An anomaly detection method, device and computer readable storage medium

By acquiring multiple indicator values ​​and determining anomaly detection rules based on the detection cycle, and integrating them with indicator linkage conditions, the problem of low anomaly detection accuracy in existing technologies is solved, and higher precision anomaly detection results are achieved.

CN113535445BActive Publication Date: 2026-04-24TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TENCENT TECHNOLOGY (SHENZHEN) CO LTD
Filing Date
2021-01-06
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing anomaly detection methods have low accuracy, mainly due to their reliance on year-on-year/month-on-month comparisons of a single indicator and the lack of indicator-linked detection, resulting in inaccurate results.

Method used

By acquiring multiple indicator values ​​and determining anomaly detection rules based on the detection cycle, and integrating them with indicator linkage conditions, target detection results are formed, thereby improving detection accuracy.

Benefits of technology

By integrating multiple indicators, the accuracy of anomaly detection is improved, resource consumption is reduced, and more accurate anomaly detection results are provided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113535445B_ABST
    Figure CN113535445B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide an anomaly detection method, device and computer readable storage medium; the method comprises: for each of at least one to-be-detected indicator, when the detection time is determined to arrive based on the detection period in the detection window, obtaining an anomaly detection rule and a business data source; based on the business data source, calculating the indicator value corresponding to each to-be-detected indicator, thereby obtaining N indicator values corresponding to the detection window, N is a positive integer determined based on the ratio of the detection window to the detection period; detecting the N indicator values based on the anomaly detection rule to determine the anomaly detection result corresponding to each to-be-detected indicator, thereby obtaining at least one anomaly detection result corresponding to at least one to-be-detected indicator; obtaining the indicator linkage condition corresponding to at least one to-be-detected indicator; based on the indicator linkage condition, integrating at least one anomaly detection result to obtain a target detection result. Through the embodiments of the present application, the accuracy of anomaly detection can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to anomaly detection technology in the field of computers, and more particularly to anomaly detection method, device and computer-readable storage medium. Background Technology

[0002] An anomaly refers to a situation during business operations where the corresponding indicator value of the business data exceeds or falls below an anomaly threshold, or the difference between the indicator value and the historical indicator value exceeds the difference threshold. Anomaly detection can ensure the stable operation of the business.

[0003] Generally, anomaly detection is performed based on reported business data, undergoing year-on-year / month-on-month comparisons to determine the anomaly detection results. However, because the anomaly detection results are determined based on year-on-year / month-on-month comparisons, the method used to determine the anomaly detection results is singular; that is, anomaly detection is achieved through a single indicator, resulting in low accuracy. Summary of the Invention

[0004] This application provides an anomaly detection method, device, and computer-readable storage medium, which can improve the accuracy of anomaly detection.

[0005] The technical solution of this application embodiment is implemented as follows:

[0006] This application provides an anomaly detection method, including:

[0007] For each of the at least one indicators to be detected, in the detection window, when the detection time is determined based on the detection cycle, the anomaly detection rules and business data sources are obtained.

[0008] Based on the business data source, the index value corresponding to each index to be detected is calculated, thereby obtaining N index values ​​corresponding to the detection window, where N is a positive integer determined based on the ratio of the detection window to the detection period;

[0009] Based on the anomaly detection rules, the N index values ​​are detected to determine the anomaly detection result corresponding to each index to be detected, thereby obtaining at least one anomaly detection result corresponding to the at least one index to be detected.

[0010] Obtain the indicator linkage conditions corresponding to the at least one indicator to be detected;

[0011] Based on the aforementioned indicator linkage conditions, at least one anomaly detection result is integrated to obtain the target detection result.

[0012] This application provides an anomaly detection device, including:

[0013] The detection triggering module is used to obtain the anomaly detection rules and business data sources for each of the at least one to be detected indicators in the detection window when the detection time is determined based on the detection cycle.

[0014] An anomaly detection module is used to calculate the index value corresponding to each index to be detected based on the business data source, thereby obtaining N index values ​​corresponding to the detection window, where N is a positive integer determined based on the ratio of the detection window to the detection period;

[0015] The result determination module is used to detect the N index values ​​based on the anomaly detection rules to determine the anomaly detection result corresponding to each index to be detected, thereby obtaining at least one anomaly detection result corresponding to the at least one index to be detected.

[0016] The condition acquisition module is used to acquire the indicator linkage conditions corresponding to the at least one indicator to be detected.

[0017] The result integration module is used to integrate at least one anomaly detection result based on the indicator linkage conditions to obtain the target detection result.

[0018] In this embodiment, the anomaly detection device further includes an anomaly configuration module for displaying an anomaly indicator configuration page. The anomaly indicator configuration page includes a business data source selection control, an indicator selection control, and a detection period configuration control. In response to a business data source selection operation performed on the business data source selection control, the selected business data source is displayed. In response to an indicator selection operation performed on the indicator selection control for the business data source, the selected at least one indicator to be detected is displayed, and the indicator linkage conditions are configured for the at least one indicator to be detected. The detection window and the anomaly detection rule are configured for each indicator to be detected. In response to a detection period configuration operation performed on the detection period configuration control, the configured detection period is displayed.

[0019] In this embodiment, the anomaly configuration module is further configured to display a detection rule configuration page for each indicator to be detected, wherein the detection rule configuration page includes a detection strategy selection control; in response to a detection strategy selection operation performed on the detection strategy selection control, display the selected indicator detection strategy and the indicator anomaly condition configuration control corresponding to the indicator detection strategy, wherein the indicator detection strategy includes one or more of a threshold detection strategy, a year-on-year / month-on-month comparison detection strategy, and a lone forest detection strategy; in response to an indicator anomaly condition configuration operation performed on the indicator anomaly condition configuration control for the indicator detection strategy, display the configured detection window and the indicator anomaly condition corresponding to the detection window, thereby obtaining the anomaly detection rule including the indicator detection strategy and the indicator anomaly condition.

[0020] In this embodiment of the application, the result determination module is further configured to determine whether the N index values ​​meet the index anomaly conditions based on the index detection strategy, so as to determine the anomaly detection result corresponding to each index to be detected.

[0021] In this embodiment, the exception configuration module is further configured to display an indicator configuration page, wherein the indicator configuration page includes an indicator-associated data source selection control, an indicator configuration control, and an indicator model configuration control; in response to an indicator-associated data source selection operation performed on the indicator-associated data source selection control, the selected business data source is displayed; in response to an indicator configuration operation performed on the indicator configuration control, each configured indicator to be detected is displayed, wherein each indicator to be detected includes one or more of an indicator identifier to be detected, indicator description information to be detected, and indicator unit to be detected; in response to an indicator model configuration operation performed on the indicator model configuration control, the configured indicator model is displayed, wherein the model parameters in the indicator model are data fields in the business data source.

[0022] In this embodiment of the application, the anomaly detection module is further configured to obtain parameter data corresponding to the model parameters from the business data source; and to calculate the parameter data based on the indicator model to determine the indicator value corresponding to each indicator to be detected.

[0023] In this embodiment of the application, the abnormal configuration module is further configured to display a data source configuration page, wherein the data source configuration page includes a data source configuration control; in response to a data source configuration operation performed on the data source configuration control, the configured business data source is displayed, wherein the business data source includes one or more of the following: data source identifier, data source description information, data source access method, data latency, and data granularity, wherein the detection period is an integer multiple of the data granularity.

[0024] In this embodiment of the application, the abnormal indicator configuration page further includes a filter condition configuration control; the abnormal configuration module is also used to display the configured data filter conditions in response to the filter condition configuration operation performed on the filter condition configuration control.

[0025] In this embodiment of the application, the anomaly detection module is further configured to obtain the data filtering conditions; obtain the data to be detected that meets the data filtering conditions from the business data source; and calculate the indicator value corresponding to each indicator to be detected based on the data to be detected.

[0026] In this embodiment, the exception configuration module is further configured to display a dimension configuration page, wherein the dimension configuration page includes a dimension-associated data source selection control and a dimension configuration control; in response to an indicator-associated data source selection operation performed on the indicator-associated data source selection control, the selected business data source is displayed; in response to a dimension configuration operation performed on the dimension configuration control for the business data source, the configured data dimension is displayed, wherein the data dimension includes one or both of dimension field identifiers and dimension field description information, and the data dimension is a data field in the business data source.

[0027] In this embodiment of the application, the exception configuration module is further configured to display the data filtering conditions selected from the data dimension in response to the filtering condition configuration operation performed on the filtering condition configuration control.

[0028] In this embodiment of the application, when the indicator detection strategy includes the isolated forest detection strategy, the result determination module is further configured to, based on the isolated forest detection strategy, compare the N indicator values ​​with the N historical indicator values ​​corresponding to the detection window of the obtained preset historical period number, obtain the preset period number of abnormal comparison scores, and obtain the number of abnormal scores greater than the abnormal threshold among the preset historical period number of abnormal comparison scores, wherein the N historical indicator values ​​are year-on-year indicator values ​​or month-on-month indicator values; when the number of abnormal scores is greater than the abnormal number threshold, and the abnormal directions among the abnormal scores of the abnormal scores are consistent, it is determined that the N indicator values ​​meet the indicator abnormality condition, thereby obtaining the target detection result that an abnormality has been detected.

[0029] In this embodiment, the result determination module is further configured to obtain the current statistical features corresponding to the N indicator values, wherein the current statistical features include one or more of the current maximum value, current minimum value, current mean, current variance, and current range; obtain the historical statistical features corresponding to the N historical indicator values ​​corresponding to the detection window; obtain the feature ratio of the current statistical features to the historical data statistical features, thereby obtaining the feature ratio of the preset number of periods; perform standardization processing on the feature ratio of the preset number of periods; and input each standardized feature ratio into a multidimensional isolated forest model based on preset weights to obtain the outlier score of the preset number of periods, wherein the multidimensional isolated forest model is used to determine the outlier score.

[0030] In this embodiment, the anomaly detection device further includes a result sending module, configured to perform attribution processing on the target detection result to obtain anomaly extended information; combine one or more of the anomaly extended information, the business data source, the at least one indicator to be detected, the detection window, and anomaly details into anomaly information, wherein the anomaly details are determined based on the anomaly detection rules and the N indicator values; obtain an anomaly sending strategy for the at least one indicator to be detected, wherein the anomaly sending strategy includes a sending channel and a sending target; and send the anomaly information to the sending target through the sending channel, so that...

[0031] The feedback device corresponding to the sending object displays the abnormal information based on the abnormal shielding information, and in response to the rule modification operation for the abnormal information, displays a rule modification page to modify the abnormal configuration information based on the rule modification page. The abnormal configuration information includes one or more of the following: the abnormal detection rule, the at least one indicator to be detected, the indicator linkage condition, the detection window, and the abnormal shielding information.

[0032] In this embodiment of the application, the anomaly detection device further includes a configuration modification module, configured to receive feedback information sent by the feedback terminal device in response to the anomaly information, wherein the feedback information is obtained in response to an operation performed on the rule modification page; and based on the feedback information, update the anomaly detection configuration information to perform anomaly detection based on the updated anomaly configuration information, wherein the updated anomaly configuration information includes one or more of the following: updated anomaly detection rules, updated at least one indicator to be detected, updated indicator linkage conditions, updated detection window, and updated anomaly shielding information.

[0033] In this embodiment, the abnormal configuration module is further configured to display a sending strategy configuration page for each indicator to be detected, wherein the sending strategy configuration page includes a hierarchical configuration control; in response to a hierarchical configuration operation applied to the hierarchical configuration control, the configured sending level and the sending strategy configuration control corresponding to the sending level are displayed; in response to the sending strategy configuration control applied to the sending strategy configuration control, the configured sending channel and the sending object are displayed, thereby obtaining an abnormal sending strategy for the indicator including the sending level, the sending channel, and the sending object;

[0034] In this embodiment of the application, the result sending module is further configured to select an abnormal sending strategy from the at least one abnormal sending strategy for the at least one indicator based on the priority of the sending level in the abnormal sending strategy for each indicator to be detected, and use it as the abnormal sending strategy for the at least one indicator to be detected.

[0035] In this embodiment of the application, the abnormal configuration module is further configured to display the configured sending channel, the sending object, and the abnormal aggregation condition in response to the sending strategy configuration control acting on the sending strategy configuration control, thereby obtaining the indicator abnormal sending strategy including the sending level, the sending channel, the sending object, and the abnormal aggregation condition.

[0036] In this embodiment of the application, the result sending module is further configured to perform attribution processing on the target detection result to obtain the anomaly extended information when the target detection result satisfies the anomaly aggregation condition.

[0037] This application provides an anomaly detection device, including:

[0038] Memory, used to store executable instructions;

[0039] The processor, when executing executable instructions stored in the memory, implements the anomaly detection method provided in the embodiments of this application.

[0040] This application provides a computer-readable storage medium storing executable instructions for inducing a processor to execute and implement the anomaly detection method provided in this application.

