Data acquisition method and device, electronic equipment and storage medium

By using native JVMTI interface functions to obtain call stack data in the runtime environment of Java applications, the problem of high performance overhead in call stack information acquisition in Java applications is solved, achieving more efficient stack trace data acquisition and reducing performance consumption and memory usage.

CN120973440APending Publication Date: 2025-11-18ALIBABA (CHINA) CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510906507.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-01
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

In existing technologies, getStackTrace(), written in Java, suffers from significant performance overhead when collecting call stack information in Java applications, especially in high-traffic scenarios.

Method used

By injecting data collection code into the runtime environment of the target application, the call stack data can be directly obtained using the native interface functions of JVMTI, bypassing the Java layer. The granularity of metadata collection can be flexibly set to obtain attribute values ​​such as class name, method name, source file and line number, forming stack trace data.

Benefits of technology

It reduces the performance consumption and memory overhead of call stack collection operations, improves performance, adapts to different JVM implementations, and supports flexible data collection needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120973440A_ABST
    Figure CN120973440A_ABST
Patent Text Reader

Abstract

The invention discloses a data acquisition method and device, electronic equipment and a storage medium. The data acquisition method comprises the following steps: injecting a data acquisition code into a runtime environment of a target application program; determining data acquisition demand information in a runtime environment of the target application program; calling the data acquisition code according to the data acquisition demand information; when the data collection code is called, stack tracking data are obtained from original calling stack data of the target application program according to the data collection requirement information, and the stack tracking data are output. By adopting the method, the performance loss of call stack acquisition can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of computers, and in particular to a data collection method and device, electronic equipment and a computer readable storage medium. BACKGROUND

[0002] With the increasing complexity of the architecture of JAVA software systems, the increasing scale of JAVA software systems and the increasing importance of stability requirements, observability assurance, real-time security protection and fine-grained performance monitoring of JAVA software systems have gradually become an important part of core infrastructure. Therefore, it is particularly important to implant basic capabilities such as observability, security protection and performance monitoring into a runtime environment. In practical applications, basic capabilities such as observability, security protection and performance monitoring are integrated into JAVA application systems in the form of plug-ins, such as seamlessly integrating link tracking, performance monitoring and security protection plug-ins in JAVA application programs in a zero-code invasive manner. These plug-ins often rely on call stack collection technology to obtain call stack information as the data basis for link tracking, performance monitoring and security protection.

[0003] In a traditional JAVA application program, call stack information is generally collected using getStackTrace() written based on JAVA. However, this getStackTrace() written based on JAVA creates a new stack information object at each call, resulting in high performance overhead, especially in the case of frequent calls, which can cause significant performance bottlenecks, and the performance loss is particularly evident in high-traffic scenarios.

[0004] Therefore, how to collect call stack information for JAVA application programs to reduce the performance loss of call stack collection operations is a problem to be solved. SUMMARY

[0005] The present application provides a data collection method, device, electronic equipment and computer readable storage medium, which can reduce the performance loss of call stack collection. The specific scheme is as follows:

[0006] In a first aspect, the present application provides a data collection method, which comprises: injecting data collection code into the runtime environment of a target application program; determining data collection requirement information in the runtime environment of the target application program; calling the data collection code according to the data collection requirement information; and the data collection code, when called, obtains stack trace data from the original call stack data of the target application program according to the data collection requirement information, and outputs the stack trace data.

[0007] Optionally, the metadata collection requirement information comprises a metadata collection granularity, and the metadata collection granularity is formed based on any combination of the following attributes: class name, method name, source file, and line number; when the data collection code is invoked, the following steps are included: parsing the specified attributes included in the metadata collection granularity; invoking an interface function corresponding to each specified attribute to obtain the attribute value of the specified attribute from the original call stack data of the target application program through the interface function; and forming the stack trace data according to the attribute values of the specified attributes.

