Analysis Method, Device and Storage Medium for Abnormal Data
Generate fingerprints and compare them through similar hashing algorithms, which solves the problem of low aggregation rate of crash stacks and achieves more efficient classification and processing of exception data.
Patent Information
- Application Number
- CN202010426953.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-05-19
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2040-05-19
AI Technical Summary
In the prior art, the aggregation rate of the crashed stack is low, resulting in problems that cannot be effectively classified, processing efficiency is low, and stack changes caused by new and old versions are incompatible, and maintenance costs are high.
The filtered abnormal data is calculated using a preset similar hashing algorithm, and the fingerprint is generated, and compared with the fingerprint library to judge similar fingerprints to realize the classification and aggregation of problems.
It improves the aggregation rate of the stack, is compatible with stack changes caused by new and old versions, and improves the accuracy and processing efficiency of problem classification.
Smart Images

Figure CN111752734B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and in particular, to a method, device, and storage medium for analyzing abnormal data. Background Art
[0002] At present, client applications may crash for certain reasons, and analyzing the crash stack has become one of the most effective ways to solve the crash problem. In order to reduce the types of crash problems and improve the efficiency of problem handling, it is often necessary to aggregate the stacks. Since the original crash stack contains a large number of interference items, generally, the original stack will be filtered before aggregation to filter out the part containing key information, and then the stacks with the same filtering results will be aggregated.
[0003] This rule of aggregating according to equality has great limitations. Because even for the same type of problem, if there is a string difference in the filtered content, aggregation will not be possible. Secondly, this rule cannot be compatible with the stack changes caused by new and old functions. Even for the same type of problem, if the stack changes due to new functions, the filtered stacks will be inconsistent.
[0004] Therefore, for two stacks to be successfully aggregated, the filtering must completely filter out all interference items. In this case, the filtering algorithm and the engine must be iterated simultaneously in version, and the maintenance cost is relatively high. And for the new functions that objectively change the original stack but are essentially the same type of crash problem, they can only be classified as new problems, resulting in a sharp increase in the number of new problem types, so that the problems cannot be well classified, and thus the efficiency of problem handling is low. Summary of the Invention
[0005] Embodiments of the present invention provide a method, device, and storage medium for analyzing abnormal data, which can effectively solve the problems of low stack aggregation rate in the prior art, inability to well classify problems, and thus low efficiency of problem handling.
[0006] An embodiment of the present invention provides a method for classifying abnormal data, including:
[0007] Obtain abnormal data and perform filtering processing on the abnormal data;
[0008] Calculate the filtered abnormal data according to a preset similarity hashing algorithm to obtain the fingerprint corresponding to the abnormal data;
[0009] Determine whether there is a similar fingerprint of the fingerprint in the fingerprint library;
[0010] In response to the determination result that there is a similar fingerprint of the fingerprint, classify the fingerprint into the problem category corresponding to the similar fingerprint;
[0011] In response to the judgment result that there is no similar fingerprint of the fingerprint, the fingerprint is marked as a new problem category.
[0012] As an improvement to the above solution, before obtaining the abnormal data and filtering the abnormal data, it further includes:
[0013] Obtain historical abnormal data and calculate the fingerprint of each historical abnormal data;
[0014] Generate a problem category corresponding to the fingerprint of each historical abnormal data and save it to the fingerprint database.
[0015] As an improvement to the above solution, after calculating the fingerprint of each historical abnormal data, before generating a problem category corresponding to the fingerprint of each historical abnormal data and saving it to the fingerprint database, it further includes:
[0016] Calculate the md5 value of the historical abnormal data;
[0017] Combine the fingerprint of the historical abnormal data and the md5 value and store them in a map structure.
[0018] As an improvement to the above solution, determining whether there is a similar fingerprint of the fingerprint in the fingerprint database specifically includes:
[0019] Determine whether there is a similar fingerprint in the fingerprint database whose Hamming distance from the fingerprint is less than a preset standard value.
