A method, apparatus, device, and storage medium for generating monitoring rules

By dividing the time period into units, performing data correction and estimation value calculation, and using the integrated learning model to generate monitoring rules, the problem of poor scalability of monitoring rules in the prior art is solved, and higher accuracy and adaptability of business exception perception are achieved.

CN114612106BActive Publication Date: 2025-07-22CHINA UNIONPAY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210145788.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-17
Publication Date
2025-07-22
Estimated Expiration
2042-02-17

AI Technical Summary

Technical Problem

In the prior art, the scalability of monitoring rules is poor, resulting in low accuracy of business abnormality perception, and the manually set monitoring rules cannot adapt to changes in different business scenarios and time periods.

Method used

The first time period is divided into multiple time units, the original transaction data is corrected, the cumulative and mean index values are determined, and the monitoring rules for each rule time period are generated through the integrated learning model, and the monitoring rules are dynamically adjusted according to the indicator values of different time periods.

Benefits of technology

Improve the accuracy of business exception perception, so that monitoring rules can adapt to changes in different monitoring scenarios, with higher accuracy and scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114612106B_ABST
    Figure CN114612106B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides a method, apparatus, device, and storage medium for generating monitoring rules, which relates to the technical field of data processing. The method includes: dividing a first time period into multiple time units, and respectively correcting the original transaction data corresponding to each of the multiple time units to obtain the corrected transaction data corresponding to each of the multiple time units. Then, based on the corrected transaction data corresponding to each of the multiple time units, respectively determine the cumulative index value corresponding to each of the multiple time units and the average index value corresponding to each of the multiple time units. Divide the first time period according to the regular time slice to obtain multiple regular time periods. Then, respectively input the multiple cumulative index values and multiple average index values corresponding to each regular time period into the integrated learning model to obtain the monitoring rules corresponding to each regular time period. Since each regular time period corresponds to a different monitoring rule, the accuracy of business anomaly perception is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the technical field of data processing, and in particular, to a method, apparatus, device, and storage medium for generating monitoring rules. Background Art

[0002] In order to ensure the normal operation of the company's business system, business anomaly perception is a basic requirement for the business system. However, with the development of the company's business, the business scenarios are becoming more and more complex, and the requirements for business anomaly perception are also getting higher and higher.

[0003] Currently, the simplest method for business anomaly perception is to directly determine whether the business is abnormal based on preset monitoring rules. Under the related technology, the monitoring rules are determined according to expert experience, and different monitoring rules need to be manually set for different business scenarios, resulting in poor scalability of the monitoring rules. Moreover, for different time periods in a business scenario, the manually set monitoring rules are fixed, thus affecting the accuracy of business anomaly perception. Summary of the Invention

[0004] Embodiments of the present application provide a method, apparatus, device, and storage medium for generating monitoring rules, which are used to improve the accuracy of business anomaly perception.

[0005] On the one hand, embodiments of the present application provide a method for generating monitoring rules, and the method includes:

[0006] Dividing a first time period into multiple time units, and respectively correcting the original transaction data corresponding to each of the multiple time units to obtain the corrected transaction data corresponding to each of the multiple time units;

[0007] Based on the corrected transaction data corresponding to each of the multiple time units, respectively determine the cumulative index value corresponding to each of the multiple time units and the average index value corresponding to each of the multiple time units;

[0008] Divide the first time period according to a regular time slice to obtain multiple regular time periods;

[0009] Respectively input the multiple cumulative index values and multiple average index values corresponding to each regular time period into an ensemble learning model to obtain the monitoring rules corresponding to each regular time period.

[0010] Optionally, the respectively correcting the original transaction data corresponding to each of the multiple time units to obtain the corrected transaction data corresponding to each of the multiple time units includes:

[0011] For each of the multiple time units, respectively perform the following steps:

[0012] Based on the business type, data correction is performed on the original transaction data corresponding to a time unit to obtain corrected transaction data.

[0013] Optionally, the cumulative metric value includes the consecutive failed transaction volume.

[0014] Determining the cumulative metric value corresponding to each of the multiple time units based on the corrected transaction data corresponding to each of the multiple time units includes:

[0015] For each of the multiple time units, the following steps are respectively executed:

[0016] If the failed transaction volume of the corrected transaction data within a time unit is 0, it is determined that the consecutive failed transaction volume corresponding to the time unit is 0;

[0017] If the failed transaction volume of the corrected transaction data within a time unit is not 0, based on the consecutive failed transaction volume corresponding to the previous time unit of the time unit and the failed transaction volume, the consecutive failed transaction volume corresponding to the time unit is determined.

