Network service monitoring method, device, equipment and storage medium based on SQL query

By analyzing and comparing SQL statements and database log files in network traffic of the service system, the portability and automated monitoring of network service monitoring systems in the existing technology are solved, and automatic monitoring of network services for different service systems is realized, and the efficiency and accuracy of abnormal data detection are improved.

CN111475705BActive Publication Date: 2025-07-22CHINA PING AN LIFE INSURANCE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010141190.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-03-05
Publication Date
2025-07-22
Estimated Expiration
2040-03-05

AI Technical Summary

Technical Problem

The existing network service monitoring methods or monitoring systems cannot achieve high portability in different business systems, and real-time and automated monitoring cannot be achieved, making it difficult for operators to quickly find abnormal network services in a big data environment.

Method used

By crawling network traffic of the service system, parsing SQL statements and performing SQL operations on the target database, obtaining and comparing the first and second SQL operation information to determine whether the network service is abnormal.

Benefits of technology

It realizes automatic monitoring of network services for different business systems, improves the portability of the monitoring system, and enhances the efficiency and accuracy of checking abnormal data of large-data network services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN111475705B_ABST
    Figure CN111475705B_ABST
Patent Text Reader

Abstract

The present application discloses a network service monitoring method, device, equipment and storage medium based on SQL query, belonging to the field of computer technology. The monitoring method includes: capturing network traffic on at least one business system; parsing the network traffic to obtain SQL statements in the network traffic; performing SQL operations on a target database according to the SQL statements to obtain first SQL operation information; obtaining a log file of the target database, and querying second SQL operation information corresponding to the SQL statements in the log file of the target database; comparing the first SQL operation information with the second SQL operation information, and judging whether the network service is abnormal according to the comparison result; if the comparison result is not a null value and the comparison results are the same, it is determined that the network service is a normal service, otherwise it is determined that the network service is an abnormal service. The network service monitoring method provided by the present application can realize the automatic monitoring of network services in different business systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a network service monitoring method, device, equipment, and storage medium based on SQL queries. Background Art

[0002] Currently, most enterprises will develop and run one or more business systems that match their own business needs according to their business requirements. Due to different business needs, when developers develop systems, they need to use different structures and frameworks for development according to the requirements. Eventually, there are certain differences in the data processing methods of each developed system. When it is necessary to monitor the network traffic of these business systems, developers need to develop a monitoring system according to the different structural frameworks of the business systems to achieve the monitoring of the network traffic of different business systems, that is, each business system needs to develop a network traffic monitoring system that matches itself, which will undoubtedly increase the work pressure of developers.

[0003] Moreover, in the prior art, developers often use architectures such as zabbix and prometheus to develop network traffic monitoring systems. However, in actual use, when using the monitoring method of the zabbix architecture for traffic monitoring, there is a problem that it is difficult for operators to find abnormal data from a large number of data monitoring results; when using the monitoring method of the prometheus architecture for data monitoring, operators need to continuously modify the configuration file to achieve continuous monitoring of data services, and the more data there is during the monitoring process, the more configuration files need to be modified, and the task is cumbersome, bringing a great workload to operators.

[0004] Therefore, the existing network service monitoring methods or monitoring systems have low portability and cannot complete the monitoring of network services in different business systems. Therefore, they are not suitable for the investigation of abnormal network services in multi-system and big data, and during the monitoring of network traffic, automated monitoring and real-time monitoring cannot be achieved either. Summary of the Invention

[0005] The purpose of the embodiments of this application is to propose a network service monitoring method, device, equipment, and storage medium based on SQL queries to solve the problems that the existing network service monitoring methods or monitoring systems have low portability, cannot complete the monitoring of network services in different business systems, and cannot achieve real-time and automated monitoring.

[0006] To solve the above technical problems, the embodiments of this application provide a network service monitoring method based on SQL queries, and adopt the following technical solutions:

[0007] Capture the network traffic on at least one business system;

[0008] Parse the network traffic to obtain the SQL statements in the network traffic;

[0009] Perform SQL operations on the target database according to the SQL statements to obtain the first SQL operation information, where the target database is the database of at least one business system;

[0010] Obtain the log file of the target database and query the second SQL operation information corresponding to the SQL statements in the log file of the target database, where the second SQL operation information is the information generated when the business system performs the SQL statement operations;

[0011] Compare the first SQL operation information with the second SQL operation information, and judge whether the network service is abnormal according to the comparison result;

[0012] If the comparison result is not a null value and the comparison results are the same, determine that the network service is a normal service, otherwise determine that the network service is an abnormal service.

[0013] Further, after parsing the network traffic to obtain the SQL statements in the network traffic, it further includes:

[0014] Obtain the TCP network traffic packets in the network traffic;

[0015] Parse the TCP network traffic packets to obtain TCP packet information, where the TCP packet information includes the IP address of the target database, the port number of the target database, the IP address of the local port, the port number of the local port, and the first time information, and the first time information is the capture time of the TCP packet.

[0016] Further, before performing SQL operations on the target database according to the SQL statements to obtain the first SQL operation information, it further includes:

[0017] Obtain the second time information, where the second time information is the capture time of the SQL statements;

[0018] Judge whether the first time information is consistent with the second time information;

[0019] If the first time information is consistent with the second time information, combine the TCP packet information and the SQL statements to form a request instruction;

[0020] According to the request instruction, request to perform SQL operations on the target database.

[0021] Further, before requesting to perform SQL operations on the target database according to the request instruction, it further includes:

[0022] Receive the authentication instruction of the target database;

[0023] Perform authentication operations on the IP address of the target database, the port number of the target database, the IP address of the local port, and the port number of the local port;

[0024] If the authentication is passed, perform SQL operations on the target database according to the request instruction.

