Data monitoring method and device, electronic equipment and computer readable storage medium

By acquiring and storing key data from raw data messages, and using fingerprint database comparison and violation testing, the problem of difficulty in comprehensively monitoring abnormal data in existing technologies has been solved. This enables rapid identification and timely monitoring of abnormal data in the Internet ecosystem, thereby improving network security protection capabilities.

CN113934593BActive Publication Date: 2026-05-08STATE GRID BEIJING ELECTRIC POWER CO +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
STATE GRID BEIJING ELECTRIC POWER CO
Filing Date
2021-10-12
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing technologies are insufficient for comprehensive monitoring of abnormal data, especially in the internet ecosystem where massive business systems and IoT terminals are connected, making it difficult for enterprises to quickly identify and protect against attacks that expose violations.

Method used

By acquiring the original data messages, extracting key data and storing it in the dataset according to a predetermined hierarchy, receiving abnormal data query operations, and monitoring abnormal data on a regular basis, the system uses fingerprint database data comparison and violation testing to screen for illegal data.

Benefits of technology

It enables rapid and comprehensive monitoring and regular screening of abnormal data, improving the efficiency and accuracy of network security protection and reducing the harm of illegal data to the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113934593B_ABST
    Figure CN113934593B_ABST
Patent Text Reader

Abstract

The application discloses a data monitoring method and device, electronic equipment and a computer readable storage medium. The method comprises the following steps: obtaining a data original message; extracting key data in the data original message, and storing the key data in a data set according to a predetermined level; receiving an abnormal data query operation, determining abnormal data in the data set; and performing timing monitoring on the abnormal data. The application solves the technical problem that it is difficult to comprehensively monitor abnormal data in related technologies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computers, and more specifically, to a data monitoring method, apparatus, electronic device, and computer-readable storage medium. Background Technology

[0002] With the rapid development of information technology, the level of informatization of domestic enterprises is getting higher and higher, and enterprises are becoming more and more dependent on information technology. The fundamental role of networks and information systems is becoming increasingly important. Information security has become an important means to promote the further development of informatization and protect the results of informatization, and an important part of enterprise safety production.

[0003] With the convergence of the Internet, mobile Internet, and the Internet of Things (IoT), the informatization of various business systems in domestic enterprises is developing rapidly. The number of connected business systems, mobile terminals, and IoT terminals is increasing daily. The vast number of interconnected business systems on the Internet constitute a powerful ecosystem. However, the unauthorized and haphazard construction of business systems by various departments and branches of key enterprises is a serious problem, making it difficult to clearly grasp the construction status of all business systems and to provide comprehensive protection. This creates an attack surface that is illegally exposed to the Internet without following proper enterprise deployment procedures. Furthermore, given the current new cybersecurity attack methods and the continuous emergence of zero-day vulnerabilities, enterprises face immense pressure in identifying and supervising the security of their systems in the face of massive information assets in cyberspace.

[0004] There is currently no effective solution to the above problems. Summary of the Invention

[0005] This invention provides a data monitoring method, apparatus, electronic device, and computer-readable storage medium to at least solve the technical problem in the related art of making it difficult to comprehensively monitor abnormal data.

[0006] According to one aspect of the present invention, a data monitoring method is provided, comprising: acquiring raw data messages; extracting key data from the raw data messages and storing the key data in a dataset according to a predetermined hierarchy; receiving an abnormal data query operation and identifying abnormal data in the dataset; and performing periodic monitoring on the abnormal data.

[0007] Optionally, obtaining the raw data message includes: determining a predetermined range of the raw data message; and obtaining the raw data message within the predetermined range according to a predetermined period.

[0008] Optionally, determining the predetermined range of the original data message includes: obtaining query data for the target object; and determining the predetermined range of the original data message according to the query data.