[0018] Optionally, determining the mean metric value corresponding to each of the multiple time units based on the corrected transaction data corresponding to each of the multiple time units includes:

[0019] For each of the multiple time units, the following steps are respectively executed:

[0020] Obtain the corrected transaction data corresponding to each of the multiple time units within the target sliding window corresponding to a time unit;

[0021] Based on the obtained multiple corrected transaction data, determine the mean metric value corresponding to the time unit.

[0022] Optionally, the following method is used to determine the target sliding window corresponding to a time unit, including:

[0023] From multiple window category time periods, determine the target window category time period that matches the time unit, and obtain the sliding window length corresponding to the target window category time period. The multiple window category time periods are obtained by dividing the second time period according to a preset rule, where each window category time period corresponds to a sliding window length;

[0024] Based on the end time point of the time unit and the sliding window length, determine the target sliding window corresponding to the time unit, where the end time point of the time unit is the same as the end time point of the target sliding window.

[0025] Optionally, the sliding window length corresponding to the target window category time period is determined in the following manner, including:

[0026] Obtain the total trading volume of the second time period, and determine the lower limit value and the upper limit value of the sliding window length based on the total trading volume;

[0027] Based on the ratio of the trading volume within the target window category time period to the total trading volume, determine the trading ratio corresponding to the target window category time period;

[0028] Based on the trading ratio, the lower limit value, and the upper limit value, determine the sliding window length corresponding to the target window category time period.

[0029] Optionally, the mean index value includes a negative volatility value;

[0030] The determining the mean index value corresponding to the one time unit based on the obtained multiple corrected trading data includes:

[0031] Based on the obtained multiple corrected trading data, determine the total trading volume corresponding to the target sliding window;

[0032] Based on the total trading volume corresponding to the target sliding window and the total trading volume corresponding to the previous sliding window of the target sliding window, determine the negative volatility value corresponding to the one time unit.

[0033] Optionally, the determining the negative volatility value corresponding to the one time unit based on the total trading volume corresponding to the target sliding window and the total trading volume corresponding to the previous sliding window of the target sliding window includes:

[0034] Take the difference between the total trading volume corresponding to the previous sliding window and the total trading volume corresponding to the target sliding window as the trading growth amount corresponding to the target sliding window;

[0035] Take the ratio of the trading growth amount corresponding to the target sliding window to the total trading volume corresponding to the target sliding window as the negative volatility value corresponding to the one time unit.

[0036] Optionally, the inputting the multiple cumulative index values and multiple mean index values corresponding to each rule time period into the integrated learning model to obtain the monitoring rule corresponding to each rule time period respectively includes:

[0037] For the multiple rule time periods, perform the following steps respectively:

[0038] Input the multiple cumulative index values corresponding to a rule time period into the integrated learning model to obtain multiple first monitoring thresholds;

[0039] Take the maximum monitoring threshold among the multiple first monitoring thresholds as the cumulative index monitoring threshold corresponding to the multiple cumulative index values in the one regular time period;

[0040] Input the multiple mean index values corresponding to the one regular time period into the ensemble learning model to obtain multiple second monitoring thresholds;

[0041] Take the maximum monitoring threshold among the multiple second monitoring thresholds as the mean index monitoring threshold corresponding to the multiple mean index values in the one regular time period;

[0042] Take the obtained cumulative index monitoring threshold and mean index monitoring threshold as the monitoring rule corresponding to the one regular time period.

[0043] Optionally, the ensemble learning model includes multiple sub - learning models;

[0044] The step of inputting the multiple cumulative index values corresponding to the one regular time period into the ensemble learning model to obtain multiple first monitoring thresholds includes:

[0045] Input the multiple cumulative index values corresponding to the one regular time period into the multiple sub - learning models respectively to obtain the first monitoring thresholds output by each of the multiple sub - learning models;

[0046] The step of inputting the multiple mean index values corresponding to the one regular time period into the ensemble learning model to obtain multiple second monitoring thresholds includes:

[0047] Input the multiple mean index values corresponding to the one regular time period into the multiple sub - learning models respectively to obtain the second monitoring thresholds output by each of the multiple sub - learning models.

