Abnormal Handling Method, Device and Computer Equipment for Internet Service Platform
By obtaining and processing public opinion information from the Internet, and combining the business log data of the Internet service platform to identify and analyze abnormal information, the problem of the inability to accurately identify and handle Internet resource service abnormalities in the existing technology is solved, and more efficient abnormal response and data security guarantee are achieved.
Patent Information
- Application Number
- CN202210012280.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-07
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2042-01-07
AI Technical Summary
The prior art cannot accurately identify external and internal exceptions and business security exceptions related to Internet resource services, and cannot effectively help business personnel respond abnormally.
By obtaining public opinion information from the Internet, text processing is carried out to identify abnormal public opinion information; obtaining business log data of the Internet service platform to identify abnormal personnel and events; matching, evaluating and positioning abnormal public opinion information and event information, and processing is carried out in accordance with the predetermined strategy.
It realizes accurate identification and comprehensive analysis of abnormal public opinion information and event information on the Internet service platform, improves the agility, accuracy and intelligence of abnormal recognition, and ensures the data security of Internet resource services.
Smart Images

Figure CN114398465B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer information processing, and particularly to an exception handling method, apparatus, and computer device for an Internet service platform. Background Art
[0002] In Internet-based application technologies, it is often necessary to exchange resources among different participants. The resources referred to here mean any utilizable substances, information, money, time, etc. Information resources include computing resources and various types of data resources. Data resources include various specialized data in various fields. In the process of allocating resources, it is often necessary to authenticate the resource configuration rights of users and allocate different resource quotas to different users. The resource configuration right refers to an authentication of whether a user has the right to obtain resources, which can be authenticated by a specific resource management agency or by the owner of the resources. The so-called resource quota refers to the maximum amount of resources that the user can obtain within a specific time.
[0003] Resources related to money are usually also called Internet resources. The Internet resources refer to the sum or aggregate of a series of objects regarding the structure, quantity, scale, distribution, and their effects and interaction relationships between the resource service subject and object in the Internet field. In production and life, only when the Internet resource allocation is efficient can the sustainable development of Internet resources and the economy be achieved. Among them, the Internet resources can be the total amount of funds, or the amount of assets equivalent to funds, etc. For a company providing Internet resource services, a part of the Internet assets can be used to provide resource services for individual users, and another part can be used to provide Internet resources services for other enterprise users, and the other part can be used for the development of the company itself or for other Internet-related operations.
[0004] In the process of providing or allocating existing Internet resource services, there are business security problems such as data leakage exceptions, basic security exceptions, and user fraud exceptions. In addition, in the process of monitoring Internet public opinion for existing Internet resource services, manual approval of public opinion information and reporting of negative public opinion information are mostly used. The monitoring process is cumbersome, and it is easy to cause data errors due to monitoring errors caused by manual intervention, and even lead to business security problems. In addition, in the prior art, there are technical problems that external exceptions, internal exceptions, and business security exceptions related to Internet resource services cannot be accurately identified, and it is also impossible to help relevant business personnel respond to exceptions more effectively. Therefore, there is still much room for improvement in aspects such as information data monitoring, data security, and data processing of Internet resource services.
[0005] Therefore, it is necessary to provide a more optimized exception handling method for an Internet service platform. Summary of the Invention
[0006] In order to solve the technical problems in the prior art that external anomalies, internal anomalies, and business security anomalies related to Internet resource services cannot be accurately identified, and it is also impossible to help relevant business personnel respond to anomalies more effectively, etc.
[0007] A first aspect of the present invention provides an anomaly handling method for an Internet service platform, including: obtaining public opinion information from the Internet, performing text processing on the public opinion information to identify anomaly public opinion information related to the Internet service platform; obtaining business log data of the Internet service platform, identifying anomaly events of anomaly personnel to obtain anomaly event information; performing anomaly matching on the anomaly public opinion information and the anomaly event information, and performing anomaly evaluation and anomaly positioning according to the matching result, and accordingly performing anomaly handling operations in accordance with a predetermined anomaly handling strategy.
[0008] According to an optional implementation manner, the text processing of the public opinion information includes: using the simihash method to perform an approximation judgment on the text content of the monitored public opinion information and a specific text, and determining the public opinion information with a similarity greater than a specified value as anomaly public opinion information.
[0009] According to an optional implementation manner, before performing the approximation judgment on the text content of the public opinion information and a specific text, performing sentiment analysis and semantic analysis on the text content according to a predetermined positive and negative text corpus, and the corpus is a corpus related to the security of the Internet service platform.
[0010] According to an optional implementation manner, the identifying of the anomaly events of the anomaly personnel to obtain anomaly event information includes: monitoring and identifying anomaly operations performed by the anomaly personnel in the database or data warehouse of the background system of the Internet service platform to obtain anomaly event information.
[0011] According to an optional implementation manner, the identifying of the anomaly events of the anomaly personnel to obtain anomaly event information further includes: adding a monitoring script to the background system to monitor the anomaly operations of the anomaly personnel.
[0012] According to an optional implementation manner, the anomaly handling method further includes triggering linkage analysis processing, wherein when it is determined that the external public opinion information contains trigger point information, triggering the obtaining of relevant business log data of the Internet service platform for performing linkage analysis processing on the external public opinion information and the relevant business log data. According to an optional implementation manner, the anomaly evaluation includes: creating a manual follow-up work order for manual anomaly confirmation.
[0013] According to an optional implementation manner, the anomaly evaluation includes: triggering a chatbot to automatically chat with the anomaly personnel for anomaly confirmation.
[0014] According to an alternative embodiment, the anomaly location includes: building a streaming computing engine using Flink, and performing real-time analysis on the monitored public opinion anomalies or service anomalies through rule matching, neural network algorithms or frequency analysis methods, and finding the anomaly location and / or the anomalous personnel therefrom.
[0015] According to an alternative embodiment, the anomaly matching includes: matching the abnormal public opinion information and the abnormal event information according to the correlation of the abnormal public opinion information and the abnormal event information in terms of time, frequency, and number of occurrences.
[0016] According to an alternative embodiment, it further includes: performing formatting processing on the abnormal public opinion information and the abnormal event information to generate abnormal log data; storing the abnormal log data in full, as well as the service data related to the abnormal log data.