[0009] Optionally, extracting key data from the original data message and storing the key data in a dataset according to a predetermined hierarchy includes: comparing the key data with fingerprint database data to determine the predetermined hierarchy to which the key data belongs; and storing the key data in the dataset according to the predetermined hierarchy.

[0010] Optionally, receiving the abnormal data query operation and identifying abnormal data in the dataset includes: parsing the query rule instruction in the abnormal data query operation; executing the abnormal data query operation according to the query rule instruction, and identifying abnormal data in the dataset.

[0011] Optionally, after periodically monitoring the abnormal data, the method further includes: screening the abnormal data through violation testing to identify the violation data.

[0012] According to one aspect of the present invention, a data monitoring device is provided, comprising: an acquisition module for acquiring raw data messages; an extraction module for extracting key data from the raw data messages and storing the key data in a dataset according to a predetermined hierarchy; a determination module for receiving an abnormal data query operation and determining abnormal data in the dataset; and a monitoring module for periodically monitoring the abnormal data.

[0013] According to one aspect of the present invention, an electronic device is provided, comprising: a processor; and a memory for storing processor-executable instructions; wherein the processor is configured to execute the instructions to implement any of the data monitoring methods described herein.

[0014] According to one aspect of the present invention, a computer-readable storage medium is provided, wherein when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform any of the data monitoring methods described herein.

[0015] According to one aspect of the present invention, a computer program product is provided, including a computer program that, when executed by a processor, implements any of the data monitoring methods described above.

[0016] In this embodiment of the invention, by acquiring the original data message, extracting key data from the original message, and storing the key data in a dataset according to a predetermined hierarchy, an abnormal data query operation can be received. Abnormal data can be identified in the dataset, and the abnormal data can be monitored periodically. Because the abnormal data query is performed in the dataset containing the key data, the abnormal data can be identified more quickly. Moreover, since the key data is extracted from the original data message, a large amount of data can be monitored, thereby solving the technical problem of difficulty in comprehensively monitoring abnormal data in related technologies. Attached Figure Description

[0017] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0018] Figure 1 This is a flowchart of a data monitoring method according to an embodiment of the present invention;

[0019] Figure 2 This is a flowchart of a method for monitoring the illegal exposure surface of massive cyberspace assets provided by an optional embodiment of the present invention;

[0020] Figure 3 This is an overall framework diagram of the massive cyberspace asset violation exposure surface monitoring device provided by an optional embodiment of the present invention;

[0021] Figure 4 This is a structural block diagram of a data monitoring device according to an embodiment of the present invention;

[0022] Figure 5 This is a structural block diagram of a terminal according to an exemplary embodiment. Detailed Implementation

[0023] According to an embodiment of the present invention, an embodiment of a data monitoring method is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0024] Figure 1 This is a flowchart of a data monitoring method according to an embodiment of the present invention, such as... Figure 1 As shown, the method includes the following steps:

[0025] Step S102: Obtain the original data message;

[0026] Step S104: Extract key data from the original data message and store the key data in the dataset according to a predetermined hierarchy;

[0027] Step S106: Receive an abnormal data query operation and identify abnormal data in the dataset;

[0028] Step S108: Monitor abnormal data periodically.

[0029] Through the above steps, by acquiring the original data message, extracting key data from the original message, and storing the key data in a dataset according to a predetermined hierarchy, the abnormal data can be identified in the dataset when receiving abnormal data query operations, and the abnormal data can be monitored regularly. Because the abnormal data query is performed in the dataset containing the key data, the abnormal data can be identified more quickly. Moreover, since the key data is extracted from the original data message, comprehensive data monitoring can be guaranteed, thereby solving the technical problem of difficulty in comprehensively monitoring abnormal data in related technologies.

[0030] As an optional implementation, the raw data packets are acquired. These raw data packets include massive amounts of network data, which can be understood as data blocks. This includes the data to be transmitted, as well as necessary additional information such as destination IP, destination port, source address, source port, data length, protocol used, encryption, etc. In other words, it does not simply refer to data sent by the user. It should be noted that acquiring the raw data packets requires granted data acquisition permissions. By acquiring the raw data packets, abnormal data can be monitored within the massive amounts of network data, laying the foundation for comprehensive abnormal data monitoring.

