical structure of service dependencies and identify critical paths so that performance issues of core services can be prioritized for subsequent analysis; Output call chain graph: Output the service call chain graph after topological sorting.

[0040] The algorithm analyzes the service call relationships in log information and constructs a call chain diagram, which can clearly display the call sequence and dependency relationships of services in the target application software system, providing a data basis for locating performance bottlenecks.

[0041] Circular call detection involves using specific methods and techniques during the software development process to detect the presence of circular call issues in the system. This method can identify redundant calls within the target application software system and provide optimization strategies. For example, specialized static analysis tools, such as code checkers and code quality assessment tools, can be used to scan and analyze source code. These tools can automatically detect patterns of circular and redundant calls and provide corresponding warnings and suggestions. Alternatively, by inserting logs into the code, using performance analysis tools or debuggers, and monitoring the system's call relationships during software runtime, circular and redundant calls can be detected in real time.

[0042] In some embodiments, the performance bottleneck location algorithm in step S3 includes the following steps: Cluster analysis: Extract performance data for each service node during the target application system's runtime from stored log information. This performance data includes response time, throughput, and exception frequency. Using clustering algorithms such as K-means and DBSCAN, we analyze service nodes whose response times exceed thresholds and identify them as performance bottlenecks. Association rule mining: Uses association rule mining algorithms (such as the Apriori algorithm or the FP-Growth algorithm) to mine performance correlations between service nodes in the target application software system from stored log information. Based on these correlations, performance bottlenecks are located. In particular, the association between response time delays and frequent exceptions is identified to locate highly correlated service nodes that affect performance. Bottleneck node detection: Combined with the topologically sorted service call chain graph, the path with the longest response time during the runtime of the target application software system is analyzed. Service nodes on the path with the longest response time that exceed the threshold or the abnormal frequency that exceeds the threshold are marked as performance bottlenecks. Outlier detection: This algorithm uses an anomaly detection algorithm (such as the Z-score or Grubbs algorithm) to calculate and count outliers in the performance data of each service node during the runtime of the target application software system. Based on the outlier location and frequency, the algorithm is used to identify outliers and locate performance bottlenecks. Combined with the dynamic threshold adjustment strategy, the location of performance bottlenecks obtained through cluster analysis, association rule mining, bottleneck detection and outlier detection is output.

[0043] The performance bottleneck location algorithm uses cluster analysis, association rule mining, and other algorithms based on the service call chain graph and performance data (such as response time and throughput) to pinpoint performance bottlenecks. This algorithm automatically identifies service nodes with long or abnormally high response times and provides specific performance bottleneck information. The algorithm outputs bottleneck service nodes and a description of their performance issues, providing clear guidance for optimizing the target application software system.

[0044] In some embodiments, step S3 further includes: evaluating the performance level of the target application software system based on a performance data statistical analysis algorithm. The performance data statistical analysis algorithm includes: collecting performance data of each service node when the target application software system is running, performing statistical analysis on the collected performance data to obtain key performance indicators, which include average response time, maximum response time, throughput, and error rate; and calculating a performance score of the target application software system based on weighted different key performance indicators to provide a quantitative reference for the overall health status of the target application software system, where the weight coefficients of different key performance indicators are determined based on their importance.

[0045] Among the key performance indicators, average response time is the average response time of a service node over a period of time, which is used to evaluate the processing efficiency of the service node; maximum response time can help identify high latency issues; throughput is the number of requests processed by the target application software system per unit time, which is used to measure the system load capacity; error rate is the number and proportion of request errors for each service node, which is used to analyze system reliability.

[0046] The performance data statistical analysis algorithm also includes time series analysis of the collected key performance indicators. Using methods such as autocorrelation analysis and moving averages, the algorithm identifies peak and valley performance periods, providing support for load forecasting and optimization. Time series forecasting models (such as ARIMA or Prophet models) are then used to predict key performance indicator trends based on the time series analysis results. By analyzing the predicted key performance indicators, potential future performance anomalies can be detected.

[0047] The performance data statistical analysis algorithm also includes statistics on the distribution characteristics of key performance indicators, identifying extreme values and long-tail distributions of performance, and analyzing the possible sources of performance bottlenecks in the target application software system through data distribution characteristics.