[0017] In addition, a second aspect of the present invention further provides an anomaly processing device for an Internet service platform, including: a first acquisition module, configured to acquire public opinion information from the Internet, perform text processing on the public opinion information to identify abnormal public opinion information related to the Internet service platform; a second acquisition module, configured to acquire service log data of the Internet service platform, identify abnormal events of abnormal personnel to obtain abnormal event information; a matching processing module, configured to perform anomaly matching on the abnormal public opinion information and the abnormal event information, perform anomaly evaluation and anomaly location according to the matching result, and perform anomaly processing operations according to a predetermined anomaly processing strategy accordingly.
[0018] In addition, a third aspect of the present invention further provides a computer device, including a processor and a memory, where the memory is used to store computer-executable programs, and when the computer program is executed by the processor, the processor executes the anomaly processing method as described in the first aspect of the present invention.
[0019] In addition, a fourth aspect of the present invention further provides a computer program product, storing a computer-executable program, and when the computer-executable program is executed, the anomaly processing method as described in the present invention is implemented.
[0020] Beneficial effects
[0021] Compared with the prior art, by obtaining public opinion information from the Internet and performing text processing on the public opinion information, the present invention can accurately identify abnormal public opinion information related to the Internet service platform, and can provide security information and analysis results of abnormal events in a timely manner for relevant personnel such as security operation and maintenance personnel and business security personnel. By obtaining the business log data of the Internet service platform and identifying abnormal events of abnormal personnel, accurate abnormal event information can be obtained, potential data leakage abnormalities and basic security abnormalities can be identified in a timely manner, and security information and analysis results of abnormal events in a timely manner can be provided for relevant personnel such as security operation and maintenance personnel and business security personnel; by performing abnormal matching on the abnormal public opinion information and the abnormal event information, and performing abnormal evaluation and abnormal positioning according to the matching results, that is, by comprehensively analyzing external abnormal public opinion information and internal abnormal event information, abnormal evaluation and abnormal positioning can be carried out more effectively and quickly, and abnormal handling operations can be carried out more effectively, and the agility, accuracy, and intelligence of security anomaly identification can be significantly improved, and the data security of data related to Internet resource services can be effectively guaranteed.
[0022] Further, by using a machine learning model to perform text processing on the obtained public opinion information, abnormal public opinion information related to the Internet service platform can be accurately identified to obtain more accurate external abnormal public opinion information; by adding a proxy component (i.e., an agent component) to identify the system log data and business log data of the Internet service platform, or through a monitoring script, the internal business personnel and their high-risk behaviors can be monitored more effectively, and abnormal event information can be accurately obtained; by constructing a situation awareness probe, abnormal monitoring and analysis can be carried out from two perspectives of external network situation awareness and internal network security, using external public opinion information as a trigger point to trigger the acquisition of relevant business log data (i.e., internal business log data), and through a data analysis engine to perform linkage analysis on external public opinion information and internal business log data, thereby potential data leakage abnormalities, basic security abnormalities, etc. can be quickly identified, and the agility, accuracy, and intelligence of anomaly identification can be significantly improved. Brief Description of the Drawings
[0023] In order to make the technical problems solved by the present invention, the technical means adopted, and the technical effects obtained clearer, the specific embodiments of the present invention will be described in detail below with reference to the drawings. However, it should be noted that the drawings described below are only the drawings of the exemplary embodiments of the present invention, and those skilled in the art can obtain the drawings of other embodiments without creative efforts based on these drawings.
[0024] Figure 1 It is a flowchart of an example of the abnormal handling method of the Internet service platform of the present invention.
[0025] Figure 2 It is a flowchart of another example of the method for handling exceptions in the Internet service platform of the present invention.
[0026] Figure 3 It is a flowchart of yet another example of the method for handling exceptions in the Internet service platform of the present invention.
[0027] Figure 4 It is a schematic structural block diagram of an example of the apparatus for handling exceptions in the Internet service platform of the present invention.
[0028] Figure 5 It is a schematic structural block diagram of another example of the apparatus for handling exceptions in the Internet service platform of the present invention.
[0029] Figure 6 It is a schematic structural block diagram of yet another example of the apparatus for handling exceptions in the Internet service platform of the present invention.
[0030] Figure 7 It is a structural block diagram of an exemplary embodiment of a computer device according to the present invention.
[0031] Figure 8 It is a structural block diagram of an exemplary embodiment of a computer program product according to the present invention. Detailed implementation manners
[0032] Now, exemplary embodiments of the present invention will be described more comprehensively with reference to the accompanying drawings. However, the exemplary embodiments can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, providing these exemplary embodiments enables the present invention to be more comprehensive and complete, and more conveniently conveys the inventive concept to those skilled in the art. Identical reference numerals in the figures denote the same or similar elements, components, or parts, and thus their repeated description will be omitted.
[0033] On the premise of conforming to the technical concept of the present invention, the features, structures, characteristics, or other details described in a specific embodiment may not be excluded from being combined in a suitable manner in one or more other embodiments.
[0034] In the description of specific embodiments, the features, structures, characteristics, or other details described in the present invention are for enabling those skilled in the art to fully understand the embodiments. However, it does not exclude that those skilled in the art can practice the technical solutions of the present invention without one or more of the specific features, structures, characteristics, or other details.
[0035] The flowcharts shown in the accompanying drawings are only exemplary and do not necessarily include all the contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps can be decomposed, and some operations / steps can be combined or partially combined, so the actual execution order may change according to actual conditions.
[0036] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0037] It should be understood that although the terms "first", "second", "third", etc. may be used herein to describe various devices, elements, components or parts, this should not be limited by these terms. These terms are used to distinguish one from another. For example, a first device may also be called a second device without departing from the essential technical solution of the present invention.
[0038] The term "and / or" or "and / or" includes any one and all combinations of one or more of the associated listed items.
