A data processing method and related equipment
By monitoring the client input data, identifying and generating antibody information to intercept abnormal data, solving the impact of client abnormalities, improving user experience, and reducing waiting time.
Patent Information
- Application Number
- CN202010533467.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-06-11
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2040-06-11
AI Technical Summary
The client experience is damaged in abnormal situations, and the existing solutions require a long time to fix and may cause overall functionality to be unavailable, affecting the user experience.
By monitoring the client input data, identify abnormal data as antigen, generate antibody information and perform policy configuration, intercept abnormal data in real time to avoid repeated effects.
Improve user experience, avoid abnormal data from continuously affecting the client, reduce waiting time, and ensure the normal operation of core functions.
Smart Images

Figure CN111694614B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and in particular to a data processing method and related equipment. Background Art
[0002] Occasionally, client exceptions may occur during user use, such as freezing or crashing. When a client freezes or crashes, the error data reporting module collects and uploads the information. For example, when the Windows version of the QQ client crashes, a bugreport program collects contextual information about the client crash (including dump files) and submits it to the server for subsequent diagnostic analysis by technical personnel.
[0003] If a client experiences an anomaly, the next time you start it, you'll be prompted to "Start XXX in safe mode." This mode only starts core modules, preventing the loading of potentially unstable add-ins and extensions. Microsoft Office software, such as Outlook, supports this safe mode. More intelligent versions can identify the add-in causing the client anomaly and block the loading of the problematic add-in the next time the client is started.
[0004] After the technical staff understands and resolves the abnormal problem of the online client, they will release a new version or patch to the user side to avoid the abnormal problem caused by the same reason in the future.
[0005] The above solutions to client-side anomalies can be combined and used together, but waiting for the client-side issue to be truly fixed often takes a long time. During this period, even using "safe mode" will significantly reduce the user experience. Blocking problematic plug-ins can also render the entire plug-in function inoperable. For example, blocking the file transfer plug-in will completely disable the file transfer function, and you may not even be able to detect the other party sending files. Summary of the Invention
[0006] This application provides a data processing method and related equipment, which can prevent the same illegal data from having a continuous impact on the client, thereby improving the user experience.
[0007] The first aspect of the present application provides a data processing method, comprising:
[0008] Monitor the target input data corresponding to the target client;
[0009] When target antigen data matching the target input data is stored in a database, target antibody information corresponding to the target antigen data is obtained, wherein the database stores a plurality of antigen data including the target antigen data and a plurality of antibody information including the target antibody information, wherein the target antigen data is the input data causing the target client abnormality, and the target antibody information includes the source, protocol number, data content, and policy configuration of the target input data;
[0010] Execute corresponding operations based on the policy configuration of the target antibody information.
[0011] Optionally, the method further includes:
[0012] When the target client is abnormal and the database does not store target antigen data matching the target input data, marking the target input data as target suspected antigen data;
[0013] generating target antibody data information corresponding to the target suspected antigen data, wherein the target antibody data information includes the target input data and abnormal information of the target client;
[0014] Determining whether a target statistical number corresponding to the target antibody data information is stored in the database;
[0015] If so, updating the target statistics;
[0016] When the updated target statistics match a preset threshold, marking the target input data as first antigen data;
[0017] generating first antibody information corresponding to the first antigen data;
[0018] Execute corresponding operations based on the policy configuration of the first antibody information.
[0019] Optionally, the method further includes:
[0020] When the target statistical number is not stored in the database, the target statistical number is recorded and the target statistical number is set.
[0021] Optionally, the method further includes:
[0022] The first antigen data and the first antibody information are associated and stored in the database.
[0023] Optionally, the method further includes:
[0024] Obtaining M identical second antibody data information, where the M identical second antibody data information corresponds to M clients, where M is a positive integer greater than or equal to 2;
[0025] Generating second antibody information corresponding to the M identical second antibody data information;
[0026] The M identical second antibody data information and the second antibody information are reported, so that the server generates a corresponding target strategy according to the M identical second antibody data information and the second antibody information, and broadcasts the target strategy.
[0027] A second aspect of the present application provides a data processing device, comprising:
[0028] A first acquisition unit is used to monitor target input data corresponding to a target client;
[0029] a second acquiring unit, configured to acquire target antibody information corresponding to the target antigen data when target antigen data matching the target input data is stored in a database, wherein the database stores a plurality of antigen data including the target antigen data and a plurality of antibody information including the target antibody information, the target antigen data being the input data causing the target client abnormality, and the target antibody information including the source, protocol number, data content, and policy configuration of the target input data;
[0030] The first processing unit is configured to execute corresponding operations based on the policy configuration of the target antibody information.