[0020] Another embodiment of the present invention provides an abnormal data classification device, including:
[0021] A first acquisition module, configured to acquire abnormal data and filter the abnormal data;
[0022] A first calculation module, configured to calculate the abnormal data according to a preset similar hashing algorithm to obtain the fingerprint corresponding to the abnormal data;
[0023] A judgment module, configured to judge whether there is a similar fingerprint of the fingerprint in the fingerprint database;
[0024] A first response module, configured to, in response to the judgment result that there is a similar fingerprint of the fingerprint, classify the fingerprint into the problem category corresponding to the similar fingerprint;
[0025] A second response module, configured to, in response to the judgment result that there is no similar fingerprint of the fingerprint, mark the fingerprint as a new problem category.
[0026] Another embodiment of the present invention provides a storage medium. The computer-readable storage medium includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the method for classifying abnormal data described in the above-mentioned embodiment of the present invention.
[0027] The embodiment of the present invention provides a method, device and storage medium for classifying abnormal data. By calculating the filtered abnormal data using a preset similar hashing algorithm to obtain the fingerprint corresponding to the abnormal data, and then comparing the fingerprint with the fingerprints in the fingerprint library to find whether there are similar fingerprints. It can be seen that after adding similarity aggregation, the dependence on filtering processing during the aggregation process can be avoided, and the stack changes caused by new and old versions can be compatible, improving the aggregation rate of the stack, enabling problems to be well classified, and thus improving the efficiency of problem handling.
[0028] Another embodiment of the present invention provides an analysis method for abnormal data, including:
[0029] Obtaining the abnormal data in the fingerprint library and at least one preset client personality index;
[0030] Calculating the proportion of abnormal data according to the abnormal data;
[0031] Calculating the corresponding index scores for at least one preset client personality index according to a preset index score algorithm;
[0032] Analyzing the current game quality according to the index scores in combination with the proportion of abnormal data.
[0033] As an improvement to the above solution, the calculating the proportion of abnormal data according to the abnormal data specifically includes:
[0034] Determining the corresponding client model according to each piece of abnormal data and classifying the client models;
[0035] Obtaining the number of active users corresponding to the client model;
[0036] Calculating the total abnormal proportion and the abnormal proportion of each client model according to the number of abnormal data, the number of each client model, and the number of active users respectively.
[0037] Another embodiment of the present invention provides an analysis device for abnormal data, including:
[0038] A second acquisition module, configured to acquire the abnormal data in the fingerprint library and at least one preset client personality index;
[0039] A second calculation module, configured to calculate the proportion of abnormal data according to the abnormal data;
[0040] A third calculation module, configured to calculate at least one preset client personality index according to a preset index score algorithm to obtain a corresponding index score;
[0041] A processing module, configured to analyze the current game quality according to the index score in combination with the abnormal data ratio.
[0042] Another embodiment of the present invention provides a storage medium. The computer-readable storage medium includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the analysis method of abnormal data described in the above-mentioned embodiment of the present invention.
[0043] The embodiments of the present invention provide an analysis method, device and storage medium for abnormal data. By obtaining abnormal data in a fingerprint database and preset client personality indexes; calculating an abnormal data ratio according to the abnormal data; calculating a mean value of the preset client personality indexes according to a preset index score algorithm to obtain a corresponding index score; calculating a comprehensive score according to the index score, and then analyzing the current game quality according to the comprehensive score and the abnormal data ratio, and moreover, the game quality between different clients can be compared to improve the efficiency of problem handling. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 is a flowchart of a method for classifying abnormal data provided by an embodiment of the present invention;
[0045] Figure 2 is a flowchart of a similar hashing algorithm provided by an embodiment of the present invention;
[0046] Figure 3 is a flowchart of an analysis method for abnormal data provided by an embodiment of the present invention;
[0047] Figure 4 is a structural diagram of a device for classifying abnormal data provided by an embodiment of the present invention;
[0048] Figure 5 is a structural diagram of an analysis device for abnormal data provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0049] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0050] See Figure 1 , which is a schematic flowchart of a method for classifying abnormal data provided by an embodiment of the present invention.