[0039] In order to further improve the accuracy of information data monitoring and more accurately identify external anomalies, internal anomalies and business security anomalies related to Internet resource services, the present invention provides an exception handling method for an Internet service platform. The method obtains public opinion information from the Internet and performs text processing on the public opinion information, so as to accurately identify abnormal public opinion information related to the Internet service platform. By obtaining the business log data of the Internet service platform, the abnormal events of abnormal personnel are identified, and accurate abnormal event information can be obtained. By performing abnormal matching on the abnormal public opinion information and the abnormal event information, and performing abnormal evaluation and abnormal location based on the matching results, that is, by performing a comprehensive analysis of the external abnormal public opinion information and the internal abnormal event information, the abnormal evaluation and abnormal location can be performed more effectively and quickly, and the abnormal handling operation can be performed more effectively.
[0040] In order to make the purpose, technical scheme and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with specific embodiments and with reference to the accompanying drawings. For convenience, the present invention uses Internet data resources as an example to illustrate the implementation of the Internet resource service product pricing method, but those skilled in the art should understand that the present invention can also be used for pricing other resource service products.
[0041] Example 1
[0042] Next, we will refer to Figures 1 to 3An embodiment of an exception handling method for an Internet service platform of the present invention is described.
[0043] Figure 1 It is a flowchart of an example of an exception handling method for an Internet service platform of the present invention.
[0044] As Figure 1 shown, the exception handling method includes the following steps.
[0045] Step S101: Obtain public opinion information from the Internet, perform text processing on the public opinion information to identify abnormal public opinion information related to the Internet service platform.
[0046] Step S102: Obtain the business log data of the Internet service platform, identify abnormal events of abnormal personnel to obtain abnormal event information.
[0047] Step S103: Perform abnormal matching on the abnormal public opinion information and the abnormal event information, perform abnormal evaluation and abnormal positioning according to the matching result, and perform abnormal handling operations according to a predetermined abnormal handling strategy.
[0048] It should be noted that in the present invention, the Internet service platform refers to a service platform that provides Internet resource services such as shopping, riding, maps, takeaways, shared bicycles, etc. based on applications of user devices or clients. For example, the Internet resource services include resource usage services, resource allocation services, resource raising services, resource guarantee services or mutual assistance services, group buying, and riding services, etc. Among them, resources refer to any available substances, information, time, and information resources include computing resources and various types of data resources. Data resources include various special data in various fields.
[0049] First, in step S101, obtain public opinion information from the Internet, perform text processing on the public opinion information to identify abnormal public opinion information related to the Internet service platform.
[0050] As a specific implementation manner, for example, collect information from social websites, news websites or other third-party platforms, etc., and obtain public opinion information from them.
[0051] It should be noted that in the present invention, the public opinion information refers to text information reflecting the public opinion status and its changes of public opinion matters related to Internet services. The public opinion matters include abnormal events that may cause economic losses to the Internet service platform or abnormal events caused by abnormal personnel, etc.
[0052] Optionally, deploy robots to specific user groups (such as telegram groups), forums, etc. for real-time information collection or manual follow-up, etc. to obtain public opinion information.
[0053] Further, the obtained or monitored public opinion information is processed textually to determine it as abnormal public opinion information.
[0054] Specifically, for example, the simihash method is used to judge the similarity between the text content of the public opinion information and a specific text, and the public opinion information with a similarity greater than a specified value is determined as abnormal public opinion information.
[0055] It should be noted that simhash, as a type of locality sensitive hash, mainly maps high-dimensional feature vectors into low-dimensional feature vectors, and determines whether the text content is repeated or highly similar through the Hamming Distance (also known as the Hamming distance) between two vectors. In addition, the specific text is the text content determined according to historical abnormal public opinion information, such as the text content determined by calculating outliers based on a deep neural network learning model.
[0056] For example, historical abnormal public opinion information related to different Internet service types is obtained, public opinion abnormal events and their related personnel are determined, public opinion abnormal features are extracted, and a corpus is established according to the public opinion abnormal features.
[0057] As a specific implementation manner, call record data and / or APP download information data of historical users are extracted from the historical abnormal public opinion information, and an information relationship network graph is established based on the call record data and / or APP download information data.
[0058] Specifically, the information relationship network graph includes multiple interconnected nodes and edges, where the nodes include user abnormal nodes, public opinion abnormal thing nodes, etc.
[0059] Further, public opinion abnormal features are screened from the information relationship network graph. For example, abnormal feature variables are extracted from the connection information between associated users in the information relationship network graph, where the connection information includes the connection relationship between public opinion abnormal event nodes, the connection relationship between users and each public opinion abnormal event node, etc.
[0060] It should be noted that the above is only for illustrative purposes as an optional example and should not be construed as a limitation to the present invention. In other implementation manners, it also includes performing cross-combination operations on the screened abnormal feature variables using the correlation coefficient CORR to amplify the abnormal feature variables.
[0061] In another implementation manner, for example, public opinion information is obtained from multiple data sources such as forums, the Internet, and social software, and population portraits of the blacklist and the white list are respectively depicted according to the user-related data in the obtained public opinion information to form a preset white list and a preset blacklist.
[0062] For example, according to the relevant personnel and their corresponding data (such as abnormal feature variables, etc.) in the determined public opinion abnormal event, the population portrait of the blacklist is depicted.
[0063] In another embodiment, as Figure 2 shown, the abnormal processing method further includes step S201 of performing sentiment analysis and semantic analysis on the text content of the public opinion information.
[0064] In step S201, sentiment analysis and semantic analysis are performed on the text content of the public opinion information.
[0065] Specifically, before judging the similarity between the text content of the public opinion information and a specific text, sentiment analysis and semantic analysis are performed on the text content according to a predetermined text positive and negative corpus.
[0066] In one embodiment, a machine learning model is used to perform sentiment analysis on the text content, and a training data set is established using manually annotated data to train the machine learning model. For example, the training data set includes text data labeled with positive sentiment tendency labels or negative sentiment tendency labels.
[0067] Specifically, the text content to be predicted is input into the machine model, and a sentiment tendency prediction value is output. Further, the sentiment tendency is determined according to the calculated sentiment tendency prediction value.