[0031] Optionally, the device further comprises:
[0032] A second processing unit, wherein the second processing unit is configured to:
[0033] When the target client is abnormal and the database does not store target antigen data matching the target input data, marking the target input data as target suspected antigen data;
[0034] generating target antibody data information corresponding to the target suspected antigen data, wherein the target antibody data information includes the target input data and abnormal information of the target client;
[0035] Determining whether a target statistical number corresponding to the target antibody data information is stored in the database;
[0036] If so, updating the target statistics;
[0037] When the updated target statistics match a preset threshold, marking the target input data as first antigen data;
[0038] generating first antibody information corresponding to the first antigen data;
[0039] Execute corresponding operations based on the policy configuration of the first antibody information.
[0040] Optionally, the second processing unit is further configured to:
[0041] When the target statistical number is not stored in the database, the target statistical number is recorded and the target statistical number is set.
[0042] Optionally, the second processing unit is further configured to:
[0043] The first antigen data and the first antibody information are associated and stored in the database.
[0044] Optionally, the second processing unit is further configured to:
[0045] Obtaining M identical second antibody data information, where the M identical second antibody data information corresponds to M clients, where M is a positive integer greater than or equal to 2;
[0046] Generating second antibody information corresponding to the M identical second antibody data information;
[0047] The M identical second antibody data information and the second antibody information are reported, so that the server generates a corresponding target strategy according to the M identical second antibody data information and the second antibody information, and broadcasts the target strategy.
[0048] A third aspect of the present application provides a computer device comprising at least one connected processor, memory and transceiver, wherein the memory is used to store program code, and the program code is loaded and executed by the processor to implement the steps of the data processing method described above.
[0049] A fourth aspect of the present application provides a computer-readable storage medium comprising instructions, which, when executed on a computer, enables the computer to execute the steps of the above-mentioned data processing method.
[0050] In summary, it can be seen that in the embodiment provided by the present application, the data processing device monitors the external input data of the target client in real time, and queries the data stored in the database based on the input data of the client, determines the abnormal problem of the client, and performs corresponding operations based on the antibody information corresponding to the abnormal problem stored in the database, thereby avoiding the same illegal data from causing continuous impact on the client, thereby improving the user experience BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 A flowchart of a data processing method provided in an embodiment of the present application;
[0052] Figure 2 A schematic diagram of an application scenario of the data processing method provided in an embodiment of the present application;
[0053] Figure 3 A schematic diagram of a virtual structure of a data processing device provided in an embodiment of the present application;
[0054] Figure 4 A schematic diagram of the hardware structure of a terminal device provided in an embodiment of the present application;
[0055] Figure 5 A schematic diagram of the hardware structure of the server provided in an embodiment of the present application. DETAILED DESCRIPTION
[0056] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments.
[0057] The terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable under appropriate circumstances so that the embodiments described herein can be implemented in a sequence other than the content illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or modules is not necessarily limited to those steps or modules clearly listed, but may include other steps or modules that are not clearly listed or inherent to these processes, methods, products or devices. The division of modules that appears in this application is only a logical division. In actual application, there can be other division methods when implemented. For example, multiple modules can be combined into or integrated into another system, or some feature vectors can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between each other shown or discussed can be through some interfaces, and the indirect coupling or communication connection between modules can be electrical or other similar forms, which are not limited in this application. Moreover, the modules or sub-modules described as separate components may or may not be physically separated, may or may not be physical modules, or may be distributed into multiple circuit modules, and some or all of the modules may be selected according to actual needs to achieve the purpose of the present application.
[0058] The client will inevitably crash or freeze during actual use due to insufficiently strict handling of exception logic. Both of these problems are very serious for users, interrupting the normal client usage process and greatly affecting the user experience.
[0059] The data processing method provided by the present application identifies abnormal problems of the client caused by specific illegal input data of the client, and performs intelligent interception processing in the same subsequent scenario. This ensures that the same illegal data will not repeatedly cause abnormalities to the client. For example, an "illegal" server reply packet data is actually just an overlong data packet, which causes the client to trigger an inaccurate processing logic and crash. The client will pull and update the data every time it logs in, and it will crash every time it logs in. After using this application, after the client crashes due to this problem, the antigen information can be identified and antibody data can be generated. When the client logs in later, the antibody can be used to intercept and process the reply packet data, with a relatively small impact (core functions and normal scenario data are often rigorously tested and verified before release, and scenarios where illegal data causes abnormalities are relatively rare), avoiding the serious impact of the client being completely unavailable.