[0025] Further, after parsing the network traffic and obtaining the SQL statement in the network traffic, it further includes:

[0026] Judge whether the SQL statement already exists in the cache;

[0027] If the SQL statement does not exist in the cache, save the SQL statement to the cache and save the second time information of the SQL statement at the same time;

[0028] If the cache already contains the SQL statement, update the second time information of the SQL statement.

[0029] Further, comparing the first SQL operation information and the second SQL operation information, and judging whether the network service is abnormal according to the comparison result specifically includes:

[0030] Extract the table name and SQL fields in the first SQL operation information and the second SQL operation information respectively. Among them, the first SQL operation information includes the first table name and the first SQL field, and the second SQL operation information includes the second table name and the second SQL field;

[0031] Compare the first table name with the second table name, and the first SQL field with the second SQL field respectively to obtain the comparison result;

[0032] Judge whether the network service is abnormal according to the comparison result.

[0033] Further, after determining that the network service is an abnormal service, it further includes:

[0034] Obtain the SQL statement of the abnormal service and the abnormal prompt message generated after executing the SQL statement of the abnormal service;

[0035] Combine the SQL statement of the abnormal service and the abnormal prompt message to obtain the service abnormal prompt information;

[0036] Output the service abnormal prompt information.

[0037] To solve the above technical problems, the embodiment of the present application further provides a network service monitoring device based on SQL query, which adopts the following technical solutions:

[0038] A traffic capture module for capturing network traffic on at least one business system;

[0039] A traffic analysis module for analyzing the network traffic to obtain SQL statements in the network traffic;

[0040] An SQL operation module for performing SQL operations on a target database according to the SQL statements to obtain first SQL operation information, where the target database is the database of at least one business system;

[0041] An SQL query module for obtaining a log file of the target database and querying second SQL operation information corresponding to the SQL statements in the log file of the target database, where the second SQL operation information is the information generated by the business system when performing SQL statement operations;

[0042] An exception judgment module for comparing the first SQL operation information and the second SQL operation information and judging whether the network service is abnormal according to the comparison result;

[0043] A judgment result module for determining that the network service is a normal service if the comparison result is not a null value and the comparison results are the same, otherwise determining that the network service is an abnormal service.

[0044] To solve the above technical problems, an embodiment of the present application further provides a computer device, which adopts the following technical solutions:

[0045] Capture network traffic on at least one business system; analyze the network traffic to obtain SQL statements in the network traffic; perform SQL operations on a target database according to the SQL statements to obtain first SQL operation information, where the target database is the database of at least one business system; obtain a log file of the target database and query second SQL operation information corresponding to the SQL statements in the log file of the target database, where the second SQL operation information is the information generated by the business system when performing SQL statement operations; compare the first SQL operation information and the second SQL operation information and judge whether the network service is abnormal according to the comparison result; if the comparison result is not a null value and the comparison results are the same, determine that the network service is a normal service, otherwise determine that the network service is an abnormal service.

[0046] To solve the above technical problems, an embodiment of the present application further provides a computer-readable storage medium, which adopts the following technical solutions:

[0047] Capture the network traffic on at least one business system; parse the network traffic to obtain the SQL statements in the network traffic; perform SQL operations on the target database according to the SQL statements to obtain the first SQL operation information, where the target database is the database of at least one business system; obtain the log file of the target database, and query the second SQL operation information corresponding to the SQL statements in the log file of the target database, where the second SQL operation information is the information generated by the business system when performing SQL statement operations; compare the first SQL operation information and the second SQL operation information, and determine whether the network service is abnormal according to the comparison result; if the comparison result is not a null value and the comparison results are the same, determine that the network service is a normal service, otherwise determine that the network service is an abnormal service.

[0048] Compared with the prior art, the embodiments of the present application mainly have the following beneficial effects:

[0049] The present application discloses a network service monitoring method, device, device and storage medium based on SQL query, belonging to the field of computer technology. The monitoring method captures the network traffic on at least one business system; parses the network traffic to obtain the SQL statements in the network traffic; performs SQL operations on the target database according to the SQL statements to obtain the first SQL operation information, where the target database is the database of at least one business system; obtains the log file of the target database, and queries the second SQL operation information corresponding to the SQL statements in the log file of the target database, where the second SQL operation information is the information generated by the business system when performing SQL statement operations; compares the first SQL operation information and the second SQL operation information, and determines whether the network service is abnormal according to the comparison result; if the comparison result is not a null value and the comparison results are the same, determine that the network service is a normal service, otherwise determine that the network service is an abnormal service. Compared with the prior art, the network service monitoring method based on SQL query disclosed in the present application does not require the business system to perform SQL statement operations again to judge the abnormal situation of the network service. Only need to compare the first SQL operation information obtained by the monitoring system performing SQL operations on the target database according to the SQL statements with the second SQL operation information obtained by querying the log file of the target database, then the abnormal situation of the network service can be judged. Therefore, it can realize the automatic monitoring of the network services of different business systems, improve the portability of the monitoring system, and is conducive to the system operators of the enterprise to quickly find abnormal network services, greatly improving the efficiency and accuracy of troubleshooting abnormal data of network services with large amounts of data. Description of the Drawings

[0050] To more clearly illustrate the solutions in this application, the following provides a brief introduction to the accompanying drawings required for the description of the embodiments of this application. Obviously, the accompanying drawings in the following description are some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0051] Figure 1 It is an exemplary system architecture diagram of the bypass monitoring system in a network service monitoring method based on SQL query according to an embodiment of this application;