[0008] Optionally, when the data collection code is invoked, the following steps are further included: obtaining one or more call stack frames of the current thread as the original call stack data of the target application program based on a native tool interface; the native tool interface refers to a programming interface of a virtual machine, and the virtual machine provides a runtime environment for the target application program; traversing the call stack frames, and sequentially performing the following steps for each call stack frame: invoking an interface function corresponding to each specified attribute in the native tool interface to obtain the attribute value of the specified attribute contained in the call stack frame through the interface function corresponding to the specified attribute; forming the stack trace data of the call stack frame according to the attribute values of the specified attributes; and after the traversal is completed, taking the stack trace data of each call stack frame as the target stack trace data obtained by this time invoking the data collection code, and outputting the target stack trace data.

[0009] Optionally, the obtaining one or more call stack frames of the current thread based on the native tool interface comprises: obtaining a specified number of call stack frames of the current thread according to a native GetStackTrace interface function included in the native tool interface.

[0010] Optionally, the invoking an interface function corresponding to each specified attribute in the native tool interface to obtain the attribute value of the specified attribute contained in the call stack frame through the interface function corresponding to the specified attribute comprises: determining that the specified attribute includes a method name, and invoking a native GetMethodName interface function included in the native tool interface to obtain a method identifier from the call stack frame; determining that the specified attribute includes a class name, and invoking a native GetMethodDeclaringClass interface function included in the native tool interface to obtain reference information of a class to which the method belongs from the call stack frame, the reference information being used to determine the class name of the class to which the method belongs; and invoking a native GetClassSignature interface function included in the native tool interface to obtain a class signature of the class identified by the class identifier from the call stack frame.

[0011] Optionally, the calling the interface function corresponding to the specified attribute included in the native tool interface according to the specified attribute comprises: judging whether the class source file information needs to be acquired and the class is not an anonymous class, calling a native GetSourceFileName interface function included in the native tool interface to acquire the source file name of the class, and forming the stack trace record; judging whether the line number needs to be acquired, and if yes, calling a native GetLineNumberTable interface function included in the native tool interface according to the position information in the stack frame to acquire the line number information according to the position information in the stack frame; and constructing the class name, the method name, the source file and the line number information into a stack frame and adding the stack frame to a list.

[0012] Optionally, the method further comprises: acquiring a link calling process and stack trace data of the distributed application, distinguishing the calling path between the distributed applications according to the stack trace data, and forming a full link topology; and / or, reconstructing a context on an attack chain according to the stack trace data, and identifying an abnormal behavior pattern; and / or, locating a code segment whose execution frequency meets a preset condition and resource consumption of the code segment according to the stack trace data.

[0013] In a second aspect, the present application provides a data acquisition device, comprising: an injection unit configured to inject a data acquisition code into a runtime environment of a target application; a collection granularity definition unit configured to determine data acquisition requirement information in the runtime environment of the target application; and a call stack acquisition unit configured to call the data acquisition code according to the data acquisition requirement information; the data acquisition code, when called, acquires stack trace data from original call stack data of the target application according to the data acquisition requirement information, and outputs the stack trace data.

[0014] In a third aspect, the present application further provides an electronic device, comprising: a processor, a memory, and computer program instructions stored in the memory and executable on the processor; the processor, when executing the computer program instructions, implements the method provided in the present application.

[0015] In a fourth aspect, the present application provides a computer readable storage medium, wherein computer execution instructions are stored in the computer readable storage medium, and the computer execution instructions, when executed by a processor, are used to implement the method provided in the present application.

[0016] In a fifth aspect, an embodiment of the present application provides a computer program product, comprising a computer program, wherein the computer program, when executed by a processor, implements the method according to any one of the first aspect.