[0051] An embodiment of the present invention provides a method for classifying abnormal data, including:
[0052] S10. Obtain abnormal data and perform filtering processing on the abnormal data.
[0053] It should be noted that in this embodiment, the abnormal data is uploaded by the client. It can be understood that the client has different models, such as Android clients, Apple clients, etc.
[0054] Specifically, the stack uploaded by the client contains a large number of interference items, such as pointer addresses, code line numbers, etc. Therefore, after obtaining the stack, it is necessary to filter the stack according to the filtering algorithm first to filter out the interference items.
[0055] S20. Calculate the filtered abnormal data according to a preset similar hashing algorithm to obtain the fingerprint corresponding to the abnormal data.
[0056] Among them, see Figure 2 , the preset similar hashing algorithm includes: dividing the filtered abnormal data into several terms and performing term frequency statistics on the terms; mapping each term according to the hashing algorithm to obtain a corresponding binary array vector; modifying 0 in the binary array vector to -1 and multiplying it by the corresponding term frequency to obtain a calculated binary array vector; then adding up each calculated binary array vector and modifying the positive term to 1 and the negative term to 0 to obtain the fingerprint corresponding to the abnormal data.
[0057] Since there may be a collision probability in the hashing algorithm, that is, the fingerprints generated by two different texts may be the same, and objectively, the collision probability is related to the length of the fingerprint. The longer the fingerprint, the lower the collision probability. The selection of the length of the fingerprint can be determined according to the magnitude of the system data, 32 bits, 64 bits, 128 bits. The advantage of a long fingerprint is a low collision probability, and the disadvantages are slower calculation speed and larger required storage space. Therefore, in the scenario of crash stack aggregation, a 32-bit length fingerprint is usually selected.
[0058] S30. Determine whether there is a similar fingerprint to the fingerprint in the fingerprint library.
[0059] Preferably, determining whether there is a similar fingerprint of the fingerprint in the fingerprint database specifically includes:
[0060] Determining whether there is a similar fingerprint in the fingerprint database whose Hamming distance from the fingerprint is less than a preset standard value.
[0061] In this embodiment, the preset standard value is set to 3 to 5. The smaller the distance standard value, the higher the requirement for similarity. It can be set as needed and is not limited here. It can be understood that the smaller the Hamming distance, the higher the similarity of the stack. Then it can be considered that the problem of the stack belongs to the same problem category as a certain type of fingerprint in the fingerprint database, thereby improving the problem aggregation rate.
[0062] S40. In response to the judgment result that there is a similar fingerprint of the fingerprint, classify the fingerprint into the problem category corresponding to the similar fingerprint.
[0063] Specifically, when a similar fingerprint is found in the fingerprint database, it is classified into the same problem category. Thus, it can be seen that the stack changes caused by new and old versions are avoided, the aggregation rate of the stack is improved, and the problems can be well classified.
[0064] S50. In response to the judgment result that there is no similar fingerprint of the fingerprint, mark the fingerprint as a new problem category.
[0065] Specifically, when there is no similar fingerprint in the fingerprint database, it means that the current fingerprint is a new problem category. Therefore, it is marked as a new problem category and saved in the fingerprint database.
[0066] In summary, by using the preset similar hashing algorithm to calculate the filtered abnormal data to obtain the fingerprint corresponding to the abnormal data, and then comparing it with the fingerprints in the fingerprint database to find whether there are similar fingerprints. Thus, it can be seen that after increasing the similarity aggregation, the dependence on the filtering process during the aggregation process can be avoided, and the stack changes caused by new and old versions can be compatible, the aggregation rate of the stack is improved, the problems can be well classified, and thus the efficiency of problem handling is improved.
[0067] As an improvement to the above solution, before obtaining the abnormal data and performing filtering processing on the abnormal data, it further includes:
[0068] Obtaining historical abnormal data and calculating the fingerprint of each historical abnormal data.