[0052] Figure 2 The implementation flowchart of a network service monitoring method based on SQL query according to an embodiment of this application;

[0053] Figure 3 is Figure 2 The flowchart of a specific implementation manner of step S202 in

[0054] Figure 4 is Figure 2 The flowchart of a specific implementation manner of step S203 in

[0055] Figure 5 is Figure 4 The flowchart of a specific implementation manner of step S404 in

[0056] Figure 6 is Figure 2 The flowchart of another specific implementation manner of step S202 in

[0057] Figure 7 Figure 2 The flowchart of a specific implementation manner of step S205 in

[0058] Figure 8 Figure 2 The flowchart of a specific implementation manner of step S206 in

[0059] Figure 9 The structural schematic diagram of an embodiment of a network service monitoring device based on SQL query according to this application;

[0060] Figure 10 It is the structural schematic diagram of an embodiment of a computer device according to this application. Specific implementation manner

[0061] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which this application belongs; the terms used in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above drawings are intended to cover non-exclusive inclusion. The terms "first", "second", etc. in the specification and claims of this application or the above drawings are used to distinguish different objects and not to describe a specific order.

[0062] Reference herein to "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of this application. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive of other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0063] In order to enable those skilled in the technical field to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings. Embodiment 1

[0064] In the embodiments provided by this application, the execution subject of each step may be a bypass monitoring system. Please refer to Figure 1 , Figure 1 which shows an exemplary system architecture diagram of the bypass monitoring system in a network service monitoring method based on SQL query according to an embodiment of this application. The bypass monitoring system 102 is composed of a traffic capture component 121, a monitoring center 122, and a cache 123. The traffic capture component 121 captures the network traffic transmitted on the middleware 101. The monitoring center 122 analyzes the captured network traffic to obtain the SQL statements therein, and the cache 123 caches the parsed SQL statements. Further, the monitoring center 122 performs SQL operations on the database of the service system according to the obtained SQL statements to obtain a first SQL operation result, and compares the first SQL operation result with the second SQL operation result obtained when the service system directly performs the SQL operation. According to the comparison result, the abnormal situation of the network service is judged to realize automatic monitoring of the network service.

[0065] It should be noted that since the bypass monitoring system 102 is independent of the business system, setting up the bypass monitoring system 102 can monitor the network services of different business systems. The bypass monitoring system 102 can be applied to different business systems for monitoring, improving the portability of the network service monitoring system. Optionally, the execution entity of each step can be the monitoring system running in the monitoring device, and the above-mentioned monitoring device can be a terminal or a server.

[0066] In the embodiments provided in the present application, the middleware is used to connect different business systems to achieve data intercommunication and resource sharing among different business systems, reducing the workload of maintaining, operating, and managing the entire network. In a specific embodiment provided in the present application, please continue to refer to Figure 1 , the middleware 101 is communicatively connected to the business system 1, the business system 2, and the business system 3. The data traffic generated during the operation of the business system 1, the business system 2, and the business system 3 is uploaded to the middleware 101 for data sharing. In other embodiments provided in the present application, the middleware 101 can also be connected to more or fewer business systems, and the present application does not make any limitations here.

[0067] Please continue to refer to Figure 2 , Figure 2 FIG. shows the implementation flowchart of a network service monitoring method based on SQL query in an embodiment of the present application. For the sake of convenience of description, only the parts related to the present application are shown. The network service monitoring method based on SQL query includes:

[0068] S201, capturing the network traffic on at least one business system.

[0069] Specifically, the traffic capture component of the bypass monitoring system captures the network traffic on at least one business system, where the network traffic on the at least one business system is the network traffic transmitted on the middleware. It should be noted that the bypass monitoring system is independent of the business system. By setting up the bypass monitoring system to monitor the network traffic on at least one business system, the monitoring of different business systems is realized, and the portability of the network service monitoring system is improved.

[0070] In the embodiments of the present application, the network traffic refers to the amount of data transmitted in the network, that is, the data stream generated when a user accesses or downloads data. The network traffic includes data traffic in HTTP message format, TCP message format, UDP message format, FTP format, NFS format, etc., which are data traffic of message types based on transmission protocols, as well as all non-protocol type data traffic. Among them, SQL statements belong to one of the non-protocol type data traffic.

[0071] S202, Parse the network traffic to obtain the SQL statements in the network traffic.

[0072] Specifically, the monitoring center of the bypass monitoring system parses the captured network traffic to obtain the SQL statements in the network traffic.

[0073] In the embodiment of the present application, the captured network traffic is parsed by a traffic parsing tool. Optionally, the traffic parsing tool in the present application can be based on a Lua data parsing script. A Tshark command for parsing network traffic is set in the Lua data parsing script. After parsing the network traffic captured in step S101, a filter is used to filter the parsing result to obtain the SQL statements therein. Optionally, the filter can be an SQL statement filter, and other format information is filtered through the SQL statement filter to obtain the SQL statements in the parsing result.

[0074] In the embodiment of the present application, setting a filter can effectively filter out information other than SQL statements, reduce the operating pressure of the bypass monitoring system, and at the same time help improve the maintenance efficiency of operation and maintenance technicians.

[0075] S203, Perform SQL operations on the target database according to the SQL statements to obtain first SQL operation information, where the target database is the database of at least one business system.

[0076] Specifically, the monitoring center of the bypass monitoring system performs SQL operations on the target database according to the SQL statements obtained in step S202 to obtain first SQL operation information.

[0077] It should be noted that during the network service monitoring process of the present application, the monitoring center of the bypass monitoring system performs SQL operations on the target database to obtain first SQL operation information. Therefore, it is not necessary for the business system to perform SQL operations again to judge the abnormal situation of the network service, thus saving the operating resources of the business system and reducing the pressure on the business system.