[0017] Compared with the prior art, the present application has the following advantages:

[0018] The data acquisition method and device, the electronic device and the computer readable storage medium provided by the embodiments of the present application inject the data acquisition code into the runtime environment of the target application program; determine the data acquisition requirement information in the runtime environment of the target application program; call the data acquisition code according to the data acquisition requirement information; and the data acquisition code acquires the stack trace data from the original call stack data of the target application program according to the data acquisition requirement information when being called, and outputs the stack trace data. The stack trace data is acquired from the original call stack data according to the data acquisition requirement, which reduces the performance consumption of the call stack acquisition operation. Further, the stack trace data of the call stack is acquired based on the native interface function included in the virtual machine tool interface of the runtime environment, instead of the stack standard library function written based on Java, which can improve the performance to a certain extent. BRIEF DESCRIPTION OF DRAWINGS

[0019] Figure 1 is a processing flow diagram of the data acquisition method provided by an embodiment of the present application;

[0020] Figure 2 is a collection flow diagram of the stack trace data of the call stack provided by an embodiment of the present application;

[0021] Figure 3 is a schematic diagram of a data acquisition device provided by an embodiment of the present application;

[0022] Figure 4 is a structural block diagram of an electronic device provided by the present application. DETAILED DESCRIPTION

[0023] In order for those skilled in the art to better understand the technical solutions of the present application, the present application will be described in detail below with reference to the drawings in the embodiments of the present application. However, the present application can be implemented in many ways different from the description below, therefore, based on the embodiments provided by the present application, all other embodiments obtained by those skilled in the art without creative labor shall belong to the scope of protection of the present application.

[0024] It should be noted that the terms "first", "source domain", "third", and the like in the claims, the specification, and the drawings of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. The data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include", "have" and their variants are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0025] In order to facilitate the understanding of the embodiments of the present application, some concepts related to the embodiments are given.

[0026] JVM (Java Virtual Machine, Java virtual machine): is a computing model and runtime environment based on Java technology, which is responsible for interpreting or compiling the bytecode compiled based on Java source code into machine code and executing on various platforms.

[0027] JVMTI (Java Virtual Machine Tool Interface, Java virtual machine tool interface): is a set of native programming interfaces provided by the Java virtual machine, which allows developers to use C / C++ language to write applications (especially tool applications) that interact with the Java virtual machine. It provides the ability to check the state of the JVM and control the execution of applications in the JVM. The JVMTI supports tools that need to access the state of the JVM, including but not limited to: performance analysis tools, debuggers, monitoring tools, thread analysis tools, and code coverage analysis tools, etc.

[0028] Java Agent (Java agent): a technical mechanism that can dynamically modify and enhance the behavior of Java applications through bytecode instrumentation technology when the JVM is started or running.

[0029] In the existing stack acquisition scheme for collecting the call stack information of the Java application, the stack acquisition scheme based on the Java standard library such as Thread.getStackTrace(), new Exception().getStackTrace() and the like, although it can obtain the complete Java call stack, has a significant performance bottleneck, and the performance loss is particularly obvious in high-flow scenarios, making it difficult to use in online Java applications in production environments.

[0030] To solve the above problems, the embodiments of the present application provide a data acquisition method and device, electronic equipment and computer readable storage medium. The purpose is to bypass the Java layer and directly call the JVMTI native interface function, so as to realize the stack operation based on the native interface function, thereby reducing the performance loss of the stack operation.

[0031] Embodiment one

[0032] The first embodiment of the present application provides a data acquisition method, which can be executed by electronic equipment with corresponding processing capability. The following will be combined with Figures 1 to 2 The data acquisition method is described. Figure 2 The data acquisition method shown in the figure includes steps S101 to S103.

[0033] Step S101, inject the data acquisition code into the runtime environment of the target application program.

[0034] The target application program is a JAVA application program, and the data acquisition code is the call stack acquisition code generated based on the programming of the native interface function of the JVMTI. Through the call stack acquisition code, the stack tracking data of the thread call stack of the Java application program can be acquired. The data acquisition code can be an executable file compiled based on C / C++ language. The acquisition code bypasses the JAVA layer and directly calls the underlying interface.