[0069] Specifically, calculate the filtered stack according to the similar hashing algorithm to obtain the fingerprint of the historical abnormal data.
[0070] Generate a problem category corresponding to the fingerprint of each historical abnormal data and save it to the fingerprint library.
[0071] Specifically, each type of problem corresponds to a fingerprint, which is saved to the fingerprint library for easy comparison with new fingerprints, making the classification of problems more accurate.
[0072] It should be noted that in the present invention, without considering the influence of historical abnormal data, the problem classification of abnormal data can also be directly performed.
[0073] As an improvement of the above solution, after calculating the fingerprint of each historical abnormal data and before generating a problem category corresponding to the fingerprint of each historical abnormal data and saving it to the fingerprint library, it further includes:
[0074] Calculate the md5 value of the historical abnormal data.
[0075] Combine the fingerprint of the historical abnormal data and the md5 value and store them in a map structure.
[0076] Specifically, calculate the md5 value of the filtered stack to form a pair of K-V (the key is the fingerprint and the value is the md5 value of the filtered stack), and then use the map structure to store the calculation. Among them, the value stores the md5 value of the filtered stack, rather than the full text of the filtered stack, in order to reduce space occupancy. Therefore, this map structure needs to be loaded into memory.
[0077] See Figure 3 , which is a schematic flow chart of an abnormal data analysis method provided by an embodiment of the present invention.
[0078] Another embodiment of the present invention provides an abnormal data analysis method, including:
[0079] S100, Obtain the abnormal data in the fingerprint library and at least one preset client personality index;
[0080] Among them, the client personality index includes: average frame rate, CPU average value, average traffic per second, PSS memory average value, battery temperature, average power consumption, etc. In this embodiment, the above personality indexes are all statistically obtained according to the data collected by Bugly.
[0081] S101, Calculate the proportion of abnormal data according to the abnormal data.
[0082] Preferably, for calculating the proportion of abnormal data according to the abnormal data, S101 specifically includes the following steps:
[0083] S1010, Determine the corresponding client model according to each abnormal data and classify the client model.
[0084] Specifically, since the client reports abnormal data, the model of the client can be obtained and classified. For example, under the same problem type, the Android model client reported 10 pieces of abnormal data, and the Apple model client reported 12 pieces of abnormal data.
[0085] S1011. Obtain the corresponding number of active users according to the client model.
[0086] Specifically, by matching the client model with the number of active users of the corresponding model, the analysis result is more accurate.
[0087] S1012. Calculate the total abnormal proportion and the abnormal proportion of each client model according to the quantity of the abnormal data, the quantity of each client model, and the number of active users.
[0088] In this embodiment, the total abnormal proportion r = (n / a) * 100%; the abnormal proportion r1 of each client model = (m / a) * 100%, where a is the number of active users, n is the total quantity of abnormal data, and m is the quantity of abnormal data of each client model.
[0089] S102. Calculate the corresponding index scores for at least one preset client personality index according to a preset index score algorithm.
[0090] In this embodiment, referring to Table 1 and Table 2, input the mean value, threshold, and industry reference value of the client personality index into the preset index score algorithm to calculate each index score. Then calculate the comprehensive performance index score according to the preset weight for each index score.
[0091] It should be noted that the threshold represents the threshold of the gap between the index and the industry reference value. It can be understood that the threshold can be adjusted according to the actual situation. In this embodiment, the threshold is set to π.
[0092] Table 1 Client Personality Index
[0093] Index Unit Variable Name Average Frame Rate Frames per Second <![CDATA[x1]]> CPU Mean Value Percentage <![CDATA[x2]]> Average Traffic per Second KB / S <![CDATA[x3]]> PSS Memory Mean Value MB <![CDATA[x4]]> Mobile Phone Battery Temperature ℃ <![CDATA[x5]]> mAh Milliampere-hour mAh <![CDATA[x6]]> Average Crash Rate Percentage <![CDATA[x7]]> Average Error Rate Percentage <![CDATA[x8]]>
[0094] Table 2 Industry Reference Value
[0095]
[0096] Among them, the preset index score algorithm includes:
[0097] 1. Positive index (average frame rate)
[0098]
[0099] Among them: sign is the sign function, which takes the sign of the independent variable. For example, sign(-9) = -1. x1 is the mean value of the personality index of the average frame rate, is the industry reference value of the average frame rate. f(x) is the score of the frame rate relative to the industry reference value, and Y1 is the threshold corresponding to the average frame rate.