[0048] On the one hand, an embodiment of the present application provides a device for generating a monitoring rule, and the device includes:

[0049] A correction module, configured to divide the first time period into multiple time units, and respectively correct the original transaction data corresponding to each of the multiple time units to obtain the corrected transaction data corresponding to each of the multiple time units;

[0050] A calculation module, configured to respectively determine the cumulative index values corresponding to each of the multiple time units and the mean index values corresponding to each of the multiple time units based on the corrected transaction data corresponding to each of the multiple time units;

[0051] A division module, configured to divide the first time period according to regular time slices to obtain multiple regular time periods;

[0052] A rule acquisition module, configured to input multiple cumulative metric values and multiple mean metric values corresponding to each rule time period into an ensemble learning model respectively, so as to obtain a monitoring rule corresponding to each rule time period.

[0053] Optionally, the correction module is specifically configured to:

[0054] For the multiple time units, respectively perform the following steps:

[0055] Based on the business type, perform data correction on the original transaction data corresponding to one time unit to obtain corrected transaction data.

[0056] Optionally, the cumulative metric value includes the consecutive failed transaction volume;

[0057] The calculation module is specifically configured to:

[0058] For the multiple time units, respectively perform the following steps:

[0059] If the failed transaction volume of the corrected transaction data within one time unit is 0, determine that the consecutive failed transaction volume corresponding to the one time unit is 0;

[0060] If the failed transaction volume of the corrected transaction data within one time unit is not 0, determine the consecutive failed transaction volume corresponding to the one time unit based on the consecutive failed transaction volume corresponding to the previous time unit of the one time unit and the failed transaction volume.

[0061] Optionally, the calculation module is specifically configured to:

[0062] For the multiple time units, respectively perform the following steps:

[0063] Obtain the corrected transaction data corresponding to each of the multiple time units within the target sliding window corresponding to one time unit;

[0064] Based on the obtained multiple corrected transaction data, determine the mean metric value corresponding to the one time unit.

[0065] Optionally, the following method is adopted to determine the target sliding window corresponding to one time unit, including:

[0066] From multiple window category time periods, determine a target window category time period matching the one time unit, and obtain the sliding window length corresponding to the target window category time period. The multiple window category time periods are obtained by dividing a second time period according to a preset rule, where each window category time period corresponds to a sliding window length;

[0067] Determine a target sliding window corresponding to the one time unit based on the end time point of the one time unit and the sliding window length, where the end time point of the one time unit is the same as the end time point of the target sliding window.

[0068] Optionally, the sliding window length corresponding to the target window category time period is determined in the following manner, including:

[0069] Obtain the total trading volume of the second time period, and determine a lower limit value and an upper limit value of the sliding window length based on the total trading volume;

[0070] Determine a trading ratio corresponding to the target window category time period based on the ratio of the trading volume within the target window category time period to the total trading volume;

[0071] Determine the sliding window length corresponding to the target window category time period based on the trading ratio, the lower limit value, and the upper limit value.

[0072] Optionally, the mean index value includes a negative volatility value;

[0073] The calculation module is specifically configured to:

[0074] Determine the total trading volume corresponding to the target sliding window based on the obtained multiple corrected trading data;

[0075] Determine the negative volatility value corresponding to the one time unit based on the total trading volume corresponding to the target sliding window and the total trading volume corresponding to the previous sliding window of the target sliding window.

[0076] Optionally, the calculation module is specifically configured to:

[0077] Use the difference between the total trading volume corresponding to the previous sliding window and the total trading volume corresponding to the target sliding window as the trading growth amount corresponding to the target sliding window;

[0078] Use the ratio of the trading growth amount corresponding to the target sliding window to the total trading volume corresponding to the target sliding window as the negative volatility value corresponding to the one time unit.

[0079] Optionally, the rule acquisition module is specifically configured to:

[0080] For each of the multiple rule time periods, perform the following steps respectively:

[0081] Input multiple cumulative index values corresponding to one rule time period into the integrated learning model to obtain multiple first monitoring thresholds;

[0082] Use the maximum monitoring threshold among the multiple first monitoring thresholds as the cumulative index monitoring threshold corresponding to the multiple cumulative index values in the one regular time period;

[0083] Input the multiple mean index values corresponding to the one regular time period into the ensemble learning model to obtain multiple second monitoring thresholds;

[0084] Use the maximum monitoring threshold among the multiple second monitoring thresholds as the mean index monitoring threshold corresponding to the multiple mean index values in the one regular time period;

[0085] Use the obtained cumulative index monitoring threshold and mean index monitoring threshold as the monitoring rule corresponding to the one regular time period.