[0031] As an optional embodiment, obtaining raw data messages includes: determining a predetermined range of raw data messages, and obtaining raw data messages within the predetermined range according to a predetermined period. When obtaining raw data messages, it can be specified that raw messages are obtained within a certain range, that is, raw data messages within the predetermined range can be obtained selectively, making it more effective to filter out abnormal data and speeding up the processing of abnormal data.

[0032] It should be noted that determining the predetermined range of the original data packets can be achieved through the following methods: obtaining query data targeting the target object; and determining the predetermined range of the original data packets based on the query data. The target object can be the original data packets to be obtained from the query data, data related to the query data, or abnormal data related to the query data, etc. When determining the predetermined range of the original data packets by obtaining query data targeting the target object, the query can be performed based on one or more types of data, or based on one or more specific types of data; this is not limited here. Based on the query data, various types of data related to the query data can be obtained, i.e., a certain data query range can be obtained based on the query data. Based on this range, the original data packets are obtained, and the original data packets in the network are queried in a distributed manner.

[0033] As an optional embodiment, key data is extracted from the original data message and stored in a dataset according to a predetermined hierarchy. The dataset is a platform or collection capable of storing data, and may also include other functionalities, such as a dataset with search and data analysis engine capabilities, like Elasticsearch. The key data is the data obtained after analyzing and processing the original data message; that is, irrelevant data is filtered out through analysis and processing to extract the key data, which is then stored in the dataset according to a predetermined hierarchy. This predetermined hierarchy can be divided according to different data types or functions, for example, by host IP, operating system, open ports, protocols, services, or components, so that key data is stored in the corresponding hierarchy. Specifically, the stored key data can be further divided into layers. Data is labeled, indicating the level, location, and anomaly status of key data. By storing key data in the dataset according to predetermined levels, anomaly processing can be performed more quickly. For different levels of key data, corresponding anomaly query and processing methods can be used, making the handling of anomalies more targeted. It should be noted that when storing key data in the dataset according to predetermined levels, relationships between key data can be established, such as relationships between IPs, services, domains, components, protocols, and operating systems, making the data more organized. Storing both the relationships between key data and the key data itself in the dataset ensures faster and more efficient anomaly retrieval.

[0034] As an optional embodiment, extracting key data from the original data message and storing the key data in a dataset according to a predetermined hierarchy can include the following methods: comparing the key data with fingerprint database data to determine the predetermined hierarchy to which the key data belongs; and storing the key data in the dataset according to the predetermined hierarchy. That is, by comparing the key data with fingerprint database information, the predetermined hierarchy to which the key data belongs is obtained. The fingerprint database is a standard database capable of obtaining the predetermined hierarchy to which key data belongs through comparison, accurately determining the hierarchy to which the key data belongs, and achieving reasonable division and storage of the key data.

[0035] As an optional implementation, an abnormal data query operation is received, and abnormal data is identified in the dataset. This allows for timely processing of abnormal data. It should be noted that when receiving an abnormal data query operation and identifying abnormal data in the dataset, the query rule instructions within the query operation can be parsed, and then the abnormal data query operation can be executed according to these instructions to identify the abnormal data in the dataset. The query rule instructions can be configured in various ways; for example, they can be set based on data at different levels, such as setting site keyword rules, IP segment screening rules, etc. When multiple rules exist, logical judgment symbols (AND, OR, NOT) can be set to execute multiple rules, enabling more rigorous and targeted acquisition of abnormal data under a specific rule, thereby facilitating investigation and protecting network and data security.

[0036] As an optional implementation, abnormal data is monitored periodically. A scheduled task monitors the abnormal data stored in the dataset at regular intervals. This prevents abnormal data from causing program malfunctions and avoids damage to the network and data.