[0078] Moreover, since the bypass monitoring system is independent of the business system, setting up a bypass monitoring system can monitor the network services of different business systems and improve the portability of the network service monitoring system.

[0079] S204, Obtain the log file of the target database, and query the second SQL operation information corresponding to the SQL statements in the log file of the target database, where the second SQL operation information is the information generated by the business system when performing SQL statement operations;

[0080] Specifically, the monitoring center of the bypass monitoring system obtains the log file of the target database through the middleware, and queries the second SQL operation information corresponding to the SQL statement in the log file of the target database, where the target database is the database of at least one business system.

[0081] It should be noted that the second SQL operation information is the information generated by the business system when performing the SQL statement operation.

[0082] S205. Compare the first SQL operation information with the second SQL operation information, and determine whether the network service is abnormal according to the comparison result.

[0083] Specifically, comparing the first SQL operation information with the second SQL operation information means comparing the first SQL operation information obtained by the monitoring center performing the SQL operation on the target database according to the SQL statement with the second SQL operation information generated by the business system when performing the SQL statement operation, and determining whether the network service is abnormal according to the comparison result.

[0084] In an embodiment of the present application, comparing the first SQL operation information with the second SQL operation information specifically means comparing the first table name in the first SQL operation information with the second table name in the second SQL operation information, and comparing the first SQL field in the first SQL operation information with the second SQL field in the second SQL operation information.

[0085] S206. If the comparison result is not a null value and the comparison results are the same, determine that the network service is a normal service; otherwise, determine that the network service is an abnormal service.

[0086] Specifically, if the comparison result is not a null value and the comparison results are the same, it proves that the first SQL operation information obtained by the monitoring center performing the SQL operation on the target database according to the SQL statement in step S203 is the same as the second SQL operation information corresponding to the queried SQL statement, indicating that the network service has not appeared abnormal during the operation, that is, the network service is a normal service; if a null value appears in the comparison result, it means that data loss has occurred during the operation of the network service, that is, the network service is an abnormal service; if the comparison results are different, it means that data abnormality has occurred during the operation of the network service, that is, the network service is an abnormal service.

[0087] The present application discloses a network service monitoring method based on SQL query. Compared with the prior art, the network service monitoring method based on SQL query disclosed in the present application does not require the business system to perform SQL statement operations again to judge the abnormal conditions of network services. Only by comparing the first SQL operation information obtained by the bypass monitoring system performing SQL operations on the target database according to the SQL statement and the second SQL operation information obtained by querying the log file of the target database, the abnormal conditions of network services can be judged, realizing the automatic monitoring of network services of different business systems, improving the portability of the network service monitoring system, facilitating the system operators of enterprises to quickly find abnormal network services, and greatly improving the efficiency and accuracy of troubleshooting abnormal data of network services with large data volumes.

[0088] Please continue to refer to Figure 3 , Figure 3 is Figure 2 a flowchart of a specific implementation manner of step S202 in

[0089] As some optional implementation manners of this embodiment, after parsing the network traffic in step S202 to obtain the SQL statement in the network traffic, it further includes: step S301 and step S302.

[0090] S301, obtaining the TCP network traffic packets in the network traffic;

[0091] S302, parsing the TCP network traffic packets to obtain TCP packet information, where the TCP packet information includes the IP address of the target database, the port number of the target database, the IP address of the local port, the port number of the local port, and the first time information, and the first time information is the capture time of the TCP packet.

[0092] In a specific embodiment provided by the present application, after parsing the network traffic in step S202 to obtain the parsing result, it further includes: using the TCP Dump component to capture the data with the protocol format of TCP in the parsing result, filtering out the data with other formats, and then summarizing the data with the TCP format to obtain the TCP network traffic packets. Among them, the Dump component can capture in real time according to the protocol type of the network traffic, such as the TCP Dump component. It should be additionally noted that while the TCPDump component captures the TCP format data, the monitoring center records the time of capturing the TCP format data, that is, each TCP packet has a corresponding capture time, and this time is the first time information.

[0093] In a specific embodiment provided by the present application, parsing the TCP network traffic packet to obtain the TCP packet information specifically means setting a Tshark command for parsing the TCP network traffic packet in the Lua data parsing script to obtain the TCP packet information.

[0094] Please continue to refer to Figure 4 , Figure 4 is Figure 2 a flowchart of a specific implementation manner of step S203 in

[0095] As some optional implementation manners of this embodiment, before performing SQL operations on the target database according to the SQL statement in step S203 to obtain the first SQL operation information, it further includes: step S401, step S402, step S403, and step S404.

[0096] S401, obtain the second time information, where the second time information is the capture time of the SQL statement;

[0097] S402, determine whether the first time information and the second time information are consistent;

[0098] S403, if the first time information and the second time information are consistent, then combine the TCP packet information and the SQL statement to form a request instruction;

[0099] S404, according to the request instruction, request to perform SQL operations on the target database.

[0100] In the embodiment provided by the present application, before the monitoring center performs SQL operations on the target database according to the SQL statement, it further includes obtaining the capture time of the SQL statement, that is, the second time information; determining whether the first time information and the second time information are consistent, that is, determining whether the capture time of the TCP packet is consistent with the capture time of the SQL statement; if the first time information and the second time information are consistent, that is, the TCP packet information corresponds to the SQL statement, then the monitoring center combines the TCP packet information and the SQL statement to form a complete request instruction, and according to this request instruction, requests to perform SQL operations on the target database; if the first time information and the second time information are inconsistent, the monitoring center is not allowed to combine the TCP packet information and the SQL statement. It should be additionally noted that while parsing the network traffic to obtain the SQL statement in the network traffic, the monitoring center records the time when the SQL statement is captured, that is, each SQL statement has a corresponding capture time, and this time is the second time information.