[0086] Optionally, the ensemble learning model includes multiple sub - learning models;

[0087] The rule acquisition module is specifically configured to:

[0088] Input the multiple cumulative index values corresponding to the one regular time period into the multiple sub - learning models respectively to obtain the first monitoring thresholds output by the multiple sub - learning models respectively;

[0089] The rule acquisition module is specifically configured to:

[0090] Input the multiple mean index values corresponding to the one regular time period into the multiple sub - learning models respectively to obtain the second monitoring thresholds output by the multiple sub - learning models respectively.

[0091] On the one hand, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the steps of the method for generating a monitoring rule as described above.

[0092] On the one hand, an embodiment of the present application provides a computer - readable storage medium, which stores a computer program executable by a computer device. When the program runs on the computer device, it causes the computer device to execute the steps of the method for generating a monitoring rule as described above.

[0093] In the embodiments of the present application, the first time period is divided into multiple time units, and the original transaction data corresponding to each of the multiple time units is corrected respectively to obtain the corrected transaction data corresponding to each of the multiple time units. Then, based on the corrected transaction data corresponding to each of the multiple time units, the cumulative index values corresponding to each of the multiple time units and the average index values corresponding to each of the multiple time units are determined respectively. The first time period is divided according to regular time slices to obtain multiple regular time periods. Then, the multiple cumulative index values and the multiple average index values corresponding to each regular time period are input into the ensemble learning model respectively to obtain the monitoring rules corresponding to each regular time period. Since different monitoring rules correspond to each regular time period, the accuracy of business anomaly perception is improved. The monitoring rules corresponding to each regular time period are determined according to the multiple cumulative index values and the multiple average index values corresponding to each regular time period, rather than being determined based on expert experience. Therefore, the accuracy of the monitoring rules corresponding to each regular time period is higher, and corresponding monitoring rules can be obtained for changes in different monitoring scenarios, with strong scalability. BRIEF DESCRIPTION OF THE DRAWINGS

[0094] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0095] Figure 1 It is a schematic diagram of a system architecture provided by the embodiments of the present application;

[0096] Figure 2 It is a schematic flowchart of a method for generating monitoring rules provided by the embodiments of the present application;

[0097] Figure 3 It is a schematic diagram of a structure for dividing time units provided by the embodiments of the present application;

[0098] Figure 4 It is a schematic diagram of a structure for dividing time periods provided by the embodiments of the present application;

[0099] Figure 5 It is a schematic diagram of a structure for dividing time units provided by the embodiments of the present application;

[0100] Figure 6 It is a schematic flowchart of a method for determining a target sliding window provided by the embodiments of the present application;

[0101] Figure 7 It is a schematic flowchart of a method for determining the sliding window length corresponding to the time period of the target window category provided by the embodiments of the present application;

[0102] Figure 8 A structural schematic diagram of a structure for dividing window category time periods provided by an embodiment of the present application;

[0103] Figure 9 A structural schematic diagram of a target sliding window provided by an embodiment of the present application;

[0104] Figure 10 A flowchart of a process for obtaining a monitoring rule provided by an embodiment of the present application;

[0105] Figure 11 A structural schematic diagram of a device for generating a monitoring rule provided by an embodiment of the present application;

[0106] Figure 12 A structural schematic diagram of a device for generating a monitoring rule provided by an embodiment of the present application;

[0107] Figure 13 A structural schematic diagram of a computer device provided by an embodiment of the present application. Detailed implementation manners

[0108] In order to make the objectives, technical solutions and beneficial effects of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0109] Refer to Figure 1 , which is a system architecture diagram for generating a monitoring rule applicable to an embodiment of the present application. The system architecture diagram for generating a monitoring rule at least includes a terminal device 101 and a monitoring rule generation system 102.

[0110] The terminal device 101 is installed with a target application for generating a monitoring rule. This application can be a pre-installed client, a web version application, or a small program embedded in other applications, etc. The terminal device 101 can be a smart phone, a tablet computer, a notebook computer, a desktop computer, etc., but is not limited thereto.

[0111] The monitoring rule generation system 102 is the background server of the target application and provides services for the target application. The monitoring rule generation system 102 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms.

[0112] The terminal device 101 and the monitoring rule generation system 102 can be directly or indirectly connected through wired or wireless communication means, which is not limited in this application.