[0041] The embodiments of this application have at least the following beneficial effects: for each of the at least one detectable indicators, by obtaining N indicator values ​​corresponding to the detection window, the abnormal detection result corresponding to each detectable indicator is determined, and then the at least one abnormal detection result corresponding to the at least one detectable indicator is integrated to obtain the final target detection result; thus, the target detection result is determined based on the linkage of at least one detectable indicator, thereby the accuracy of the target detection result is high, and thus the accuracy of abnormal detection can be improved. Attached Figure Description

[0042] Figure 1 This is an optional architecture diagram of the anomaly detection system provided in the embodiments of this application;

[0043] Figure 2 This is provided by the embodiments of this application. Figure 1 A schematic diagram of the composition structure of a server;

[0044] Figure 3 This is an optional flowchart of the anomaly detection method provided in the embodiments of this application;

[0045] Figure 4 This is an optional interactive schematic diagram of the anomaly detection method provided in the embodiments of this application;

[0046] Figure 5 This is an exemplary anomaly detection system architecture diagram provided in an embodiment of this application;

[0047] Figure 6 This is a schematic diagram of an exemplary data source configuration page provided in an embodiment of this application;

[0048] Figure 7 This is a schematic diagram of an exemplary data source list page provided in an embodiment of this application;

[0049] Figure 8 This is a schematic diagram of an exemplary indicator configuration page provided in an embodiment of this application;

[0050] Figure 9 This is a schematic diagram of an exemplary dimension configuration page provided in an embodiment of this application;

[0051] Figure 10 This is a schematic diagram of an exemplary alarm rule list page provided in an embodiment of this application;

[0052] Figure 11 This is a schematic diagram of an exemplary abnormal indicator configuration page provided in an embodiment of this application;

[0053] Figure 12This is a schematic diagram of an exemplary detection rule configuration page provided in an embodiment of this application;

[0054] Figure 13 This is a schematic diagram of another exemplary detection rule configuration page provided in an embodiment of this application;

[0055] Figure 14 This is a schematic diagram of another exemplary detection rule configuration page provided in the embodiments of this application;

[0056] Figure 15 This is a schematic diagram of another exemplary detection rule configuration page provided in the embodiments of this application;

[0057] Figure 16 This is a schematic diagram of an exemplary sending strategy configuration page provided in an embodiment of this application;

[0058] Figure 17 This is an exemplary schematic diagram of displaying alarm information provided in an embodiment of this application;

[0059] Figure 18 This is another exemplary schematic diagram of displaying alarm information provided in the embodiments of this application;

[0060] Figure 19 This is another exemplary schematic diagram of displaying alarm information provided in the embodiments of this application;

[0061] Figure 20 This is a schematic diagram illustrating yet another exemplary method for displaying alarm information provided in an embodiment of this application;

[0062] Figure 21 This is yet another exemplary diagram illustrating the display of alarm information provided in this application embodiment;

[0063] Figure 22 This is a schematic flowchart of an exemplary anomaly detection method provided in an embodiment of this application;

[0064] Figure 23 This is an exemplary data retrieval and processing flowchart provided in an embodiment of this application;

[0065] Figure 24 This is an exemplary detection process for a unique forest detection algorithm provided in an embodiment of this application;

[0066] Figure 25 This is an exemplary standardized processing diagram provided in an embodiment of this application;

[0067] Figure 26 This is an exemplary flowchart of sending abnormal information provided in an embodiment of this application. Detailed Implementation

[0068] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0069] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0070] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0071] In the implementation of this application, the collection and processing of relevant data should be strictly in accordance with the requirements of relevant laws and regulations, obtain the informed consent or separate consent of the personal information subject, and carry out subsequent data use and processing within the scope of laws and regulations and the authorization of the personal information subject.

[0072] Before providing a further detailed description of the embodiments of this application, the nouns and terms involved in the embodiments of this application will be explained, and the nouns and terms involved in the embodiments of this application shall be interpreted as follows.

[0073] 1) Data source, i.e., the source of data, is the database or original media that provides the required data; the data source stores information for establishing database connections. By using the data source name, the corresponding database or database system (e.g., the distributed data storage system "Druid" for big data processing, the relational database management system "MySQL" and the object-relational database management system "PgSQL") can be found to connect and obtain data; in this embodiment of the application, the data source includes business data sources.

[0074] 2) Year-on-year and month-on-month comparisons, including year-on-year and month-on-month comparisons; where year-on-year refers to comparing the current period with the same period last year, and month-on-month refers to comparing the current period with the previous period.

[0075] 3) A control is a triggerable piece of information displayed in the form of a button, icon, link, text, selection box, input box, tab, etc. The triggering method can be contact triggering, non-contact triggering, or instruction-based triggering, etc. In addition, the various controls in the embodiments of this application can be a single control or a collective term for multiple controls.

[0076] 4) An operation is a way to trigger a device to perform processing, such as a click operation, a double-click operation, a long-press operation, a swipe operation, a gesture operation, a received trigger command, etc. In addition, the various operations in the embodiments of this application can be a single operation or a collective term for multiple operations.

[0077] 5) In response to, used to indicate the conditions or states on which the performed processing depends, when the conditions or states on which it depends are met, one or more operations performed may be performed in real time or with a set delay; unless otherwise specified, there is no restriction on the order in which the multiple operations are performed.

[0078] Generally, anomaly detection is achieved through monitoring platforms such as "tmp" or "miaoji". The "tmp" monitoring platform interfaces with the business platform, receiving data reported by the business platform and then performing year-on-year / month-on-month comparisons or amplitude / range comparisons to achieve anomaly detection. However, because the anomaly detection result determination in the "tmp" monitoring platform is based on year-on-year / month-on-month processing and does not support cross-indicator detection, the method for determining anomaly detection results is singular; anomaly detection is achieved through a single indicator, resulting in low accuracy.

[0079] Miaoji monitoring platform is a big data real-time monitoring platform. It also receives reported data and performs anomaly detection based on the reported data and algorithms based on year-on-year / month-on-month / threshold / average values. However, it does not support indicator linkage detection, so the accuracy of anomaly detection is relatively low.

[0080] In addition, both of the above monitoring platforms rely on the business platform to actively report data. Therefore, in practical applications, since the business data in the business platform is already stored in the database, data reporting requires an additional reporting function, which increases the resource consumption of developing the reporting function for the business platform.

[0081] Based on this, embodiments of this application provide an anomaly detection method, apparatus, device, and computer-readable storage medium, which can improve the accuracy of anomaly detection and reduce the resource consumption of anomaly detection. The following describes exemplary applications of the anomaly detection device provided in this application. The anomaly detection device provided in this application can be implemented as various types of user terminals such as laptops, tablets, desktop computers, set-top boxes, and mobile devices (e.g., mobile phones, portable music players, personal digital assistants, dedicated messaging devices, portable gaming devices), or as a server. The following will describe exemplary applications when the device is implemented as a server.

[0082] See Figure 1 , Figure 1 This is a schematic diagram of an optional architecture of the anomaly detection system provided in the embodiments of this application; as shown... Figure 1 As shown, to support an anomaly detection application, in the anomaly detection system 100, a terminal 400 (terminals 400-1 and 400-2 are shown as examples, serving as feedback devices) connects to a server 200 (anomaly detection device) via a network 300. The network 300 can be a wide area network (WAN), a local area network (LAN), or a combination of both. In addition, the anomaly detection system 100 also includes a business data source 500, which includes a database 500-1. The business data source 500 is used to provide data support to the server 200, that is, the server 200 performs anomaly detection on the business data in the business data source 500.

[0083] Terminal 400 is used to receive target detection results sent by server 200 via network 300 and display the target detection results on a graphical page.

[0084] Server 200 is configured to, for each of at least one to-be-detected indicators, within a detection window, when the detection time is determined based on the detection period, acquire anomaly detection rules and business data sources; based on the business data sources, calculate the indicator value corresponding to each to-be-detected indicator, thereby obtaining N indicator values ​​corresponding to the detection window, where N is a positive integer determined based on the ratio of the detection window to the detection period; detect the N indicator values ​​based on the anomaly detection rules to determine the anomaly detection result corresponding to each to-be-detected indicator, thereby obtaining at least one anomaly detection result corresponding to at least one to-be-detected indicator; acquire indicator linkage conditions corresponding to at least one to-be-detected indicator; and based on the indicator linkage conditions, integrate at least one anomaly detection result to obtain a target detection result. It is also configured to send the target detection result to terminal 400.

[0085] In some embodiments, server 200 may be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. Terminal 400 may be a smartphone, tablet, laptop, desktop computer, smart speaker, smartwatch, etc., but is not limited to these. The terminal and server can be directly or indirectly connected via wired or wireless communication, which is not limited in this embodiment of the invention.

[0086] See Figure 2 , Figure 2 This is provided by the embodiments of this application. Figure 1A schematic diagram of the composition structure of a server. Figure 2 The server 200 shown includes at least one processor 210, memory 250, at least one network interface 220, and a user interface 230. The various components in server 200 are coupled together via a bus system 240. It is understood that the bus system 240 is used to implement communication between these components. In addition to a data bus, the bus system 240 also includes a power bus, a control bus, and a status signal bus. However, for clarity, ... Figure 2 The general labeled all buses as Bus System 240.

[0087] Processor 210 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor can be a microprocessor or any conventional processor, etc.

[0088] User interface 230 includes one or more output devices 231 that enable the presentation of media content, including one or more speakers and / or one or more visual displays. User interface 230 also includes one or more input devices 232, including user interface components that facilitate user input, such as a keyboard, mouse, microphone, touch screen display, camera, other input buttons and controls.

[0089] The memory 250 may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state storage, hard disk drives, optical disk drives, etc. The memory 250 may optionally include one or more storage devices physically located away from the processor 210.

[0090] The memory 250 may include volatile memory or non-volatile memory, or both. The non-volatile memory may be read-only memory (ROM), and the volatile memory may be random access memory (RAM). The memory 250 described in this application embodiment is intended to include any suitable type of memory.

[0091] In some embodiments, memory 250 is capable of storing data to support various operations, examples of which include programs, modules, and data structures or subsets or supersets thereof, as illustrated below.

[0092] Operating system 251 includes system programs for handling various basic system services and performing hardware-related tasks, such as the framework layer, core library layer, driver layer, etc., for implementing various basic business functions and handling hardware-based tasks;

[0093] The network communication module 252 is used to reach other computing devices via one or more (wired or wireless) network interfaces 220, such as Bluetooth, Wi-Fi, and Universal Serial Bus (USB).

[0094] Presentation module 253 is configured to enable the presentation of information (e.g., a user interface for operating peripheral devices and displaying content and information) via one or more output devices 231 associated with user interface 230 (e.g., a display screen, a speaker, etc.).

[0095] The input processing module 254 is used to detect and translate one or more user inputs or interactions from one or more input devices 232.

[0096] In some embodiments, the anomaly detection device provided in this application can be implemented in software. Figure 2 An anomaly detection device 255 stored in memory 250 is shown. This device can be software in the form of programs or plug-ins, and includes the following software modules: a detection trigger module 2551, an anomaly detection module 2552, a result determination module 2553, a condition acquisition module 2554, a result integration module 2555, an anomaly configuration module 2556, a result sending module 2557, and a configuration modification module 2558. These modules are logically connected and can therefore be arbitrarily combined or further separated according to their implemented functions. The functions of each module will be described below.

[0097] In other embodiments, the anomaly detection device provided in this application can be implemented in hardware. As an example, the anomaly detection device provided in this application can be a processor in the form of a hardware decoding processor, which is programmed to execute the anomaly detection method provided in this application. For example, the processor in the form of a hardware decoding processor can be one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components.

[0098] The anomaly detection method provided in this application will be described below with reference to exemplary applications and implementations of the server provided in the embodiments of this application.

[0099] See Figure 3 , Figure 3 This is an optional flowchart illustrating an anomaly detection method provided in an embodiment of this application, which will be combined with... Figure 3 The steps shown are explained.

[0100] S301. For each of the at least one indicators to be detected, in the detection window, when the detection time is determined based on the detection cycle, obtain the anomaly detection rules and business data source.

[0101] In this embodiment, when performing anomaly detection on running services (such as advertising services, virtual scene rendering services, resource scheduling services, etc.), it is done through at least one indicator to be detected. Here, since a detection period and business data source are pre-set for at least one indicator to be detected, and a detection window and anomaly detection rules are pre-set for each of the at least one indicator to be detected, the anomaly detection device can obtain the anomaly detection rules and business data source used to obtain the anomaly detection results corresponding to each indicator to be detected when the detection time is determined based on the detection period within the detection window. Here, the detection time can be any time within a time period corresponding to a detection period.

[0102] It should be noted that each metric to be detected is a metric used to measure whether the operational status of a business is abnormal, such as failure rate, call volume, etc.; the detection window is the time period for measuring whether an abnormal operational status of a business generates an alarm, such as 1 hour, 5 minutes, 25 minutes, etc.; the detection cycle is the detection granularity of business data, such as 1 minute, etc.; the anomaly detection rules are used to determine whether the operational status of a business is abnormal and whether an alarm is generated, such as the number of suppressions for the detection window (2 times, 3 times, etc.), the detection algorithm (year-on-year comparison algorithm, threshold algorithm, isolated forest algorithm, etc.), the anomaly judgment conditions for metric values ​​(abnormal interval, etc.), and the linkage conditions for the anomaly judgment conditions of metric values ​​(satisfying all / at least one anomaly judgment condition), etc.; the business data source is used to obtain the data corresponding to the metric value to be detected, which can be reported data (such as feature identifiers), or the accessed database system (such as database tables), or other accessed storage devices, etc., and this application embodiment does not specifically limit this.

[0103] S302. Based on the business data source, calculate the indicator value corresponding to each indicator to be detected, thereby obtaining N indicator values ​​corresponding to the detection window.

[0104] In this embodiment, after obtaining the business data source, the anomaly detection device retrieves the business data from the business data source for calculating the indicator value corresponding to each indicator to be detected, and then calculates the indicator value corresponding to each indicator to be detected based on the obtained business data. Here, the indicator value corresponds to the detection period. Since a detection window includes at least one detection period, the anomaly detection device calculates the indicator value corresponding to each indicator to be detected for each detection period of the detection window, thus obtaining N indicator values ​​corresponding to the detection window.

[0105] It should be noted that N is a positive integer determined based on the ratio of the detection window to the detection period. When the ratio of the detection window to the detection period is an integer, N is the ratio of the detection window to the detection period. For example, if the detection window is 1 hour and the detection period is 5 minutes, then N is 12; or if the detection window is 5 minutes and the detection period is 1 minute, then N is 5. When the ratio of the detection window to the detection period is not an integer, N is the rounded result of the ratio of the detection window to the detection period. Here, it can be rounded up or rounded down.

[0106] S303. Detect N index values ​​based on anomaly detection rules to determine the anomaly detection result corresponding to each index to be detected, thereby obtaining at least one anomaly detection result corresponding to at least one index to be detected.