[0035] Specifically, the step is to inject the data collection code into the runtime environment. The runtime environment is a running environment for executing the target application, which provides a virtual machine JVM, Java class library, etc. for the running of the target application. The data collection code can be injected at the start of the JVM or at the running of the target application. If injected at the start, in one way, the data collection code can be injected through the Agent OnLoad method. Specifically, at the start of the JVM, a JAR package containing the Agent_OnLoad method is specified through the -Javaagent parameter. The method is called in the JVM initialization process, at which time the JVMTI event callback, such as the method call, class loading, etc. can be registered, so as to collect the call stack data before and after the execution of the target method. In another way, the data collection code can be injected in the premain method of the Java Agent through the Java Agent technology. The premain method is called before the main method is executed, and can be used to implement the call stack collection. If the data collection code is injected at the running, in one way, the Attach API of the JVM can be used to dynamically attach a Java agent to the JVM process during the running of the program. A JAR package containing the Agent_OnAttach method can be loaded through the load command, the method is executed after the successful attachment of the Java agent, and the data collection code can be injected in the method. In one way, the Instrumentation API of Java can be used to modify and redefine the loaded classes at the running, and through the registration of the ClassFileTransformer, the bytecode can be modified to insert the call stack collection code at the class loading.

[0036] Step S102, determining data collection requirement information in the runtime environment of the target application.

[0037] The step is to determine data collection requirements, so that the call stack metadata required can be collected according to the needs of the call stack taking scene. The call stack taking scene can include but is not limited to: distributed application tracking scene, security attack and defense scene, performance profiling scene, etc. The so-called distributed application tracking scene refers to the application gradually distributed, such as microservices, distributed caching, distributed storage, cross-service calling, etc. When it is necessary to analyze link topology and / or call path, etc. The call stack can be collected for link analysis. The so-called security attack and defense scene refers to the scene where it is necessary to reconstruct the context of the attack chain in real time to identify abnormal behavior patterns. In this scene, the call stack can be collected to analyze the context of the attack chain. The so-called performance profiling scene refers to quantitatively determining the execution frequency of the code level method, so that the frequently called or performance-impacting hot methods can be identified, and the distribution of resource consumption can be quantified. The quantification of resource consumption distribution refers to measuring and evaluating the resource usage of methods or code fragments in CPU and memory.

[0038] For example, for the distributed application tracking scene, the data collection requirements can include the information of the method and the method declaration class, so that the stack trace data including the function call path can be extracted from the original stack data, including the function call path of the target application program from the start of execution to the current position. By analyzing the extracted stack trace data, the execution flow of the program can be understood, including the execution order of each function, the nesting relationship, etc.

[0039] For another example, in the performance profiling scene, the data collection code can be executed to obtain the call stack data related to the events such as the response time of the target application program, the CPU occupancy rate, etc. and the class name, method name, line number, etc. can be extracted from the call stack data.

[0040] For another example, in the security attack and defense scene, the call stack data can be collected to obtain the stack trace data with finer granularity, such as parameter values. By analyzing the extracted stack trace data, potential security vulnerabilities can be identified. By analyzing the call stack, it can be understood whether there is unverified input passed to sensitive operations in the program, or whether there is a code path that may cause buffer overflow, stack overflow, etc. Security problems can be analyzed. The execution path and function call relationship related to the stack trace data can also be analyzed to track the occurrence process of the security event.

[0041] In step S103, the data collection code is called according to the data collection requirement information; when the data collection code is called, the stack trace data is obtained from the original call stack data of the target application program according to the data collection requirement information, and the stack trace data is output.

[0042] Specifically, the original call stack data can be thread stack data of the JVM obtained based on a JVMTI native interface function, and call stack information is further extracted from the data according to data collection requirements to form stack trace data. The extracted call stack information can include information of all or part of metadata loaded by the target application during runtime, and the extracted metadata information can be formed into a call stack as stack trace data. The metadata embodies information of classes, interfaces, fields, and methods and other elements loaded and processed by the JVM during runtime of the target application. Of course, parameter information during runtime can also be extracted. The data collection requirement information includes metadata collection granularity, and the metadata collection granularity is formed based on any combination of the following attributes: class name, method name, source file, and line number. Correspondingly, when the data collection code is called, it includes: parsing the specified attributes included in the metadata collection granularity; calling the interface function corresponding to each specified attribute for each specified attribute to obtain the attribute value of the specified attribute from the original call stack data of the target application through the interface function; and forming the stack trace data according to the attribute values of the specified attributes. Thus, the field attributes that need to be collected can be dynamically customized, that is, the specified attributes are specified to collect the fields.