[0048] The log analysis step recorded in step S3 is the core part of the present invention, which can achieve a comprehensive and detailed analysis of the performance of application software in a distributed system, helping developers and operation and maintenance personnel to accurately locate performance bottlenecks and improve optimization efficiency.

[0049] In this embodiment, the software analysis method based on penetrating logs uses a log collection tool, such as Logstash, Fluentd, etc., to collect log information at various levels in the target application software system.

[0050] In some embodiments, this embodiment can also generate software performance optimization suggestions based on the results obtained in step S3, specifically including the following steps: 1. Problem Identification Based on the results of log analysis, system performance issues are categorized and located to identify the root cause of performance bottlenecks: (1) Performance problem classification: The system divides performance problems into the following categories: Response delay issue: The response time of a service node is significantly higher than the average level. This may be due to a long call chain, a large amount of computation, or strong external dependencies.

[0051] Architectural bottleneck: The calling relationship between services is complex and the dependency chain is too long, resulting in slow response time of the overall system.

[0052] Uneven resource usage: Service node resource usage is uneven, with some nodes overloaded, resulting in bottlenecks in resource consumption such as CPU and memory.

[0053] Frequent exceptions: Some nodes have high error rates, which may be caused by system configuration, network connection, or insufficient resources.

[0054] (2) Problem location: Based on the call chain diagram, response time, and error log information in the log analysis results, the specific service node, call chain location, or abnormal operation can be accurately located. With the help of timing analysis results, the time pattern (such as peak period) or specific events (such as high concurrency scenarios) of performance problems can be identified, providing accurate information for subsequent optimization.

[0055] 2. Optimization measures formulation Develop specific optimization measures based on the identified issues and best practices. Depending on the type and location of the problem, optimization measures may include the following: (1) Code optimization: For nodes with long response times, we conduct an in-depth analysis of the service's code execution efficiency and recommend the following: Algorithm optimization: Optimize time-consuming algorithms, such as replacing them with more efficient algorithms or reducing unnecessary calculation steps.

[0056] Database query optimization: Adjust complex queries or batch operations, add indexes, reduce table scans, and avoid long I / O operations.

[0057] Asynchronous processing: Introduce asynchronous processing for non-critical requests to reduce the impact of synchronous blocking on response time.

[0058] (2) Service splitting and reconstruction: For problems such as long call chains and high service coupling, it is recommended to split complex services into multiple independent services: Microservices: Split large monolithic services into multiple small microservices to reduce interdependencies between services and improve scalability.

[0059] Call path optimization: Optimize the call path between services, reduce unnecessary cross-node requests, and reduce latency.

[0060] (3) Resource adjustment and allocation: Optimize resource allocation for service nodes with uneven loads to ensure reasonable allocation of system resources and avoid excessive resource use.

[0061] Load balancing: Introduce a load balancing strategy before high-load nodes to evenly distribute request traffic and reduce the pressure on a single node.

[0062] Resource expansion: Increase CPU, memory, or hard disk resources for nodes that frequently exceed resource limits to ensure the stability of service operation.

[0063] Cache optimization: Add cache before frequently accessed data or calculation results to reduce frequent access to the database or background services.

[0064] (4) Exception handling optimization: For service nodes with frequent exceptions, it is recommended to optimize the exception handling mechanism: Retry strategy: Add a retry mechanism for network or external service exceptions to avoid high error rates caused by short-term exceptions.

[0065] Degradation processing: Introduce service degradation strategies during peak periods or abnormal times to ensure that key functions are normal and non-critical functions can be temporarily shut down when necessary.

[0066] 3. Optimization suggestion generation Record the optimization measures in a document to form an optimization suggestion document to ensure that the development and operation teams can easily understand and implement the optimization plan. The generated optimization suggestion document includes the following: (1) Problem description: Briefly describe the performance problem found and its impact, including the type of problem, the node where it occurred, key indicators (such as average response time, exception rate), etc.

[0067] (2) Optimization plan: Provide detailed optimization steps and methods, including specific code adjustment suggestions, architecture adjustment instructions, or resource allocation strategies. For example: Steps: Explain the specific implementation steps for each optimization step by step, such as modifying code locations, configuring load balancing instructions, etc.

[0068] Prioritization: Assign a priority to each optimization suggestion based on the severity of the performance issue and the difficulty of improvement so that the team can implement it according to importance.

[0069] (3) Expected results: Clearly list the expected results of the optimization to facilitate operation and maintenance personnel to evaluate the results. For example, "reduce the response time to below 500ms" or "reduce the abnormal frequency of this node by 50%."