[0060] The data processing method provided in the embodiment of the present application is described below from the perspective of a data processing device. The data processing device can be a terminal device, a server, or a service unit in a server, without specific limitation. The server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The terminal can be a smart phone, tablet computer, laptop computer, desktop computer, smart speaker, smart watch, etc., but is not limited to this. The terminal and the server can be directly or indirectly connected via wired or wireless communication, and this application does not limit this. The terminal device can be any terminal device such as a mobile phone, tablet computer, PDA (Personal Digital Assistant), POS (Point of Sales) and car computer.
[0061] The following is an explanation of the database and database management system:
[0062] A database, in short, can be thought of as a digital filing cabinet—a place where electronic files are stored, allowing users to add, query, update, and delete data. A database is a collection of data stored in a specific way, shared by multiple users, with minimal redundancy, and independent of applications.
[0063] A database management system (DBMS) is a computer software system designed for managing databases, typically providing basic functions such as storage, retrieval, security, and backup. DBMSs can be categorized by the database model they support, such as relational or Extensible Markup Language (XML); by the type of computer they support, such as server clusters or mobile phones; by the query language they use, such as Structured Query Language (SQL) or XQuery; by performance priorities, such as maximum scale or maximum speed; or by other classification methods. Regardless of the classification method used, some DBMSs are cross-category, for example, supporting multiple query languages simultaneously.
[0064] See also Figure 1 , Figure 1 A flow chart of a data processing method provided in an embodiment of the present application includes:
[0065] 101. Monitor target input data corresponding to the target client.
[0066] In this embodiment, the data processing device can monitor the target input data corresponding to the target client. In other words, the data processing device can monitor and record the external input data of the target client in real time. The recorded content includes the data source, data description information (such as protocol number and file name), and data content.
[0067] It should be noted that the target input data sources corresponding to the target client include but are not limited to the following:
[0068] 1. Network protocol data; 2. Disk file data; 3. Cross-process communication data; 4. Environment numbers, registry and environment variables, etc.; 4. User input data.
[0069] 102. When target antigen data matching the input data is stored in the database, target antibody information corresponding to the target antigen data is obtained.
[0070] In this embodiment, when the data processing device obtains the target input data corresponding to the target client, it can query the database based on the target input data to determine whether the database stores target antigen data that matches the target input data, wherein the database stores multiple antigen data including target antigen data and multiple antibody information including target antibody information. The target antigen data is the input data that causes the target client to be abnormal, and the target antibody information includes the source, protocol number, data content and policy configuration of the target input data. Antigen refers to abnormal input data that will cause the application to crash or get stuck, and the input data has unique features that can be identified. Antibody refers to the configuration information of the identification and immunization strategy for specific abnormal input data, which is specifically manifested in a set of data that records the source, protocol number, data content and policy configuration of the abnormal data.
[0071] It should be noted that, here, when the data processing device matches the target input data with the antigen data in the database, the matching algorithm used is not specifically limited, and can be an exact match or a fuzzy match according to the actual situation. Further, the data field in the antigen information can be recorded in the form of an expression (the expression, for example, can be a regular expression, of course, it can also be other ways, such as a custom expression grammar) to make more targeted data matching. For example, if the val field in the data is greater than 100, the antigen expression method in the form of an expression can be used by technicians to make a more accurate description of the antigen information to avoid excessive immune response, that is, intercepting normal data. Among them, the immune response refers to the process of processing the antigen (abnormal input data) to avoid the antigen causing program abnormality, including the process of searching for matching antibodies to process the antigen (avoiding program abnormality); in addition, in the absence of antibodies, the antigen characteristics are recorded after the antigen causes an abnormality, thereby generating antibody information so that an immune response is performed when the corresponding antigen is encountered later.
[0072] 103. Execute corresponding operations based on the strategy configuration of the target antibody information.
[0073] In this embodiment, after the data processing device obtains target antibody information by querying the database, it can perform corresponding operations based on the policy configuration of the target antibody information. For example, the policy configuration of the target antibody information packet can be configured to directly discard or log the antigen data when encountering it, or prompt the user for operation, etc. Thus, the data processing device can perform corresponding operations based on the policy configuration, and when encountering the antigen data, perform a direct discard operation. It is understood that the policy configuration of the target antibody information can be preset or determined by technicians after analyzing the results of the antibody reporting.