[0100] 2. Negative indicators (x2, x3,..., x6):
[0101]
[0102] Among them, i = 2, 3, 4, 5, 6. It can be understood that the negative indicators correspondingly include the CPU mean value, the average traffic per second, the PSS memory mean value, the mobile phone battery temperature, and mAh (milliampere-hour). is the industry reference value corresponding to each negative indicator, and Y i is the threshold corresponding to each negative indicator, so as to calculate the scores of each negative indicator.
[0103] 3. Comprehensive performance index score (combining positive indicators and negative indicators)
[0104] T = ω1f(x1) + ω2f(x2) + ω3f(x3) + ω4f(x4) + ω5f(x5) + ω6f(x6)
[0105] Among them, T is the comprehensive performance index score, ω1 is the weight corresponding to the average frame rate, ω2 is the weight corresponding to the CPU mean value, ω3 is the weight corresponding to the traffic consumption per second, ω4 is the weight corresponding to the PSS memory mean value, ω5 is the weight corresponding to the mobile phone battery temperature, and ω6 is the weight corresponding to mAh (milliampere-hour). It can be understood that the weights can be set according to needs and are not limited here.
[0106] 4. Crash rate and error rate scores:
[0107]
[0108] Among them, i = 7, 8. It can be understood that the error rate and the crash rate are obtained by statistically analyzing the data collected by Bugly. is the industry reference value corresponding to the crash rate and the error rate.
[0109] 5. Total score of the client quality: W = T×μ1 + f(x7)×μ2 + f(x8)×μ3
[0110] Among them, T is the comprehensive performance index score, μ1 is the weight of the performance index, μ2 is the weight of the crash rate, and μ3 is the weight of the error rate. It can be understood that the weights can be allocated according to the actual situation.
[0111] S103. Analyze the current game quality based on the index score in combination with the proportion of abnormal data.
[0112] In this embodiment, the total score of the client quality is calculated by allocating and calculating each index score according to different weights, and then in combination with the proportion of abnormal data, so as to analyze the game quality among different clients.
[0113] An embodiment of the present invention discloses a method for analyzing abnormal data. By obtaining the abnormal data in the fingerprint database and the preset client personality indicators; calculating the proportion of abnormal data according to the abnormal data; calculating the average value of the preset client personality indicators according to the preset index score algorithm to obtain the corresponding index score; calculating the comprehensive score according to the index score, and further according to the comprehensive score and the proportion of abnormal data, more truly reflect the game quality situation of different clients, so as to analyze the current game quality, and can also compare the game quality among different clients, improving the efficiency of problem handling.
[0114] See Figure 4 , which is a schematic structural diagram of a classification device for abnormal data provided by an embodiment of the present invention.
[0115] An embodiment of the present invention provides a classification device for abnormal data, including:
[0116] The first acquisition module 10 is used to acquire abnormal data and perform filtering processing on the abnormal data;
[0117] The first calculation module 20 is used to calculate the filtered abnormal data according to the preset similar hashing algorithm to obtain the fingerprint corresponding to the abnormal data;
[0118] The judgment module 30 is used to judge whether there is a similar fingerprint of the fingerprint in the fingerprint database;
[0119] The first response module 40 is used to respond that if the judgment result is that there is a similar fingerprint of the fingerprint, then classify the fingerprint into the problem category corresponding to the similar fingerprint;
[0120] The second response module 50 is used to respond that if the judgment result is that there is no similar fingerprint of the fingerprint, then mark the fingerprint as a new problem category.