[0107] In this embodiment of the application, after the anomaly detection device obtains N index values ​​for each index to be detected in the detection window, it uses anomaly detection rules to detect the N index values, so as to determine the anomaly detection result for each index to be detected, including whether the operation status of the service is abnormal and whether the abnormal operation status generates an alarm.

[0108] Here, once the anomaly detection device obtains the anomaly detection result corresponding to each indicator to be detected, it also obtains at least one corresponding anomaly detection result for at least one indicator to be detected. It is easy to see that at least one indicator to be detected corresponds one-to-one with at least one anomaly detection result.

[0109] S304. Obtain the linkage conditions of at least one indicator to be detected.

[0110] In this embodiment of the application, since corresponding indicator linkage conditions are preset for at least one indicator to be detected, the anomaly detection device can obtain the indicator linkage conditions. Here, the indicator linkage conditions are used to determine the linkage mode of at least one indicator to be detected. For example, if all indicators generate alarms, the final result is determined to be abnormal; if one indicator generates an alarm, the final result is determined to be abnormal.

[0111] S305. Based on the indicator linkage conditions, integrate at least one anomaly detection result to obtain the target detection result.

[0112] In this embodiment, after obtaining the indicator linkage conditions, the anomaly detection device integrates at least one anomaly detection result based on these conditions to obtain the final detection result, i.e., the target detection result. This target detection result represents the final result of whether the business operation is abnormal.

[0113] It is understood that, for each of the at least one detectable indicators, this application embodiment obtains N indicator values ​​corresponding to the detection window to determine the abnormal detection result corresponding to each detectable indicator, and then integrates at least one abnormal detection result corresponding to at least one detectable indicator to obtain the final target detection result; thus, the target detection result is determined based on the linkage of at least one detectable indicator, thereby achieving higher accuracy of the target detection result and improving the accuracy of abnormal detection.

[0114] In this embodiment of the application, S301 is followed by S306-S309; ​​that is, for each of the at least one detectable indicator, within the detection window, before acquiring the anomaly detection rules and business data source when the detection time is determined based on the detection cycle, the anomaly detection method further includes S306-S309:

[0115] S306. Display the abnormal indicator configuration page, which includes a business data source selection control, an indicator selection control, and a detection period configuration control.

[0116] It should be noted that when at least one metric to be detected is configured for anomaly detection, the anomaly metric configuration page is also triggered to be displayed on the anomaly detection device. Additionally, the business data source selection control is used to trigger the selection of a business data source, the metric selection control is used to trigger the selection of at least one metric to be detected, and the detection period configuration control is used to trigger the configuration of the detection period.

[0117] S307. In response to a business data source selection operation performed on the business data source selection control, display the selected business data source.

[0118] In this embodiment of the application, when a business data source is selected by triggering the business data source selection control, the anomaly detection device receives the business data source selection operation performed on the business data source selection control; at this time, the anomaly detection device responds to the operation, obtains the selected business data source and displays it.

[0119] It should be noted that the business data source is selected from the various data sources that have been configured beforehand, and the number of data sources included in the business data source is at least one.

[0120] S308. In response to a metric selection operation applied to the metric selection control for a business data source, display at least one selected metric to be detected, configure metric linkage conditions for at least one metric to be detected, and configure a detection window and anomaly detection rules for each metric to be detected.

[0121] In this embodiment, the business data source and the indicators have a corresponding relationship. Once the business data source is determined, when an indicator is selected from the indicators corresponding to the business data source, the anomaly detection device receives the indicator selection operation applied to the indicator selection control. At this time, the anomaly detection device responds to the indicator selection operation, obtains at least one selected indicator to be detected, and displays it. Next, the anomaly detection device configures indicator linkage conditions for at least one indicator to be detected, and configures a detection window and anomaly detection rules for each indicator to be detected.

[0122] It should be noted that a data source corresponds to at least one metric, a business data source corresponds to at least one data source, and for a business data source, there is at least one metric to be selected; the metric selected from at least one metric constitutes at least one metric to be tested, and each of the at least one metric to be tested is an metric.

[0123] S309. In response to a detection cycle configuration operation performed on the detection cycle configuration control, display the configured detection cycle.

[0124] In this embodiment of the application, when the user triggers the detection period configuration control to configure the detection period, the anomaly detection device also receives the detection period configuration operation applied to the detection period configuration control; at this time, the anomaly detection device responds to the detection period configuration operation, obtains the configured detection period and displays it.

[0125] It is understandable that by selecting a business data source from the configured data source, selecting at least one indicator to be detected from the corresponding indicators of the business data source, configuring a detection period for at least one indicator to be detected, and configuring a detection window and anomaly detection rules for each indicator to be detected, it is possible to perform anomaly detection by combining at least one indicator to be detected. The target detection result obtained is determined from at least one aspect and has high accuracy.

[0126] In this embodiment of the application, the anomaly detection device in S308 configures a detection window and anomaly detection rules for each indicator to be detected, including S3081-S3083. The steps are described below.

[0127] S3081. For each indicator to be detected, display the detection rule configuration page, which includes a detection strategy selection control.

[0128] In this embodiment of the application, after the anomaly detection device displays at least one device to be detected, a corresponding detection rule configuration page will also be displayed for each device to be detected, so as to configure the detection window and anomaly detection rules corresponding to each device to be detected based on the detection rule configuration page.

[0129] It should be noted that the detection strategy selection control is used to select the touch detection strategy, and the detection strategy is the detection algorithm corresponding to each indicator to be detected.

[0130] S3082. In response to the detection strategy selection operation applied to the detection strategy selection control, display the selected indicator detection strategy and the indicator abnormality condition configuration control corresponding to the indicator detection strategy.

[0131] In this embodiment of the application, when a user selects an indicator detection strategy by triggering the detection strategy selection control, the anomaly detection device receives the detection strategy selection operation applied to the detection strategy selection control; at this time, the anomaly detection device responds to the detection strategy selection operation, obtains the selected indicator detection strategy, and displays it.

[0132] It should be noted that the selectable detection strategies include threshold detection strategies, year-on-year and month-on-month comparison detection strategies, and isolated forest detection strategies, while the indicator detection strategies include one or more of these strategies. The threshold detection strategy is a process of anomaly detection through threshold comparison. This comparison can be a direct comparison with a threshold, or it can be a comparison after processing the indicator value (e.g., averaging or summing), etc. This application does not specifically limit the specific comparison. In this case, the indicator anomaly condition configuration control includes an anomaly interval setting control and a suppression count setting control. The anomaly interval setting control is used to set the anomaly interval, for example, greater than or equal to 50, and the suppression count setting control is used to set the suppression count, for example, 2 times or 3 times. This is suitable for anomaly detection of indicators with clearly defined anomaly conditions such as latency and failure rate. The year-on-year and month-on-month comparison detection strategy is a process of anomaly detection by obtaining year-on-year and / or month-on-month indicator values ​​and comparing them. In this case, the indicator anomaly condition configuration control includes a comparison period setting control, an anomaly interval setting control, and a suppression frequency setting control. Here, the comparison period setting control is used to set the comparison period, such as compared to 1 day ago, or compared to 7 days ago. The anomaly interval setting control corresponds to the anomaly interval, such as an increase of 50% or a decrease of 20%. This strategy is suitable for anomaly detection of indicators that focus on differences in historical data magnitude. The isolated forest detection strategy is a process of anomaly detection based on the isolated forest algorithm. In this case, the indicator anomaly condition configuration control also includes a comparison period setting control, anomaly interval setting control, and suppression frequency setting control, or it may include a configuration item selection control. This configuration item selection control is used to select different configuration items to meet the anomaly detection needs of different scenarios without requiring any parameters to be filled in, such as a stable period or a spike period. Different configuration items correspond to a different set of indicator anomaly conditions. This strategy is suitable for all anomaly detection scenarios where there are no hard thresholds for the indicators.

[0133] S3083. In response to the indicator anomaly configuration operation applied to the indicator anomaly configuration control for the indicator detection strategy, the configured detection window and the indicator anomaly conditions corresponding to the detection window are displayed, thereby obtaining the anomaly detection rules including the indicator detection strategy and the indicator anomaly conditions.

[0134] It should be noted that when a user triggers the indicator anomaly condition configuration control to configure the detection window and indicator anomaly conditions, the anomaly detection device receives the indicator anomaly condition configuration operation applied to the indicator anomaly condition configuration control for the indicator detection strategy. At this time, in response to the indicator anomaly condition configuration operation, the configured detection window and the corresponding indicator anomaly conditions are obtained and displayed. Here, the anomaly detection rules include indicator detection strategies and indicator anomaly conditions. The indicator anomaly conditions include at least one of the following: comparison period, anomaly interval, anomaly joint conditions, suppression count, and detection start and end time. The anomaly joint conditions are used to characterize the combination method of the anomaly conditions, such as an AND or OR relationship. The detection start and end time is used to characterize the time range for performing anomaly detection. For example, when the detection start and end time is one day, it is used to detect anomalies in the detection window during the day.

[0135] Accordingly, in the embodiments of this application, S303 can be implemented through S3031; that is, the anomaly detection device detects N index values ​​based on the anomaly detection rules to determine the anomaly detection result corresponding to each index to be detected, including S3031, which will be described below.

[0136] S3031. Based on the indicator detection strategy, determine whether the values ​​of N indicators meet the abnormal conditions of the indicators, so as to determine the abnormal detection result corresponding to each indicator to be detected.

[0137] It should be noted that when the anomaly detection rules include indicator detection strategies and indicator anomaly conditions, the anomaly detection device detects the N indicator values ​​corresponding to the detection window based on the detection method corresponding to the indicator detection strategy, and checks whether the N indicator values ​​meet the indicator anomaly conditions. Here, the result of whether the N indicator values ​​meet the indicator anomaly conditions is the anomaly detection result corresponding to each indicator to be detected.

[0138] For example, when the indicator detection strategy is the threshold algorithm in the threshold detection strategy, the detection method for N indicator values ​​is determined as follows: determine whether each of the N indicator values ​​belongs to the abnormal interval in the indicator abnormality condition, and then combine the abnormal joint condition to determine whether it is abnormal and count the number of abnormalities; and compare the number of abnormalities with the number of suppressions to determine whether to issue an alarm.

[0139] When the indicator detection strategy is the summation threshold algorithm in the threshold detection strategy, the detection method for N indicator values ​​is determined as follows: after accumulating N indicator values, it is determined whether the cumulative sum of the N indicator values ​​belongs to the abnormal range in the indicator abnormal conditions, so as to determine whether to issue an alarm.

[0140] When the indicator detection strategy is the year-on-year comparison algorithm (year-on-year comparison detection strategy), the detection method for N indicator values ​​is determined as follows: each of the N indicator values ​​is judged to be different from the historical data corresponding to each indicator value. If the difference is greater than the set threshold, the point is judged to be abnormal (if comparing data from multiple days, the AND or OR relationship should also be considered, i.e., the joint condition of abnormality). If the number of abnormal indicator values ​​is greater than the number of suppression times, the indicator value is judged to be abnormal.

[0141] In this embodiment, S308 is preceded by S310-S313; that is, before the anomaly detection device displays at least one selected indicator to be detected in response to the indicator selection operation applied to the indicator selection control for the business data source, the anomaly detection method further includes S310-S313, and each step is described below.

[0142] S310. Display the indicator configuration page, which includes an indicator-associated data source selection control, an indicator configuration control, and an indicator model configuration control.

[0143] In this embodiment, before selecting at least one indicator to be detected for the business data source, the anomaly detection device also includes an indicator configuration process, whereby the selected at least one indicator is chosen from the configured indicators. Here, the configuration process for each indicator to be detected is described. When the user configures each indicator to be detected, an indicator configuration page is displayed, allowing configuration of each indicator through this page.

[0144] It should be noted that the indicator association data source selection control is used to trigger the configuration of the business data source associated with each indicator to be detected.

[0145] S311. In response to the indicator-associated data source selection operation performed on the indicator-associated data source selection control, display the selected business data source.

[0146] It should be noted that when configuring each indicator to be detected, the user first selects the business data source. Here, when the user triggers the indicator-associated data source selection control to select the business data source, the anomaly detection device also receives the indicator-associated data source selection operation applied to the indicator-associated data source selection control. At this time, the anomaly detection device responds to the indicator-associated data source selection operation, obtains the selected business data source, and displays it.

[0147] S312. In response to the indicator configuration operation performed on the indicator configuration control, display each configured indicator to be detected.

[0148] It should be noted that when a user triggers the indicator configuration control to configure each indicator to be detected for the selected business data source, the anomaly detection device also receives the indicator configuration operation applied to the indicator configuration control; at this time, the anomaly detection device responds to the indicator configuration operation, obtains each configured indicator to be detected and displays it.

[0149] Here, each metric to be tested is configured to include one or more of the following: metric identifier, metric description information, and metric unit; wherein, the metric identifier is used to represent each metric to be tested, the metric description information is the description information of each metric to be tested, and the metric unit is the unit of each metric to be tested, such as "%".

[0150] S313. In response to an indicator model configuration operation performed on the indicator model configuration control, display the configured indicator model.

[0151] It should be noted that when configuring each indicator to be detected, a calculation method for obtaining the corresponding indicator value is also configured for each indicator, i.e., the indicator model. When the user triggers the indicator model configuration control to configure the indicator model for each indicator to be detected, the anomaly detection device receives the indicator model configuration operation applied to the indicator model configuration control. At this time, the anomaly detection device responds to the indicator model configuration operation, obtains the configured indicator model, and displays it.

[0152] Here, the model parameters in the indicator model are the data fields in the business data source.

[0153] In this embodiment of the application, the anomaly detection device in S302 calculates the index value corresponding to each index to be detected based on the business data source, including S3021 and S3022. The steps are described below.

[0154] S3021. Obtain the parameter data corresponding to the model parameters from the business data source.