[0074] In one embodiment, when the target client is abnormal, and the database does not store target antigen data that matches the target input data, and the target client is abnormal, the target input data is marked as target suspected antigen data;
[0075] Generate target antibody data information corresponding to the target suspected antigen data, the target antibody data information including target input data and abnormal information of the target client;
[0076] Determine whether the target statistical number corresponding to the target antibody data information is stored in the database;
[0077] If so, update the target statistics;
[0078] When the updated target statistics match a preset threshold, marking the target input data as first antigen data;
[0079] generating first antibody information corresponding to the first antigen data;
[0080] Execute corresponding operations based on the policy configuration of the primary antibody information.
[0081] In this embodiment, when the data processing device determines that the target client is abnormal and there is no target antigen data matching the target input data in the database, the target input data is marked as target suspected antigen data, and corresponding target antibody data information is generated. The target antibody data information includes the antigen data (that is, the target input data) and the abnormality type of the target client, etc. The judgment here is "suspected antigen" because the target client's most recent target input data may not be the direct cause of the target client's abnormality. Subsequently, it is determined whether the database stores a target statistic corresponding to the target antibody data information. In other words, whether there is a record of the target antibody data information in the database. If so, the target statistic corresponding to the target antibody data information is updated, and it is determined whether the target statistic matches a preset threshold. For example, the preset threshold is 3, and the target statistic is 3 (in addition to the current target antibody data information, there are two target antibody data information in the database, that is, there are two cases where the same input data causes the same abnormality to the target client). The target input data can be marked as first antigen data, and first antibody information corresponding to the first antigen data is generated. The corresponding operation is performed based on the policy configuration of the first antibody information. When the updated target statistic does not match the preset threshold, no operation is performed, indicating that there is still no way to confirm whether the target input data is the direct cause of the target client's abnormality. It is understandable that the antigen information and antibody information need to be stored persistently, for example, in a database file, so that they can continue to be used after the subsequent client logs in. Specifically, the first antigen data and the first antibody information can be associated and stored in the database. When the antigen information and antibody information are actually stored in the database, only one copy of the same part of the antigen information and the antibody information needs to be stored, and the antibody information can directly reference the same part of the antigen information.
[0082] It should be noted that when the data processing device determines that there is no target antigen data matching the target input data in the database, it is not certain whether the target input data is the direct cause of the target client abnormality. Therefore, further confirmation is required. Since each time there is suspected antigen data in the target client, corresponding antibody data information will be generated and the statistical number will be recorded. At this time, it can be determined by the preset threshold N set in advance. For example, after the same input data causes N (where N is a positive integer greater than or equal to 1) abnormalities of the same type, it is determined that there is a strong correlation between the input data and the client's abnormality, that is, it can be confirmed as antigen data.
[0083] In one embodiment, when the target statistics are not stored in the database, the target statistics are recorded and set.
[0084] In this embodiment, when the target statistical number is not stored in the database, the target statistical number is recorded and the target statistical number is set. That is, when the target antibody data information and the target statistical number corresponding to the target antibody data information are not stored in the database, it means that the target antibody data information has not appeared before. In this case, the target statistical number corresponding to the target antibody data information can be recorded in the database and the value of the target statistical number is set to 1. Of course, the target statistical number can also be of other types, for example, the first occurrence is set to A1, the second occurrence is set to A2, the third occurrence is set to A3, and so on. There is no specific limitation. Accordingly, the preset threshold value also needs to be set according to the type of the target statistical number.
[0085] In one embodiment, the data processing device further performs the following operations:
[0086] Obtain M identical second antibody data information, where the M identical second antibody data information corresponds to M clients, where M is a positive integer greater than or equal to 2;
[0087] Generate second antibody information corresponding to M identical second antibody data information;
[0088] M identical second antibody data information and second antibody information are reported, so that the server generates a corresponding target strategy according to the M identical second antibody data information and second antibody information, and performs corresponding operations based on the target strategy.
[0089] In this embodiment, when the data processing device obtains at least two identical antibody data information, that is, the same input data causes the same type of exception on different clients, it means that this is a common exception problem. A certain strategy can be used to broadcast the antigen / antibody information to more clients, so that other users can avoid exceptions caused by the same reason when using the client. Specifically, the data processing device can first generate corresponding second antibody information, and report M identical second antibody data information and second antibody information to the server. The server can generate a corresponding target strategy based on the M identical second antibody data information and second antibody information, and perform corresponding operations based on the target strategy, such as notifying other users based on the second antibody information, avoiding exceptions caused by the same reason when other users use the client, and improving user experience.
[0090] To sum up, it can be seen that in the embodiment provided by the present application, the data processing device monitors the external input data of the target client in real time, and queries the data stored in the database based on the input data of the client, determines the abnormal problem of the client, and performs corresponding operations based on the antibody information corresponding to the abnormal problem stored in the database, so as to avoid the same illegal data from causing continuous impact on the client, thereby improving the user experience.