[0037] As an optional implementation, after periodically monitoring abnormal data, the method further includes: screening the abnormal data through violation testing to identify violations. Violation testing can be manual testing, logical testing, etc. Violation testing determines whether the abnormal data violates regulations. This allows for timely processing of violating data, protecting it from leakage. After processing, continuous monitoring of violating data can prevent its recurrence and ensure network security.

[0038] Based on the above embodiments and optional embodiments, an optional implementation method is provided, which is described in detail below.

[0039] In related technologies, enterprises face enormous pressure in the face of massive information assets in the Internet space, including the investigation of system security risks and the supervision and inspection of security protection.

[0040] In view of this, an optional embodiment of the present invention provides a method for monitoring the illegal exposure surface of massive cyberspace assets, relating to the field of large-scale asset investigation in cybersecurity, and particularly to a method for monitoring the illegal exposure surface of cyberspace assets by using a distributed asset collection and detection method. It is suitable for quickly retrieving network assets with specified rules from massive cyberspace, and can solve the problems of enterprises finding network assets relevant to themselves from massive internet space and continuously tracking and monitoring network assets illegally exposed in internet space. Figure 2 This is a flowchart of a method for monitoring the illegal exposure surface of massive cyberspace assets provided by an optional embodiment of the present invention, such as... Figure 2 As shown, the optional embodiments of the present invention will be described in detail below:

[0041] S01. Scan Internet assets using cyberspace asset detection technology and obtain raw data packets of cyberspace assets: Send constructed data packets to the system's IP address, host, open port, database, Web service, etc. using a network packet sending engine, and obtain relevant information from the returned data packets, including the content of each layer of the protocol, packet retransmission time, etc.

[0042] S02. By analyzing and processing the raw data packets of the collected network space assets, the data is divided according to the host service level: the key information of the returned data packets is extracted, and the information at different positions of the returned packets is compared with the fingerprint database information to obtain the port and service information of the target assets. This information is then divided into layers according to host IP, operating system, open port, protocol, service and component, and the data is formatted and labeled.

[0043] S03. Establish associations between the formatted and labeled data according to the host service hierarchy, and store the data in the ElasticSearch cluster: Establish asset (information) associations between the formatted data according to the host service hierarchy, and label and store the key information of these assets in the ElasticSearch big data platform cluster.

[0044] S04. Formulate review rules for illegal external network assets and set up scheduled query tasks to retrieve relevant data from the ElasticSearch storage cluster: Set up site keywords and IP range screening rules suitable for your own illegal external network asset packages, and use scheduled tasks to screen and filter the massive amount of Internet asset data already stored in ElasticSearch at a certain time period.

[0045] S05. Automated labeling of the found illegal assets and continuous periodic monitoring of the target: Automated labeling of the search results from ElasticSearch, and manual secondary labeling to determine whether the asset is illegal, and continuous monitoring of the labeled assets with the same rules to discover more information on the illegal exposure of cyberspace assets.

[0046] This invention also provides an overall framework for a monitoring device for the illegal exposure of massive cyberspace assets. Figure 3 This is an overall framework diagram of the massive cyberspace asset violation exposure surface monitoring device provided by an optional embodiment of the present invention, such as... Figure 3 As shown, the optional embodiments of the present invention will be described in detail below:

[0047] The system presentation layer provides user management, task management, violation monitoring, monitoring configuration, asset auditing, and violation list to help submit and manage tasks for monitoring the exposure of violation assets.

[0048] The system's business layer provides core functions for task allocation, scheduled tasks, violation matching, violation judgment, asset association, and asset stratification, enabling the screening and automatic labeling of massive amounts of cyberspace assets.

[0049] The system data layer consists of host data, service data, domain name data, component data, protocol data, and operating system data. These are the types of data that the system's underlying layer stores after collecting, organizing, and storing internet space assets.