[0070] (4) Automation support: For routine optimization measures, provide automation scripts or process templates, such as automatically completing resource expansion or load balancing configuration adjustments through CI / CD tools to reduce manual intervention and improve implementation efficiency.

[0071] (5) Report generation: Automatically generate reports, including problem analysis, optimization suggestions and implementation results. The generated reports are clear and intuitive, which is convenient for decision-makers to refer to and track later.

[0072] This embodiment has the following advantages: 1. Comprehensive and detailed analysis: By collecting and analyzing call chain logs, this invention can comprehensively and meticulously analyze the performance issues of application software in distributed systems. This helps developers and operations personnel accurately identify performance bottlenecks and improve optimization efficiency.

[0073] 2. Automation and Intelligence: This system utilizes automated log collection and analysis technology to generate real-time performance optimization recommendations. Furthermore, by incorporating intelligent algorithms (such as cluster analysis and association rule mining), it automatically identifies potential performance issues, improving optimization accuracy and efficiency.

[0074] 3. Scalability and flexibility: This invention uses distributed storage and data analysis technologies to process large-scale log information and has good scalability and flexibility. This helps it adapt to distributed systems of different scales and complexities.

[0075] 4. Easy to implement and maintain: This system is based on the SpringCloud development framework and uses mainstream programming languages such as Java, making it easy to implement and maintain. It also features a user-friendly interface and simple operation, making it convenient for developers and maintenance personnel.

[0076] like Figure 2 As shown, the following is an embodiment of a software analysis system based on a penetrating log provided by an embodiment of the present disclosure. A software analysis system based on a penetrating log and a software analysis method based on a penetrating log in the above-mentioned embodiments belong to the same inventive concept. For details not fully described in the embodiment of a software analysis system based on a penetrating log, please refer to the embodiment of the software analysis method based on a penetrating log mentioned above.

[0077] A software analysis system based on penetrating logs, including The log collection module is configured to collect log information at all levels in the target application software system; and pre-process the collected log information; A log storage module, the log storage module is configured to store pre-processed log information; The log analysis module is configured to output a service call chain diagram based on a call chain construction algorithm, extract the performance data of each service node when the target application software system is running from the stored log information, and use a performance bottleneck location algorithm to locate the performance bottleneck point in the target application software system based on the service call chain diagram and performance data.

[0078] The implementation of the system in this embodiment includes the integration and implementation of programming languages, development frameworks, distributed storage, and data analysis technologies. After the system development is completed, multi-level testing is performed to verify the functionality, stability, and compatibility of the system to ensure its reliability and efficiency in actual applications.

[0079] An embodiment of the present application also proposes a terminal, comprising a memory, a processor, a communication unit, and a computer program stored on the memory and runnable on the processor, wherein the processor implements the steps of a software analysis method based on a penetrating log when executing the program; the memory, the processor, and the communication unit communicate through one or more buses.

[0080] A processor may include one or more processing units, such as a central processing unit (CPU), an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural network processing unit (NPU). Different processing units may be independent devices or integrated into one or more processors.

[0081] The processor can be the nerve center and command center of the terminal. The controller can generate operation control signals based on instruction opcodes and timing signals to complete the control of instruction fetching and execution.

[0082] The memory is used to store the execution instructions of the processor. The memory can be implemented by any type of volatile or non-volatile storage terminal, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk. When the execution instructions in the memory are executed by the processor, the terminal is able to perform some or all of the steps in the embodiment of the software analysis method based on penetrating logs.

[0083] The wireless communication function of an electronic device can be implemented through an antenna, a wireless communication module, a modem processor, and a baseband processor.

[0084] The wireless communication module can provide wireless communication solutions for electronic devices, including wireless LAN, Bluetooth, global navigation satellite system, frequency modulation, short-range wireless communication technology, infrared technology, etc.

[0085] This embodiment further provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of a software analysis method based on a penetrating log are implemented.

[0086] Among them, a software analysis method based on penetrating logs includes: Collect log information at all levels of the target application software system; Preprocess the collected log information; Store the preprocessed log information; Based on the call chain construction algorithm, a service call chain diagram is output, and the performance data of each service node when the target application software system is running is extracted from the stored log information. The performance bottleneck positioning algorithm is used to locate the performance bottleneck point in the target application software system based on the service call chain diagram and performance data.