[0155] It should be noted that since the value of each indicator to be detected is calculated based on the indicator model of each indicator, and the model parameters in the indicator model are data fields in the business data source; therefore, the anomaly detection device can obtain the data corresponding to the model parameters from the business data source, and thus obtain the parameter data, so as to calculate the indicator value based on the parameter data.

[0156] S3022. Calculate the parameter data based on the indicator model to determine the indicator value corresponding to each indicator to be detected.

[0157] It should be noted that after the anomaly detection equipment obtains the parameter data, since the index model also includes the relationship between the model parameters, it can calculate the parameter data based on the relationship between the model parameters in the index model. The calculation result obtained is the index value corresponding to each index to be detected.

[0158] It is understood that, since this embodiment of the application can perform each indicator to be detected for the business data source, at least one indicator to be detected can be selected from the configured indicators when performing anomaly detection on the business data source. Therefore, the configuration of the indicators to be detected provides the conditions for the joint implementation of anomaly detection by indicators.

[0159] In this embodiment, S311 can be implemented through S3111 and S3112; that is, before the anomaly detection device displays the selected business data source in response to the indicator-associated data source selection operation on the indicator-associated data source selection control, the anomaly detection method further includes S3111 and S3112, and each step is described below.

[0160] S3111 Display the data source configuration page, which includes data source configuration controls.

[0161] It's important to note that before configuring each metric to be detected for the business data source, the anomaly detection device also includes a data source configuration process. The business data source is selected from the configured data sources. Here, when a user triggers the data source configuration operation, the anomaly detection device responds to this operation by displaying the data source configuration page. The data source configuration control is used to trigger the data source configuration.

[0162] S3112. In response to a data source configuration operation performed on the data source configuration control, display the configured business data source.

[0163] In this embodiment of the application, the configuration process of the data source is illustrated by taking the configuration of the business data source as an example: when the user triggers the data source configuration control to configure the business data source, the anomaly detection device also receives the data source configuration operation performed on the data source configuration control; at this time, the anomaly detection device obtains the business data source and displays it.

[0164] It should be noted that the business data source includes one or more of the following: data source identifier, data source description information, data source access method, data latency, and data granularity. Therefore, when a user triggers the data source configuration control to configure the business data source—for example, when the user inputs the data source identifier, data source description information, data source access method, data latency, and data granularity through the data source configuration control—the anomaly detection device receives the data source configuration operation applied to the data source configuration control. Here, the data source identifier represents the data source; the data source description information describes the business data source; the data source access method is the access method for the business data source, enabling access to the business data source and obtaining the corresponding business data; the data latency is the delay time for obtaining business data from the business data source, for example, 120 minutes; and the data granularity is the minimum time period for data processing, for example, 1 minute or 1 hour. Furthermore, the detection period is an integer multiple of the data granularity; therefore, the detection period can be one detection granularity or multiple detection granularities.

[0165] Understandably, by configuring the data source, a way to actively obtain business data from external data sources is achieved, eliminating the need to report business data from external data sources and reducing the efficiency and resource consumption of business data acquisition.

[0166] In this embodiment of the application, the abnormal indicator configuration page displayed in S306 also includes a filter condition configuration control; at this time, before the abnormal detection device calculates the indicator value corresponding to each indicator to be detected based on the business data source in S302, the abnormal detection method also includes S314, which will be described below.

[0167] S314. In response to a filter configuration operation performed on the filter configuration control, display the configured data filter conditions.

[0168] It should be noted that during the configuration process before anomaly detection, for at least one metric to be detected, data filtering conditions are also configured. These data filtering conditions represent the dimensions corresponding to at least one metric to be detected. Therefore, when a user triggers the filtering condition configuration control to configure dimensions for at least one metric to be detected, the anomaly detection device receives the filtering condition configuration operation applied to the filtering condition configuration control. At this time, the anomaly detection device responds to the filtering condition configuration operation, obtains the configured data filtering conditions, and displays them.

[0169] Accordingly, in this embodiment of the application, the anomaly detection device in S302 calculates the index value corresponding to each index to be detected based on the business data source, including S3023-S3025. Each step is described below.

[0170] S3023, Obtain data filtering conditions.

[0171] It should be noted that since the anomaly detection device has previously configured anomaly detection dimensions for at least one indicator to be detected, the anomaly detection device is able to obtain the dimensions configured for anomaly detection for at least one indicator to be detected, i.e., the data filtering conditions.

[0172] S3024. Obtain the data to be tested that meets the data filtering conditions from the business data source.

[0173] In this embodiment of the application, after the anomaly detection device obtains the data filtering conditions, it filters business data from the business data source based on the data filtering conditions. The filtered business data corresponds to the dimension for anomaly detection, i.e., the data to be detected.

[0174] S3025. Based on the data to be tested, calculate the index value corresponding to each index to be tested.

[0175] It should be noted that the index value obtained by the anomaly detection equipment for each index to be detected is the index value corresponding to each dimension.

[0176] In this embodiment of the application, before the anomaly detection device displays the configured data filtering conditions in response to the filtering condition configuration operation applied to the filtering condition configuration control in S314, the anomaly detection method further includes S315-S317, and each step is described below.

[0177] S315. Display the dimension configuration page, which includes a dimension-associated data source selection control and a dimension configuration control.

[0178] In this embodiment, before the anomaly detection device obtains the configured data filtering conditions, it also includes a configuration process for each dimension. Here, when a user configures a dimension by triggering a dimension configuration operation, the anomaly detection device responds to the triggered dimension configuration operation and displays the dimension configuration page.

[0179] It should be noted that the dimension-related data source selection control is used to trigger the selection of business data sources, while the dimension configuration control is used to trigger the configuration of dimensions.

[0180] S316. In response to the indicator-associated data source selection operation performed on the indicator-associated data source selection control, display the selected business data source.

[0181] In this embodiment, the configured dimension corresponds to the business data source. Therefore, when configuring the dimension, the user first selects the business data source. When the user triggers the indicator-associated data source selection control to select the business data source, the anomaly detection device receives the indicator-associated data source selection operation performed on the indicator-associated data source selection control. At this time, the anomaly detection device responds to the indicator-associated data source selection operation, obtains the selected business data source, and displays it.

[0182] S317. In response to a dimension configuration operation applied to a dimension configuration control for a business data source, display the configured data dimensions.

[0183] In this embodiment of the application, when a user triggers the dimension configuration control to configure dimensions for the selected business data source, the anomaly detection device receives the dimension configuration operation applied to the dimension configuration control for the business data source; at this time, the anomaly detection device responds to the dimension configuration operation, obtains the configured data dimensions and displays them, thus completing the dimension configuration.

[0184] It should be noted that data dimensions include one or both of the dimension field identifier and dimension field description information. Data dimensions are data fields in the business data source. Generally speaking, data dimensions are string-type data fields in the business data source, while model parameters in the indicator model are numeric data fields in the business data source.

[0185] Accordingly, in this embodiment of the application, in S314, the anomaly detection device responds to the filter condition configuration operation applied to the filter condition configuration control and displays the configured data filter conditions, including S3141, which will be described below.

[0186] S3141. In response to a filter configuration operation performed on the filter configuration control, display the data filter criteria selected from the data dimensions.

[0187] It should be noted that the data filtering conditions obtained by the anomaly detection device are composed of data dimensions selected from various configured data dimensions.

[0188] It is understandable that by configuring dimensions and selecting dimensions for anomaly detection from the configured dimensions, anomaly detection can support the calculation of at least one indicator to be detected under different dimensions, thereby achieving finer-grained anomaly detection and improving the detection granularity of anomaly detection.

[0189] In this embodiment of the application, when the indicator detection strategy includes the isolated forest detection strategy, the anomaly detection device in S3031 determines whether the N indicator values ​​meet the indicator anomaly conditions based on the indicator detection strategy, so as to determine the anomaly detection result corresponding to each indicator to be detected, including S3031 and S3032. The steps are described below.

[0190] S3031. Based on the isolated forest detection strategy, compare N index values ​​with the N historical index values ​​corresponding to the detection window of the preset historical period number to obtain the anomaly comparison score of the preset period number, and obtain the number of anomaly scores greater than the anomaly threshold among the anomaly comparison scores of the preset historical period number.

[0191] It should be noted that the anomaly detection device acquires N historical indicator values ​​corresponding to a preset number of historical period detection windows for N indicator values. Among them, the N historical indicator values ​​are year-on-year indicator values ​​or month-on-month indicator values; for example, it acquires N year-on-year indicator values ​​corresponding to the previous 5 periods; or it acquires N month-on-month indicator values ​​corresponding to the previous 3 days.

[0192] Here, the preset number of historical period detection windows corresponds to N historical indicator values, i.e., N historical indicator values ​​in a preset number of historical period groups. Each group of N historical indicator values, after comparison with the N indicator values, corresponds to an anomaly comparison score. Therefore, when the anomaly detection device completes the comparison of the N historical indicator values ​​in the preset number of historical period groups with the N indicator values, it can obtain the preset number of anomaly comparison scores. The number of anomaly scores is the number of anomaly comparison scores in the preset number of historical period scores that are greater than the anomaly threshold.

[0193] In addition, an anomaly can be detected when the anomaly comparison score is less than the anomaly threshold. In this case, the number of anomaly scores is the number of anomaly comparison scores less than the anomaly threshold among the anomaly comparison scores of the preset historical period.

[0194] Understandably, comparing current metric values ​​with historical metric values ​​for anomaly detection improves the accuracy of anomaly detection based on the isolated forest algorithm.

[0195] S3032. When the number of abnormal scores is greater than the abnormal number threshold, and the abnormal directions among the abnormal scores are consistent, determine N index values ​​that meet the index abnormality conditions, thereby obtaining the target detection result that detected the abnormality.

[0196] It should be noted that when the number of outlier scores is not greater than the outlier threshold, the preliminary detection result is normal. When the number of outlier scores is greater than the outlier threshold, the preliminary detection result is abnormal. If the outlier scores in this case have the same direction of abnormality, it indicates that the mutation direction is the same, and only then is it confirmed that an abnormality has been detected.

[0197] Understandably, by comparing with historical data, using a projection mechanism (i.e. judging by the number of anomalies) and detecting the direction of anomalies, the target anomaly detection results are determined, thus avoiding the influence of dirty data on the anomaly detection results and improving the accuracy of the target detection results.

[0198] In this embodiment of the application, in S3031, the anomaly detection device compares N index values ​​with the N historical index values ​​corresponding to the detection window of the preset historical period number to obtain the anomaly comparison score of the preset period number, including S30311-S30315. Each step is described below.

[0199] S30311. Obtain the current statistical characteristics corresponding to N indicator values.

[0200] In this embodiment of the application, after the anomaly detection device obtains N indicator values, it does not directly detect the N indicator values, but extracts the data features corresponding to the N indicator values. Here, the anomaly detection device extracts statistical features from the N indicator values, thus obtaining the current statistical features. In other words, the current statistical features are the statistical features corresponding to the N indicator values.

[0201] It should be noted that the current statistical characteristics include one or more of the following: current maximum value, current minimum value, current mean, current variance, and current range. Among them, the current maximum value is the largest indicator value among N indicator values, the current minimum value is the smallest indicator value among N indicator values, the current mean is the mean of N indicator values, the current variance is the variance of N indicator values, and the current range is the range of N indicator values.

[0202] S30312. Obtain the historical statistical features corresponding to the N historical index values ​​of the detection window.

[0203] In this embodiment of the application, in order to compare the N historical index values ​​with the current statistical features, the anomaly detection device also extracts the statistical features of the N historical index values, thus obtaining the historical statistical features.

[0204] It should be noted that historical statistical characteristics include one or more of the following: historical maximum, historical minimum, historical mean, historical variance, and historical range. Among them, the historical maximum is the largest historical indicator value among N historical indicator values, the historical minimum is the smallest historical indicator value among N historical indicator values, the historical mean is the average of N historical indicator values, the historical variance is the variance of N historical indicator values, and the historical range is the range of N historical indicator values.

[0205] S30313. Obtain the feature ratio of the current statistical feature to the historical data statistical feature, thereby obtaining the feature ratio of the preset number of periods.

[0206] It should be noted that the feature ratio between the current statistical feature and the historical data statistical feature is a set of ratios. Since it includes a preset number of historical data statistical features, each historical data statistical feature corresponds to a feature ratio with the current statistical feature, so the anomaly detection device can obtain a preset number of feature ratios.

[0207] S30314. Standardize the characteristic ratio of the preset number of cycles.

[0208] In the embodiments of this application, the anomaly detection device can achieve standardization by converting the feature ratio into a value that conforms to a normal distribution.

[0209] For example, standardization can be achieved through equation (1), which is:

[0210] (1)

[0211] in, The value is one of the values ​​in the current statistical data corresponding to the indicator value; This refers to the value of one of the historical statistical data points corresponding to the historical indicator value. It is one of the ratios in the characteristic ratios; The weight corresponding to each indicator to be detected; For the preset number of cycles The corresponding standard deviation.

[0212] Understandably, by standardizing the feature ratios and transforming them into values ​​with the same dimension, anomaly detection can be achieved by maintaining only a single confidence range and building a monitoring model for different indicators to be detected, thus reducing the resource consumption of anomaly detection. Furthermore, different weights can be assigned to different indicators to be detected, allowing users to customize which indicator needs to be monitored based on their specific needs and scenarios.

[0213] S30315. Based on the preset weights, input the standardized feature ratios into the multidimensional isolated forest model to obtain the anomaly scores for a preset number of periods.

[0214] It should be noted that each statistical feature corresponds to a weight, and here, the preset weights are the set of weights corresponding to each statistical feature. Furthermore, the anomaly detection device is pre-trained with a multidimensional isolated forest model for determining anomaly scores; additionally, the multidimensional isolated forest model possesses multidimensionality, meaning it can obtain anomaly scores based on multidimensional data corresponding to multiple statistical features.

[0215] Understandably, by setting a weight for each statistical feature, the problem of mismatch between output and business scenario can be solved.