[0050] The core modules of this framework are as follows:

[0051] S301 Monitoring Configuration: Configure monitoring of some or all network assets on the Internet. This module can be used to define the scope of network space asset collection. The time period and depth of network space asset collection can be set. The source of network space asset monitoring and the node for execution of monitoring tasks can be configured to improve the speed of asset collection.

[0052] S302. Violation Monitoring: By configuring violation monitoring rules and monitoring periods, massive amounts of cyberspace assets can be screened. Violation monitoring rules are connected by logical judgment symbols, allowing for feature settings on specific data of an asset or combined settings for multiple features.

[0053] S303, Violation Matching: By parsing the rules configured in violation monitoring, and parsing logical judgment symbols (e.g., wildcards, AND, OR) and feature values ​​of asset attributes, it is possible to retrieve data from ElasticSearch, which stores massive amounts of cyberspace assets.

[0054] S304. Violation Determination: Identify and determine the violations of retrieved assets, automatically and manually labeling them as violations. Similar assets previously labeled within the rules can be automatically labeled as violations. Newly discovered assets not yet labeled as violations are automatically labeled as suspicious assets, requiring manual labeling. After labeling, similar assets can be automatically labeled as violations.

[0055] S305. Asset Association: Summarize the asset information collected during penetration testing and identify the attack surface exposed by the target system. Divide the assets into layers based on host IP, operating system, open ports, protocols, services, and components, and automatically associate web-related components and middleware to create asset profiles.

[0056] S306, System Data Layer: Raw asset data collected from the internet based on monitoring tasks is parsed by the asset layering and asset association modules of the core business layer to form the asset data storage for this layer. The collected information is labeled and stored according to different asset attributes, and asset association relationships are also stored.

[0057] The above optional implementation methods can achieve at least the following beneficial effects:

[0058] (1) Based on a large-scale, massive network space asset exposure surface monitoring device, it is able to scan and collect network assets exposed on the Internet and perform comprehensive searches.

[0059] (2) The analysis adopts a hierarchical model of network space hosts, services and components, establishes the relationship between IP, services, domain names, components, protocols and operating systems based on host assets, and stores host asset data through a big data platform to avoid data loss;

[0060] (3) By using the characteristics of illegal assets to perform timed automated retrieval of massive Internet assets, continuous monitoring of illegally exposed Internet assets is achieved, which solves the problem that enterprises cannot quickly and effectively locate and track the illegal asset exposure surface during the process of investigating the external network asset exposure surface, resulting in the illegal asset exposure surface being attacked.

[0061] (4) By adopting distributed control technology and taking advantage of distributed scanning, the working efficiency of the device can be improved. Scanning large-scale regional network spatial assets can play a very good role in studying the composition and distribution of Internet assets.

[0062] (5) Use search engines to retrieve information on cyberspace assets and improve the efficiency of information organization and retrieval for a wide range of cyberspace assets.

[0063] (6) By adopting a hierarchical classification and organization of cyberspace assets, information collection (IP, IP range, domain name, service, port, protocol) can be promptly stored in the database. The reuse of cyberspace self-inspection information collection content can greatly improve the output and analysis of the target network asset status. System operators only need to submit a certain IP / IP range / domain name, and the device will automatically allocate the task to each node and use distributed scanning nodes to collect cyberspace asset information of the target task.

[0064] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the present invention is not limited to the described order of actions, because according to the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.

[0065] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.

[0066] Example 2

[0067] According to embodiments of the present invention, an apparatus for implementing the above-described data monitoring method is also provided. Figure 4 This is a structural block diagram of a data monitoring device according to an embodiment of the present invention, such as... Figure 4 As shown, the device includes: an acquisition module 402, an extraction module 404, a determination module 406, and a monitoring module 408. The device will be described in detail below.