[0043] In the method, when the data collection code is called, one or more call stack frames of the current thread are further obtained based on a native tool interface (JVMTI) as the original call stack data of the target application, the native tool interface refers to a programming interface of a virtual machine, and the virtual machine provides a runtime environment for the target application; the call stack frames are traversed, and the following steps are performed for each call stack frame in turn: an interface function corresponding to each specified attribute in the native tool interface is called according to the specified attribute to obtain an attribute value of the specified attribute contained in the call stack frame through the interface function corresponding to the specified attribute; and stack trace data of the call stack frame is formed according to the attribute values of the specified attributes; after the traversal is completed, the stack trace data of each call stack frame is taken as target stack trace data obtained by calling the data collection code this time, and the target stack trace data is output.

[0044] Preferably, the obtaining one or more call stack frames of the current thread based on the native tool interface comprises: obtaining a specified number of call stack frames of the current thread according to a native GetStackTrace interface function contained in the native tool interface. The obtaining the attribute value of the specified attribute in the call stack frame by calling the interface function corresponding to the specified attribute in the native tool interface comprises: determining that the specified attribute comprises a method name, and calling a native GetMethodName interface function contained in the native tool interface to obtain a method identifier from the call stack frame; determining that the specified attribute comprises a class name, and calling a native GetMethodDeclaringClass interface function contained in the native tool interface to obtain reference information of a class to which the method belongs from the call stack frame, the reference information being used to determine the class name of the class to which the method belongs, the reference information being a JNI reference, and the reference information being parsed to obtain an identifier (i.e., the class name) of the class to which the method belongs; and calling a native GetClassSignature interface function contained in the native tool interface to obtain a class signature of the class identified by the class identifier from the call stack frame. The JNI reference refers to a manner of passing and operating Java objects between a JVM and native code (C / C++, etc.) in JNI (Java Native Interface), and the C / C++-based data acquisition code can obtain information of the Java objects by using the manner.

[0045] In the embodiment, the obtaining the attribute value of the specified attribute in the call stack frame by calling the interface function corresponding to the specified attribute in the native tool interface comprises: determining whether class source file information needs to be obtained and the class is not an anonymous class, calling a native GetSourceFileName interface function contained in the native tool interface to obtain a source file name of the class, and forming a stack trace record; determining whether a line number needs to be obtained, and if so, calling a native GetLineNumberTable interface function contained in the native tool interface to obtain line number information according to position information in the stack frame; and constructing the obtained class name, method name, source file, and line number information into a stack frame and adding the stack frame to a list.

[0046] Further, the data collection method further comprises: acquiring link calling processes and stack tracking data of the distributed applications, distinguishing calling paths between the distributed applications according to the stack tracking data, and forming a full-link topology; and / or, reconstructing attack chain contexts according to the stack tracking data, and identifying abnormal behavior patterns; and / or, locating code segments with execution frequencies satisfying preset conditions and resource consumption of the code segments according to the stack tracking data.

[0047] Please refer to Figure 2 , a calling stack collection process is shown in the figure, including the following steps after being called to start execution:

[0048] S201, initializing an empty stack tracking list. That is, creating a stack tracking list containing no elements, which is initially empty. An empty stack tracking list can be constructed by dynamically allocating memory, and the stack top pointer is set to -1. S202, calling GetStackTrace to acquire stack frames, that is, acquiring original calling stack data of a specified thread object. GetStackTrace is a native interface function included in JVMTI, especially an interface function that can be used in C / C++ language, which is used to acquire calling stack data of a thread. For example, including necessary JVMTI header files <jni.h> and <jvmti.h> in a C / CPP file, registering a JNI callback function, and acquiring calling stack data of a thread in the callback function:

[0049]