[0216] See Figure 4 , Figure 4 This is an optional interactive schematic diagram of the anomaly detection method provided in the embodiments of this application; as shown... Figure 4 As shown in the embodiment of this application, when the target detection result is that an anomaly is detected, after obtaining the target detection result in S305, the anomaly detection method further includes S318-S322, and each step is described below.

[0217] S318. Perform attribution processing on the target detection results to obtain anomaly extended information.

[0218] It should be noted that when the target detection result indicates that an anomaly has been detected, it signifies that an alarm message needs to be sent. At this time, the anomaly detection device performs attribution processing on the target detection result to obtain richer alarm information; here, the attribution processing result obtained by the anomaly detection device is the anomaly extended information, such as the release event and experimental changes.

[0219] S319. Combine one or more of the following into anomaly information: extended anomaly information, business data source, at least one indicator to be detected, detection window, and anomaly details.

[0220] In this embodiment of the application, the abnormal information is the alarm information to be sent, including one or more of the following: abnormal extended information, business data source, at least one indicator to be detected, detection window, and abnormal details; wherein, the abnormal details are determined based on abnormal detection rules and N indicator values, such as alarm details.

[0221] S320. Obtain at least one abnormal sending strategy for a target indicator, wherein the abnormal sending strategy includes a sending channel and a sending target.

[0222] In this embodiment of the application, when the anomaly detection device obtains and sends anomaly information, it can obtain the anomaly sending strategy because a corresponding anomaly sending strategy, namely the sending channel and sending object of the anomaly information, is pre-configured for at least one indicator to be detected.

[0223] It should be noted that the sending channels may include instant messaging clients, telephones, SMS messages, etc., and the recipients may include on-duty personnel, telephone numbers, instant messaging accounts, etc.

[0224] S321. Send an exception message to the recipient through the sending channel.

[0225] It should be noted that the anomaly detection device sends anomaly information based on the acquired sending channel and recipient to complete the alarm message transmission. Here, the recipient corresponds to the feedback device.

[0226] S322. The feedback device corresponding to the sending object displays the abnormal information based on the abnormal shielding information, and displays the rule modification page in response to the rule modification operation for the abnormal information.

[0227] It should be noted that after the anomaly detection device sends an anomaly message to the sending object, the corresponding feedback device also receives the anomaly message. Since the previous display configuration for the anomaly message included anomaly masking information, which determines the displayed content of the anomaly message (e.g., text content and / or curve information), the feedback device displays the anomaly message based on this masking information. Here, the feedback device displays a rule modification page to modify the anomaly configuration information.

[0228] In this embodiment, when the sending object modifies the rules for the displayed anomaly information, for example, by clicking the "Modify Alarm Rule" button, the feedback device receives the rule modification operation. At this time, the feedback device responds to the rule modification operation by displaying a rule modification page for modifying anomaly configuration information. Here, the anomaly configuration information includes one or more of the following: anomaly detection rules, at least one indicator to be detected, indicator linkage conditions, detection window, and anomaly masking information. Therefore, the rule modification page includes modification controls corresponding to one or more of the following: anomaly detection rules, at least one indicator to be detected, indicator linkage conditions, detection window, and anomaly masking information.

[0229] See also Figure 4 In this embodiment of the application, after S322, the anomaly detection method further includes S323 and S324, and each step is described below.

[0230] S323. Receive feedback information sent by the feedback terminal device in response to abnormal information.

[0231] It should be noted that when the sending object modifies the abnormal configuration information through the rule modification page, the feedback device also receives the operation performed on the rule modification page. In response to the operation performed on the rule modification page, it generates feedback information and sends the feedback information to the anomaly detection device. At this time, the anomaly detection device also receives the feedback information sent for the abnormal information.

[0232] S324. Based on the feedback information, update the anomaly detection configuration information to perform anomaly detection based on the updated anomaly configuration information.

[0233] Here, the updated anomaly configuration information includes one or more of the following: updated anomaly detection rules, updated at least one indicator to be detected, updated indicator linkage conditions, updated detection window, and updated anomaly masking information.

[0234] In this embodiment, steps S325-S327 are included before step S320; that is, before the anomaly detection device obtains the anomaly transmission strategy of at least one indicator to be detected, the anomaly detection method further includes steps S325-S327. Each step is described below.

[0235] S325. For each indicator to be detected, display the sending strategy configuration page, which includes a hierarchical configuration control.

[0236] It should be noted that each metric to be detected corresponds to a sending strategy, and the sending strategy for each metric is pre-configured. Here, when the user triggers a configuration operation for the sending strategy for each metric to be detected, the anomaly detection device responds to the configuration operation of that sending strategy by displaying the sending strategy configuration page, allowing the user to configure the sending strategy through the sending strategy configuration page.

[0237] Here, the hierarchical configuration control is used to set different levels of sending strategies for each metric to be detected.

[0238] S326. In response to a hierarchical configuration operation performed on the hierarchical configuration control, display the configured sending level and the corresponding sending strategy configuration control.

[0239] In this embodiment of the application, when the user triggers the hierarchical configuration control to set different levels of sending strategies for each indicator to be detected, the anomaly detection device also receives the hierarchical configuration operation applied to the hierarchical configuration control; at this time, the anomaly detection device responds to the hierarchical configuration operation, obtains the configured sending level, and displays the sending level and the sending strategy configuration control corresponding to the sending level.

[0240] It should be noted that the sending strategy configuration control is used to trigger the configuration processing of the sending strategy at the sending level.

[0241] S327. In response to the sending policy configuration control acting on the sending policy configuration control, display the configured sending channels and sending objects, thereby obtaining indicators including sending level, sending channel and sending object abnormal sending policy.

[0242] In this embodiment, when a user triggers the sending strategy configuration control to configure the sending strategy corresponding to the sending level, the anomaly detection device receives the sending strategy configuration control applied to it. At this time, the anomaly detection device responds to the sending strategy configuration control to obtain the configured sending channel and sending object. Thus, the anomaly detection device obtains the indicator anomaly sending strategy, including the sending level and the corresponding sending channel and sending object. Here, the indicator anomaly sending strategy refers to the sending strategy corresponding to each indicator to be detected.

[0243] Accordingly, in this embodiment of the application, the anomaly detection device in S320 acquires the anomaly transmission strategy of at least one indicator to be detected, including: the anomaly detection device selects an indicator anomaly transmission strategy from at least one indicator anomaly transmission strategy based on the priority of the transmission level in the indicator anomaly transmission strategy of each indicator to be detected, and uses it as the anomaly transmission strategy of at least one indicator to be detected. That is, the anomaly detection device selects the indicator anomaly transmission strategy corresponding to the highest priority transmission level as the anomaly transmission strategy of at least one indicator to be detected.

[0244] In this embodiment of the application, a triggering condition is also set for each transmission level. For example, the P0 level transmission strategy is triggered when the indicator value is greater than 20.

[0245] In this embodiment, after the anomaly detection device displays the configured sending level and the corresponding sending strategy configuration control in response to the hierarchical configuration operation applied to the hierarchical configuration control, the anomaly detection method further includes: displaying the configured sending channel, sending object, and anomaly aggregation conditions in response to the sending strategy configuration control applied to the sending strategy configuration control, thereby obtaining an indicator anomaly sending strategy including sending level, sending channel, sending object, and anomaly aggregation conditions; that is, for each sending level corresponding to each indicator to be detected, it includes sending driver, sending object, and anomaly aggregation conditions; wherein, the anomaly aggregation conditions refer to the aggregation information of anomaly information, such as aggregation time, aggregation number, etc.

[0246] Accordingly, in this embodiment, the anomaly detection device in S318 performs attribution processing on the target detection result to obtain anomaly extension information, including: when the target detection result meets the anomaly aggregation condition, the anomaly detection device performs attribution processing on the target detection result to obtain anomaly extension information. That is, the anomaly detection device only performs attribution processing when the anomaly aggregation condition is met.

[0247] In this embodiment of the application, the sending strategy configuration page also includes a title setting control; therefore, the anomaly detection method further includes: the anomaly detection device responds to the title setting operation on the title setting control and displays the set anomaly title; at this time, in S319, the anomaly detection device combines one or more of the following into anomaly information: anomaly extended information, business data source, at least one indicator to be detected, detection window, and anomaly details.

[0248] It should be noted that the anomaly detection method provided in this application embodiment is not specifically limited to the application field. For example, it can be applied to anomaly detection in the multimedia field such as advertising, and it can also be applied to anomaly detection in the artificial intelligence field such as model training, etc.

[0249] The following will describe an exemplary application of the embodiments of this application in a real-world application scenario.

[0250] For example, see Figure 5 , Figure 5 This is an exemplary anomaly detection system architecture diagram provided in an embodiment of this application; as shown... Figure 5As shown, the anomaly detection system 5-1 includes a presentation layer 5-11, a logic layer 5-12, and a storage layer 5-13. Here, the presentation layer 5-11 includes an alarm configuration module 5-111, an alarm information display module 5-112, and a negative feedback module 5-113; the logic layer 5-12 includes a service scheduling module 5-121, a data module 5-122, an algorithm module 5-123, and a business module 5-124; the storage layer 5-13 includes a configuration data storage module 5-131, an alarm source data storage module 5-132, and a data source module 5-133; wherein:

[0251] Alarm configuration module 5-111 is used for various configurations related to anomaly detection, including data source configuration, metric configuration, dimension configuration, alarm rule (anomaly detection rule and detection window) configuration, and sending strategy configuration. See [link / reference]. Figures 6 to 16 .

[0252] See Figure 6 , Figure 6 This is a schematic diagram of an exemplary data source configuration page provided in an embodiment of this application; as shown... Figure 6 As shown, the data source configuration page 6-1 displays a data source configuration control 6-11, a cancel button 6-12, and an confirm button 6-13. The data source configuration control 6-11 is used to configure the table name (data source identifier), table description (data source description information), access method (data source access method), table delay (data delay), and table granularity (data granularity). The table name is the actual table name in the database, the table description is the Chinese name of the table, the access method is the table's query information (including database address, username, password, and time dimension, etc., which differ between different databases), the table delay is the data delay time, and the table granularity is the smallest data time granularity (e.g., 1 minute / 5 minutes / 1 hour / 1 day). The cancel button 6-12 is used to cancel the configured data source (business data source), and the confirm button 6-13 is used to complete the data source configuration. Additionally, if the configured data source is reported data, the data source configuration control 6-11 is used to configure the feature name, feature identifier, access method, feature delay, and feature granularity. Figure 6 (Not shown in the image).

[0253] You can also manage the configured data sources through the data source list page, see [link / reference]. Figure 7 , Figure 7 This is a schematic diagram of an exemplary data source list page provided in an embodiment of this application; as shown... Figure 7As shown, the data source list page 7-1 displays a page title (7-11) including the data source type, a query control (7-12), a data source configuration trigger control (7-13), a data source list (7-14), and a data source editing control (7-15). The data source list 7-14 is managed through the query control (7-12), the data source configuration trigger control (7-13), the data source list (7-14), and the data source editing control (7-15). Furthermore, when the data source configuration trigger control (7-13) is clicked, it displays... Figure 6 See page 6-1 for data source configuration.

[0254] After configuring the data source, you can configure the metrics for that data source (see...). Figure 8 Configuration of ) and dimension fields (see Figure 9 ).in, Figure 8 This is a schematic diagram of an exemplary indicator configuration page provided in an embodiment of this application; as shown... Figure 8 As shown, the indicator configuration page 8-1 displays a page title 8-11, an indicator associated data source selection control 8-12, an indicator configuration control 8-13, an indicator model configuration control 8-14, a cancel button 8-15, and an confirm button 8-16. Among them, the indicator configuration control 8-13 is used to configure the indicator name (description information of the indicator to be tested), indicator identifier (identifier of the indicator to be tested), and indicator unit (unit of the indicator to be tested); the cancel button 8-15 is used to cancel the configured indicator (each indicator to be tested), and the confirm button 8-16 is used to complete the indicator configuration.

[0255] See Figure 9 , Figure 9 This is a schematic diagram of an exemplary dimension configuration page provided in an embodiment of this application; as shown... Figure 9 As shown, the dimension configuration page 9-1 displays a page title 9-11, a dimension-related data source selection control 9-12, a dimension configuration control 9-13, a cancel button 9-14, and an OK button 9-15. Among them, the dimension configuration control 9-13 is used to configure the Chinese (dimension field description information) and English (dimension field identifier) ​​of the dimension field; the cancel button 9-14 is used to cancel the configured dimension field (data dimension); and the OK button 9-15 is used to complete the configuration of the dimension field.

[0256] After configuring the metrics and dimension fields for the data source, you can then configure alerting rules for the configured data source, metrics, and dimensions. See also Figure 10 , Figure 10 This is a schematic diagram of an exemplary alarm rule list page provided in an embodiment of this application; as shown... Figure 10As shown, the alarm rule list page 10-1 displays a page title 10-11, query controls for various keywords 10-12, an alarm rule creation control 10-13, an alarm rule list 10-14, and an alarm rule editing control 10-15. Additionally, on the alarm rule list page 10-1, the alarm ID (Identity Document) is automatically generated after configuring an alarm rule; the relevant personnel refer to the creator and / or administrator. When a user clicks the alarm rule creation control 10-13, the alarm rule configuration operation is triggered, displaying as shown below. Figure 11 The example abnormal indicator configuration page is shown.

[0257] like Figure 11 As shown, the abnormal indicator configuration page 11-1 displays the page title 11-11 and the configuration area 11-12; within the configuration area 11-12, the indicator configuration page title 11-121, the business data source selection control 11-122, the indicator selection control 11-123, the detection period configuration control 11-124, the data latency configuration control 11-125, the dimension selection control 11-126, and the filter condition configuration control 11-127 are displayed.