[0068] Further, for example, a BERT pre-trained model is used to perform semantic representation on the text content of the public opinion information for semantic vector conversion to obtain corresponding sentence vectors and word vectors for each word. However, this is not limited thereto. In other examples, RoBERTa model, DistilBERT model, XLNet model, etc. can also be used. Further, semantic analysis is performed according to the sentence vectors after semantic vector conversion and the corresponding word vectors for each word.
[0069] Therefore, by using a machine learning model to perform text processing on the obtained public opinion information, abnormal public opinion information related to the Internet service platform can be accurately identified to obtain more accurate external abnormal public opinion information.
[0070] It should be noted that the above is only for illustrative purposes as an optional example and should not be construed as a limitation to the present invention.
[0071] Next, in step S102, the business log data of the Internet service platform is obtained, and abnormal events of abnormal personnel are identified to obtain abnormal event information.
[0072] In one embodiment, by adding an agent component, the system log data and business log data of the Internet service platform are monitored. For example, the monitoring includes monitoring business personnel to identify abnormal personnel and / or abnormal events.
[0073] Specifically, the Internet service platform includes one or more business systems corresponding to different Internet services, and each business system includes system log data (such as Syslog message data, etc.) and business log data.
[0074] More specifically, the business log data of the Internet service platform is obtained, and abnormal events of abnormal personnel are identified. Among them, abnormal operations performed by abnormal personnel in the database or data warehouse of the back-end system of the Internet service platform are monitored and identified to obtain abnormal event information.
[0075] For system log data and business log data (i.e., internal business log data), for example, monitoring is performed from three dimensions: host security, business services, and user behavior. In the case of detecting abnormal personnel and / or abnormal events, relevant abnormal information is identified, and the relevant abnormal information is obtained for data analysis and processing. Thus, potential data leakage anomalies and basic security anomalies can be identified in a timely manner, and security information and abnormal event analysis results can be provided to relevant personnel such as security operation and maintenance personnel and business security personnel in a timely manner.
[0076] For example, the agent component identifies the system log data and business log data (such as business critical log data, etc.) of the Internet service platform, and determines internal business personnel and their high-risk behaviors according to judgment rules. For example, the judgment rules include whether there are more than a specified number of addition operations, deletion operations, change operations, and query operations on the database and data warehouse within a specific time, whether the number of queries of core data or key data in is greater than the specified number, whether a login behavior is executed within a set time, and whether identity verification is performed during login, etc. Thus, by monitoring the service side through the agent component, abnormal event information can be accurately obtained.
[0077] Optionally, a monitoring script is added to the back-end system and the monitoring script is embedded in each business system to monitor the abnormal behaviors (or abnormal operations) of the abnormal personnel, identify abnormal events to obtain abnormal event information. Thus, by embedding the monitoring script to monitor the business side, relevant personnel can be effectively monitored, and abnormal personnel and abnormal events can be effectively identified.
[0078] Therefore, by adding an agent component (i.e., the agent component), the system log data and business log data of the Internet service platform can be identified, or through monitoring scripts, it is possible to more effectively monitor internal business personnel and their high-risk behaviors, and accurately obtain abnormal event information.
[0079] In another embodiment, it further includes storing and real-time processing of the obtained public opinion information and abnormal event information.
[0080] Specifically, for example, a distributed database (such as Hadoop) or Hadoop Distributed File System (HDFS) is used to store the public opinion information and abnormal event information, and a processing system (such as the Kafka open source stream processing platform) is used to collect all log data and information data to be stored in real time, and perform real-time processing on the information data before storage.
[0081] Optionally, the abnormal public opinion information and abnormal event information are formatted to generate abnormal log data. Then, the abnormal log data and the business data related to the abnormal log data are stored in full.
[0082] Therefore, by obtaining the business log data of the Internet service platform and identifying abnormal events of abnormal personnel, abnormal event information can be obtained, potential data leakage abnormalities and basic security abnormalities can be identified in a timely manner, and security information and abnormal event analysis results can be provided to relevant personnel such as security operation and maintenance personnel and business security personnel in a timely manner.
[0083] It should be noted that the above is only an optional example for illustration and should not be construed as a limitation to the present invention.
[0084] Next, in step S103, the abnormal public opinion information and the abnormal event information are abnormally matched, and abnormal evaluation and abnormal positioning are performed according to the matching result, and accordingly, abnormal processing operations are performed according to a predetermined abnormal processing strategy.
[0085] Specifically, a streaming computing engine is built using Flink, and real-time analysis of the monitored public opinion abnormalities or business abnormalities is performed through rule matching, neural network algorithms or frequency analysis methods, and the abnormal positions and / or abnormal personnel are found therefrom.
[0086] Specifically, the abnormal positions include Internet service types, business systems, data processing positions, data storage positions, etc. The abnormal personnel include data operation and maintenance personnel, data management personnel, security personnel, public relations personnel, etc.
[0087] Furthermore, according to the correlation of the abnormal public opinion information and abnormal event information in terms of time, number of times, and frequency, the abnormal public opinion information and abnormal event information are matched.
[0088] In one embodiment, the abnormal public opinion information and abnormal event information are matched according to the occurrence time, the number of occurrences within a specific set time, or the frequency.
[0089] For example, when the occurrence times are the same and the relevant personnel in the abnormal public opinion information are relevant to the abnormal personnel in the abnormal event information, the abnormal location and abnormal personnel are determined.
[0090] For another example, when the time difference between the occurrence time of the abnormal public opinion information and the occurrence time of the abnormal event information is within a specified range and the relevant personnel in the abnormal public opinion information are relevant to the abnormal personnel in the abnormal event information, the abnormal personnel are determined, and the abnormal location is determined according to the business system where the abnormal personnel are located.
[0091] It should be noted that the above is only described as an optional example and should not be construed as a limitation to the present invention.
[0092] Furthermore, abnormal evaluation and abnormal positioning are performed according to the matching result, and accordingly, abnormal handling operations are performed in accordance with a predetermined abnormal handling strategy.
[0093] In another embodiment, an artificial follow-up work order is created to confirm the abnormality manually. The artificial follow-up work order includes the Internet service type, the business system name, the key text content of the abnormal public opinion information, the abnormal personnel, the abnormal event, and the occurrence time of the abnormal event. Thus, the abnormal type and abnormal level can be determined more accurately.