[0068] The acquisition module 402 is used to acquire the original data message; the extraction module 404 is connected to the acquisition module 402 and is used to extract key data from the original data message and store the key data in the dataset according to a predetermined hierarchy; the determination module 406 is connected to the extraction module 404 and is used to receive abnormal data query operations and determine abnormal data in the dataset; the monitoring module 408 is connected to the determination module 406 and is used to monitor the abnormal data at regular intervals.

[0069] It should be noted that the above-mentioned acquisition module 402, extraction module 404, determination module 406 and monitoring module 408 correspond to steps S102 to S108 in the implementation data monitoring method. The multiple modules and the corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in the above embodiment 1.

[0070] Example 3

[0071] Embodiments of this disclosure may provide an electronic device, which can be a terminal or a server. In this embodiment, the electronic device, as a terminal, can be any computer terminal device in a group of computer terminals. Optionally, in this embodiment, the terminal may also be a mobile terminal or other terminal device.

[0072] Optionally, in this embodiment, the terminal may be located in at least one of a plurality of network devices in a computer network.

[0073] Optionally, Figure 5 This is a structural block diagram of a terminal according to an exemplary embodiment. For example... Figure 5 As shown, the terminal may include: one or more (only one is shown in the figure) processors 51 and a memory 52 for storing processor-executable instructions; wherein the processor is configured to execute instructions to implement any of the above-mentioned data monitoring methods.

[0074] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the data monitoring method and apparatus in this embodiment. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby realizing the aforementioned data monitoring method. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to a computer terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0075] The processor can call the information and application programs stored in the memory through the transmission device to perform the following steps: obtain the original data message; extract key data from the original data message and store the key data in the dataset according to a predetermined hierarchy; receive abnormal data query operations and identify abnormal data in the dataset; and monitor the abnormal data periodically.

[0076] Optionally, the processor may also execute program code that performs the following steps: acquiring raw data messages, including: determining a predetermined range of raw data messages; acquiring raw data messages within the predetermined range according to a predetermined period.

[0077] Optionally, the processor may also execute program code that performs the following steps: determining a predetermined range of the raw data message, including: obtaining query data for the target object; and determining the predetermined range of the raw data message according to the query data.

[0078] Optionally, the processor may also execute program code that performs the following steps: extracting key data from the original data message and storing the key data in a dataset according to a predetermined hierarchy, including: comparing the key data with fingerprint database data to determine the predetermined hierarchy to which the key data belongs; and storing the key data in a dataset according to the predetermined hierarchy.

[0079] Optionally, the processor may also execute program code that performs the following steps: receiving an abnormal data query operation and identifying abnormal data in the dataset, including: parsing the query rule instructions in the abnormal data query operation; executing the abnormal data query operation according to the query rule instructions and identifying abnormal data in the dataset.

[0080] Optionally, the processor may also execute program code that performs the following steps: after periodically monitoring abnormal data, it further includes screening abnormal data through violation testing to identify violation data.

[0081] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.

[0082] Example 4

[0083] In an exemplary embodiment, a computer-readable storage medium including instructions is also provided, which, when executed by a processor of a terminal, enable the terminal to perform any of the data monitoring methods described above. Optionally, the computer-readable storage medium may be a non-transitory computer-readable storage medium, such as a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device.

[0084] Optionally, in this embodiment, the computer-readable storage medium described above can be used to store the program code executed by the data monitoring method provided in the above embodiment.

[0085] Optionally, in this embodiment, the computer-readable storage medium may be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals.

[0086] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: acquiring the original data message; extracting key data from the original data message and storing the key data in a dataset according to a predetermined hierarchy; receiving an abnormal data query operation and identifying abnormal data in the dataset; and periodically monitoring the abnormal data.

[0087] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: acquiring raw data packets, including: determining a predetermined range of raw data packets; acquiring raw data packets within the predetermined range at a predetermined period.

[0088] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: determining a predetermined range of raw data messages, including: obtaining query data for a target object; and determining the predetermined range of raw data messages according to the query data.