[0258] It should be noted that the business data source selection controls 11-122 are used to determine the data source type and data table. The data source type includes "Druid", "MySQL", "PgSQL", and other characteristics, while the data table includes the table name and characteristic identifier. The metric selection controls 11-123 are used to select... Figure 8 The pre-configured indicators are the indicators that need to be detected, and multiple indicators can be selected (at least one). The detection cycle configuration controls 11-124 are used to configure the detection cycle, and are based on... Figure 6 This is configured at the table granularity. Data latency configuration controls 11-125 are used to configure data latency, and are based on... Figure 6 The table configuration in the middle is delayed. The filter condition configuration controls 11-127 are used to configure data filtering conditions, including filter conditions and deselection conditions, and are based on... Figure 9 This is done using the dimension fields configured in the configuration.

[0259] Additionally, when a user clicks on the metric selection controls 11-123 to select the two metrics, "Interface Failure Rate" and "Call Volume," the following will be displayed: Figure 12 The example detection rule configuration page is shown.

[0260] like Figure 12As shown, the detection rule configuration page 12-1 displays the page title 12-11, indicator linkage conditions 12-12, the detection rule configuration area 12-13 for the indicator "interface failure rate", and the detection rule configuration area 12-14 for the indicator "call volume". In the detection rule configuration area 12-13, the following are displayed: prompt information 12-131 for the indicator "interface failure rate", detection algorithm selection control 12-132 (detection strategy selection control), indicator abnormal condition configuration control 12-133, detection start and end time configuration control 12-134, abnormal condition add / delete control 12-135, and detection rule add / delete control 12-136; among them, the indicator abnormal condition configuration control 12-133 is used to configure the detection window, suppression count, and abnormal interval. In the detection rule configuration area 12-14, there are the following: prompt information for the indicator "Call Volume" 12-141, detection algorithm selection control 12-142, indicator anomaly condition configuration control 12-143, detection start and end time configuration control 12-144, anomaly condition add / delete control 12-145, and detection rule add / delete control 12-146. Among them, the indicator anomaly condition configuration control 12-143 is used to configure the detection window and anomaly range.

[0261] It should be noted that when a user clicks on the metric selection controls 11-123 and selects the "Playback Stream Full Scale Failure Rate" metric, the following will be displayed: Figure 13 Another exemplary detection rule configuration page is shown. (e.g.) Figure 13 As shown, the detection rule configuration page 13-1 displays a prompt message 13-11 for the metric "Playback Stream Full Scale Failure Rate". When the user clicks the detection algorithm selection control 13-12 and selects the threshold algorithm, the user enters the detection window as 5 minutes, the number of suppression attempts as 2, and the abnormal interval as greater than or equal to 50 in the metric abnormality condition configuration control 13-13. This completes the configuration of the alarm rule for the metric "Playback Stream Full Scale Failure Rate". Here, if the detection period is 1 minute, for the 5 data points corresponding to the detection window, the metric value corresponding to each data point is compared with the abnormal interval. If the metric value corresponding to the data point is within the abnormal interval, the data point is determined to be abnormal. If the number of abnormal data points is greater than the number of suppression attempts, the metric is determined to be abnormal.

[0262] It should also be noted that when a user clicks on the metric selection controls 11-123 to select the "Attribution Success Rate" metric, the following will be displayed: Figure 14 This is another example of a detection rule configuration page. (See example...) Figure 14As shown, the detection rule configuration page 14-1 displays a prompt message 14-11 for the indicator "attribution success rate"; when the user clicks the detection algorithm selection control 14-12 and selects the year-on-year comparison algorithm, the abnormal linkage condition "all" is entered in the indicator abnormal condition configuration control 14-13, the detection window is 5 minutes, the number of suppression times is 2, the comparison period is 1 day ago and 7 days ago, and the abnormal range is an increase of 50 or a decrease of 20 in the month-on-month case and an increase of 50 or a decrease of 20 in the year-on-year case. This completes the configuration of the alarm rule for the indicator "playback stream full table failure rate".

[0263] In addition, regarding Figure 12 When the user clicks the detection algorithm selection control 12-142 and selects the isolated forest algorithm, the following is displayed: Figure 15 This is another example of a detection rule configuration page. (See example...) Figure 15 As shown, on the detection rule configuration page 15-1, enter the start and end time 15-11 in the detection start and end time configuration control 12-144, and click the indicator anomaly condition configuration control 12-143 to select configuration item 15-12; here, the indicator anomaly condition configuration control 12-143 corresponds to different configuration items, each of which includes parameters such as detection window, anomaly interval, suppression at this time, and comparison with historical period.

[0264] Once the alarm rules have been configured for the selected metrics (at least one metric to be monitored), the sending strategy can be configured for each metric (each metric to be monitored). See [link / reference] Figure 16 , Figure 16 This is a schematic diagram of an exemplary sending strategy configuration page provided in an embodiment of this application; as shown... Figure 16 As shown, the sending strategy configuration page 16-1 displays a title setting control 16-11 (used to set the exception title 16-12), an early warning level activation control 16-13 (used to set the early warning level activation status 16-14), a level information import control 16-15 (used to import the level sending strategy), prompt information for indicators 16-16, and a level configuration trigger control 16-17. If the sending level P0 is set for the level configuration trigger control 16-17, then... Figure 16 The hierarchical configuration areas 16-18 display configuration controls for the default sending level and for sending level P0. Both include configurations for the alarm channel (sending channel) and receiver (sending object), as well as configurations for aggregation time and aggregation count. Additionally, controls 16-19 allow for the configuration of maintenance duty shifts for this metric.

[0265] It should be noted that alarm channels include telephone, chat objects (e.g., WeChat), chat groups (e.g., WeChat groups), enterprise objects (e.g., WeChat Work), enterprise chat groups (e.g., WeChat Work groups), and email. Among these, the recipient of the alarm must be specified when telephone is included as an alarm channel.

[0266] The following continues... Figure 5 To explain, Figure 5 The alarm information display module 5-112 is used to display alarm information (abnormal information).

[0267] See Figure 17 , Figure 17 This is an exemplary schematic diagram of displaying alarm information provided in an embodiment of this application; as shown... Figure 17 As shown, the alarm information displayed on page 17-1 of the terminal (feedback device) includes the table name, table description, scenario description (i.e., data filtering conditions), detection window, alarm details (i.e., the data that generated the alarm), and attribution information (including the published event and experimental changes, i.e., anomaly extension information). Additionally, page 17-1 also displays information such as... Figure 18 The curve information 18-1 corresponding to the indicator value is shown; among them, the detection window for alarm information 17-11 is also marked on the curve information 18-1, such as... Figure 18 Mark 18-2 in the text.

[0268] It should be noted that when using multiple indicators for anomaly detection, it is possible to... Figure 19 In the alarm information display page 17-1, select the indicator to be viewed 19-2 using the indicator selection control 19-1, and then view the corresponding indicator curve 19-3.

[0269] The negative feedback module 5-113 is used to modify the blocking information, alarm rules, and sending strategies.

[0270] Below, based on Figure 17 The negative feedback module 5-113 is explained as follows: It can be... Figure 20 In the alarm information display page 17-1, the blocking settings control 20-1 allows for the setting of abnormal blocking information 20-2. Here, the blocking type and blocking time can be set, and the blocking type supports screen modes for curves and entire rules.

[0271] In addition, it can also be done through Figure 21In the alarm information display page 17-1, the alarm configuration tab 21-1 displays the rule modification area 21-2 (rule modification page); on the rule modification area 21-2, the modification information 21-3 for aggregation time and aggregation number, the prompt information 21-4 and the submit button 21-5 are shown for example.

[0272] The following continues... Figure 5 To explain, Figure 5 The service scheduling module 5-121 is used to initiate the anomaly detection process. It reads the warning configuration from the configuration data storage module 5-131 and coordinates the data module 5-122, algorithm module 5-123 and business module 5-124 to complete the anomaly detection process. Here, the data module 5-122, algorithm module 5-123 and business module 5-124 are independent of each other and only provide corresponding functional services by providing interfaces to the outside world.

[0273] Data module 5-122 is used to pull alarm source data (data to be detected) from data source module 5-133 based on the filtering conditions corresponding to the indicators read by service scheduling module 5-121 (data filtering conditions corresponding to at least one indicator to be detected), and to store the pulled alarm source data in alarm source data storage module 5-132. It includes direct import module 5-1221 and calculation import module 5-1222.

[0274] Algorithm modules 5-123 are used for various configuration-based detection algorithms (i.e., indicator detection strategies, for example, Figure 5 The algorithm uses the following algorithms for anomaly detection: L5 / name service detection algorithm 5-1231, Olympic detection algorithm 5-1232, isolated forest detection algorithm 5-1233, threshold detection algorithm 5-1234, and year-on-year / month-on-month comparison detection algorithm 5-1235.

[0275] Business module 5-124 is used for attribution processing and alarm sending processing. It includes business attribution analysis module 5-1241, basic attribution analysis module 5-1242 and other business attribution analysis modules 5-1243, as well as alarm sending module 5-1244.

[0276] The configuration data storage module 5-131 is used to store various configuration data for anomaly detection, which can be implemented using "MySQL".

[0277] The alarm source data storage module 5-132 is used to store business data for anomaly detection, and can be implemented using "HBase".

[0278] Data source module 5-133 is used to filter source data for anomaly detection in business data, including various database systems and reported characteristic data.

[0279] See Figure 22 , Figure 22 This is a schematic flowchart of an exemplary anomaly detection method provided in an embodiment of this application; as shown... Figure 22 As shown, this exemplary anomaly detection method includes the following steps:

[0280] S2201, Start; i.e., the service scheduling module 5-121 triggers the anomaly detection process based on the detection cycle in the set alarm rules.

[0281] S2202. Obtain the configuration information of the data source. The configuration information of the data source obtained by the service scheduling module 5-121 includes the access method of the data source.

[0282] S2203. Determine the method for acquiring business data based on the configuration information of the acquired data source. When the configuration information of the acquired data source is a database access method, read business data from the database; when the configuration information of the acquired data source is a feature access method (i.e., a business reporting method), acquire business data from the business reporting process.

[0283] S2204, Store business data. Data module 5-122 stores business data to alarm source data storage module 5-132.

[0284] S2205. Determine if the business data is valid. The validity is determined by data module 5-122. If valid, proceed to S2206; otherwise, proceed to S2218.

[0285] S2206. Obtain the configuration information of the alarm rules. The service scheduling module 5-121 obtains the configuration information of the alarm rules corresponding to the selected metrics.

[0286] S2207. Determine the detection algorithm interface based on the configuration information of the acquired alarm rules. Executed by algorithm module 5-123.

[0287] S2208. Obtain stored business data. Data module 5-122 reads the stored business data and sends it to algorithm module 5-123.

[0288] S2209. Perform anomaly detection on business data based on the detection algorithm interface. This is executed by algorithm module 5-123.

[0289] S2210, Return the anomaly detection result. Algorithm module 5-123 returns the anomaly detection result to service scheduling module 5-121.

[0290] S2211, Integrate the results of various anomaly detections.

[0291] S2212. Determine whether an alarm should be sent as a result of the integration. If yes, proceed to S2213; otherwise, proceed to S2218.

[0292] S2213. Obtain attribution configuration information based on anomaly detection results. S2213 is triggered by the service scheduling module 5-121 when it determines that the target detection result is an anomaly detected based on the integration results.

[0293] S2214. Attribution processing is performed based on the acquired attribution configuration information. This is done by business module 5-124 based on the dimension fields.

[0294] S2215. Send alarm information based on the attribution processing results. Executed by business module 5-124.

[0295] S2216. Feedback information is received in response to alarm information. This is executed by business module 5-124.

[0296] S2217. Modify configuration information based on feedback information. The business module 5-124 modifies the alarm rules, sending strategies, and anomaly masking information of the configuration data storage module 5-131 based on the feedback information.

[0297] S2218, End; that is, the service scheduling module 5-121 completes the anomaly detection process.

[0298] Next, we will continue with... Figure 5 The data module 5-122 is described below. Data module 5-122 is responsible for implementing the data retrieval logic for various data sources and providing data retrieval / query interfaces to the outside world. See also... Figure 23 , Figure 23 This is an exemplary data retrieval and processing flowchart provided in an embodiment of this application; as shown... Figure 23 As shown, it includes:

[0299] S2301, Start; that is, the data retrieval process begins in data module 5-122.

[0300] S2302, Read the configuration information of the early warning curve group; that is, the data module 5-122 reads the configuration information of the early warning curve group corresponding to the selected indicator from the configuration data storage module 5-131; here, each selected indicator corresponds to an early warning curve group, and the curve in the early warning curve group is the curve of each selected indicator under each dimension field.

[0301] S2303. Determine if the business data for the current detection period is available; to prevent the system from obtaining intermediate data and generating false alarms. If yes, proceed to S2304; otherwise, proceed to S2308.

[0302] S2304. Read the business data for the current detection cycle.

[0303] S2305: Traverse the business data of the current detection period and generate curves.

[0304] S2306. Determine whether the curve generation is complete; if yes, execute S2307; otherwise, execute S2305.

[0305] S2307. Store the generated curve in the database.

[0306] S2308, End; that is, the data retrieval process of data module 5-122 ends.

[0307] It should be noted that in S2307, the table structure of the HBase database used by data module 5-122 is shown in Table 1. The binary code stream "rowkey" is the value after MD5 processing of curve group ID + curve ID + date (year, month, day) to prevent HBase from generating hotspots. The column name is the specific time (hour and minute). The data of each curve for one day is in one "rowkey", which can improve the efficiency of data query.

[0308] Table 1

[0309]

[0310] In Table 1, 10, 20, and 30 are the corresponding indicator values.

[0311] Next, we will continue with... Figure 5 The algorithm module 5-123 is explained in detail. Each time the algorithm module 5-123 completes the anomaly detection, it obtains the anomaly detection result and stores the anomaly detection. If it is stored in HBase, the table structure is as shown in Table 2. The binary code stream "rowkey" is the value after MD5 processing of the warning rule ID + date (year, month, day). The column name is curve ID. All anomaly detection results corresponding to a warning rule are in one "rowkey", which can improve the efficiency of anomaly detection result query.