[0094] In yet another embodiment, when the abnormal personnel are determined, the corresponding chatbot is automatically triggered, and the corresponding chatbot conducts an automatic chat with the abnormal personnel to confirm the abnormality. Thus, the abnormal type and abnormal coefficient can be determined more precisely.
[0095] As a specific embodiment, historical abnormal events, abnormal public opinion information, and abnormal personnel information within a specific historical time are obtained, and the abnormal events, abnormal public opinion information, and abnormal personnel information are used as adjustment parameters to fit an abnormal trend change graph of the abnormal event and the abnormal coefficient.
[0096] Specifically, the determined abnormal events are used, and the abnormal coefficient is determined using the abnormal trend change graph.
[0097] Then, according to the determined abnormal coefficient, an abnormal policy comparison table is searched to determine the corresponding control measures from the predetermined abnormal handling strategies for abnormal handling operations. For example, changing the data access permission of the abnormal personnel or blocking the business operations of the abnormal personnel.
[0098] In another embodiment, the determined abnormal event information and abnormal personnel information are input into a damage prediction model to calculate a damage degree evaluation value of the abnormal event to the Internet service platform or Internet service system, and corresponding measures in a predetermined abnormal handling strategy are selected according to the damage degree evaluation value to perform abnormal handling operations. For example, response information for handling abnormal events is sent to security personnel, and abnormal alarm information is sent to abnormal personnel, etc.
[0099] Specifically, for example, a damage prediction model based on machine learning is established using a logistic regression model, an Xgboost model, and / or a deep neural network. The damage prediction model calculates a damage degree evaluation value of the abnormal event, and this damage degree evaluation value is a numerical value between 0 and 1. The damage prediction model is trained using a training data set, and the training data set includes historical abnormal events labeled with damage degrees.
[0100] It should be noted that the above is only described as an optional example and should not be construed as a limitation to the present invention.
[0101] Therefore, by comprehensively analyzing external abnormal public opinion information and internal abnormal event information, abnormal evaluation and positioning can be carried out more effectively and quickly, and abnormal handling operations can be carried out more effectively.
[0102] In another example, as Figure 3 shown, the abnormal handling method further includes a step S301 of triggering linkage analysis processing.
[0103] It should be noted that since Figure 3 the steps S101, S102, and S103 in Figure 1 are substantially the same as the steps S101, S102, and S103 in Figure 3 the description of the steps S101, S102, and S103 in
[0104] is omitted.
[0105] Specifically, when it is determined that the trigger point information is included in the external public opinion information, the relevant business log data (i.e., internal business log data) of the Internet service platform is triggered to be obtained for performing linkage analysis processing on the external public opinion information and the internal business log data. The linkage analysis processing includes using a data analysis engine to analyze the external public opinion information and the internal business log data. For example, it is determined whether the abnormal users in the external epidemic information are associated with the abnormal users in the internal business log data and whether they are the same user, and abnormal evaluation is performed on each abnormal user.
[0106] More specifically, the trigger point information includes that the relevant personnel in the abnormal public opinion information are users in a preset blacklist, public opinion abnormal events, etc.
[0107] Optionally, a situation awareness probe is constructed, which is used to monitor external multi-channel data sources (i.e., external network situation awareness) and monitor whether the external public opinion information contains trigger point information and whether it contains abnormal public opinion information, wherein the external multi-channel includes forums, the Internet, social software, etc.
[0108] Therefore, by building a situational awareness probe, it is possible to monitor and analyze anomalies from the two perspectives of external network situational awareness and internal network security. External public opinion information is used as a trigger point to trigger the acquisition of relevant business log data (i.e., internal business log data), and the external public opinion information and internal business log data are linked and analyzed through the data analysis engine. This can quickly identify potential data leakage anomalies, basic security anomalies, etc., and can significantly improve the agility, accuracy, and intelligence of security anomaly identification.
[0109] The process of the above method is only used to illustrate the present invention, wherein the order and number of steps are not particularly limited. In addition, the steps in the above method can also be split into two or three, or some steps can also be combined into one step, and adjusted according to actual examples.
[0110] Compared with the prior art, the present invention can accurately identify abnormal public opinion information related to the Internet service platform by obtaining public opinion information from the Internet and performing text processing on the public opinion information, and can provide first-time security information and abnormal event analysis results for relevant personnel such as security operation and maintenance personnel and business security personnel. By obtaining the business log data of the Internet service platform and identifying the abnormal events of abnormal personnel, accurate abnormal event information can be obtained, potential data leakage anomalies and basic security anomalies can be identified in a timely manner, and first-time security information and abnormal event analysis results can be provided for relevant personnel such as security operation and maintenance personnel and business security personnel; by performing abnormal matching on the abnormal public opinion information and the abnormal event information, and performing abnormal evaluation and abnormal location according to the matching results, that is, by performing comprehensive analysis on external abnormal public opinion information and internal abnormal event information, abnormal evaluation and abnormal location can be performed more effectively and quickly, and abnormal processing operations can be performed more effectively, and the agility, accuracy and intelligence of security abnormality identification can be more significantly improved, and the data security of Internet resource service-related data can be effectively guaranteed.
[0111] Furthermore, by using a machine learning model to perform text processing on the acquired public opinion information, it is possible to accurately identify abnormal public opinion information related to the Internet service platform to obtain more accurate external abnormal public opinion information; by adding an agent component (i.e., an agent component), the system log data and business log data of the Internet service platform can be identified, or through a monitoring script, internal business personnel and their high-risk behaviors can be more effectively monitored, and abnormal event information can be accurately obtained; by constructing a situational awareness probe, it is possible to perform abnormal monitoring and analysis from the two perspectives of external network situational awareness and internal network security, using external public opinion information as a trigger point to trigger the acquisition of relevant business log data (i.e., internal business log data), and through a data analysis engine, external public opinion information and internal business log data are linked and analyzed, thereby quickly identifying potential data leakage anomalies, basic security anomalies, etc., and can more significantly improve the agility, accuracy, and intelligence of security anomaly identification.