[0101] Please continue to refer to Figure 5 , Figure 5 is Figure 4Flowchart of a specific implementation manner of step S404. For the sake of illustration, only parts related to this application are shown.

[0102] As some alternative implementation manners of this embodiment, before requesting an SQL operation on the target database according to the request instruction in step S404, it further includes: step S501, step S502, and step S503.

[0103] S501, receive the authentication instruction of the target database;

[0104] S502, perform an authentication operation on the IP address of the target database, the port number of the target database, the IP address of the local port, and the port number of the local port;

[0105] S503, if the authentication is passed, perform an SQL operation on the target database according to the request instruction.

[0106] In the embodiment of this application, after the monitoring center combines the TCP packet information and the SQL statement to form a request instruction, it further includes that the monitoring center sends the request instruction to the target database to request an SQL operation on the target database; after receiving the request instruction, the target database sends an authentication instruction to the monitoring center, requiring the monitoring center to authenticate the IP address of the target database, the port number of the target database, the IP address of the local port, and the port number of the local port; only when the above authentication is passed can an SQL operation be performed on the target database; if the above authentication fails, that is, the information of the target database does not match the TCP packet information, the monitoring center cannot perform an SQL operation on the target database, and the accuracy and security of the information are further improved through the authentication operation.

[0107] In a specific embodiment provided by this application, in step S202, the network traffic is parsed to obtain the SQL statement in the network traffic as "select goods_name from goods_tb where goods_status = 1", and the time when this SQL statement is captured is 15:27:30 on August 12, 2019, that is, the second time information is 15:27:30 on August 12, 2019; in the TCP network traffic packet parsed in step S302 to obtain the TCP packet information, the IP address of the target database is 192.168.*.***, the port number of the target database is ****, the IP address of the local port is 192.168.*.***, the port number of the local port is 1069, and the TCP packet capture time is 15:27:30 on August 12, 2019, that is, the first time information is 15:27:30 on August 12, 2019.

[0108] When the first-time information is consistent with the second-time information, the monitoring center combines the TCP packet information and the SQL statement to form a request instruction to request an SQL operation on the target database. It should be noted that in a specific embodiment provided by the present application, the target database connection information is http: / / 192.168.*.***:**** / . After receiving the request instruction, the target database requests the monitoring center to perform authentication. The monitoring center authenticates the IP address 192.168.*.*** of the target database, the port number **** of the target database, the IP address 192.168.*.*** of the local port, and the port number 1069 of the local port respectively; after the above authentication passes, an SQL operation of select goods_name from goods_tb where goods_status = 1 is performed on the target database, that is, at 15:27:30 on August 12, 2019, the monitoring center performed an SQL operation on the target database with the IP address 192.168.*.*** and the port number ****, and the query condition was the name of the goods with the goods status of 1.

[0109] Please continue to refer to Figure 6 , Figure 6 Yes Figure 2 It is a flowchart of another specific implementation manner of step S202 in

[0110] As some optional implementation manners of this embodiment, after parsing the network traffic in step S202 to obtain the SQL statement in the network traffic, it further includes: step S601, step S602, and step S603.

[0111] S601, determine whether the SQL statement already exists in the cache;

[0112] S602, if the SQL statement does not exist in the cache, save the SQL statement to the cache and save the second-time information of the SQL statement at the same time;

[0113] S603, if the cache already contains the SQL statement, update the second-time information of the SQL statement.

[0114] Specifically, after parsing the network traffic in step S202 and obtaining the SQL statement in the network traffic, the following steps are further included: determining whether the SQL statement already exists in the cache. If the SQL statement does not exist in the cache, the SQL statement is saved to the cache, and at the same time, the second time information of the SQL statement is saved, that is, the capture time of the SQL statement is saved. If the SQL statement already exists in the cache, it is not necessary to save the SQL statement repeatedly, and only the second time information of the SQL statement needs to be updated, that is, the capture time of the SQL statement is updated. By determining whether the SQL statement already exists in the cache, new SQL statements can be saved, and at the same time, when receiving them, only the time information of the cached SQL statements is updated, which can effectively reduce the pressure on the cache.

[0115] It should be noted that the cache is used to store information generated when the monitoring center parses network traffic, such as SQL statements, capture times of SQL statements, TCP packet information, etc., for the monitoring center to call. In the embodiments provided in the present application, the cache may be a key-value type storage system such as redis.

[0116] Please continue to refer to Figure 7 , Figure 7 is Figure 2 a flowchart of a specific implementation manner of step S205 in

[0117] As some optional implementation manners of this embodiment, step S205 compares the first SQL operation information and the second SQL operation information, and determines whether the network service is abnormal according to the comparison result, which specifically includes: step S701, step S702, and step S703.

[0118] S701, respectively extract the table names and SQL fields in the first SQL operation information and the second SQL operation information. Among them, the first SQL operation information includes the first table name and the first SQL field, and the second SQL operation information includes the second table name and the second SQL field;

[0119] S702, respectively compare the first table name with the second table name, and the first SQL field with the second SQL field, to obtain a comparison result;

[0120] S703, according to the comparison result, determine whether the network service is abnormal.

[0121] Specifically, extract the first table name and the first SQL field from the first SQL operation information, and extract the second table name and the second SQL field from the second SQL operation information.

