Monitoring Model Generation Method, Apparatus, Device, and Storage Medium
By generating a monitoring model, using the node and link topology graph characteristics of the distributed cluster system, the problem of inability to effectively monitor interactive node abnormalities in the existing technology is solved, and efficient abnormal monitoring effect is achieved.
Patent Information
- Application Number
- CN202111457501.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-02
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2041-12-02
AI Technical Summary
The prior art cannot effectively monitor whether abnormalities occur between interactive nodes in distributed cluster systems, resulting in poor monitoring results.
By obtaining the node topology diagram of the distributed cluster system at different times, performing linear processing to determine the link topology diagram, determining the graph-level characteristics of the nodes and links, and using the graph neural network to generate a monitoring model for abnormal monitoring.
It improves the abnormal monitoring effect of the operating conditions between nodes and interactive nodes in the distributed cluster system, reduces the monitoring cost and difficulty, and promptly detects system operation abnormalities.
Smart Images

Figure CN114238012B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present application relate to computer technology, and in particular, to a method, apparatus, device, and storage medium for generating a monitoring model. Background Art
[0002] With the rapid development of cloud computing and big data, data has grown exponentially. The method of simply expanding the storage capacity of a computer file system by increasing the number of hard disks can no longer meet the storage requirements of exponentially growing data in the information explosion era, and a distributed cluster system has emerged. The distributed cluster system is connected to nodes through a computer network and can effectively solve the problems of data storage and management.
[0003] In order to better reflect the data processing ability of the distributed cluster system, it is particularly important and crucial to perform anomaly monitoring on the distributed cluster system. Traditional anomaly monitoring basically uses means such as clustering, statistical learning, and general deep neural network models to perform anomaly monitoring on each node in the distributed cluster system. However, due to the interactivity between nodes in the distributed cluster system, traditional monitoring means cannot monitor whether anomalies occur between interactive nodes, resulting in poor monitoring effects. Summary of the Invention
[0004] Embodiments of the present application provide a method, apparatus, device, and storage medium for generating a monitoring model, achieving the purpose of effectively monitoring whether anomalies occur between interactive nodes in a distributed cluster system and improving the monitoring effect.
[0005] In a first aspect, an embodiment of the present application provides a method for generating a monitoring model, the method comprising:
[0006] Obtaining node topology diagrams of the distributed cluster system at different times;
[0007] Performing linear processing on each of the node topology diagrams to determine a link topology diagram corresponding to each of the node topology diagrams;
[0008] Determining node graph-level features of each of the node topology diagrams and link graph-level features of each of the link topology diagrams;
[0009] Determining node graph-level change features based on all the node graph-level features, and determining link graph-level change features based on all the link graph-level features;
[0010] Generating a monitoring model based on the node graph-level change features and the link graph-level change features for anomaly monitoring of the distributed cluster system.
[0011] In a second aspect, an embodiment of the present application provides a device for generating a monitoring model, the device comprising:
[0012] A topology graph acquisition module, configured to acquire node topology graphs of a distributed cluster system at different times;
[0013] A first determination module, configured to perform linear processing on each of the node topology graphs to determine a link topology graph corresponding to each of the node topology graphs;
[0014] A second determination module, configured to determine node graph-level features of each of the node topology graphs and link graph-level features of each of the link topology graphs;
[0015] A third determination module, configured to determine node graph-level change features according to all the node graph-level features, and determine link graph-level change features according to all the link graph-level features;
[0016] A model generation module, configured to generate a monitoring model according to the node graph-level change features and the link graph-level change features for anomaly monitoring of the distributed cluster system.
[0017] In a third aspect, an embodiment of the present application provides a monitoring model generation device, including:
[0018] A processor and a memory, where the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory to execute the monitoring model generation method described in the first aspect embodiment.
[0019] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, configured to store a computer program, and the computer program causes a computer to execute the monitoring model generation method described in the first aspect embodiment.
[0020] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the monitoring model generation method described in the first aspect embodiment is implemented.