[0091] The following combination Figure 2 Two specific application scenarios of the data processing method of this application are described:
[0092] Application Scenario 1: Assume that the following logic processing issue exists in the client that has been released online: When the value of the nType field in the protocol response data with command number 41 is greater than 3, the client will crash abnormally;
[0093] For any reply data, the input data management module 201 records the client's input data information, which includes the data source, command number, and data content, etc. Among them, the command number 41 data reply packet is as follows:
[0094]
[0095] The specific information of the recorded return packet data is as follows:
[0096]
[0097] The antigen recognition module 202 searches the antigen / antibody storage module 203 according to the above-recorded return packet data information (wherein the antigen / antibody storage module 203 stores multiple antigens and antibody information corresponding to the multiple antigens), but fails to match the corresponding antigen information. Therefore, the above data is intercepted and the client continues with the subsequent established data processing process.
[0098] The client crashed when processing the response data of command number 41.
[0099] After detecting the client crash, the abnormality monitoring module 204 reads the input data information just saved.
[0100] The antibody generation module 205 identifies the input data as a "suspected antigen" and records the "suspected antigen" statistic as 1. If the preset threshold N is set to 1, the input data is directly determined to be an antigen, and the corresponding antibody record information is automatically generated and stored in the antigen / antibody storage module 203. It is assumed here that the number of repetitions of the above steps meets the threshold N, the "suspected antigen" is confirmed to be an antigen, recorded as antigen 1, and antibody 1 is generated. By default, the content of the antibody 1 information is the same as the antigen 1 information, because the default strategy for applying antibodies is to intercept the data, output the log, and report the operation record. Of course, other antibody strategies can also be generated according to actual conditions, and are not specifically limited.
[0101] When the client logs in again, it receives the reply data of command number 41 again, and the data packet is the same as step 2. The antigen recognition module searches the antigen / antibody storage module 203 according to the above information and can retrieve the existing matching antigen 1.
[0102] The immune response processing module 206 discards the data according to the strategy of antibody 1 corresponding to antigen 1, writes the interception situation into the log, and performs an operation report.
[0103] Through the antigen / antibody management module 207, new antigen and antibody information sent by the technician through the server can be received, and the existing antigen / antibody information can also be updated, for example, the immune response strategy in the antibody information is adjusted to: set nType = 3. It can be seen from this that in the embodiment provided by the present application, the input data of the client is monitored through the antigen / antibody information stored in the database. When input data that matches the antigen data stored in the database is monitored, the antibody information corresponding to the antigen information is obtained, and the corresponding operation is performed based on the policy configuration of the antibody information, so as to avoid the same abnormal data from continuously causing abnormalities to the client and improve the user experience.
[0104] Application Scenario 2:
[0105] Assume that the following logic processing problem exists in the client that has been released online: when the user enters content containing the < symbol in the input box named "VerifyInfo" on the window named "AddBuddyWnd", clicking the Submit button will cause the client to freeze.
[0106] Through a process similar to that of application scenario 1, since the actual user input varies greatly, when the preset threshold N>1, there is a small probability that the "suspected antigen" can be matched again and confirmed. However, when the client technician learns of the abnormal situation in application scenario 2 through other means, the client's antigen / antibody management module 207 can issue the following antigen / antibody information:
[0107]
[0108]
[0109] The client will filter the < symbol entered by the user based on the above information, for example, <script>< / script> ” is replaced with “script / >” to avoid subsequent client freezes caused by the same reason and improve user experience.
[0110] The above describes the present application from the perspective of a data processing method, and the following describes the present application from the perspective of a data processing device.
[0111] See also Figure 3 , Figure 3 A virtual structural diagram of a data processing device provided in an embodiment of the present application includes:
[0112] The first acquisition unit 301 is used to monitor target input data corresponding to the target client;
[0113] A second acquiring unit 302 is configured to acquire target antibody information corresponding to the target antigen data when target antigen data matching the target input data is stored in a database, wherein the database stores a plurality of antigen data including the target antigen data and a plurality of antibody information including the target antibody information, wherein the target antigen data is input data that causes the target client to be abnormal, and the target antibody information includes a source, a protocol number, data content, and a policy configuration of the target input data;
[0114] The first processing unit 303 is configured to execute corresponding operations based on the policy configuration of the target antibody information.