[0112] Those skilled in the art will appreciate that all or part of the steps to implement the above embodiments are implemented as a program (computer program) executed by a computer data processing device. When the computer program is executed, the above method provided by the present invention can be implemented. Moreover, the computer program can be stored in a computer-readable storage medium, which can be a readable storage medium such as a disk, an optical disk, a ROM, a RAM, or a storage array composed of multiple storage media, such as a disk or a tape storage array. The storage medium is not limited to centralized storage, and it can also be distributed storage, such as cloud storage based on cloud computing.
[0113] The following describes an embodiment of the device of the present invention, which can be used to execute the method embodiment of the present invention. The details described in the embodiment of the device of the present invention should be regarded as supplementary to the above method embodiment; details not disclosed in the embodiment of the device of the present invention can be implemented with reference to the above method embodiment.
[0114] Example 2
[0115] Reference Figure 4 , Figure 5 and Figure 6, the present invention also provides an exception handling device 400 for an Internet service platform. The exception handling device 400 includes: a first acquisition module 401, configured to acquire public opinion information from the Internet, perform text processing on the public opinion information to identify abnormal public opinion information related to the Internet service platform; a second acquisition module 402, configured to acquire service log data of the Internet service platform, identify abnormal events of abnormal personnel to obtain abnormal event information; a matching processing module 403, configured to perform abnormal matching on the abnormal public opinion information and the abnormal event information, perform abnormal evaluation and abnormal positioning according to the matching result, and accordingly perform abnormal handling operations according to a predetermined abnormal handling strategy.
[0116] As Figure 5 shown, the exception handling device 400 includes an information processing module 501, that is, Figure 4 the first acquisition module 401 in is split into a first acquisition module 401 and an information processing module 501. The information processing module 501 is configured to use the simihash method to perform an approximation judgment on the text content of the monitored public opinion information and a specific text, and determine the public opinion information with a similarity greater than a specified value as abnormal public opinion information.
[0117] Specifically, before performing an approximation judgment on the text content of the public opinion information and a specific text, perform sentiment analysis and semantic analysis on the text content according to a predetermined text positive and negative corpus, and the corpus is a corpus related to the security of the Internet service platform.
[0118] It should be noted that simhash, as a type of locality sensitive hash, mainly maps a high-dimensional feature vector into a low-dimensional feature vector, and determines whether the text content is repeated or highly similar through the Hamming Distance (also known as the Hamming distance) between two vectors. In addition, the specific text is the text content determined according to historical abnormal public opinion information, for example, the text content determined by calculating abnormal values according to a deep neural network learning model.
[0119] For example, acquire historical abnormal public opinion information related to different Internet service types, determine public opinion abnormal events and their related personnel, extract public opinion abnormal features, and establish a corpus according to the public opinion abnormal features.
[0120] As a specific implementation manner, extract call record data and / or APP download information data of historical users from the historical abnormal public opinion information, and establish an information relationship network diagram based on the call record data and / or APP download information data.
[0121] Specifically, the information relationship network diagram includes multiple interconnected nodes and edges, where the nodes include user anomaly nodes, public opinion anomaly thing nodes, etc.
[0122] Furthermore, screen public opinion anomaly features from the information relationship network diagram. For example, extract anomaly feature variables from the connection information between associated users in the information relationship network diagram, where the connection information includes the connection relationships between public opinion anomaly event nodes, the connection relationships between users and each public opinion anomaly event node, etc.
[0123] It should be noted that the above is only for illustrative purposes as an optional example and should not be construed as a limitation to the present invention. In other embodiments, it also includes using the correlation coefficient CORR to perform cross - combination operations on the screened anomaly feature variables to amplify the anomaly feature variables.
[0124] In another embodiment, before judging the approximation between the text content of the public opinion information and a specific text, perform sentiment analysis and semantic analysis on the text content according to a predetermined positive - negative text corpus.
[0125] Optionally, use a machine learning model to perform sentiment analysis on the text content, and establish a training data set with manually annotated data to train the machine learning model. For example, the training data set includes text data labeled with positive sentiment tendency labels or negative sentiment tendency labels.
[0126] Specifically, input the text content to be predicted into the machine model, and output a sentiment tendency prediction value. Further, determine the sentiment tendency according to the calculated sentiment tendency prediction value.
[0127] Furthermore, for example, use the BERT pre - trained model to perform semantic representation on the text content of the public opinion information for semantic vector conversion to obtain corresponding sentence vectors and word vectors for each word. However, it is not limited to this. In other examples, the RoBERTa model, DistilBERT model, XLNet model, etc. can also be used. Further, perform semantic analysis according to the sentence vectors after semantic vector conversion and the corresponding word vectors for each word.
[0128] Therefore, by using a machine learning model to perform text processing on the obtained public opinion information, it is possible to accurately identify abnormal public opinion information related to the Internet service platform to obtain more accurate external abnormal public opinion information.
[0129] Furthermore, the identification of abnormal events of abnormal personnel to obtain abnormal event information includes: monitoring and identifying abnormal operations performed by abnormal personnel in the database or data warehouse of the background system of the Internet service platform to obtain abnormal event information.
[0130] Optionally, identifying the abnormal events of the abnormal personnel to obtain abnormal event information further includes: adding a monitoring script to the background system to monitor the abnormal operations of the abnormal personnel.
[0131] As Figure 6 shown, the abnormal processing device 400 includes an evaluation module 601, that is, splitting the matching processing module 403 in Figure 4 into an evaluation module 601 and a matching processing module 403. The evaluation module 601 is used to create a manual follow-up work order for manual abnormal confirmation.
[0132] In an embodiment, the evaluation module 601 is further used to trigger a chatbot to automatically chat with the abnormal personnel for abnormal confirmation.
[0133] Preferably, use Flink to build a streaming computing engine, and perform real-time analysis on the monitored public opinion anomalies or business anomalies through rule matching, neural network algorithms or frequency analysis methods, and find the abnormal positions and / or abnormal personnel from them.
[0134] Specifically, match the abnormal public opinion information and the abnormal event information according to the correlation of the abnormal public opinion information and the abnormal event information in terms of time, number of occurrences, and frequency.
[0135] In an embodiment, match the abnormal public opinion information and the abnormal event information according to the occurrence time, the number of occurrences within a specific set time, or the frequency.