[0122] In a specific embodiment provided by the present application, comparing the first table name and the second table name, and the first SQL field and the second SQL field can be performed using a null algorithm. The specific comparison process is as follows:

[0123] if (null == a && null == b) {System.out.println(“The comparison result is a null value”)}

[0124] where a represents the first table name or the first SQL field in the first SQL operation information, and b represents the second table name or the second SQL field in the second SQL operation information. It should be noted that during the comparison process, if any one of the values of a or b does not exist, the output comparison result is a null value.

[0125] if (null != a && null != b && a.equals(b)) {System.out.println(“The comparison result is not a null value and is the same”)}

[0126] During the comparison process, if both a and b are not null values and the value of a is the same as the value of b, the output comparison result is not a null value and is the same, that is, the comparison result is not a null value and the comparison results are the same.

[0127] In some other specific embodiments provided by the present application, a ternary algorithm or other algorithms can also be used to compare the first table name and the second table name, and the first SQL field and the second SQL field. The present application does not make any limitations in this regard.

[0128] In the embodiment provided by the present application, according to the comparison result, determining the abnormal situation of the network service specifically includes: if the comparison result is not a null value and the comparison results are the same, it is determined that the network service is a normal service; if the comparison result is a null value or the comparison results are different, it is determined that the network service is an abnormal service. Through the above determination, automatic monitoring of the network service is realized.

[0129] Please continue to refer to Figure 8 , Figure 8 is Figure 2 a flowchart of a specific implementation manner of step S206 in

[0130] As some optional implementation manners of this embodiment, after determining that the network service is an abnormal service in step S206, it further includes:

[0131] S801, obtaining the SQL statement of the abnormal service and the abnormal prompt message generated after executing the SQL statement of the abnormal service;

[0132] S802, combining the SQL statement of the abnormal service and the abnormal prompt message to obtain service abnormal prompt information;

[0133] S803 outputs the service exception prompt message.

[0134] Specifically, after determining in step S206 that the network service is an abnormal service, obtain the SQL statement of the abnormal service and the abnormal prompt message generated after executing the SQL statement of the abnormal service, combine the SQL statement of the abnormal service and the abnormal prompt message to obtain the service exception prompt message, and output the service exception prompt message.

[0135] In a specific embodiment provided by the present application, the SQL statement of the abnormal network service is: "select * from tb_user where username={username} and password={pwd}", and the abnormal prompt message of "service function call failed" is obtained after executing the SQL statement of the abnormal network service. The monitoring center combines the SQL statement of the abnormal service and the abnormal prompt message to obtain the service exception prompt message "service function call failed select * from tb_user where username={username} and password={pwd}", and finally outputs the obtained service exception prompt message to the user interface for the user to view conveniently.

[0136] The present application discloses a network service monitoring method, device, equipment and storage medium based on SQL query, belonging to the field of computer technology. The monitoring method captures network traffic on at least one business system; parses the network traffic to obtain SQL statements in the network traffic; performs SQL operations on the target database according to the SQL statements to obtain first SQL operation information, where the target database is the database of at least one business system; obtains the log file of the target database, and queries the second SQL operation information corresponding to the SQL statements in the log file of the target database, where the second SQL operation information is the information generated when the business system performs SQL statement operations; compares the first SQL operation information and the second SQL operation information, and determines whether the network service is abnormal according to the comparison result; if the comparison result is not a null value and the comparison results are the same, it is determined that the network service is a normal service, otherwise it is determined that the network service is an abnormal service. Compared with the prior art, the network service monitoring method based on SQL query disclosed in the present application does not require the business system to perform SQL statement operations again to judge the abnormal situation of the network service. Only by comparing the first SQL operation information obtained by performing SQL operations on the target database according to the SQL statements and the second SQL operation information obtained by querying the log file of the target database, the abnormal situation of the network service can be judged. Therefore, it is possible to automatically monitor the network services of different business systems, improve the portability of the monitoring system, and facilitate the system operators of enterprises to quickly find abnormal network services, greatly improving the efficiency and accuracy of troubleshooting abnormal data of network services with large amounts of data.

[0137] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through computer-readable instructions, and the computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).

[0138] It should be understood that although the steps in the flowchart of the accompanying drawings are shown sequentially according to the indication of the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless otherwise clearly stated in this document, there is no strict order restriction for the execution of these steps, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps. Embodiment Two

[0139] Further referring to Figure 9 , as an implementation of the method shown above Figure 2 , this application provides an embodiment of a network service monitoring device based on SQL query. This device embodiment corresponds to Figure 2 the method embodiment shown, and this device can be specifically applied to various electronic devices. The network service monitoring device based on SQL query includes:

[0140] A traffic capture module 901, configured to capture network traffic on at least one service system;

[0141] A traffic analysis module 902, configured to analyze the network traffic to obtain SQL statements in the network traffic;

[0142] An SQL operation module 903, configured to perform SQL operations on a target database according to the SQL statements to obtain first SQL operation information, where the target database is a database of at least one service system;

[0143] An SQL query module 904, configured to obtain a log file of the target database and query second SQL operation information corresponding to the SQL statements in the log file of the target database, where the second SQL operation information is information generated when the service system performs SQL statement operations;

[0144] An exception judgment module 905, configured to compare the first SQL operation information with the second SQL operation information and judge whether the network service is abnormal according to the comparison result;

[0145] A judgment result module 906, configured to determine that the network service is a normal service if the comparison result is not a null value and the comparison results are the same, otherwise determine that the network service is an abnormal service.

[0146] Furthermore, the network service monitoring device based on SQL query further includes:

[0147] The TCP information acquisition module 907 is used to acquire TCP network traffic packets in the network traffic.

[0148] The TCP information parsing module 908 is used to parse the TCP network traffic packets to obtain TCP message information, where the TCP message information includes the IP address of the target database, the port number of the target database, the IP address of the local port, the port number of the local port, and the first time information, and the first time information is the capture time of the TCP message.