[0312] Table 2

[0313]

[0314] Below, on Figure 5 The isolated forest detection algorithm 5-123 in algorithm module 5-123 is explained. See [link / reference]. Figure 24 , Figure 24 This application provides an exemplary detection process for a solitary forest detection algorithm; such as... Figure 24 As shown, it includes:

[0315] S2401. Extract the statistical characteristics (current statistical characteristics) of all data points within 1 hour.

[0316] Here, the detection window is 1 hour. When the detection period is 5 minutes, the number of all data points is 12, which corresponds to 12 index values ​​(N index values). The statistical characteristics include five types: maximum / minimum value, mean, variance, and range.

[0317] S2402. Calculate the statistical characteristics (historical statistical characteristics) of the year-on-year data for the previous 5 periods (preset number of periods).

[0318] S2403. Obtain the ratio of the statistical characteristics corresponding to 1 hour to the statistical characteristics of the same period data of the previous 5 periods.

[0319] S2404, Standardize the comparison values.

[0320] The ratio of each statistical feature was standardized using Equation (1) to obtain 5 sets of data including 5 standardized values.

[0321] S2405. Use the weights corresponding to each statistical feature to fuse the 5 standardized values ​​of each group, and input the 5 fusion results into the multidimensional isolated forest model to obtain 5 anomaly scores (anomaly scores).

[0322] See Figure 25 , Figure 25 This is an exemplary standardized processing diagram provided in an embodiment of this application; as shown... Figure 25 As shown, curve 25-1 is the curve of the statistical characteristics corresponding to the indicator value in 1 hour; curve 25-2 is the curve of the ratio of the statistical characteristics corresponding to the indicator value in 1 hour to the statistical characteristics of the year-on-year data of the previous 5 periods; curve 25-3 is the curve obtained by fusing various ratios based on the weights corresponding to each statistical characteristic; finally, curve 25-4 is obtained corresponding to the standardized value.

[0323] S2406. Count the number of abnormal scores that are higher than the scoring threshold (abnormal threshold).

[0324] S2407. When the number of abnormal scores is not less than the voting threshold and the mutation direction is consistent, an anomaly is determined to be detected.

[0325] S2408. When the number of abnormal scores is not less than the voting threshold, but the mutation directions are inconsistent, it is determined that no abnormality has been detected.

[0326] S2409. If the number of abnormal scores is less than the voting threshold, it is determined that no abnormality has been detected.

[0327] Below, on Figure 5 The business module 5-124 is explained in detail. See also... Figure 26 , Figure 26 This is an exemplary flowchart of sending exception information provided in an embodiment of this application; such as Figure 26 As shown, it includes:

[0328] S2601, Start; that is, business module 5-124 begins sending and processing of exception information.

[0329] S2602. Determine whether all anomaly detection results have been generated; here, all anomaly detection results means at least one anomaly detection result; if yes, execute S2603, otherwise execute S2608.

[0330] S2603. Calculate the final detection result (target detection result).

[0331] S2604. Determine whether an alarm needs to be sent based on the final detection result (whether an anomaly has been detected); if yes, proceed to S2605; otherwise, proceed to S2608.

[0332] S2605. Determine whether to send an alarm message immediately based on the abnormal aggregation information; if yes, execute S2606; otherwise, execute S2607.

[0333] S2606. Determine the recipient and the sending channel, and request attribution service.

[0334] S2607, Register the sending time and wait for scheduling; so that S2608 can be executed during scheduling.

[0335] S2608. Send the final detection results and attribution service information to the sending object through the sending channel.

[0336] S2609, End; This means that the processing of exception information sent by business module 5-124 has ended.

[0337] Understandably, since anomaly detection is based on selected metrics, its accuracy is improved. Furthermore, the business data used for anomaly detection includes not only reported data but also data that can be read from configured data sources, improving access efficiency and reducing resource consumption associated with business data access. Additionally, the isolated forest algorithm defines anomalies as a comparison between differences from historical data and a difference threshold, making it applicable even in scenarios where the anomaly threshold cannot be determined, further enhancing accuracy. Moreover, the effective display of alarm information improves the efficiency of alarm notification.

[0338] The following description continues to illustrate the exemplary structure of the anomaly detection device 255 provided in the embodiments of this application as a software module. In some embodiments, such as Figure 2 As shown, the software module stored in the anomaly detection device 255 in the memory 250 may include:

[0339] The detection triggering module 2551 is used to acquire the anomaly detection rules and business data sources for each of the at least one detectable indicators in the detection window when the detection time is determined based on the detection cycle.

[0340] Anomaly detection module 2552 is used to calculate the index value corresponding to each index to be detected based on the business data source, thereby obtaining N index values ​​corresponding to the detection window, where N is a positive integer determined based on the ratio of the detection window to the detection period;

[0341] Result determination module 2553 is used to detect the N index values ​​based on the anomaly detection rules to determine the anomaly detection result corresponding to each index to be detected, thereby obtaining at least one anomaly detection result corresponding to the at least one index to be detected.

[0342] Condition acquisition module 2554 is used to acquire the indicator linkage conditions corresponding to the at least one indicator to be detected.

[0343] The result integration module 2555 is used to integrate at least one abnormal detection result based on the indicator linkage conditions to obtain the target detection result.

[0344] In this embodiment, the anomaly detection device 255 further includes an anomaly configuration module 2556, used to display an anomaly indicator configuration page, wherein the anomaly indicator configuration page includes a business data source selection control, an indicator selection control, and a detection period configuration control; in response to a business data source selection operation performed on the business data source selection control, the selected business data source is displayed; in response to an indicator selection operation performed on the indicator selection control for the business data source, the selected at least one indicator to be detected is displayed, and the indicator linkage conditions are configured for the at least one indicator to be detected, and the detection window and the anomaly detection rule are configured for each indicator to be detected; in response to a detection period configuration operation performed on the detection period configuration control, the configured detection period is displayed.

[0345] In this embodiment, the anomaly configuration module 2556 is further configured to display a detection rule configuration page for each indicator to be detected, wherein the detection rule configuration page includes a detection strategy selection control; in response to a detection strategy selection operation performed on the detection strategy selection control, display the selected indicator detection strategy and the indicator anomaly condition configuration control corresponding to the indicator detection strategy, wherein the indicator detection strategy includes one or more of a threshold detection strategy, a year-on-year / month-on-month comparison detection strategy, and a lone forest detection strategy; in response to an indicator anomaly condition configuration operation performed on the indicator anomaly condition configuration control for the indicator detection strategy, display the configured detection window and the indicator anomaly condition corresponding to the detection window, thereby obtaining the anomaly detection rule including the indicator detection strategy and the indicator anomaly condition.

[0346] In this embodiment of the application, the result determination module 2553 is further configured to determine whether the N index values ​​meet the index abnormality conditions based on the index detection strategy, so as to determine the abnormal detection result corresponding to each index to be detected.

[0347] In this embodiment, the exception configuration module 2556 is further configured to display an indicator configuration page, wherein the indicator configuration page includes an indicator-associated data source selection control, an indicator configuration control, and an indicator model configuration control; in response to an indicator-associated data source selection operation performed on the indicator-associated data source selection control, the selected business data source is displayed; in response to an indicator configuration operation performed on the indicator configuration control, each configured indicator to be detected is displayed, wherein each indicator to be detected includes one or more of an indicator identifier to be detected, an indicator description information to be detected, and an indicator unit to be detected; in response to an indicator model configuration operation performed on the indicator model configuration control, the configured indicator model is displayed, wherein the model parameters in the indicator model are data fields in the business data source.

[0348] In this embodiment of the application, the anomaly detection module 2552 is further configured to obtain parameter data corresponding to the model parameters from the business data source; and to calculate the parameter data based on the indicator model to determine the indicator value corresponding to each indicator to be detected.

[0349] In this embodiment of the application, the abnormal configuration module 2556 is further configured to display a data source configuration page, wherein the data source configuration page includes a data source configuration control; in response to a data source configuration operation performed on the data source configuration control, the configured business data source is displayed, wherein the business data source includes one or more of the following: data source identifier, data source description information, data source access method, data latency, and data granularity, wherein the detection period is an integer multiple of the data granularity.

[0350] In this embodiment of the application, the abnormal indicator configuration page also includes a filter condition configuration control; the abnormal configuration module 2556 is further configured to display the configured data filter conditions in response to the filter condition configuration operation performed on the filter condition configuration control.

[0351] In this embodiment of the application, the anomaly detection module 2552 is further configured to obtain the data filtering conditions; obtain the data to be detected that meets the data filtering conditions from the business data source; and calculate the indicator value corresponding to each indicator to be detected based on the data to be detected.

[0352] In this embodiment, the exception configuration module 2556 is further configured to display a dimension configuration page, wherein the dimension configuration page includes a dimension-related data source selection control and a dimension configuration control; in response to an indicator-related data source selection operation performed on the indicator-related data source selection control, the selected business data source is displayed; in response to a dimension configuration operation performed on the dimension configuration control for the business data source, the configured data dimension is displayed, wherein the data dimension includes one or both of dimension field identifier and dimension field description information, and the data dimension is a data field in the business data source.

[0353] In this embodiment of the application, the exception configuration module 2556 is further configured to display the data filtering conditions selected from the data dimension in response to the filtering condition configuration operation performed on the filtering condition configuration control.

[0354] In this embodiment of the application, when the indicator detection strategy includes the isolated forest detection strategy, the result determination module 2553 is further configured to, based on the isolated forest detection strategy, compare the N indicator values ​​with the N historical indicator values ​​corresponding to the detection window of the preset historical period number, obtain the preset period number of abnormal comparison scores, and obtain the number of abnormal scores greater than the abnormal threshold among the preset historical period number of abnormal comparison scores, wherein the N historical indicator values ​​are year-on-year indicator values ​​or month-on-month indicator values; when the number of abnormal scores is greater than the abnormal number threshold, and the abnormal directions among the abnormal scores of the abnormal scores are consistent, it is determined that the N indicator values ​​meet the indicator abnormality condition, thereby obtaining the target detection result that an abnormality has been detected.

[0355] In this embodiment, the result determination module 2553 is further configured to obtain the current statistical features corresponding to the N indicator values, wherein the current statistical features include one or more of the current maximum value, current minimum value, current mean, current variance, and current range; obtain the historical statistical features corresponding to the N historical indicator values ​​corresponding to the detection window; obtain the feature ratio of the current statistical features to the historical data statistical features, thereby obtaining the feature ratio of the preset number of periods; perform standardization processing on the feature ratio of the preset number of periods; and input each standardized feature ratio into a multidimensional isolated forest model based on preset weights to obtain the outlier score of the preset number of periods, wherein the multidimensional isolated forest model is used to determine the outlier score.

[0356] In this embodiment, the anomaly detection device 255 further includes a result sending module 2557, used to perform attribution processing on the target detection result to obtain anomaly extended information; combine one or more of the anomaly extended information, the business data source, the at least one indicator to be detected, the detection window, and anomaly details into anomaly information, wherein the anomaly details are determined based on the anomaly detection rules and the N indicator values; obtain an anomaly sending strategy for the at least one indicator to be detected, wherein the anomaly sending strategy includes a sending channel and a sending target; and send the anomaly information to the sending target through the sending channel, so that...

[0357] The feedback device corresponding to the sending object displays the abnormal information based on the abnormal shielding information, and in response to the rule modification operation for the abnormal information, displays a rule modification page to modify the abnormal configuration information based on the rule modification page. The abnormal configuration information includes one or more of the following: the abnormal detection rule, the at least one indicator to be detected, the indicator linkage condition, the detection window, and the abnormal shielding information.

[0358] In this embodiment of the application, the anomaly detection device 255 further includes a configuration modification module 2558, which is used to receive feedback information sent by the feedback terminal device in response to the anomaly information, wherein the feedback information is obtained in response to an operation performed on the rule modification page; based on the feedback information, the anomaly detection configuration information is updated to perform anomaly detection based on the updated anomaly configuration information, wherein the updated anomaly configuration information includes one or more of the following: updated anomaly detection rules, updated at least one indicator to be detected, updated indicator linkage conditions, updated detection window, and updated anomaly shielding information.

[0359] In this embodiment of the application, the abnormal configuration module 2556 is further configured to display a sending strategy configuration page for each indicator to be detected, wherein the sending strategy configuration page includes a hierarchical configuration control; in response to a hierarchical configuration operation applied to the hierarchical configuration control, the configured sending level and the sending strategy configuration control corresponding to the sending level are displayed; in response to the sending strategy configuration control applied to the sending strategy configuration control, the configured sending channel and the sending object are displayed, thereby obtaining an abnormal sending strategy for the indicator including the sending level, the sending channel, and the sending object;

[0360] In this embodiment of the application, the result sending module 2557 is further configured to select an abnormal sending strategy from the at least one abnormal sending strategy for ...

[0361] In this embodiment of the application, the abnormal configuration module 2556 is further configured to display the configured sending channel, the sending object, and the abnormal aggregation condition in response to the sending strategy configuration control acting on the sending strategy configuration control, thereby obtaining the indicator abnormal sending strategy including the sending level, the sending channel, the sending object, and the abnormal aggregation condition.

[0362] In this embodiment of the application, the result sending module 2557 is further configured to perform attribution processing on the target detection result to obtain the abnormal extended information when the target detection result satisfies the abnormal aggregation condition.

[0363] This application provides a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the anomaly detection method described above in this application.

[0364] This application provides a computer-readable storage medium storing executable instructions. When these executable instructions are executed by a processor, they cause the processor to perform the method provided in this application, for example... Figure 3 The anomaly detection method is shown.

[0365] In some embodiments, the computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, flash memory, magnetic surface memory, optical disk, or CD-ROM; or it may be a variety of devices including one or any combination of the above-mentioned memories.

[0366] In some embodiments, executable instructions may take the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as a standalone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.