[0021] The technical solution disclosed in the embodiment of the present application has the following beneficial effects:
[0022] By using node topology graphs at different times, a monitoring model for monitoring whether an anomaly occurs in a distributed cluster system is generated, and through the monitoring model, anomaly monitoring is performed on the operating conditions of each node and nodes with interactivity in the distributed cluster system, thereby providing conditions for timely discovery of anomalies in the operation of the distributed cluster system and improving the monitoring effect. Description of the Drawings
[0023] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0024] Figure 1 It is a schematic flowchart of the first method for generating a monitoring model provided by an embodiment of the present application;
[0025] Figure 2 It is a schematic diagram showing the dynamic change of the node topology map over time in a distributed cluster system provided by an embodiment of the present application;
[0026] Figure 3 It is the node topology map at the k-th moment provided by an embodiment of the present application;
[0027] Figure 4 It is the link topology map at the k-th moment provided by an embodiment of the present application;
[0028] Figure 5 It is a schematic diagram of the default splicing method when the structural feature is a ring topology structure provided by an embodiment of the present application;
[0029] Figure 6 It is a schematic diagram of the default splicing method when the structural feature is a star topology structure provided by an embodiment of the present application;
[0030] Figure 7 It is a schematic flowchart of the second method for generating a monitoring model provided by an embodiment of the present application;
[0031] Figure 8 It is a schematic flowchart of the third method for generating a monitoring model provided by an embodiment of the present application;
[0032] Figure 9 It is a schematic flowchart of the fourth method for generating a monitoring model provided by an embodiment of the present application;
[0033] Figure 10 It is a schematic flowchart of the fifth method for generating a monitoring model provided by an embodiment of the present application;
[0034] Figure 11 It is a schematic block diagram of the second method for determining the node graph-level change feature and the link graph-level change feature provided by an embodiment of the present application;
[0035] Figure 12 It is a schematic block diagram of a monitoring model generation device provided by an embodiment of the present application;
[0036] Figure 13It is a schematic block diagram of a monitoring model generation device provided by an embodiment of the present application. Detailed implementation manners
[0037] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.
[0038] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned accompanying drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or server including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0039] In the embodiments of the present invention, mainly aiming at the problem in the prior art that only the nodes in the distributed cluster system are monitored for anomalies by using traditional anomaly monitoring means, and the anomalies between interactive nodes cannot be effectively monitored, resulting in poor monitoring effects, a monitoring model generation method, device, equipment and storage medium are proposed.
[0040] Next, a monitoring model generation method, device, equipment and storage medium provided by an embodiment of the present application will be described in detail with reference to the accompanying drawings.
[0041] First, in combination with Figure 1 , a monitoring model generation method provided by an embodiment of the present application will be described. Figure 1 It is a schematic flowchart of the first monitoring model generation method of an embodiment of the present application. The monitoring model generation method provided in this embodiment can be executed by a monitoring model generation device to control the process of generating a monitoring model for monitoring a distributed cluster system. The monitoring model generation device can be composed of hardware and / or software and can be integrated into a monitoring model generation device. Among them, the monitoring model generation method includes the following steps:
[0042] S101, obtain the node topology diagrams of the distributed cluster system at different times.
[0043] Among them, the node topology diagram is composed of nodes and connection lines, and can represent the hierarchical relationship between each node.
[0044] Due to the number of nodes and the connection relationship between nodes in the distributed cluster system, which will change over time. For example, as Figure 2 shown. For the above reasons, optionally, the embodiments of the present application can respectively obtain the positions of each node and the connection relationship between each node in the physical space layer of the distributed cluster system at different times, and construct the node topology diagrams of the distributed cluster system at different times according to the obtained positions of each node and the connection relationship between each node; or, the embodiments of the present application can also naturally map to obtain the node topology diagrams of the distributed cluster system at different times based on the obtained positions of each node and the connection relationship between each node.
[0045] S102. Perform linear processing on each of the node topology diagrams to determine the link topology diagrams corresponding to each of the node topology diagrams.
[0046] For example, as Figure 3 shown, in the node topology diagram at the k-th moment, the nodes are v1, v2, v3, and v4, and the links are e1, e2, e3, and e4. At this time, by mapping the links e1, e2, e3, and e4 into new nodes, and generating new links between the links e1, e2, e3, and e4 and their adjacent links, the link topology diagram at the k-th moment is obtained. For details, see Figure 4 .
[0047] That is to say, by using the links in each node topology diagram as new nodes, and generating new links between the new nodes, the link topology diagrams corresponding to each node topology diagram are generated.
[0048] S103. Determine the node graph-level features of each of the node topology diagrams and the link graph-level features of each of the link topology diagrams.
[0049] Specifically, when determining the node graph-level features and the link graph-level features, the node topology diagrams and the link topology diagrams at each moment can be used as input data and input into the graph neural network to obtain the node-level features of the node topology diagrams and the node-level features of the link topology diagrams. In this embodiment, the node-level features include attribute features and structural features. Among them, the attribute features are specifically the feature vectors of each node in the topology diagram, and the feature vectors can include, but are not limited to: node degree, node centrality, and graph element degree vector, etc. The structural features are specifically the topological structure of the topology diagram, and the structural relationship between each node is reflected through the topological structure.
[0050] After determining the node-level features of the node topology diagrams and the node-level features of the link topology diagrams, this embodiment can determine the node graph-level features of each node topology diagram and the link graph-level features of each link topology diagram based on the above two types of node-level features.