[0149] Furthermore, the network service monitoring device based on SQL query further includes:

[0150] The SQL information acquisition module 909 is used to acquire the second time information, and the second time information is the capture time of the SQL statement.

[0151] The time information judgment module 910 is used to judge whether the first time information and the second time information are consistent.

[0152] The time information judgment result module 911 is used to combine the TCP message information and the SQL statement to form a request instruction if the first time information and the second time information are consistent.

[0153] The request operation module 912 is used to request an SQL operation on the target database according to the request instruction.

[0154] Furthermore, the network service monitoring device based on SQL query further includes:

[0155] The instruction authentication module 913 is used to receive the authentication instruction of the target database.

[0156] The authentication operation module 914 is used to perform an authentication operation on the IP address of the target database, the port number of the target database, the IP address of the local port, and the port number of the local port.

[0157] The authentication result module 915 is used to perform an SQL operation on the target database according to the request instruction if the authentication is passed.

[0158] Furthermore, the network service monitoring device based on SQL query further includes:

[0159] The cache judgment module 916 is used to judge whether the SQL statement already exists in the cache.

[0160] The cache judgment result module 917 is used to save the SQL statement to the cache and save the second time information of the SQL statement if the SQL statement does not exist in the cache.

[0161] An update module 918, configured to update the second time information of the SQL statement if the SQL statement is already included in the cache.

[0162] Further, the exception judgment module 905 specifically includes:

[0163] An operation information extraction unit 951, configured to extract the table names and SQL fields in the first SQL operation information and the second SQL operation information respectively, where the first SQL operation information includes a first table name and a first SQL field, and the second SQL operation information includes a second table name and a second SQL field;

[0164] A comparison unit 952, configured to compare the first table name with the second table name, and the first SQL field with the second SQL field respectively, to obtain a comparison result;

[0165] A judgment unit 953, configured to judge the exception situation of the network service according to the comparison result.

[0166] Further, the network service monitoring device based on SQL query further includes:

[0167] An exception information acquisition module 919, configured to acquire the SQL statement of the exception service and the exception prompt message generated after executing the SQL statement of the exception service;

[0168] An exception information combination module 920, configured to combine the SQL statement of the exception service and the exception prompt message to obtain a service exception prompt message;

[0169] An exception information output module 921, configured to output the service exception prompt message.

[0170] The present application discloses a network service monitoring device based on SQL query, including: a traffic capture module 901 for capturing network traffic on at least one service system; a traffic parsing module 902 for parsing the network traffic to obtain SQL statements in the network traffic; an SQL operation module 903 for performing SQL operations on a target database according to the SQL statements to obtain first SQL operation information, where the target database is the database of at least one service system; an SQL query module 904 for obtaining the log file of the target database and querying second SQL operation information corresponding to the SQL statements in the log file of the target database, where the second SQL operation information is the information generated when the service system performs SQL statement operations; an exception judgment module 905 for comparing the first SQL operation information and the second SQL operation information and judging whether the network service is abnormal according to the comparison result; a judgment result module 906 for determining that the network service is a normal service if the comparison result is not a null value and the comparison results are the same, otherwise, determining that the network service is an abnormal service. Compared with the prior art, the network service monitoring device based on SQL query disclosed in the present application does not require the service system to perform SQL statement operations again to judge the abnormal situation of the network service. Only by comparing the first SQL operation information obtained by performing SQL operations on the target database according to the SQL statements and the second SQL operation information obtained by querying the log file of the target database, the abnormal situation of the network service can be judged. Therefore, automatic monitoring of network services of different service systems can be realized, the portability of the monitoring system is improved, which is beneficial for the system operators of enterprises to quickly find abnormal network services, and greatly improves the efficiency and accuracy of troubleshooting abnormal data of network services with large amounts of data. Embodiment III

[0171] To solve the above technical problems, the embodiments of the present application also provide a computer device. For details, please refer to Figure 10 , Figure 10 which is the basic structural block diagram of the computer device in this embodiment.

[0172] The computer device 6 includes a memory 61, a processor 62, and a network interface 63 that are communicatively connected to each other via a system bus. It should be noted that only the computer device 6 with components 61-63 is shown in the figure, but it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. Among them, those skilled in the art of the present technology can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0173] The computer device can be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The computer device can interact with the user through a keyboard, a mouse, a remote control, a touchpad, a voice control device, etc.

[0174] The memory 61 includes at least one type of readable storage medium, and the readable storage medium includes flash memory, a hard disk, a multimedia card, a card-type memory (such as an SD or DX memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, an optical disk, etc. In some embodiments, the memory 61 can be an internal storage unit of the computer device 6, such as the hard disk or memory of the computer device 6. In other embodiments, the memory 61 can also be an external storage device of the computer device 6, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device 6. Of course, the memory 61 can also include both the internal storage unit and the external storage device of the computer device 6. In this embodiment, the memory 61 is generally used to store the operating system and various application software installed on the computer device 6, such as the program code of the network service monitoring method based on SQL queries. In addition, the memory 61 can also be used to temporarily store various data that have been output or will be output.

[0175] In some embodiments, the processor 62 may be a Central Processing Unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips. The processor 62 is generally used to control the overall operation of the computer device 6. In this embodiment, the processor 62 is used to run the program code stored in the memory 61 or process data, such as running the program code of the network service monitoring method based on SQL query.

[0176] The network interface 63 may include a wireless network interface or a wired network interface, which is generally used to establish a communication connection between the computer device 6 and other electronic devices.