[0050] S203, traverse the stack frames, traverse the actual taken stack frames. Perform S204 to S217 in each round until the end of the traversal. The judgment of whether the traversal ends includes: the stack frame method is empty or has traversed each stack frame. S204, process each stack frame. S205, call GetMethodName to obtain the method name. S206, call GetMethodDeclaringClass to obtain the method declaration, specifically including obtaining the JNI reference of the class to which the method belongs through the function, and parsing the reference to obtain the class name of the class to which the method belongs. S207, call GetClassSignature to obtain the class signature. S208, judge whether to obtain the class source file information and the class is not an anonymous class? If yes, perform S209 to S210; if not, directly jump to S211. S210 is executed after S211 is executed. S209, call GetSourceFileName to obtain the original file name. S210, update the cached class and source file name. S211, add stack trace record. S212, judge whether to obtain the line number? If yes, perform S213-S214; otherwise, perform S215. S214 or S215 is executed after S216 is executed. S213, call GetLineNumberTable to obtain the line number. S214, search for the corresponding line number. S215, if the line number does not need to be obtained, the line number is set to -1. S216, create a stack trace object such as StackTrace. Specifically, the obtained class name, method name, source file and line number and other information can be constructed into a stack frame, which is used as a stack trace object. In the next step, it is added to the stack trace list. S217, add the stack trace object to the stack trace list such as stack_traces. S218, the end of the traversal. S219, return the stack trace list. Among them, GetMethodName, GetMethodDeclaringClass, GetClassSignature, GetSourceFileName, GetLineNumberTable, and GetStackTrace are similar, which are native interface functions included in JVMTI, and can be programmed in C / C++ language.

[0051] Compared with the Java api call stack collection scheme provided by Thread.getStackTrace(), new Exception().getStackTrace() and the like of the Java standard library, the call stack collection method provided in this embodiment optimizes the data collection requirements of the target application program through a bottom interface, bypasses the Java language level restriction, directly obtains original stack data through a JVMTI interface, and supports on-demand combination of metadata collection granularity such as class name, method name and line number, so that runtime metadata can be extracted from the native call stack data as stack trace data, the performance loss and memory overhead of the Java stack acquisition scheme are reduced, and the memory allocation pressure is reduced. Moreover, it does not need to be processed and can be directly adapted to different JVM implementations.

[0052] It should be noted that the features given in this embodiment and other embodiments of the present application can be combined with each other without conflict, and steps S101 and S102 or similar terms do not limit the execution of the steps.

[0053] So far, the method provided in this embodiment has been described, in which the data collection requirements of the target application program are optimized through a bottom interface, and the performance consumption and memory occupation of call stack collection are reduced.

[0054] Embodiment Two

[0055] Corresponding to the first embodiment, the second embodiment of the present application also provides a data collection device. Since the device embodiment is basically similar to the method embodiment, it is described relatively simply, and the details of the related technical features and the effects achieved can be referred to the corresponding description of the corresponding method embodiment. Please refer to the data collection device shown in Figure 3 , Figure 3 The data collection device comprises:

[0056] The injection unit 301 is configured to inject the data collection code into the runtime environment of the target application program.

[0057] The collection granularity definition unit 302 is configured to determine data collection requirement information in the runtime environment of the target application program.

[0058] The call stack collection unit 303 is configured to call the data collection code according to the data collection requirement information; the data collection code, when called, obtains stack trace data from the original call stack data of the target application program according to the data collection requirement information, and outputs the stack trace data.

[0059] Optionally, the metadata collection requirement information comprises a metadata collection granularity, and the metadata collection granularity is formed based on any combination of the following attributes: class name, method name, source file, and line number; the call stack collection unit 303 is specifically configured to: parse the specified attributes included in the metadata collection granularity; call an interface function corresponding to each specified attribute, so as to obtain the attribute value of the specified attribute from the original call stack data of the target application program through the interface function; and form the stack trace data according to the attribute values of the specified attributes.