[0121] An embodiment of the present invention provides an abnormal data classification device. By using a preset similarity hashing algorithm to calculate the filtered abnormal data, fingerprints corresponding to the abnormal data are obtained, and then compared with the fingerprints in the fingerprint library to find similar fingerprints. It can be seen that after adding similarity aggregation, the dependence on filtering during the aggregation process can be avoided, and the stack changes caused by new and old versions can be compatible, improving the stack aggregation rate, enabling problems to be well classified, and thus improving the efficiency of problem handling.
[0122] See Figure 5 , which is a schematic structural diagram of an abnormal data analysis device provided by an embodiment of the present invention.
[0123] An embodiment of the present invention provides an abnormal data analysis device, including:
[0124] A second acquisition module 100, configured to acquire abnormal data in the fingerprint library and at least one preset client personality index;
[0125] A second calculation module 101, configured to calculate the proportion of abnormal data based on the abnormal data;
[0126] A third calculation module 102, configured to calculate corresponding index scores according to a preset index score algorithm for at least one preset client personality index;
[0127] A processing module 103, configured to analyze the current game quality according to the index scores in combination with the proportion of abnormal data.
[0128] An embodiment of the present invention discloses an abnormal data analysis device. By acquiring abnormal data in the fingerprint library and the mean value of preset client personality indexes; calculating the proportion of abnormal data based on the abnormal data; calculating corresponding index scores according to a preset index score algorithm for the proportion of abnormal data and the mean value of preset client personality indexes; calculating a comprehensive score according to the index scores, it can more truly reflect the game quality situation of the client, thereby analyzing the current game quality, and can also compare the game quality between different clients, improving the efficiency of problem handling.
[0129] Another embodiment of the present invention provides a storage medium. The computer-readable storage medium includes a stored computer program, wherein when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the abnormal data classification method described in the above-mentioned embodiment of the invention.
[0130] Another embodiment of the present invention provides a storage medium. The computer-readable storage medium includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the method for analyzing abnormal data described in the above-mentioned embodiment of the present invention.
[0131] Among them, if the classification device for abnormal data or the module / unit integrated in the analysis device for abnormal data is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-mentioned embodiment methods of the present invention, it can also be completed by a computer program instructing relevant hardware. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium, etc.
[0132] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the drawings of the device embodiments provided by the present invention, the connection relationship between the modules indicates that they have a communication connection, which can be specifically implemented as one or more communication buses or signal lines. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0133] The above is the preferred embodiment of the present invention. It should be pointed out that for those of ordinary skill in the art of the present technology, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present invention.
Claims
1. A method for analyzing abnormal data, characterized in that, Including: Obtain abnormal data and perform filtering processing on the abnormal data; Calculate the filtered abnormal data according to a preset similar hashing algorithm to obtain the fingerprint corresponding to the abnormal data; Determine whether there is a similar fingerprint of the fingerprint in the fingerprint library; In response to the judgment result that there is a similar fingerprint of the fingerprint, classify the fingerprint into the problem category corresponding to the similar fingerprint; In response to the judgment result that there is no similar fingerprint of the fingerprint, mark the fingerprint as a new problem category and save it in the fingerprint library; Obtain the abnormal data and at least one preset client personality index under the same problem category in the fingerprint library; Calculate the abnormal data proportion according to the abnormal data obtained from the fingerprint library; Calculate the corresponding index score according to at least one preset client personality index according to a preset index score algorithm; Analyze the current game quality according to the index score in combination with the abnormal data proportion; Calculating the abnormal data proportion according to the abnormal data obtained from the fingerprint library specifically includes: Determine the corresponding client model according to each piece of abnormal data obtained from the fingerprint library, and classify the client model; Obtain the corresponding active user number according to the client model; Calculate the total abnormal proportion and the abnormal proportion of each client model respectively according to the number of abnormal data obtained from the fingerprint library, the number of each client model, and the active user number.