[0113] The terminal device 101 responds to the user's operation of generating a monitoring rule, and sends a monitoring rule generation instruction for the first time period to the monitoring rule generation system 102. The monitoring rule generation system 102 receives the monitoring rule generation instruction, divides the first time period into multiple time units, and respectively corrects the original transaction data corresponding to each of the multiple time units to obtain the corrected transaction data corresponding to each of the multiple time units. Then, based on the corrected transaction data corresponding to each of the multiple time units, the cumulative index values corresponding to each of the multiple time units and the average index values corresponding to each of the multiple time units are respectively determined. According to the regular time slices, the first time period is divided to obtain multiple regular time periods. Then, the multiple cumulative index values and the multiple average index values corresponding to each regular time period are respectively input into the integrated learning model to obtain the monitoring rules corresponding to each regular time period.

[0114] Based on Figure 1 the system architecture diagram described above, an embodiment of this application provides a process for a method of generating a monitoring rule, as Figure 2 shown. The process of this method is executed by the monitoring rule generation system 102 shown in Figure 1 and includes the following steps:

[0115] Step S201: Divide the first time period into multiple time units, and respectively correct the original transaction data corresponding to each of the multiple time units to obtain the corrected transaction data corresponding to each of the multiple time units.

[0116] Specifically, the first time period is a historical time period. To ensure the accuracy of the generated monitoring rules, for natural day monitoring, the historical time period is 7 natural days; for working day monitoring, the historical time period is 5 working days; for non - working day monitoring, the historical time period is the most recent 4 non - working days. For other monitoring, the setting of the historical time period is not limited here.

[0117] The time unit can be in seconds, minutes, or hours. For example, the time unit is 15 seconds.

[0118] For example, Figure 3As shown, if the first time period is 2 natural days, namely September 1st and September 2nd, and the time unit is 15 seconds, the 2 natural days in the first time period are divided to obtain 11,520 time units, which are {September 1st 00:00:00 - September 1st 00:00:15}, {September 1st 00:00:15 - September 1st 00:00:30}, …, {September 1st 23:59:45 - September 1st 24:00:00}, …, {September 2nd 00:00:00 - September 2nd 00:00:15}, …, {September 2nd 23:59:45 - September 2nd 24:00:00}.

[0119] Each time unit includes multiple transactions. The multiple transactions within each time unit are counted to obtain the original transaction data corresponding to each time unit. The original transaction data includes the original transaction volume, the original successful transaction volume, and the original response time.

[0120] Among them, the number of multiple transactions within the time unit is counted to obtain the original transaction volume. The number of successful transactions among the multiple transactions within the time unit is counted to obtain the original successful transaction volume. The transaction times corresponding to the multiple transactions within the time unit are accumulated to obtain the original response time.

[0121] For multiple time units, the following steps are respectively executed: Based on the business type, the original transaction data corresponding to a time unit is corrected to obtain the corrected transaction data. The corrected transaction data includes the transaction volume, the successful transaction volume, and the response time.

[0122] For different business types, different data correction methods are adopted for the original transaction data. When the business type is the shunt scenario, if the proportion of the original transaction volume in a time unit before shunt to the total monitored transaction volume is m%, and the proportion of the original transaction volume in a time unit after shunt to the total monitored transaction volume is n%, then the corrected transaction data can be obtained using the following formulas (1), (2), and (3). Among them, the corrected transaction data includes the transaction volume, the successful transaction volume, and the response time:

[0123]

[0124] Among them, Total modify is the transaction volume corresponding to a time unit in the shunt scenario, Total is the original transaction volume corresponding to a time unit in the shunt scenario, n% is the proportion of the original transaction volume in a time unit after shunt to the total monitored transaction volume, and m% is the proportion of the original transaction volume in a time unit before shunt to the total monitored transaction volume.

[0125]

[0126] Among them, Secmodify For the successful transaction volume corresponding to a time unit in the traffic splitting scenario, Sec is the original successful transaction volume corresponding to a time unit in the traffic splitting scenario, n% is the proportion of the original transaction volume within a time unit after traffic splitting in the total monitored transaction volume, and m% is the proportion of the original transaction volume within a time unit before traffic splitting in the total monitored transaction volume.

[0127]

[0128] Among them, Time modify For the response time corresponding to a time unit in the traffic splitting scenario, Time is the original response time corresponding to a time unit in the traffic splitting scenario, n% is the proportion of the original transaction volume within a time unit after traffic splitting in the total monitored transaction volume, and m% is the proportion of the original transaction volume within a time unit before traffic splitting in the total monitored transaction volume.