[0177] The present application also provides another implementation manner, that is, to provide a computer-readable storage medium storing a program of the network service monitoring method based on SQL query, and the program of the network service monitoring method based on SQL query can be executed by at least one processor, so that the at least one processor executes the steps of the network service monitoring method based on SQL query as described above.

[0178] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation manner. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc) and includes several instructions for causing a terminal device (which may be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in the various embodiments of the present application.

[0179] Obviously, the above-described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The preferred embodiments of the present application are shown in the drawings, but do not limit the patent scope of the present application. The present application can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosure content of the present application more thorough and comprehensive. Although the present application has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions described in the foregoing specific embodiments, or perform equivalent replacements for some of the technical features. Any equivalent structure made by using the specification and drawings of the present application, directly or indirectly applied in other related technical fields, shall be similarly within the scope of patent protection of the present application.

Claims

1. A network service monitoring method based on SQL query, characterized in that Including: Capturing network traffic on at least one business system, wherein the network traffic on at least one business system is captured by a traffic capture component of a bypass monitoring system, and the network traffic on at least one business system is network traffic transmitted on middleware; Parsing the network traffic to obtain SQL statements in the network traffic; Obtaining TCP network traffic packets in the network traffic; Parsing the TCP network traffic packets to obtain TCP packet information, where the TCP packet information includes the IP address of the target database, the port number of the target database, the IP address of the local port, the port number of the local port, and first time information, and the first time information is the capture time of the TCP packet, and the target database is the database of at least one business system; Obtaining second time information, where the second time information is the capture time of the SQL statement; Judging whether the first time information and the second time information are consistent; If the first time information and the second time information are consistent, combining the TCP packet information and the SQL statement to form a request instruction; According to the request instruction, requesting the monitoring center of the bypass monitoring system to perform an SQL operation on the target database to obtain first SQL operation information, where the monitoring center of the bypass monitoring system performs an SQL operation on the target database according to the SQL statement in the request instruction; The monitoring center of the bypass monitoring system obtains the log file of the target database through middleware, and queries the second SQL operation information corresponding to the SQL statement in the log file of the target database, where the second SQL operation information is information generated when the business system performs the SQL statement operation; Judging whether the network service is abnormal by comparing the first SQL operation information and the second SQL operation information; If the first SQL operation information and the second SQL operation information are the same, determining that the network service is a normal service; if the first SQL operation information is a null value, or the second SQL operation information is a null value, or the first SQL operation information and the second SQL operation information are different, determining that the network service is an abnormal service.

2. The network service monitoring method based on SQL query according to claim 1, wherein, Before requesting to perform an SQL operation on the target database according to the request instruction, it further includes: Receiving an authentication instruction of the target database; Performing an authentication operation on the IP address of the target database, the port number of the target database, the IP address of the local port, and the port number of the local port; If the authentication is passed, performing an SQL operation on the target database according to the request instruction.

3. The network service monitoring method based on SQL query according to any one of claims 1 or 2, characterized in that, After parsing the network traffic to obtain SQL statements in the network traffic, it further includes: Judging whether the SQL statement already exists in the cache; If the SQL statement does not exist in the cache, saving the SQL statement to the cache and simultaneously saving the second time information of the SQL statement; If the SQL statement is already included in the cache, update the second time information of the SQL statement.

4. The network service monitoring method based on SQL query according to claim 1, wherein, The comparison of the first SQL operation information and the second SQL operation information and the determination of whether the network service is abnormal according to the comparison result specifically include: Respectively extract the table names and SQL fields in the first SQL operation information and the second SQL operation information. Among them, the first SQL operation information includes a first table name and a first SQL field, and the second SQL operation information includes a second table name and a second SQL field; Respectively compare the first table name with the second table name, and the first SQL field with the second SQL field to obtain a comparison result; Judge whether the network service is abnormal according to the comparison result.

5. The network service monitoring method based on SQL query according to claim 1, characterized in that, After determining that the network service is an abnormal service, it further includes: Obtain the SQL statement of the abnormal service and the error message generated after executing the SQL statement of the abnormal service; Combine the SQL statement of the abnormal service and the error message to obtain a service error message; Output the service error message.

6. A network service monitoring device based on SQL query, characterized in that, The network service monitoring device based on SQL query executes the steps of the network service monitoring method based on SQL query according to any one of claims 1 to 5. The network service monitoring device based on SQL query includes: A traffic capture module for capturing network traffic on at least one service system; A traffic analysis module for analyzing the network traffic to obtain the SQL statement in the network traffic; An SQL operation module for performing SQL operations on the target database according to the SQL statement to obtain first SQL operation information, where the target database is the database of the at least one service system; An SQL query module for obtaining the log file of the target database and querying the second SQL operation information corresponding to the SQL statement in the log file of the target database, where the second SQL operation information is the information generated when the service system performs the SQL statement operation; An abnormality judgment module for comparing the first SQL operation information and the second SQL operation information and judging whether the network service is abnormal according to the comparison result; A judgment result module for determining that the network service is a normal service if the comparison results are the same, and determining that the network service is an abnormal service if the comparison result is a null value or the comparison results are different.

7. A computer device, characterized in that, It includes a memory and a processor. Computer-readable instructions are stored in the memory, and when the processor executes the computer-readable instructions, the steps of the network service monitoring method based on SQL query according to any one of claims 1 to 5 are implemented.

8. A computer-readable storage medium, characterized in that, Computer-readable instructions are stored on the computer-readable storage medium, and when the computer-readable instructions are executed by the processor, the steps of the network service monitoring method based on SQL query according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Method and device for structured query language (SQL) performance statistics

    CN108182215A

  • Database management method and system, computer device and readable storage medium

    CN109933601A