[0051] Specifically, when determining the node graph-level features of each node topology graph, first, according to the structural features in the node-level features of each node topology graph, determine the splicing method of the nodes in each node topology graph. Then, according to the splicing method, splice the attribute features of the nodes to obtain a splicing result, and determine the splicing result as the node graph-level feature of each node topology graph.
[0052] Correspondingly, when determining the link graph-level features of each link topology graph, first, according to the structural features in the node-level features of each link topology graph, determine the splicing method of the nodes in each link topology graph. Then, according to the splicing method, splice the attribute features of the nodes to obtain a splicing result, and determine the splicing result as the link graph-level feature of each link topology graph.
[0053] In this embodiment, when determining the splicing method of the nodes in each topology graph, the graph isomorphism algorithm can be used to determine it according to the structural features in the node-level features. Or, the default splicing method corresponding to the structural features in the node-level features can also be used as the splicing method of the nodes in each topology graph, and so on. There is no specific limitation here.
[0054] Among them, the default splicing method is specifically determined according to the structural features. For example, when the node structural feature is a ring topology structure, the default splicing method is to splice each node in turn according to the data transmission direction, specifically as Figure 5 shown. Among them, node 1 is the starting node, then each node is spliced in turn according to the order of node 1, node 2, node 3, node 4, node 5, and node 6. Another example is that when the node structural feature is a star topology structure, the default splicing method is to splice in turn according to the node numbers in ascending order, specifically as Figure 6 shown. Among them, this structure includes four nodes, namely node 22, node 23, node 24, and node 21. Then, according to the node numbers, after sorting the above four nodes, the sorting result is: node 21, node 22, node 23, and node 24. Then, the above four nodes can be spliced in turn according to the order of node 21, node 22, node 23, and node 24.
[0055] S104. Determine the node graph-level change features according to all the node graph-level features, and determine the link graph-level change features according to all the link graph-level features.
[0056] In practical applications, the number of nodes and the connection relationships between nodes in a distributed cluster system will change, that is, the node topology graph and the link topology graph determined by the node topology graph will change. Then, based on all node graph-level features, this embodiment can determine which nodes in the node topology graph have changed, obtain node graph-level change features based on the node change situation, and based on all link graph-level features, determine which links in the link topology graph have changed, and obtain link graph-level change features based on the link change situation. Thus, based on the node graph-level change features and the link graph-level change features, a foundation is laid for generating a monitoring model for monitoring the distributed cluster system subsequently.
[0057] Optionally, the embodiments of this application can adopt the following method to determine the node graph-level change features and the link graph-level change features.
[0058] The first method is to take all node graph-level features and all link graph-level features as an overall feature, and input the overall feature into a model for determining graph-level change features, so as to process the overall feature through this model to determine the node graph-level change features and the link graph-level change features.
[0059] The second method is to input all node graph-level features and all link graph-level features into different models for determining graph-level change features respectively, so as to process all node graph-level features and all link graph-level features through different models for determining graph-level change features to determine the node graph-level change features and the link graph-level change features.
[0060] It should be noted that the model for determining graph-level change features in this embodiment is preferably a time series network structure model. The time series network structure includes at least one of the following: long short-term memory network, time recurrent neural network, and hidden Markov model. In this embodiment, the time series network structure is preferably a long short-term memory network.
[0061] S104, generate a monitoring model according to the node graph-level change features and the link graph-level change features for abnormal monitoring of the distributed cluster system.
[0062] Specifically, this embodiment can use the node graph-level change features and the link graph-level change features to train a preset graph neural network to generate an abnormal monitoring model.
[0063] That is to say, take the node graph-level change features and the link graph-level change features as input values and input them into a preset graph neural network to train the preset graph neural network, and use the training result as a monitoring model for abnormal monitoring of the distributed cluster system. Thus, a monitoring model is trained by using a graph neural network according to the supervised learning of a dynamic network.
[0064] Furthermore, after generating the monitoring model, the embodiments of the present application can utilize the monitoring model to perform anomaly monitoring on the distributed cluster system. Thus, the purpose of anomaly monitoring on the operation processes of each node and the nodes with interactivity in the distributed cluster system can be achieved based on a single monitoring model, avoiding the training and maintenance of separate monitoring models for each node, effectively reducing the monitoring cost and difficulty, and improving the anomaly monitoring effect.
[0065] The monitoring model generation method provided by the embodiments of the present application generates a monitoring model for monitoring whether anomalies occur in the distributed cluster system by using the node topology graphs at different times, and performs anomaly monitoring on the operation status of each node and the nodes with interactivity in the distributed cluster system through the monitoring model, thereby providing conditions for timely discovering anomalies in the operation of the distributed cluster system and improving the monitoring effect.