2. The method for analyzing abnormal data according to claim 1, wherein Before the step of obtaining abnormal data and performing filtering processing on the abnormal data, it further includes: Obtain historical abnormal data and calculate the fingerprint of each historical abnormal data; Generate a problem category corresponding to the fingerprint of each historical abnormal data and save it to the fingerprint library.
3. The analysis method of abnormal data according to claim 2, characterized in that, After calculating the fingerprint of each historical abnormal data and before generating a problem category corresponding to the fingerprint of each historical abnormal data and saving it to the fingerprint library, it further includes: Calculate the md5 value of the historical abnormal data; Combine the fingerprint of the historical abnormal data and the md5 value and store it in a map structure.
4. The analysis method of abnormal data according to claim 1, wherein The step of determining whether there is a similar fingerprint of the fingerprint in the fingerprint library specifically includes: Determine whether there is a similar fingerprint in the fingerprint library whose Hamming distance from the fingerprint is less than a preset standard value.
5. A method for analyzing abnormal data, characterized in that, Including: Obtain the abnormal data in the fingerprint library and at least one preset client personality index; Calculate the abnormal data proportion according to the abnormal data; Calculate the corresponding index score according to at least one preset client personality index according to a preset index score algorithm; Analyze the current game quality according to the index score in combination with the abnormal data proportion; The step of calculating the abnormal data proportion according to the abnormal data specifically includes: Determine the corresponding client model according to each piece of abnormal data and classify the client model; Obtain the corresponding active user number according to the client model; Calculate the total abnormal proportion and the abnormal proportion of each client model respectively according to the number of abnormal data, the number of each client model, and the active user number.
6. An analysis device for abnormal data, characterized in that, Including: A first acquisition module, configured to acquire abnormal data and perform filtering processing on the abnormal data; A first calculation module, configured to calculate the filtered abnormal data according to a preset similar hashing algorithm to obtain a fingerprint corresponding to the abnormal data; A judgment module, configured to judge whether there is a similar fingerprint of the fingerprint in a fingerprint database; A first response module, configured to, in response to a judgment result that there is a similar fingerprint of the fingerprint, classify the fingerprint into a problem category corresponding to the similar fingerprint; A second response module, configured to, in response to a judgment result that there is no similar fingerprint of the fingerprint, mark the fingerprint as a new problem category; A second acquisition module, configured to acquire abnormal data in a fingerprint database and at least one preset client personality index; A second calculation module, configured to calculate an abnormal data ratio according to the abnormal data acquired from the fingerprint database; A third calculation module, configured to calculate corresponding index scores for at least one preset client personality index according to a preset index score algorithm; A processing module, configured to analyze the current game quality according to the index scores in combination with the abnormal data ratio; Calculating an abnormal data ratio according to the abnormal data acquired from the fingerprint database specifically includes: Determining a corresponding client model according to each piece of abnormal data acquired from the fingerprint database, and classifying the client models; Obtaining the corresponding number of active users according to the client model; Calculating a total abnormal ratio and an abnormal ratio of each client model respectively according to the number of abnormal data acquired from the fingerprint database, the number of each client model, and the number of active users.
7. An analysis device for abnormal data, characterized in that, Including: A second acquisition module, configured to acquire abnormal data in a fingerprint database and at least one preset client personality index; A second calculation module, configured to calculate an abnormal data ratio according to the abnormal data; A third calculation module, configured to calculate corresponding index scores for at least one preset client personality index according to a preset index score algorithm; A processing module, configured to analyze the current game quality according to the index scores in combination with the abnormal data ratio; The calculating an abnormal data ratio according to the abnormal data specifically includes: Determining a corresponding client model according to each piece of abnormal data and classifying the client models; Obtaining the corresponding number of active users according to the client model; Calculating a total abnormal ratio and an abnormal ratio of each client model respectively according to the number of abnormal data, the number of each client model, and the number of active users.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the analysis method of abnormal data according to any one of claims 1 to 4.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the analysis method of abnormal data according to claim 5.
Citation Information
Patent Citations
Abnormality processing method and device
CN108111328A
Abnormal event root cause positioning method and device
CN111158977A