[0115] Optionally, the device further comprises:
[0116] The second processing unit 304 is configured to:
[0117] When the target client is abnormal and the database does not store target antigen data matching the target input data, marking the target input data as target suspected antigen data;
[0118] generating target antibody data information corresponding to the target suspected antigen data, wherein the target antibody data information includes the target input data and abnormal information of the target client;
[0119] Determining whether a target statistical number corresponding to the target antibody data information is stored in the database;
[0120] If so, updating the target statistics;
[0121] When the updated target statistics match a preset threshold, marking the target input data as first antigen data;
[0122] generating first antibody information corresponding to the first antigen data;
[0123] Execute corresponding operations based on the policy configuration of the first antibody information.
[0124] Optionally, the second processing unit 304 is further configured to:
[0125] When the target statistical number is not stored in the database, the target statistical number is recorded and the target statistical number is set.
[0126] Optionally, the second processing unit 304 is further configured to:
[0127] The first antigen data and the first antibody information are associated and stored in the database.
[0128] Optionally, the second processing unit 304 is further configured to:
[0129] Obtaining M identical second antibody data information, where the M identical second antibody data information corresponds to M clients, where M is a positive integer greater than or equal to 2;
[0130] Generating second antibody information corresponding to the M identical second antibody data information;
[0131] The M identical second antibody data information and the second antibody information are reported, so that the server generates a corresponding target strategy according to the M identical second antibody data information and the second antibody information, and broadcasts the target strategy.
[0132] To sum up, it can be seen that in the embodiment provided by the present application, the data processing device monitors the external input data of the target client in real time, and queries the data stored in the database based on the input data of the client, determines the abnormal problem of the client, and performs corresponding operations based on the antibody information corresponding to the abnormal problem stored in the database, so as to avoid the same illegal data from causing continuous impact on the client, thereby improving the user experience.
[0133] The present application also provides another data processing device, such as Figure 4For ease of explanation, only the parts related to the embodiments of the present application are shown. For specific technical details not disclosed, please refer to the method part of the embodiments of the present application. The data processing device can be any terminal device including a mobile phone, a tablet computer, a PDA (Personal Digital Assistant), a POS (Point of Sales), and an in-vehicle computer. Taking the mobile phone as an example:
[0134] Figure 4 The block diagram shows a partial structure of a mobile phone related to the terminal provided in the embodiment of the present application. Figure 4 The mobile phone includes components such as a radio frequency (RF) circuit 410, a memory 420, an input unit 430, a display unit 440, a sensor 450, an audio circuit 460, a wireless fidelity (WiFi) module 470, a processor 480, and a power supply 490. Those skilled in the art will understand that Figure 4 The mobile phone structure shown in the figure does not constitute a limitation to the mobile phone, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0135] The following combination Figure 4 A detailed introduction to the various components of a mobile phone:
[0136] The RF circuit 410 can be used to receive and send signals during information transmission or calls. In particular, after receiving the downlink information from the base station, it is sent to the processor 480 for processing; in addition, the designed uplink data is sent to the base station. Generally, the RF circuit 410 includes but is not limited to an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier (LNA), a duplexer, etc. In addition, the RF circuit 410 can also communicate with the network and other devices through wireless communication. The above-mentioned wireless communication can use any communication standard or protocol, including but not limited to Global System of Mobile communication (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Long Term Evolution (LTE), email, Short Messaging Service (SMS), etc.
[0137] Memory 420 can be used to store software programs and modules. Processor 480 executes the various functional applications and data processing of the mobile phone by running the software programs and modules stored in memory 420. Memory 420 may mainly include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function (such as a sound playback function, an image playback function, etc.); the data storage area may store data created based on the use of the mobile phone (such as audio data, a phone book, etc.). In addition, memory 420 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0138] The input unit 430 can be used to receive input digital or character information, and to generate key signal input related to the user settings and function control of the mobile phone. Specifically, the input unit 430 may include a touch panel 431 and other input devices 432. The touch panel 431, also known as a touch screen, can collect user touch operations on or near it (such as operations performed by the user using any suitable object or accessory such as a finger, stylus, etc. on or near the touch panel 431) and drive the corresponding connection device according to a pre-set program. Optionally, the touch panel 431 may include two parts: a touch detection device and a touch controller. Among them, the touch detection device detects the user's touch direction, detects the signal caused by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device and converts it into touch point coordinates, which are then sent to the processor 480, and can receive commands sent by the processor 480 and execute them. In addition, the touch panel 431 can be implemented using various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch panel 431, the input unit 430 may further include other input devices 432. Specifically, the other input devices 432 may include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control keys, power keys, etc.), a trackball, a mouse, and a joystick.