[0066] As can be seen from the above analysis, the embodiments of the present application generate a monitoring model by using the node graph-level change features and link graph-level change features determined by the node topology graphs at different times, and utilize the monitoring model to perform anomaly monitoring on the distributed cluster system.
[0067] In the specific implementation process, the embodiments of the present application can determine the node graph-level features of the node topology graphs at each time and the link graph-level features of the link topology graphs at each time in different ways. The following combines Figure 7 and Figure 8 to further optimize the determination of the node graph-level features of the node topology graphs at each time and the link graph-level features of the link topology graphs at each time in the embodiments of the present application.
[0068] First, the first method for determining the node graph-level features of the node topology graphs at each time and the link graph-level features of the link topology graphs at each time is described in detail in combination with Figure 7 The flowchart of the second monitoring model generation method of the embodiments of the present application is shown in
[0069] Figure 7 This method includes the following steps:
[0070] S201, Obtain the node topology graphs of the distributed cluster system at different times.
[0071] S202, Perform linear processing on each of the node topology graphs to determine the corresponding link topology graphs.
[0072] S203, Input each of the node topology graphs and each of the link topology graphs into a first graph neural network to obtain the node-level features of each of the node topology graphs and the node-level features of each of the link topology graphs.
[0073] In the embodiments of the present application, the first graph neural network is preferably a graph convolutional neural network.
[0074] Specifically, when implemented, by inputting each node topology graph and each link topology Figure 1 into the first graph neural network, so that the first graph neural network learns based on the above-mentioned sequence of each node topology graph and each link topology graph, in order to obtain the node-level features of each node topology graph and the node-level features of each link topology graph.
[0075] Among them, during the learning process based on each node topology graph and each link topology graph, the transfer method between layers in the first graph neural network can be represented by the following formula (1):
[0076]
[0077] Among them, H is the feature of each layer, l is the l-th layer in the preset graph neural network, σ is the non-linear activation function, is the degree matrix of is the adjacency matrix, and W is the weight parameter.
[0078] Since the role of the adjacency matrix in the above formula is to determine the transfer strategy of node states, and the role of the weight parameter W is to determine the aggregation strategy of node attributes, then the adjacency matrix and the weight parameter W can be regarded as decoupled. Therefore, even when the first graph neural network learns based on the node topology graph and the link topology graph with a time sequence, the weight parameters in the first graph neural network do not need to be continuously updated, thereby achieving the simplification of the learning process of the first graph neural network.
[0079] In other words, during the learning process of the first graph neural network based on each node topology graph and each link topology graph in this embodiment, the weight parameters in the first graph neural network do not change with time, thereby realizing parameter sharing in the dynamic learning process.
[0080] It should be understood that when the global topological properties of the node topology graph or the link topology graph in the distributed cluster system, such as degree distribution, centrality, betweenness, compactness, average path length, and clustering coefficient, are relatively stable, the independence of the weight parameters in the graph neural network will be stronger.
[0081] S204. Based on the graph isomorphism algorithm, according to the node-level features of each of the node topology graphs, determine the node graph-level features of each of the node topology graphs.
[0082] S205. Based on the graph isomorphism algorithm, according to the node-level features of each of the link topology graphs, determine the link graph-level features of each of the link topology graphs.
[0083] In this embodiment, the graph isomorphism algorithm refers to the Weisfeiler-Lehman algorithm (abbreviated as the WL algorithm).
[0084] Since the first graph neural network is used to perform graph embedding representation on each node topology graph and each link topology graph, the obtained result is the node-level feature of each topology graph. To summarize and obtain the graph-level feature of each topology graph, the embodiment of the present application uses the WL algorithm to solve this problem. Specifically, the WL algorithm tests the similarity of two graphs by iteratively partitioning the roles of the vertices of the graph. During the calculation process of the WL algorithm, nodes are colored (tagged). In different graphs, nodes in similar positions will get the same coloring, that is, the same tag. Then, using the calculation result of the WL algorithm, the nodes are sorted to obtain the graph-level feature representation of the entire graph.
[0085] That is to say, in this embodiment, by using the WL algorithm, the node-level features of each topology graph are calculated, and the calculation results are sorted to obtain the graph-level features of each topology graph.
[0086] S206. Determine the node graph-level change feature according to all node graph-level features, and determine the link graph-level change feature according to all link graph-level features.
[0087] S207. Generate a monitoring model according to the node graph-level change feature and the link graph-level change feature for anomaly monitoring of the distributed cluster system.
[0088] Secondly, combine Figure 8 A second method for determining the node graph-level features of each node topology graph and the link graph-level features of each link topology graph at each moment is described in detail.
[0089] Figure 8 It is a schematic flowchart of the third monitoring model generation method of the embodiment of the present application. This method includes the following:
[0090] S301. Obtain the node topology graphs of the distributed cluster system at different moments.