[0129] For other business types, there is no restriction here.

[0130] For example, there are a total of 4 transactions within a time unit. The first transaction and the second transaction are both successful, and the third transaction and the fourth transaction are both failed. The transaction time corresponding to the first transaction is 2s, the transaction time corresponding to the second transaction is 1s, the transaction time corresponding to the third transaction is 1s, and the transaction time corresponding to the fourth transaction is 3s. Therefore, the original transaction volume corresponding to this time unit is 4, the original successful transaction volume is 2, and the original response time is 2s + 1s + 1s + 3s = 7s.

[0131] In the traffic splitting scenario, if the proportion of the original transaction volume within this time unit in the total monitored transaction volume is adjusted from 100% to 50%, then the transaction volume corresponding to this time unit is The successful transaction volume is The response time is

[0132] Step S202: Based on the corrected transaction data corresponding to multiple time units, respectively determine the cumulative index values and the average index values corresponding to multiple time units.

[0133] Specifically, the cumulative index values include the consecutive failed transaction volume, etc., and the average index values include the average transaction volume, the average successful transaction volume, the negative fluctuation value, the average response time, etc.

[0134] Step S203: Divide the first time period according to the regular time slice to obtain multiple regular time periods.

[0135] Specifically, the regular time slice can be in seconds, or in minutes, or in hours. For example, the regular time slice is 1 hour.

[0136] If the first time period includes multiple natural days, divide the multiple natural days according to the regular time slices. Specifically, each natural day is divided into multiple time periods according to the regular time slices, and the same time period of different natural days is used as a regular time period.

[0137] For example, as Figure 4 shown, if the first time period is 2 natural days, namely September 1st and September 2nd, and the regular time slice is 1 hour, then September 1st and September 2nd are respectively divided into 24 time periods with 1 hour as the division unit. Then, the same time period in September 1st and September 2nd is used as a regular time period, obtaining 24 regular time periods. Among them, the regular time period 00:00:00 - 01:00:00 includes {September 1st 00:00:00 - September 1st 01:00:00}, {September 1st 24:00:00 (also referring to September 2nd 00:00:00) - September 2nd 01:00:00}; the regular time period 01:00:00 - 02:00:00 includes {September 1st 01:00:00 - September 1st 02:00:00}, {September 2nd 01:00:00 - September 2nd 02:00:00},..., the regular time period 23:00:00 - 24:00:00 includes {September 1st 23:00:00 - September 1st 24:00:00}, {September 2nd 23:00:00 - September 2nd 24:00:00}.

[0138] A regular time period includes multiple time units, and the duration of a regular time period is greater than the duration of one time unit.

[0139] Step S204: Input the multiple cumulative index values and multiple mean index values corresponding to each regular time period into the integrated learning model respectively, and obtain the monitoring rules corresponding to each regular time period.

[0140] Specifically, if a regular time period includes multiple time units, then the multiple cumulative index values corresponding to each time unit within the regular time period are used as the multiple cumulative index values corresponding to the regular time period; the multiple mean index values corresponding to each time unit within the regular time period are used as the multiple mean index values corresponding to the regular time period.

[0141] For example, as Figure 4As shown, for the regular time period 00:00:00 - 01:00:00, the regular time period 00:00:00 - 01:00:00 includes two time periods, namely {00:00:00 on September 1 - 01:00:00 on September 1}, {24:00:00 on September 1 (also referring to 00:00:00 on September 2) - 01:00:00 on September 2}. Among them, the time period 00:00:00 on September 1 - 01:00:00 on September 1 includes 240 time units, and the time period 24:00:00 on September 1 - 01:00:00 on September 2 includes 240 time units. Therefore, the regular time period 00:00:00 - 01:00:00 includes 480 time units. Since each time unit corresponds to a cumulative index value and an average index value, the regular time period 00:00:00 - 01:00:00 corresponds to 480 cumulative index values and 480 average index values.

[0142] The integrated learning model includes multiple sub - learning models, and the sub - learning model can be any one of IsolationForest, Local Outlier Factor (LOF), and Median Absolute Deviation (MAD). The integrated learning model can include all sub - learning models or some of the sub - learning models.

[0143] For one of the regular time periods, the following steps are performed:

[0144] Input the multiple cumulative index values corresponding to this regular time period into the integrated learning model to obtain the cumulative index monitoring thresholds corresponding to the multiple cumulative index values in this regular time period;

[0145] Input the multiple average index values corresponding to this regular time period into the integrated learning model to obtain the average index monitoring thresholds corresponding to the multiple average index values in this regular time period;

[0146] Take the obtained cumulative index monitoring thresholds and average index monitoring thresholds as the monitoring rules corresponding to this regular time period.