[0136] For example, when the occurrence times are the same and the relevant personnel of the abnormal public opinion information are correlated with the abnormal personnel in the abnormal event information, determine the abnormal position and the abnormal personnel.
[0137] For another example, when the time difference between the occurrence time of the abnormal public opinion information and the occurrence time of the abnormal event information is within a specified range and the relevant personnel of the abnormal public opinion information are correlated with the abnormal personnel in the abnormal event information, determine the abnormal personnel, and determine the abnormal position according to the business system where the abnormal personnel are located.
[0138] It should be noted that the above is only an optional example for illustration and should not be construed as a limitation to the present invention.
[0139] It should be noted that in Embodiment 2, the description of the same parts as in Embodiment 1 is omitted.
[0140] Those skilled in the art can understand that each module in the above device embodiments can be distributed in the device as described, or can be correspondingly changed and distributed in one or more devices different from the above embodiments. The modules of the above embodiments can be combined into one module, or can be further split into multiple sub-modules.
[0141] Compared with the prior art, by obtaining public opinion information from the Internet and performing text processing on the public opinion information, the present invention can accurately identify abnormal public opinion information related to the Internet service platform, and can provide security information and analysis results of abnormal events in a timely manner for relevant personnel such as security operation and maintenance personnel and business security personnel. By obtaining the business log data of the Internet service platform and identifying abnormal events of abnormal personnel, accurate abnormal event information can be obtained, potential data leakage abnormalities and basic security abnormalities can be identified in a timely manner, and security information and analysis results of abnormal events can be provided for relevant personnel such as security operation and maintenance personnel and business security personnel in a timely manner; by performing abnormal matching on the abnormal public opinion information and the abnormal event information and performing abnormal evaluation and abnormal positioning according to the matching results, that is, by comprehensively analyzing external abnormal public opinion information and internal abnormal event information, abnormal evaluation and abnormal positioning can be carried out more effectively and quickly, and abnormal processing operations can be carried out more effectively, and the agility, accuracy and intelligence of security anomaly identification can be significantly improved, and the data security of data related to Internet resource services can be effectively guaranteed.
[0142] Furthermore, by using a machine learning model to perform text processing on the obtained public opinion information, abnormal public opinion information related to the Internet service platform can be accurately identified to obtain more accurate external abnormal public opinion information; by adding a proxy component (i.e., an agent component) to identify the system log data and business log data of the Internet service platform, or through a monitoring script, the internal business personnel and their high-risk behaviors can be monitored more effectively, and abnormal event information can be accurately obtained; by constructing a situation awareness probe, abnormal monitoring and analysis can be carried out from two perspectives of external network situation awareness and internal network security, using external public opinion information as a trigger point to trigger the acquisition of relevant business log data (i.e., internal business log data), and through a data analysis engine to perform linkage analysis on external public opinion information and internal business log data, thereby potential data leakage abnormalities, basic security abnormalities, etc. can be quickly identified, and the agility, accuracy and intelligence of security anomaly identification can be significantly improved.
[0143] Embodiment 3
[0144] The embodiments of the computer device of the present invention are described below. The computer device can be regarded as a specific physical implementation of the above-described method and apparatus embodiments of the present invention. For the details described in the embodiments of the computer device of the present invention, they should be regarded as a supplement to the above-described method or apparatus embodiments; for the details not disclosed in the embodiments of the computer device of the present invention, reference can be made to the above-described method or apparatus embodiments for implementation.
[0145] Figure 7 is a structural block diagram of an exemplary embodiment of a computer device according to the present invention. The following refers to Figure 7 to describe the computer device 200 according to this embodiment of the present invention. Figure 7 The computer device 200 shown is merely an example and should not impose any limitation on the functions and scope of use of the embodiments of the present invention.
[0146] As Figure 7 shown, the computer device 200 is presented in the form of a general-purpose computing device. The components of the computer device 200 may include, but are not limited to: at least one processing unit 210, at least one storage unit 220, a bus 230 connecting different device components (including the storage unit 220 and the processing unit 210), a display unit 240, etc.
[0147] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 210, so that the processing unit 210 executes the steps according to various exemplary embodiments of the present invention described in the processing method part of the above computer device of this specification. For example, the processing unit 210 can execute steps as Figure 1 shown.
[0148] The storage unit 220 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 2201 and / or a cache storage unit 2202, and may further include a read-only storage unit (ROM) 2203.
[0149] The storage unit 220 may further include a program / utilities 2204 having a set (at least one) of program modules 2205. Such program modules 2205 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.
[0150] The bus 230 may represent one or more of several types of bus structures, including a storage unit bus or a storage unit controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the various bus structures.
[0151] The computer device 200 can also communicate with one or more external devices 300 (such as a keyboard, a pointing device, a Bluetooth device, etc.), and can also communicate with one or more devices that enable a user to interact with the computer device 200, and / or communicate with any device that enables the computer device 200 to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 250. Moreover, the computer device 200 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 260. The network adapter 260 can communicate with other modules of the computer device 200 through the bus 230. It should be understood that although not shown in the figure, other hardware and / or software modules can be used in combination with the computer device 200, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0152] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described in the present invention can be implemented by software, or can be implemented by the way of software combined with necessary hardware. Therefore, the technical solutions according to the embodiments of the present invention can be embodied in the form of a software product, and the software product can be stored in a computer-readable storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on the network, including several instructions to enable a computing device (which can be a personal computer, a server, or a network device, etc.) to execute the above method according to the present invention. When the computer program is executed by a data processing device, the computer program product can implement the above method of the present invention.
[0153] As Figure 8 shown, the computer program can be stored on one or more computer program products. The computer program products can be, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples (a non-exhaustive list) of computer program products include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0154] The computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the readable program code. Such propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The computer program product may send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0155] The program code for performing the operations of the present invention may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by using an Internet service provider to connect through the Internet).
[0156] In summary, the present invention may be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. Those skilled in the art should understand that general-purpose data processing devices such as microprocessors or digital signal processors (DSPs) may be used in practice to implement some or all of the functions of some or all of the components in accordance with some embodiments of the present invention. The present invention may also be implemented as a device or apparatus program (e.g., a computer program and a computer program product) for performing part or all of the methods described herein. Such a program implementing the present invention may be stored on a computer program product, or may be in the form of one or more signals. Such signals may be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.