[0091] S302. Perform linear processing on each of the node topology graphs to determine the link topology graph corresponding to each of the node topology graphs.
[0092] S303. Input each of the node topology graphs into a second graph neural network to obtain the node-level features of each of the node topology graphs.
[0093] S304. Input each of the link topology graphs into a third graph neural network to obtain the node-level features of each of the link topology graphs.
[0094] In the embodiments of the present application, the second graph neural network and the third graph neural network are preferably graph convolutional neural networks.
[0095] Specifically, the implementation principles and processes of S303 and S304 are basically the same as those of the foregoing S203. For the specific implementation process, refer to S203.
[0096] It should be noted that the execution order of S303 and S304 can be to execute S303 first and then S304; or, execute S304 first and then S303; or, execute S303 and S304 simultaneously. There is no specific limitation here. In this embodiment, it is preferably to execute S303 and S304 simultaneously.
[0097] S305, based on the graph isomorphism algorithm, determine the node graph-level features of each of the node topology graphs according to the node-level features of each of the node topology graphs.
[0098] S306, based on the graph isomorphism algorithm, determine the link graph-level features of each of the link topology graphs according to the node-level features of each of the link topology graphs.
[0099] Specifically, the implementation principles and processes of S305 - S306 are basically the same as those of the foregoing S204 - S205. For the specific implementation process, refer to S204 - S205.
[0100] It should be noted that the execution order of S305 and S306 can be to execute S305 first and then S306; or, execute S306 first and then S305; or, execute S305 and S306 simultaneously. There is no specific limitation here. In this embodiment, it is preferably to execute S305 and S306 simultaneously.
[0101] S307, determine the node graph-level change features according to all the node graph-level features, and determine the link graph-level change features according to all the link graph-level features.
[0102] S308, generate a monitoring model according to the node graph-level change features and the link graph-level change features for anomaly monitoring of the distributed cluster system.
[0103] In the embodiments of the present application, by using the node topology graphs at different times, a monitoring model for monitoring whether an abnormality occurs in a distributed cluster system is generated, and through the monitoring model, the running conditions of each node and the nodes with interactivity in the distributed cluster system are monitored for abnormalities, thereby providing conditions for timely discovering the abnormal operation of the distributed cluster system and improving the monitoring effect. In addition, the present application determines the node graph-level features of the node topology graphs at each time and the link graph-level features of the link topology graphs at each time in multiple ways, effectively helping the device to perform graph processing in different ways based on its own performance, and also meeting the personalized needs of users for topology graph processing.
[0104] Through the above analysis, it can be seen that in the embodiments of the present application, the node graph-level features of the node topology graphs at each time and the link graph-level features of the link topology graphs at each time are determined in different ways.
[0105] The following combines Figure 9 and Figure 10 , and further optimizes the determination of the node graph-level change features and the link graph-level change features in the embodiments of the present application. First, the first method for determining the node graph-level change features and the link graph-level change features is described in detail in combination with Figure 9 .
[0106] Figure 9 is a schematic flowchart of the fourth method for generating a monitoring model in the embodiments of the present application. The method includes the following:
[0107] S401, obtain the node topology graphs of the distributed cluster system at different times.
[0108] S402, perform linear processing on each of the node topology graphs to determine the corresponding link topology graphs.
[0109] S403, determine the node graph-level features of each of the node topology graphs and the link graph-level features of each of the link topology graphs.
[0110] S404, splice all the node graph-level features and all the link graph-level features together to form a spliced feature.
[0111] Optionally, in this embodiment, all the node graph-level features and all the link graph-level features can be spliced together according to a preset rule. Wherein, the preset rule refers to any method of splicing the node graph-level features and the link graph-level features together.
[0112] For example, the preset rule can be in the following format: node graph-level feature + link graph-level feature; or, link graph-level feature + node graph-level feature, etc., and no specific limitation is made here.
[0113] S405. Input the splicing feature into the first feature determination model to determine the node graph-level change feature and the link graph-level change feature.
[0114] Among them, the first feature determination model is a model for determining the graph-level change feature. In this embodiment, the network structure of the first feature determination model is a time series network structure. Optionally, the time series network structure includes at least one of the following: long short-term memory network, time recurrent neural network, and hidden Markov model. In this embodiment, the time series network structure is preferably a long short-term memory network.
[0115] Specifically, after splicing all the node graph-level features and all the link graph-level features together to form a splicing feature, the splicing feature is input into the first feature determination model, so as to process the splicing feature through the first feature determination model to obtain the node graph-level change feature and the link graph-level change feature.
[0116] S406. Generate a monitoring model according to the node graph-level change feature and the link graph-level change feature for abnormal monitoring of the distributed cluster system.