[0060] Optionally, the call stack collection unit 303 is specifically configured to: obtain one or more call stack frames of a current thread as the original call stack data of the target application program based on a native tool interface; the native tool interface refers to a programming interface of a virtual machine, and the virtual machine provides a runtime environment for the target application program; and traverse the call stack frames, and sequentially perform the following steps for each call stack frame: call an interface function corresponding to each specified attribute in the native tool interface, so as to obtain the attribute value of the specified attribute contained in the call stack frame through the interface function corresponding to the specified attribute; and form the stack trace data of the call stack frame according to the attribute values of the specified attributes; and after the traversal is completed, output the target stack trace data obtained by calling the data collection code this time as the target stack trace data, and output the target stack trace data.

[0061] Optionally, the call stack collection unit 303 is specifically configured to: obtain a specified number of call stack frames of a current thread according to a native GetStackTrace interface function included in the native tool interface.

[0062] Optionally, the call stack collection unit 303 is specifically configured to: determine that the specified attribute comprises a method name, call a native GetMethodName interface function included in the native tool interface to obtain a method identifier from the call stack frame; determine that the specified attribute comprises a class name, call a native GetMethodDeclaringClass interface function included in the native tool interface to obtain reference information of a class to which the method belongs from the call stack frame, and the reference information is used to determine the class name of the class to which the method belongs; and call a native GetClassSignature interface function included in the native tool interface to obtain a class signature of the class identified by the class identifier from the call stack frame.

[0063] Optionally, the call stack collection unit 303 is specifically configured to: determine whether class source file information needs to be acquired and the class is not an anonymous class, acquire the source file name of the class by calling the native GetSourceFileName interface function included in the native tool interface, and form stack trace records; determine whether line numbers need to be acquired, and if so, acquire line number information according to the location information in the stack frame by calling the native GetLineNumberTable interface function included in the native tool interface according to the location information in the stack frame; and construct the acquired class name, method name, source file, and line number information into a stack frame and add the stack frame to a list.

[0064] Optionally, the call stack collection unit 303 is further configured to: acquire a link calling process and stack trace data of a distributed application, distinguish calling paths between the distributed applications according to the stack trace data, and form a full-link topology; and / or, according to the stack trace data, reconstruct a context on an attack chain, and identify an abnormal behavior pattern; and / or, according to the stack trace data, locate a code segment whose execution frequency meets a preset condition and resource consumption of the code segment.

[0065] Based on the above embodiments, an embodiment of the present application provides an electronic device, and related parts can be understood by referring to the corresponding description of the above embodiments. Please refer to Figure 4 The electronic device schematic diagram shown in the figure includes a processor and a memory; the memory is used to store computer instructions for data processing, and the computer instructions are executed by the processor when read, to execute the method provided by the embodiment of the present application. The computer instructions can be a computer program.

[0066] Based on the above embodiments, an embodiment of the present application further provides a computer readable storage medium. Related parts can be understood by referring to the corresponding description of the above embodiments. The computer readable storage medium schematic diagram is similar to the electronic device schematic diagram, and the memory in the figure can be understood as the readable storage medium. The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the method provided by the embodiment of the present application.

[0067] In a typical configuration, the computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0068] The memory can include non-permanent memory in the computer readable medium, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of the computer readable medium.

[0069] 1. Computer-readable media includes permanent and non-permanent, removable and non-removable media can be implemented by any method or technology to store information. Information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information that can be accessed by a computing device. According to the definition herein, computer-readable media does not include transitory media, such as modulated data signals and carriers.

[0070] 2. Those skilled in the art should understand that the embodiments of the present application can be provided as a method, system or computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0071] Although the present application is disclosed with reference to the preferred embodiments above, it is not intended to limit the present application, and any person skilled in the art can make possible changes and modifications without departing from the spirit and scope of the present application. Therefore, the scope of protection of the present application should be defined by the scope defined by the claims of the present application.

Claims

1. A data acquisition method, characterized by, The method comprises: injecting data collection code into a runtime environment of a target application; determining metadata collection requirement information in the runtime environment of the target application; calling the data collection code according to the metadata collection requirement information; when the data collection code is called, it acquires stack trace data from original call stack data of the target application according to the metadata collection requirement information, and outputs the stack trace data.