[0087] The storage medium of the present disclosure can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, a system, device or component of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination thereof. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0088] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. The software analysis method based on penetrating logs is characterized by: The following steps are involved: Collect log information at all levels of the target application software system; Preprocess the collected log information; Store the preprocessed log information; Based on the call chain construction algorithm, a service call chain diagram is output, and the performance data of each service node when the target application software system is running is extracted from the stored log information. The performance bottleneck positioning algorithm is used to locate the performance bottleneck point in the target application software system based on the service call chain diagram and performance data.

2. The software analysis method based on penetrating log according to claim 1 is characterized in that: Before collecting log information at each level in the target application software system, the method includes the following steps: Configure the log level for each service node or functional module in the target application software system according to business needs; And / or, formulate a log format for the log information, which at least includes a timestamp, service name, request ID, call relationship, and response time.

3. The software analysis method based on penetrating logs according to claim 1 or 2, characterized in that: The preprocessing includes log cleaning, log formatting and log segmentation.

4. The software analysis method based on penetrating log according to claim 1 is characterized in that: The call chain construction algorithm includes the following steps: Call chain analysis: extract call information related to the call relationship from the stored log information; Dependency identification: organize call information into a chain structure in chronological order and build a service call chain diagram; Circular call detection: Detect and mark circular call paths during the construction of the service call chain graph; Topological sorting: topological sorting of the service call chain graph; Output call chain graph: Output the service call chain graph after topological sorting.

5. The software analysis method based on penetrating log according to claim 4 is characterized in that: The performance bottleneck location algorithm includes the following steps: Cluster analysis: Extracts performance data for each service node during the target application system's runtime from stored log information. Performance data includes response time, throughput, and exception frequency. Using the K-Means clustering algorithm or the DBSCAN algorithm, the cluster analyzes service nodes whose response times exceed the threshold to locate performance bottlenecks. Association rule mining: Use association rule mining algorithms to mine the performance correlation between service nodes in the target application software system from the stored log information, and locate performance bottlenecks based on the performance correlation; Bottleneck node detection: Combined with the topologically sorted service call chain graph, the path with the longest response time during the runtime of the target application software system is analyzed. Service nodes on the path with the longest response time that exceed the threshold or the abnormal frequency that exceeds the threshold are marked as performance bottlenecks. Outlier detection: Calculates outliers in the performance data of each service node during the runtime of the target application software system using an anomaly detection algorithm, and locates performance bottlenecks based on the locations of the outliers. Combined with the dynamic threshold adjustment strategy, the location of performance bottlenecks obtained through cluster analysis, association rule mining, bottleneck detection and outlier detection is output.

6. The software analysis method based on penetrating logs according to claim 1 is characterized in that: After storing the pre-processed log information, the method further includes: The performance level of the target application software system is evaluated based on a performance data statistical analysis algorithm; the performance data statistical analysis algorithm includes: collecting performance data of each service node when the target application software system is running, performing statistical analysis on the collected performance data, and obtaining key performance indicators, which include average response time, maximum response time, throughput and error rate; and calculating the performance score of the target application software system based on weighted calculations of different key performance indicators.

7. The software analysis method based on penetrating logs according to claim 1 is characterized in that: Use log collection tools to collect log information at all levels in the target application software system.

8. The software analysis system based on penetrating logs is characterized by: include: A log collection module, the log collection module is configured to collect log information at various levels in the target application software system; Preprocess the collected log information; A log storage module, the log storage module is configured to store pre-processed log information; The log analysis module is configured to output a service call chain diagram based on a call chain construction algorithm, extract the performance data of each service node when the target application software system is running from the stored log information, and use a performance bottleneck location algorithm to locate the performance bottleneck point in the target application software system based on the service call chain diagram and performance data.

9. A terminal comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the software analysis method based on penetrating logs as described in any one of claims 1 to 7 are implemented.

10. A medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the software analysis method based on penetrating logs as described in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Log analysis-based micro-service performance optimization system and analysis method

    CN109756364A

  • Performance bottleneck accurate positioning system for Web application

    CN113568804A

  • User management system based on big data

    CN116467726A

  • Business process optimization scheme generation method and device, equipment and medium

    CN116882724A

  • Performance bottleneck positioning method and device, equipment and storage medium

    CN117573491A