[0147] In the embodiments of the present application, the first time period is divided into multiple time units, and the original transaction data corresponding to each of the multiple time units is corrected respectively to obtain the corrected transaction data corresponding to each of the multiple time units. Then, based on the corrected transaction data corresponding to each of the multiple time units, the cumulative index values corresponding to each of the multiple time units and the average index values corresponding to each of the multiple time units are determined respectively. The first time period is divided according to regular time slices to obtain multiple regular time periods. Then, the multiple cumulative index values and multiple average index values corresponding to each regular time period are input into the integrated learning model respectively to obtain the monitoring rules corresponding to each regular time period. Since different monitoring rules correspond to each regular time period, the accuracy of business anomaly perception is improved. The monitoring rules corresponding to each regular time period are determined according to the multiple cumulative index values and multiple average index values corresponding to each regular time period, rather than being determined based on expert experience. Therefore, the accuracy of the monitoring rules corresponding to each regular time period is higher, and corresponding monitoring rules can be obtained for changes in different monitoring scenarios, with strong scalability.

[0148] Optionally, in step S202 above, when the cumulative index value is the consecutive failed transaction volume, based on the corrected transaction data corresponding to each of the multiple time units, determining the cumulative index value corresponding to each of the multiple time units includes the following steps:

[0149] For each of the multiple time units, the following steps are performed respectively:

[0150] If the failed transaction volume of the corrected transaction data within a time unit is 0, it is determined that the consecutive failed transaction volume corresponding to one time unit is 0.

[0151] If the failed transaction volume of the corrected transaction data within a time unit is not 0, based on the consecutive failed transaction volume corresponding to the previous time unit of one time unit and the failed transaction volume, the consecutive failed transaction volume corresponding to one time unit is determined.

[0152] Specifically, the corrected transaction data corresponding to one time unit includes transaction volume, successful transaction volume, and response time. The difference between the transaction volume and the successful transaction volume corresponding to one time unit is used as the failed transaction volume of the corrected transaction data within one time unit.

[0153] For example, as Figure 5 shown, assuming the time unit is 15 seconds, September 1st is divided to obtain 5760 time units, which are {September 1st 00:00:00 - September 1st 00:00:15}, …, {September 1st 23:59:45 - September 1st 24:00:00}.

[0154] Set the failed transaction volume corresponding to {September 1st, 10:00:00 - September 1st, 10:00:15} to 20, the failed transaction volume corresponding to {September 1st, 10:00:15 - September 1st, 10:00:30} to 10, the failed transaction volume corresponding to {September 1st, 10:00:30 - September 1st, 10:00:45} to 0, the failed transaction volume corresponding to {September 1st, 10:00:45 - September 1st, 10:01:00} to 10, and the failed transaction volume corresponding to {September 1st, 10:01:00 - September 1st, 10:01:15} to 20.

[0155] Set the consecutive failed transaction volume corresponding to {September 1st, 10:00:00 - September 1st, 10:00:15} to 20, the consecutive failed transaction volume corresponding to {September 1st, 10:00:15 - September 1st, 10:00:30} to 20 + 10 = 30, the consecutive failed transaction volume corresponding to {September 1st, 10:00:30 - September 1st, 10:00:45} to 0, the consecutive failed transaction volume corresponding to {September 1st, 10:00:45 - September 1st, 10:01:00} to 10, and the consecutive failed transaction volume corresponding to {September 1st, 10:01:00 - September 1st, 10:01:15} to 20 + 10 = 30.

[0156] In the embodiments of the present application, when the cumulative metric value is the consecutive failed transaction volume, by calculating the consecutive failed transaction volume of one time unit, the influence of the previous time unit on the current time unit can be statistically analyzed, which is beneficial to improving the accuracy of the determined monitoring rules.

[0157] Optionally, in the above step S202, determining the mean metric value corresponding to each of the multiple time units based on the corrected transaction data corresponding to each of the multiple time units includes the following steps:

[0158] For each of the multiple time units, the following steps are respectively executed:

[0159] Obtain the corrected transaction data corresponding to each of the multiple time units within the target sliding window corresponding to one time unit. Then, based on the obtained multiple corrected transaction data, determine the mean metric value corresponding to the one time unit.