[0089] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: extracting key data from the original data message and storing the key data in a dataset according to a predetermined hierarchy, including: comparing the key data with fingerprint database data to determine the predetermined hierarchy to which the key data belongs; and storing the key data in a dataset according to the predetermined hierarchy.

[0090] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: receiving an abnormal data query operation and identifying abnormal data in the dataset, including: parsing query rule instructions in the abnormal data query operation; executing the abnormal data query operation according to the query rule instructions and identifying abnormal data in the dataset.

[0091] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: after periodically monitoring abnormal data, the method further includes: screening the abnormal data through violation testing to identify the violation data.

[0092] In an exemplary embodiment, a computer program product is also provided, which, when executed by a processor of an electronic device, enables the electronic device to perform any of the data monitoring methods described above.

[0093] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0094] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0095] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between units or modules may be electrical or other forms.

[0096] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0097] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0098] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0099] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A data monitoring method, characterized in that, include: Obtain the raw data message, which includes the destination IP, destination port, source address, source port, data length, protocol used, and encryption information; Extract key data from the original data message and store the key data in the dataset according to a predetermined hierarchy, wherein the predetermined hierarchy is divided into layers according to host IP, operating system, open port, protocol, service, and component; Receive an abnormal data query operation, identify abnormal data in the dataset, wherein the abnormal data query operation includes query rule instructions, and different levels of key data correspond to different query rule instructions; The abnormal data shall be monitored periodically; The step of extracting key data from the original data message and storing the key data in a dataset according to a predetermined hierarchy includes: comparing the key data with fingerprint database data to determine the predetermined hierarchy to which the key data belongs; and storing the key data in the dataset according to the predetermined hierarchy, wherein the predetermined hierarchy is divided according to the different types of the key data. The step of obtaining the original data message includes: obtaining query data for the target object; determining a predetermined range of the original data message according to the query data; and obtaining the original data message within the predetermined range according to a predetermined period.

2. The method according to claim 1, characterized in that, The abnormal data query operation, which identifies abnormal data in the dataset, includes: Parse query rule commands in abnormal data query operations; The abnormal data query operation is executed according to the query rule instructions to identify abnormal data in the dataset.

3. The method according to claim 1, characterized in that, After periodically monitoring the abnormal data, the method further includes: The abnormal data is screened through violation testing to identify the violation data.

4. A data monitoring device, characterized in that, include: The acquisition module is used to acquire the original data message, which includes the destination IP, destination port, source address, source port, data length, protocol used, and encryption information. The extraction module is used to extract key data from the original data message and store the key data in the dataset according to a predetermined hierarchy. The predetermined hierarchy is divided into layers according to host IP, operating system, open port, protocol, service, and component. The determination module is used to receive abnormal data query operations and determine abnormal data in the dataset. The abnormal data query operation includes query rule instructions, and different levels of key data correspond to different query rule instructions. The monitoring module is used to monitor the abnormal data at regular intervals; The extraction module is further configured to compare the key data with fingerprint database data to determine the predetermined level to which the key data belongs; and store the key data in the dataset according to the predetermined level, wherein the predetermined level is divided according to the different types of the key data; The acquisition module is further configured to acquire query data for the target object; determine a predetermined range of the original data message according to the query data; and acquire the original data message within the predetermined range according to a predetermined period.

5. An electronic device, characterized in that, include: processor; Memory used to store the processor's executable instructions; The processor is configured to execute the instructions to implement the data monitoring method as described in any one of claims 1 to 3.

6. A computer-readable storage medium, characterized in that, When the instructions in the computer-readable storage medium are executed by the processor of the electronic device, the electronic device is able to perform the data monitoring method as described in any one of claims 1 to 3.

7. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the data monitoring method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Cloud service quality monitoring method and system

    CN109905276A

  • Industrial anomaly monitoring method and device, computer equipment and readable storage medium

    CN112468488A