[0157] In the specific embodiments described above, the object, technical solution and beneficial effects of the present invention have been further described in detail. It should be understood that the present invention is not inherently related to any specific computer, virtual device or electronic device, and various general-purpose devices can also implement the present invention. The above are only specific embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. An abnormal handling method for an Internet service platform, characterized in that Including: Obtaining public opinion information from the Internet, processing the public opinion information to identify abnormal public opinion information related to the Internet service platform, including: performing sentiment analysis and semantic analysis on the text content of the public opinion information according to a predetermined text positive and negative corpus, where the corpus is related to the security of the Internet service platform; judging the similarity between the text content of the monitored public opinion information and a specific text, and determining the public opinion information with a similarity greater than a specified value as abnormal public opinion information; Monitoring the system log data and business log data of the Internet service platform by adding a proxy component, obtaining the business log data of the Internet service platform, and determining internal business personnel and their high-risk behaviors according to judgment rules to identify abnormal events of abnormal personnel and obtain abnormal event information; Matching the abnormal public opinion information and the abnormal event information according to the correlation of time, frequency, and number of times between the abnormal public opinion information and the abnormal event information, and performing abnormal evaluation and abnormal positioning according to the matching result, and accordingly performing abnormal handling operations according to a predetermined abnormal handling strategy, including: determining the abnormal location and abnormal personnel when the occurrence time is the same and there is a correlation between the relevant personnel of the abnormal public opinion information and the abnormal personnel of the abnormal event information; determining the abnormal personnel and the abnormal location according to the business system where the abnormal personnel are located when the time difference between the occurrence time of the abnormal public opinion information and the occurrence time of the abnormal event information is within a specified range and there is a correlation between the relevant personnel of the abnormal public opinion information and the abnormal personnel of the abnormal event information.
2. The method according to claim 1, wherein Judging the similarity between the text content of the monitored public opinion information and a specific text, and determining the public opinion information with a similarity greater than a specified value as abnormal public opinion information, including: using the simihash method to judge the similarity between the text content of the monitored public opinion information and a specific text; the specific text includes the text content determined according to historical abnormal public opinion information.
3. The method according to claim 2, wherein The corpus includes: Obtaining historical abnormal public opinion information related to different Internet service types, determining public opinion abnormal events and their related personnel, extracting public opinion abnormal characteristics, and establishing a corpus according to the public opinion abnormal characteristics.
4. The method according to claim 1, characterized in that, Identifying abnormal events of abnormal personnel to obtain abnormal event information includes: Monitoring and identifying abnormal operations performed by abnormal personnel in the database or data warehouse of the background system of the Internet service platform to obtain abnormal event information.
5. The method according to claim 4, wherein Identifying abnormal events of abnormal personnel to obtain abnormal event information also includes: Adding a monitoring script to the background system and embedding the monitoring script into each business system to monitor the abnormal operations of abnormal personnel.
6. The method according to claim 1 or 2, characterized in that, It also includes: Triggering linkage analysis and processing, where when it is determined that the public opinion information contains trigger point information, triggering the acquisition of relevant business log data of the Internet service platform for linkage analysis and processing of external public opinion information and the relevant business log data.
7. The method according to claim 1, characterized in that The abnormal evaluation includes: Creating a manual follow-up work order for manual abnormal confirmation.
8. The method according to claim 1, characterized in that The abnormal evaluation includes: Triggering a chatbot to automatically chat with abnormal personnel for abnormal confirmation.
9. The method according to claim 1, wherein The abnormal positioning includes: Build a streaming computing engine using Flink, and perform real-time analysis on the monitored public opinion anomalies or business anomalies through rule matching, neural network algorithms, or frequency analysis methods to find the anomaly locations and / or anomalous personnel therefrom.
10. The method according to claim 1, wherein The matching also includes: Matching according to the occurrence time, the number of occurrences within a specific set time, or the frequency.
11. The method according to any one of claims 1 to 10, characterized in that, It also includes: Formatting the abnormal public opinion information and abnormal event information to generate abnormal log data; Storing all the abnormal log data and the business data related to the abnormal log data in full.
12. An exception handling device for an Internet service platform, characterized in that, It includes: A first acquisition module, configured to acquire public opinion information from the Internet, perform text processing on the public opinion information to identify abnormal public opinion information related to the Internet service platform, including: performing sentiment analysis and semantic analysis on the text content of the public opinion information according to a predetermined positive and negative text corpus, where the corpus is related to the security of the Internet service platform; making an approximation judgment on the text content of the monitored public opinion information and a specific text, and determining the public opinion information with a similarity greater than a specified value as abnormal public opinion information; A second acquisition module, configured to monitor the system log data and business log data of the Internet service platform by adding a proxy component, acquire the business log data of the Internet service platform, determine internal business personnel and their high-risk behaviors according to judgment rules to identify abnormal events of abnormal personnel, and obtain abnormal event information; A matching processing module, configured to perform abnormal matching on the abnormal public opinion information and abnormal event information according to the correlation of time, number of occurrences, and frequency between the abnormal public opinion information and abnormal event information, and perform abnormal evaluation and abnormal positioning according to the matching result, and accordingly perform abnormal processing operations according to a predetermined abnormal processing strategy, including: determining the abnormal location and abnormal personnel when the occurrence time is the same and there is a correlation between the relevant personnel of the abnormal public opinion information and the abnormal personnel of the abnormal event information; determining the abnormal personnel and determining the abnormal location according to the business system where the abnormal personnel are located when the time difference between the occurrence time of the abnormal public opinion information and the occurrence time of the abnormal event information is within a specified range and there is a correlation between the relevant personnel of the abnormal public opinion information and the abnormal personnel of the abnormal event information.
13. A computer device, including a processor and a memory, where the memory is used to store computer-executable programs, and when the computer-executable programs are executed by the processor, the processor executes the method according to claims 1-11.
Citation Information
Patent Citations
Abnormal application processing method and device and mobile terminal
CN106776245A
Information processing method and apparatus
CN107016561A