[0117] In the embodiment of the present application, by splicing the node graph-level feature and the link graph-level feature and using the first feature determination model to perform overall processing on the splicing feature, the node graph-level change feature and the link graph-level change feature are obtained, thereby laying a foundation for generating a monitoring model subsequently.
[0118] The following combines Figure 10 to elaborate in detail on the second method for determining the node graph-level change feature and the link graph-level change feature.
[0119] Figure 10 is a schematic flowchart of the fifth monitoring model generation method in the embodiment of the present application. This method includes the following:
[0120] S501. Obtain the node topology graphs of the distributed cluster system at different times.
[0121] S502. Perform linear processing on each of the node topology graphs to determine the link topology graph corresponding to each of the node topology graphs.
[0122] S503. Determine the node graph-level features of each of the node topology graphs and the link graph-level features of each of the link topology graphs.
[0123] S504. Based on the graph-level feature properties, input all the node graph-level features into the second feature determination model to determine the node graph-level change feature.
[0124] S505. Input all the link graph-level features into the third feature determination model to determine the link graph-level change feature.
[0125] Among them, the second feature determination model and the third feature determination model are models for determining graph-level change features respectively. In this embodiment, the network structures of the second feature determination model and the third feature determination model are time series network structures. Optionally, the time series network structure includes at least one of the following: long short-term memory network, time recurrent neural network, and hidden Markov model. In this embodiment, the time series network structure is preferably a long short-term memory network.
[0126] In the embodiment of the present application, based on the properties of graph-level features, the node graph-level features and link graph-level features are divided into two categories, and each category of features is separately input into a feature determination model to respectively determine the node graph-level change features and link graph-level change features, thereby not only improving the determination speed of graph-level change features, but also improving the accuracy of determining graph-level change features.
[0127] It should be noted that the execution order of S504 and S505 can be to execute S504 first and then S505; or, execute S505 first and then S504; or, execute S504 and S505 in parallel. There is no specific limitation here. In this embodiment, it is preferably to execute S504 and S505 in parallel to improve the processing speed.
[0128] S506, generate a monitoring model according to the node graph-level change features and the link graph-level change features for abnormal monitoring of the distributed cluster system.
[0129] For ease of understanding, the second method for determining the node graph-level change features and the link graph-level change features in this embodiment can be represented by the Figure 11 schematic block diagram shown, specifically see Figure 11 shown.
[0130] In the embodiment of the present application, by separately inputting the node graph-level features and the link graph-level features into the second feature determination model and the third feature determination model to determine the node graph-level change features and the link graph-level change features, it can not only improve the determination speed of graph-level change features, but also improve the accuracy of determining graph-level change features, providing favorable conditions for generating a monitoring model.
[0131] Next, with reference to the attached Figure 12 , a monitoring model generation device proposed in the embodiment of the present application will be described. Figure 12 is a schematic block diagram of a monitoring model generation device in the embodiment of the present application.
[0132] Among them, the monitoring model generation device 600 includes: a topology graph acquisition module 610, a first determination module 620, a second determination module 630, a third determination module 640, and a model generation module 650.
[0133] Among them, the topology graph acquisition module 610 is used to acquire the node topology graphs of the distributed cluster system at different times;
[0134] The first determination module 620 is used to perform linear processing on each of the node topology graphs to determine the link topology graphs corresponding to each of the node topology graphs;
[0135] The second determination module 630 is used to determine the node graph-level features of each of the node topology graphs and the link graph-level features of each of the link topology graphs;
[0136] The third determination module 640 is used to determine the node graph-level change features according to all the node graph-level features, and determine the link graph-level change features according to all the link graph-level features;
[0137] The model generation module 650 is used to generate a monitoring model according to the node graph-level change features and the link graph-level change features for abnormal monitoring of the distributed cluster system.
[0138] In an optional implementation manner of the embodiment of the present application, the second determination module 630 is specifically used for:
[0139] Input each of the node topology graphs and each of the link topology graphs into the first graph neural network to obtain the node-level features of each of the node topology graphs and the node-level features of each of the link topology graphs;
[0140] Based on the graph isomorphism algorithm, determine the node graph-level features of each of the node topology graphs according to the node-level features of each of the node topology graphs;
[0141] Based on the graph isomorphism algorithm, determine the link graph-level features of each of the link topology graphs according to the node-level features of each of the link topology graphs.
[0142] In an optional implementation manner of the embodiment of the present application, the second determination module 630 is specifically used for:
[0143] Input each of the node topology graphs into the second graph neural network to obtain the node-level features of each of the node topology graphs;
[0144] Input each of the link topology graphs into the third graph neural network to obtain the node-level features of each of the link topology graphs;
[0145] Based on the graph isomorphism algorithm, determine the node graph-level features of each of the node topology graphs according to the node-level features of each of the node topology graphs;
[0146] Based on the graph isomorphism algorithm, determine the link graph-level features of each of the link topology graphs according to the node-level features of each of the link topology graphs.