[0139] The display unit 440 can be used to display information input by the user or information provided to the user and various menus of the mobile phone. The display unit 440 may include a display panel 441. Optionally, the display panel 441 may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc. Further, the touch panel 431 may cover the display panel 441. When the touch panel 431 detects a touch operation on or near it, it is transmitted to the processor 480 to determine the type of touch event. Subsequently, the processor 480 provides corresponding visual output on the display panel 441 according to the type of touch event. Although in Figure 4 In the embodiment, the touch panel 431 and the display panel 441 are used as two independent components to realize the input and output functions of the mobile phone, but in some embodiments, the touch panel 431 and the display panel 441 can be integrated to realize the input and output functions of the mobile phone.
[0140] The mobile phone may also include at least one sensor 450, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor, wherein the ambient light sensor may adjust the brightness of the display panel 441 according to the brightness of the ambient light, and the proximity sensor may turn off the display panel 441 and / or the backlight when the mobile phone is moved to the ear. As a type of motion sensor, the accelerometer sensor can detect the magnitude of acceleration in all directions (generally three axes), and can detect the magnitude and direction of gravity when stationary. It can be used for applications that identify the posture of the mobile phone (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc.; as for other sensors that the mobile phone can also be configured with, such as gyroscopes, barometers, hygrometers, thermometers, infrared sensors, etc., they will not be repeated here.
[0141] Audio circuit 460, speaker 461, and microphone 462 provide an audio interface between the user and the phone. Audio circuit 460 converts received audio data into electrical signals and transmits them to speaker 461, which then converts them into sound signals for output. Microphone 462, on the other hand, converts collected sound signals into electrical signals, which are then received by audio circuit 460 and converted into audio data. The audio data is then processed by processor 480 and transmitted to, for example, another phone via RF circuit 410, or stored in memory 420 for further processing.
[0142] WiFi is a short-range wireless transmission technology. The mobile phone can help users send and receive emails, browse the web and access streaming media through the WiFi module 470. It provides users with wireless broadband Internet access. Figure 4A WiFi module 470 is shown, but it is understandable that it is not an essential component of the mobile phone and can be omitted as needed without changing the essence of the invention.
[0143] Processor 480 is the control center of the mobile phone, connecting all parts of the mobile phone using various interfaces and circuits. It executes software programs and / or modules stored in memory 420 and accesses data stored in memory 420 to perform various functions and process data. Processor 480 may optionally include one or more processing units. Preferably, processor 480 integrates an application processor and a modem processor. The application processor primarily handles the operating system, user interface, and application programs, while the modem processor primarily handles wireless communications. It is understood that the modem processor may not be integrated into processor 480.
[0144] The mobile phone also includes a power supply 490 (such as a battery) for supplying power to various components. Preferably, the power supply can be logically connected to the processor 480 through a power management system, thereby managing charging, discharging, and power consumption management functions through the power management system.
[0145] Although not shown, the mobile phone may also include a camera, a Bluetooth module, etc., which will not be described in detail here.
[0146] In the embodiment of the present application, the processor 480 included in the terminal is further configured to execute the operations performed by the aforementioned data processing device.
[0147] Figure 5 : This is a schematic diagram of a server structure provided in an embodiment of the present application. The server 500 may have relatively large differences due to different configurations or performances, and may include one or more central processing units (CPUs) 522 (for example, one or more processors) and a memory 632, and one or more storage media 530 (for example, one or more mass storage devices) for storing application programs 542 or data 544. Among them, the memory 532 and the storage medium 530 can be temporary storage or permanent storage. The program stored in the storage medium 530 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the server. Furthermore, the central processing unit 522 can be configured to communicate with the storage medium 530 to execute a series of instruction operations in the storage medium 530 on the server 500.
[0148] The server 500 may also include one or more power supplies 526, one or more wired or wireless network interfaces 550, one or more input and output interfaces 558, and / or one or more operating systems 541, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.
[0149] The steps performed by the data processing device in the above embodiment can be based on the Figure 5 The server structure shown.
[0150] An embodiment of the present application further provides a computer-readable storage medium on which a program is stored, and when the program is executed by a processor, the steps of the above-mentioned data processing method are implemented.
[0151] An embodiment of the present application further provides a processor, which is used to run a program, wherein the program executes the steps of the above-mentioned data processing method when it is run.
[0152] An embodiment of the present application also provides a terminal device, which includes a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program code is loaded and executed by the processor to implement the steps of the above-mentioned data processing method.
[0153] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing the steps of the above-mentioned data processing method.
[0154] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0155] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and modules described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0156] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0157] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products of the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0158] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0159] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0160] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0161] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0162] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission medium that can be used to store information that can be accessed by a computing device.