2. The method of claim 1, wherein, The metadata collection requirement information includes a metadata collection granularity, and the metadata collection granularity is formed based on any combination of the following attributes: class name, method name, source file, and line number; When the data collection code is called, it includes: parsing the specified attributes included in the metadata collection granularity; for each specified attribute, calling an interface function corresponding to the specified attribute to acquire the attribute value of the specified attribute from the original call stack data of the target application through the interface function; forming the stack trace data according to the attribute values of the specified attributes.

3. The method of claim 2, wherein, When the data collection code is called, it also includes: acquiring one or more call stack frames of the current thread as the original call stack data of the target application based on a native tool interface; the native tool interface refers to a programming interface of a virtual machine that provides a runtime environment for the target application; traversing the call stack frames, and sequentially performing the following steps for each call stack frame: for each specified attribute, calling an interface function corresponding to the specified attribute in the native tool interface to acquire the attribute value of the specified attribute contained in the call stack frame through the interface function corresponding to the specified attribute; forming the stack trace data of the call stack frame according to the attribute values of the specified attributes; after traversal, the stack trace data of each call stack frame is taken as the target stack trace data acquired by this time calling the data collection code, and the target stack trace data is output.

4. The method of claim 2, wherein, The acquisition of one or more call stack frames of the current thread based on the native tool interface includes: acquiring a specified number of call stack frames of the current thread according to a native GetStackTrace interface function included in the native tool interface.

5. The method of claim 2, wherein, The acquisition of the attribute value of the specified attribute contained in the call stack frame through the interface function corresponding to the specified attribute includes: when it is determined that the specified attribute includes a method name, a native GetMethodName interface function included in the native tool interface is called to acquire a method identifier from the call stack frame; when it is determined that the specified attribute includes a class name, a native GetMethodDeclaringClass interface function included in the native tool interface is called to acquire reference information of a class to which the method belongs from the call stack frame, and the reference information is used to determine the class name of the class to which the method belongs; a native GetClassSignature interface function included in the native tool interface is called to acquire a class signature of the class identified by the class identifier from the call stack frame.

6. The method of claim 2, wherein, The calling the interface function corresponding to the specified attribute according to each specified attribute includes the interface function corresponding to the specified attribute included in the native tool interface, so as to obtain the attribute value of the specified attribute included in the call stack frame through the interface function corresponding to the specified attribute, including: If it is determined that the class source file information needs to be obtained and the class is not an anonymous class, a native GetSourceFileName interface function included in the native tool interface is called to obtain the source file name of the class, and a stack trace record is formed; If it is determined that the line number needs to be obtained, the native GetLineNumberTable interface function included in the native tool interface is called according to the position information in the stack frame to obtain the line number information according to the position information in the stack frame; The obtained class name, method name, source file and line number information are constructed into a stack frame and added to a list.

7. The method according to any one of claims 1 to 6, characterized in that, Further comprising: Obtaining a link calling process and stack trace data of a distributed application, distinguishing the calling path between the distributed applications according to the stack trace data, and forming a full-link topology; And / or, According to the stack trace data, reconstructing the attack chain context, and identifying abnormal behavior patterns; and / or According to the stack trace data, positioning the code segment whose execution frequency meets the preset condition and the resource consumption of the code segment.

8. A data acquisition device, characterized by Comprising: An injection unit configured to inject data collection code into a runtime environment of a target application program; A collection granularity definition unit configured to determine data collection requirement information in the runtime environment of the target application program; A call stack collection unit configured to call the data collection code according to the data collection requirement information; The data collection code, when called, obtains stack trace data from original call stack data of the target application program according to the data collection requirement information, and outputs the stack trace data.

9. An electronic device, comprising: Comprising: A processor, a memory, and computer program instructions stored on the memory and executable on the processor; The processor executes the computer program instructions to implement the method of any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the method of any one of claims 1-7.

Citation Information

Cited By

  • Java application function call data acquisition method, device, medium and product

    CN121597309A