[0147] An alternative implementation of the embodiment of the present application, the third determination module 640 is specifically configured to:
[0148] Concatenate all node graph-level features and all link graph-level features together to form a concatenated feature;
[0149] Input the concatenated feature into the first feature determination model to determine the node graph-level change feature and the link graph-level change feature.
[0150] An alternative implementation of the embodiment of the present application, the third determination module 640 is specifically configured to:
[0151] Determining the node graph-level change feature and the link graph-level change feature includes:
[0152] Based on the graph-level feature nature, input all node graph-level features into the second feature determination model to determine the node graph-level change feature;
[0153] Input all link graph-level features into the third feature determination model to determine the link graph-level change feature.
[0154] An alternative implementation of the embodiment of the present application, the network structure of the feature determination model is a time series type network structure.
[0155] An alternative implementation of the embodiment of the present application, the time series type network structure includes at least one of the following: long short-term memory network, time recurrent neural network, and hidden Markov model.
[0156] An alternative implementation of the embodiment of the present application, the model generation module 650 is specifically configured to:
[0157] Use the node graph-level change feature and the link graph-level change feature to train a preset graph neural network to generate a monitoring model.
[0158] It should be understood that the embodiment of the monitoring model generation device and the embodiment of the monitoring model generation method can correspond to each other, and similar descriptions can refer to the method embodiment. To avoid repetition, it will not be elaborated here. Specifically, Figure 12 The shown monitoring model generation device 600 can execute Figure 1 the corresponding method embodiment, and the foregoing and other operations and / or functions of each module in the monitoring model generation device 600 are respectively for implementing Figure 1 the corresponding processes in each method, and for the sake of brevity, it will not be elaborated here.
[0159] In the above, the monitoring model generation device 600 according to the embodiments of the present application has been described from the perspective of functional modules in combination with the accompanying drawings. It should be understood that the functional modules can be implemented in the form of hardware, can also be implemented by instructions in the form of software, or can be implemented by a combination of hardware and software modules. Specifically, the steps of the monitoring model generation method embodiments in the present application can be completed by the integrated logic circuit in the hardware of the processor and / or instructions in the form of software. Combining the steps of the monitoring model generation method disclosed in the embodiments of the present application can be directly embodied as being completed by the hardware decoding processor, or can be completed by a combination of the hardware and software modules in the decoding processor. Optionally, the software module can be located in a mature storage medium in the art such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps in the above method embodiments.
[0160] Figure 13 FIG. 4 is a schematic block diagram of a monitoring model generation device 700 provided by an embodiment of the present application.
[0161] As Figure 13 shown, the monitoring model generation device 700 may include:
[0162] A memory 710 and a processor 720. The memory 710 is used to store a computer program and transmit the program code to the processor 720. In other words, the processor 720 can call and run the computer program from the memory 710 to implement the monitoring model generation method in the embodiments of the present application.
[0163] For example, the processor 720 can be used to execute the above monitoring model generation method embodiments according to the instructions in the computer program.
[0164] In some embodiments of the present application, the processor 720 may include, but is not limited to:
[0165] A general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and so on.
[0166] In some embodiments of the present application, the memory 710 includes, but is not limited to:
[0167] Volatile memory and / or non-volatile memory. Among them, the non-volatile memory can be Read-Only Memory (ROM), Programmable ROM (PROM), Erasable PROM (EPROM), Electrically Erasable PROM (EEPROM), or flash memory. The volatile memory can be Random Access Memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double DataRate SDRAM (DDR SDRAM), Enhanced SDRAM (ESDRAM), synch link DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).
[0168] In some embodiments of the present application, the computer program can be divided into one or more modules, and the one or more modules are stored in the memory 710 and executed by the processor 720 to complete the method provided by the present application. The one or more modules can be a series of computer program instruction segments capable of completing specific functions, and the instruction segments are used to describe the execution process of the computer program in the monitoring model generation device.
[0169] As Figure 13 shown, the monitoring model generation device 700 may further include:
[0170] A transceiver 730, which can be connected to the processor 720 or the memory 710.
[0171] Among them, the processor 720 can control the transceiver 730 to communicate with other devices. Specifically, it can send information or data to other devices, or receive information or data sent by other devices. The transceiver 730 can include a transmitter and a receiver. The transceiver 730 can further include an antenna, and the number of antennas can be one or more.
[0172] It should be understood that each component in the monitoring model generation device 700 is connected through a bus system. Among them, the bus system includes, in addition to the data bus, a power bus, a control bus, and a status signal bus.