[0163] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0164] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0165] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
Claims
1. A data processing method, characterized in that: include: Monitor the target input data corresponding to the target client; When target antigen data matching the target input data is stored in a database, target antibody information corresponding to the target antigen data is obtained, wherein the database stores a plurality of antigen data including the target antigen data and a plurality of antibody information including the target antibody information, wherein the target antigen data is the input data causing the abnormality of the target client, and the target antibody information includes the source, protocol number, data content, and policy configuration of the target input data; the policy configuration of the target antibody information is to perform a direct discard operation when encountering the target antigen data; Performing a direct discard operation on the target input data based on the policy configuration of the target antibody information; The method further comprises: When the target client is abnormal and the database does not store target antigen data matching the target input data, marking the target input data as target suspected antigen data; generating target antibody data information corresponding to the target suspected antigen data, wherein the target antibody data information includes the target input data and abnormal information of the target client; If a target statistical number corresponding to the target antibody data information is stored in the database, updating the target statistical number; When the updated target statistics match a preset threshold, marking the target input data as first antigen data; First antibody information corresponding to the first antigen data is generated, and the first antigen data and the first antibody information are associated and stored in the database.
2. The method according to claim 1, characterized in that The method further comprises: When the target statistical number is not stored in the database, the target statistical number is recorded and the target statistical number is set.
3. The method according to claim 1, characterized in that After generating the first antibody information corresponding to the first antigen data, the method further includes: Execute corresponding operations based on the policy configuration of the first antibody information.
4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: Obtaining M identical second antibody data information, where the M identical second antibody data information corresponds to M clients, where M is a positive integer greater than or equal to 2; Generating second antibody information corresponding to the M identical second antibody data information; The M identical second antibody data information and the second antibody information are reported, so that the server generates a corresponding target strategy according to the M identical second antibody data information and the second antibody information, and broadcasts the target strategy.
5. A data processing device, characterized in that: include: A first acquisition unit is used to monitor target input data corresponding to a target client; a second acquiring unit, configured to acquire target antibody information corresponding to the target antigen data when target antigen data matching the target input data is stored in a database, wherein the database stores a plurality of antigen data including the target antigen data and a plurality of antibody information including the target antibody information, the target antigen data being the input data causing the target client abnormality, and the target antibody information including the source, protocol number, data content, and policy configuration of the target input data; The target antibody information strategy is configured to perform a direct discard operation when encountering the target antigen data; a first processing unit, configured to perform a direct discard operation on the target input data based on a policy configuration of the target antibody information; The device further comprises: a second processing unit, configured to, when the target client is abnormal and the database does not store target antigen data matching the target input data, mark the target input data as target suspected antigen data; generate target antibody data information corresponding to the target suspected antigen data, the target antibody data information including the target input data and abnormal information of the target client; if a target statistic corresponding to the target antibody data information is stored in the database, update the target statistic; and mark the target input data as first antigen data when the updated target statistic matches a preset threshold; The second processing unit is further configured to generate first antibody information corresponding to the first antigen data, and associate the first antigen data and the first antibody information and store them in the database.
6. The device according to claim 5, characterized in that The second processing unit is further configured to: When the target statistical number is not stored in the database, the target statistical number is recorded and the target statistical number is set.
7. The device according to claim 5, characterized in that The second processing unit is further configured to: After generating the first antibody information corresponding to the first antigen data, a corresponding operation is performed based on the policy configuration of the first antibody information.
8. The device according to any one of claims 5 to 7, characterized in that The second processing unit is further configured to: Obtaining M identical second antibody data information, where the M identical second antibody data information corresponds to M clients, where M is a positive integer greater than or equal to 2; Generating second antibody information corresponding to the M identical second antibody data information; The M identical second antibody data information and the second antibody information are reported, so that the server generates a corresponding target strategy according to the M identical second antibody data information and the second antibody information, and broadcasts the target strategy.
9. A terminal device, characterized in that: The method comprises a processor, a memory, and a program stored in the memory and running on the processor, wherein the program is loaded and executed by the processor to implement the steps of the data processing method according to any one of claims 1 to 4.
10. A computer-readable storage medium, characterized in that The method comprises instructions which, when executed on a computer, cause the computer to execute the steps of the data processing method according to any one of claims 1 to 4.
11. A computer program product, characterized in that The method comprises instructions which, when executed on a data processing device, implement the steps of the data processing method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Content extraction method, device and computer equipment
CN108304330A
Application crash processing method and device, computer device and storage medium
CN109901941A
Data processing method, system and device
CN110597649A
Equipment exception warning system, method and computer readable storage medium
CN110719181A