[0367] As an example, executable instructions may, but do not necessarily, correspond to files in a file system. They may be stored as part of a file that holds other programs or data, for example, in one or more scripts within a Hyper Text Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple co-located files (e.g., files storing one or more modules, subroutines, or code sections). As an example, executable instructions may be deployed to execute on a single computing device, or on multiple computing devices located in one location, or on multiple computing devices distributed across multiple locations and interconnected via a communication network.

[0368] In summary, through the embodiments of this application, for each of the at least one detectable indicator, N indicator values ​​corresponding to the detection window are obtained to determine the abnormal detection result corresponding to each detectable indicator. Then, the at least one abnormal detection result corresponding to the at least one detectable indicator is integrated to obtain the final target detection result. In this way, the target detection result is determined based on the linkage of at least one detectable indicator, thus the accuracy of the target detection result is high, thereby improving the accuracy of abnormal detection.

[0369] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, and improvements made within the spirit and scope of this application are included within the scope of protection of this application.

Claims

1. An anomaly detection method, characterized in that, Applied to database systems, including: For each of the at least one indicators to be detected, within the detection window, when the detection time is determined based on the detection cycle, the anomaly detection rules and the business data source of the database system are obtained; wherein, the anomaly detection rules include indicator detection strategies and indicator anomaly conditions; the indicator detection strategies include the isolated forest detection strategy; Based on the business data source, the index value corresponding to each index to be detected is calculated, thereby obtaining N index values ​​corresponding to the detection window, where N is a positive integer determined based on the ratio of the detection window to the detection period; Based on the indicator detection strategy, it is determined whether the N indicator values ​​meet the indicator anomaly conditions, so as to determine the anomaly detection result corresponding to each indicator to be detected. When the indicator detection strategy includes the isolated forest detection strategy, based on the isolated forest detection strategy, the N indicator values ​​are compared with the N historical indicator values ​​corresponding to the detection window of the preset historical period number to obtain the preset period number of abnormal comparison scores, and the number of abnormal scores greater than the abnormal threshold among the preset historical period number of abnormal comparison scores is obtained, wherein the N historical indicator values ​​are year-on-year indicator values ​​or month-on-month indicator values. When the number of abnormal scores is greater than the abnormal number threshold, and the abnormal scores of the abnormal scores are in the same direction, the N index values ​​are determined to meet the index abnormality condition. Obtain the indicator linkage conditions corresponding to the at least one indicator to be detected; The indicator linkage condition is used to determine the linkage mode of the at least one indicator to be detected; wherein, the linkage mode includes at least one of the following: when all the indicators to be detected generate alarms, the final result is determined to be abnormal, and when one of the indicators to be detected generates the alarm, the final result is determined to be abnormal. Based on the aforementioned indicator linkage conditions, at least one anomaly detection result is integrated to obtain the target detection result.

2. The method according to claim 1, characterized in that, For each of the at least one detectable indicator, within the detection window, before acquiring the anomaly detection rules and the business data source of the database system when the detection time is determined based on the detection cycle, the method further includes: Display the abnormal indicator configuration page, which includes a business data source selection control, an indicator selection control, and a detection period configuration control. In response to a business data source selection operation performed on the business data source selection control, the selected business data source is displayed; In response to an indicator selection operation performed on the indicator selection control for the business data source, the selected at least one indicator to be detected is displayed, the indicator linkage conditions are configured for the at least one indicator to be detected, and the detection window and the anomaly detection rules are configured for each indicator to be detected. In response to a detection cycle configuration operation performed on the detection cycle configuration control, the configured detection cycle is displayed.

3. The method according to claim 2, characterized in that, The configuration of the detection window and the anomaly detection rule for each of the indicators to be detected includes: For each of the indicators to be detected, a detection rule configuration page is displayed, which includes a detection strategy selection control. In response to the detection strategy selection operation performed on the detection strategy selection control, the selected indicator detection strategy and the indicator abnormality condition configuration control corresponding to the indicator detection strategy are displayed. In response to the indicator anomaly configuration operation applied to the indicator anomaly configuration control for the indicator detection strategy, the configured detection window and the indicator anomaly conditions corresponding to the detection window are displayed, thereby obtaining the anomaly detection rules.

4. The method according to claim 2 or 3, characterized in that, Before displaying the selected at least one metric to be detected in response to a metric selection operation performed on the metric selection control for the business data source, the method further includes: Display the indicator configuration page, which includes an indicator-associated data source selection control, an indicator configuration control, and an indicator model configuration control; In response to the indicator-associated data source selection operation performed on the indicator-associated data source selection control, the selected business data source is displayed; In response to an indicator configuration operation performed on the indicator configuration control, each of the configured indicators to be detected is displayed, wherein each indicator to be detected includes one or more of the following: indicator identifier, indicator description information, and indicator unit. In response to an indicator model configuration operation performed on the indicator model configuration control, the configured indicator model is displayed, wherein the model parameters in the indicator model are data fields in the business data source; The step of calculating the indicator value corresponding to each indicator to be detected based on the business data source includes: Obtain the parameter data corresponding to the model parameters from the business data source; The parameter data is calculated based on the indicator model to determine the indicator value corresponding to each indicator to be detected.

5. The method according to claim 4, characterized in that, Before displaying the selected business data source in response to a metric-associated data source selection operation performed on the metric-associated data source selection control, the method further includes: Display the data source configuration page, which includes data source configuration controls; In response to a data source configuration operation performed on the data source configuration control, the configured business data source is displayed, wherein the business data source includes one or more of the following: data source identifier, data source description information, data source access method, data latency, and data granularity, wherein the detection period is an integer multiple of the data granularity.

6. The method according to claim 2 or 3, characterized in that, The abnormal indicator configuration page also includes a filter condition configuration control; Before calculating the indicator value corresponding to each indicator to be detected based on the business data source, the method further includes: In response to a filter configuration operation performed on the filter configuration control, the configured data filter conditions are displayed. The step of calculating the indicator value corresponding to each indicator to be detected based on the business data source includes: Obtain the data filtering conditions; Obtain the data to be detected that meets the data filtering conditions from the business data source; Based on the data to be detected, the index value corresponding to each index to be detected is calculated.

7. The method according to claim 6, characterized in that, Before displaying the configured data filter conditions in response to a filter condition configuration operation performed on the filter condition configuration control, the method further includes: Display the dimension configuration page, which includes a dimension-associated data source selection control and a dimension configuration control; In response to a dimension-associated data source selection operation performed on the dimension-associated data source selection control, the selected business data source is displayed; In response to a dimension configuration operation performed on the dimension configuration control for the business data source, the configured data dimension is displayed, wherein the data dimension includes one or both of dimension field identifier and dimension field description information, and the data dimension is a data field in the business data source; The process of displaying the configured data filtering conditions in response to a filtering condition configuration operation applied to the filtering condition configuration control includes: In response to the filter configuration operation performed on the filter configuration control, the data filter criteria selected from the data dimension are displayed.

8. The method according to claim 1, characterized in that, The step of comparing the N indicator values ​​with the N historical indicator values ​​corresponding to the detection window of the preset historical period number to obtain the anomaly comparison score of the preset period number includes: Obtain the current statistical features corresponding to the N indicator values, wherein the current statistical features include one or more of the following: current maximum value, current minimum value, current mean, current variance, and current range; Obtain the historical statistical features corresponding to the N historical index values ​​corresponding to the detection window; Obtain the feature ratio of the current statistical feature to the historical data statistical feature, thereby obtaining the feature ratio of the preset number of periods; The characteristic ratio of the preset number of cycles is standardized. Based on preset weights, the standardized feature ratios are input into the multidimensional isolated forest model to obtain the anomaly scores for the preset number of periods, wherein the multidimensional isolated forest model is used to determine the anomaly scores.

9. The method according to any one of claims 1 to 3, characterized in that, When the target detection result indicates that an anomaly has been detected, after obtaining the target detection result, the method further includes: Attribution processing is performed on the target detection results to obtain anomaly extended information; The abnormal information is formed by combining one or more of the following: the abnormal extended information, the business data source, the at least one indicator to be detected, the detection window, and the abnormal details. The abnormal details are determined based on the abnormal detection rules and the N indicator values. Obtain the abnormal transmission strategy of the at least one indicator to be detected, wherein the abnormal transmission strategy includes a transmission channel and a transmission target; The abnormal information is sent to the recipient through the sending channel, so that... The feedback device corresponding to the sending object displays the abnormal information based on the abnormal shielding information, and in response to the rule modification operation for the abnormal information, displays a rule modification page to modify the abnormal configuration information based on the rule modification page. The abnormal configuration information includes one or more of the following: the abnormal detection rule, the at least one indicator to be detected, the indicator linkage condition, the detection window, and the abnormal shielding information.

10. The method according to claim 9, characterized in that, After sending the abnormal information to the sending object through the sending channel, the method further includes: Receive feedback information sent by the feedback terminal device in response to the abnormal information, wherein the feedback information is obtained in response to an operation performed on the rule modification page; Based on the feedback information, the abnormal configuration information is updated to perform abnormal detection based on the updated abnormal configuration information. The updated abnormal configuration information includes one or more of the following: updated abnormal detection rules, updated at least one indicator to be detected, updated indicator linkage conditions, updated detection window, and updated abnormal blocking information.

11. The method according to claim 9, characterized in that, Before obtaining the abnormal transmission strategy of the at least one indicator to be detected, the method further includes: For each of the indicators to be detected, a sending strategy configuration page is displayed, which includes a hierarchical configuration control. In response to a hierarchical configuration operation performed on the hierarchical configuration control, the configured sending level and the sending strategy configuration control corresponding to the sending level are displayed. In response to a sending policy configuration operation performed on the sending policy configuration control, the configured sending channel and the sending object are displayed, thereby obtaining an abnormal sending policy including the sending level, the sending channel, and the sending object. The abnormal transmission strategy for obtaining the at least one indicator to be detected includes: Based on the priority of the sending level in the abnormal sending strategy of each indicator to be detected, an abnormal sending strategy is selected from at least one abnormal sending strategy as the abnormal sending strategy for the at least one indicator to be detected.

12. The method according to claim 11, characterized in that, After displaying the configured sending level and the corresponding sending strategy configuration control in response to a hierarchical configuration operation applied to the hierarchical configuration control, the method further includes: In response to the sending strategy configuration control acting on the sending strategy configuration control, the configured sending channel, the sending object, and the abnormal aggregation condition are displayed, thereby obtaining the indicator abnormal sending strategy including the sending level, the sending channel, the sending object, and the abnormal aggregation condition; Before performing attribution processing on the target detection results to obtain anomaly extension information, the method further includes: When the target detection result meets the anomaly aggregation condition, attribution processing is performed on the target detection result to obtain the anomaly extended information.

13. An anomaly detection device, characterized in that, Applied to database systems, including: The detection triggering module is used to, for each of the at least one detectable indicators, within the detection window, when the detection time is determined based on the detection cycle, acquire the anomaly detection rules and the business data source of the database system; wherein, the anomaly detection rules include indicator detection strategies and indicator anomaly conditions; the indicator detection strategies include the isolated forest detection strategy; An anomaly detection module is used to calculate the index value corresponding to each index to be detected based on the business data source, thereby obtaining N index values ​​corresponding to the detection window, where N is a positive integer determined based on the ratio of the detection window to the detection period; The result determination module is used to determine whether the N indicator values ​​meet the indicator anomaly conditions based on the indicator detection strategy, so as to determine the anomaly detection result corresponding to each indicator to be detected. When the indicator detection strategy includes the isolated forest detection strategy, based on the isolated forest detection strategy, the N indicator values ​​are compared with the N historical indicator values ​​corresponding to the detection window of the preset historical period number to obtain the preset period number of abnormal comparison scores, and the number of abnormal scores greater than the abnormal threshold among the preset historical period number of abnormal comparison scores is obtained, wherein the N historical indicator values ​​are year-on-year indicator values ​​or month-on-month indicator values. When the number of abnormal scores is greater than the abnormal number threshold, and the abnormal scores of the abnormal scores are in the same direction, the N index values ​​are determined to meet the index abnormality condition. The condition acquisition module is used to acquire the indicator linkage conditions corresponding to the at least one indicator to be detected. The indicator linkage condition is used to determine the linkage mode of the at least one indicator to be detected; wherein, the linkage mode includes at least one of the following: when all the indicators to be detected generate alarms, the final result is determined to be abnormal, and when one of the indicators to be detected generates the alarm, the final result is determined to be abnormal. The result integration module is used to integrate at least one anomaly detection result based on the indicator linkage conditions to obtain the target detection result.

14. The apparatus according to claim 13, characterized in that, The detection trigger module is also used for: For each of the at least one indicators to be detected, in the detection window, before obtaining the anomaly detection rules and the business data source of the database system when the detection time is determined based on the detection cycle, an anomaly indicator configuration page is displayed. The anomaly indicator configuration page includes a business data source selection control, an indicator selection control, and a detection cycle configuration control. In response to a business data source selection operation performed on the business data source selection control, the selected business data source is displayed; In response to an indicator selection operation performed on the indicator selection control for the business data source, the selected at least one indicator to be detected is displayed, the indicator linkage conditions are configured for the at least one indicator to be detected, and the detection window and the anomaly detection rules are configured for each indicator to be detected. In response to a detection cycle configuration operation performed on the detection cycle configuration control, the configured detection cycle is displayed.

15. An anomaly detection device, characterized in that, include: Memory, used to store executable instructions; A processor, when executing executable instructions stored in the memory, implements the method according to any one of claims 1 to 12.

16. A computer-readable storage medium, characterized in that, It stores executable instructions for implementing the method of any one of claims 1 to 12 when executed by a processor.

17. A computer program product comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by a processor, they implement the method described in any one of claims 1 to 12.

Citation Information

Patent Citations

  • Data monitoring method and device

    CN106878064A

  • Anomaly detection method and device, electronic device and readable storage medium

    CN109446466A