[0173] The present application also provides a computer storage medium, on which a computer program is stored. When the computer program is executed by a computer, the computer can execute the monitoring model generation method of the above embodiments. Or rather, the embodiments of the present application also provide a computer program product containing instructions. When the instructions are executed by a computer, the computer executes the method of the above method embodiments.
[0174] When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a digital video disc (DVD)), or a semiconductor medium (such as a solid state disk (SSD)), etc.
[0175] Those of ordinary skill in the art can realize that the modules and algorithm steps of each example described in combination with the embodiments disclosed in this document can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but this implementation should not be considered to exceed the scope of the present application.
[0176] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections between each other can be through some interfaces. The indirect couplings or communication connections of the devices or modules can be in electrical, mechanical, or other forms.
[0177] The modules described as separate components may or may not be physically separated. The components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. For example, in each embodiment of the present application, the various functional modules can be integrated into a processing module, or each module can exist physically alone, or two or more modules can be integrated into one module.
[0178] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for generating a monitoring model, characterized in that, Including: Obtain the node topology diagrams of the distributed cluster system at different times; Perform linear processing on each of the node topology diagrams to determine the corresponding link topology diagrams; Determine the node graph-level features of each of the node topology diagrams and the link graph-level features of each of the link topology diagrams; According to all the node graph-level features, determine the node graph-level change features, and according to all the link graph-level features, determine the link graph-level change features; Generate a monitoring model according to the node graph-level change features and the link graph-level change features for anomaly monitoring of the distributed cluster system.
2. The method according to claim 1, wherein Determine the node graph-level features of each of the node topology diagrams and the link graph-level features of each of the link topology diagrams, including: Input each of the node topology diagrams and each of the link topology diagrams into a first graph neural network to obtain the node-level features of each of the node topology diagrams and the node-level features of each of the link topology diagrams; Based on the graph isomorphism algorithm, determine the node graph-level features of each of the node topology diagrams according to the node-level features of each of the node topology diagrams; Based on the graph isomorphism algorithm, determine the link graph-level features of each of the link topology diagrams according to the node-level features of each of the link topology diagrams.
3. The method according to claim 1, wherein Determine the node graph-level features of each of the node topology diagrams and the link graph-level features of each of the link topology diagrams, including: Input each of the node topology diagrams into a second graph neural network to obtain the node-level features of each of the node topology diagrams; Input each of the link topology diagrams into a third graph neural network to obtain the node-level features of each of the link topology diagrams; Based on the graph isomorphism algorithm, determine the node graph-level features of each of the node topology diagrams according to the node-level features of each of the node topology diagrams; Based on the graph isomorphism algorithm, determine the link graph-level features of each of the link topology diagrams according to the node-level features of each of the link topology diagrams.
4. The method according to claim 1, characterized in that, Determine the node graph-level change features and the link graph-level change features, including: Concatenate all the node graph-level features and all the link graph-level features together to form a concatenated feature; Input the concatenated feature into a first feature determination model to determine the node graph-level change features and the link graph-level change features.
5. The method according to claim 1, wherein Determine the node graph-level change features and the link graph-level change features, including: Based on the graph-level feature properties, input all the node graph-level features into a second feature determination model to determine the node graph-level change features; Input all the link graph-level features into a third feature determination model to determine the link graph-level change features.
6. The method according to any one of claims 4-5, characterized in that, The network structure of the feature determination model is a time series type network structure.
7. The method according to claim 1, characterized in that Generate a monitoring model according to the node graph-level change features and the link graph-level change features, including: Use the node graph-level change features and the link graph-level change features to train a preset graph neural network to generate a monitoring model.
8. A monitoring model generation device, characterized in that Including: A topology diagram acquisition module for obtaining the node topology diagrams of the distributed cluster system at different times; A first determination module for performing linear processing on each of the node topology diagrams to determine the corresponding link topology diagrams; A second determination module, configured to determine the node graph-level features of each of the node topology graphs and the link graph-level features of each of the link topology graphs; A third determination module, configured to determine the node graph-level change features based on all the node graph-level features, and determine the link graph-level change features based on all the link graph-level features; A model generation module, configured to generate a monitoring model according to the node graph-level change features and the link graph-level change features, so as to be used for anomaly monitoring of the distributed cluster system.
9. A monitoring model generation device, characterized in that, Comprising: A processor and a memory, where the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory to execute the monitoring model generation method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, For storing a computer program, which causes a computer to execute the monitoring model generation method according to any one of claims 1 to 7.
11. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by a processor, it implements the monitoring model generation method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Information popularity prediction method based on graph neural network
CN112580879A
Topology mapping method and device based on deep learning, medium and program product
CN113568860A