[0160] Specifically, when the mean metric value is the average transaction volume, for each of the multiple time units, the following steps are respectively executed:

[0161] Obtain the corrected transaction data corresponding to each of the multiple time units within the target sliding window corresponding to one time unit. Then, average the transaction volumes in the obtained multiple corrected transaction data to determine the average transaction volume corresponding to one time unit.

[0162] When the mean index value is the average successful transaction volume, the following steps are respectively executed for the multiple time units:

[0163] Obtain the corrected transaction data corresponding to each of the multiple time units within the target sliding window corresponding to one time unit. Then, average the successful transaction volumes among the obtained multiple corrected transaction data to determine the average successful transaction volume corresponding to one time unit.

[0164] When the mean index value is the negative fluctuation value, the following steps are respectively executed for the multiple time units:

[0165] Obtain the corrected transaction data corresponding to each of the multiple time units within the target sliding window corresponding to one time unit. Based on the obtained multiple corrected transaction data, determine the total transaction volume corresponding to the target sliding window. Then, based on the total transaction volume corresponding to the target sliding window and the total transaction volume corresponding to the previous sliding window of the target sliding window, determine the negative fluctuation value corresponding to one time unit.

[0166] In the embodiments of the present application, in order to determine the negative fluctuation value corresponding to one time unit based on the total transaction volume corresponding to the target sliding window and the total transaction volume corresponding to the previous sliding window of the target sliding window, the following three methods are provided, which are respectively:

[0167] The first possible implementation method is to use the difference between the total transaction volume corresponding to the previous sliding window and the total transaction volume corresponding to the target sliding window as the negative fluctuation value corresponding to one time unit.

[0168] The second possible implementation method is to use the difference between the total transaction volume corresponding to the previous sliding window and the total transaction volume corresponding to the target sliding window as the transaction growth volume corresponding to the target sliding window. Then, use the ratio of the transaction growth volume corresponding to the target sliding window to the total transaction volume corresponding to the target sliding window as the negative fluctuation value corresponding to one time unit.

[0169] The third possible implementation method is to use the difference between the total transaction volume corresponding to the previous sliding window and the total transaction volume corresponding to the target sliding window as the transaction growth volume corresponding to the target sliding window. If the transaction growth volume corresponding to the target sliding window is less than 0, then use the ratio of the transaction growth volume corresponding to the target sliding window to the total transaction volume corresponding to the target sliding window as the negative fluctuation value corresponding to one time unit; otherwise, the negative fluctuation value corresponding to one time unit is 0.

[0170] When the mean index value is the average response time, the following steps are respectively executed for the multiple time units:

[0171] Obtain the corrected transaction data corresponding to each of the multiple time units within the target sliding window corresponding to one time unit. Then, average the response times in the obtained multiple corrected transaction data to determine the average response time corresponding to one time unit.

[0172] In the embodiment of the present application, since the mean index reflects the changes in the corrected transaction data of multiple time units within the target sliding window, therefore, the mean index corresponding to one time unit determined based on the target sliding window is more stable, which is conducive to improving the accuracy of the monitoring rule.

[0173] Optionally, in the above step S202, after respectively determining the cumulative index values and the mean index values corresponding to each of the multiple time units based on the corrected transaction data corresponding to each of the multiple time units, perform data regularization on the cumulative index value and the mean index value corresponding to each time unit respectively, including the following steps:

[0174] If the cumulative index value is of the upward trigger index type, the cumulative index value remains unchanged; if the cumulative index value is of the downward trigger index type, then take the negative of the cumulative index value. For example, if the cumulative index value is 30, the negative is -30.

[0175] If the mean index value is of the upward trigger index type, the mean index value remains unchanged; if the mean index value is of the downward trigger index type, then take the negative of the mean index value.

[0176] Among them, the consecutive failed transaction volume and the average response time are of the upward trigger index type, and the average transaction volume, the average successful transaction volume, and the negative volatility value are of the downward trigger index type.

[0177] In the embodiment of the present application, since the trigger criteria of the monitoring rules determined by different cumulative index values and mean index values are not the same, therefore, it is necessary to perform data regularization on the cumulative index value and the mean index value to facilitate the subsequent determination of the monitoring rule using the same integrated learning model.

[0178] Optionally, as Figure 6 shown, the target sliding window corresponding to one time unit can be determined in the following manner:

[0179] Step S601, determine the target window category time period matching one time unit from multiple window category time periods, and obtain the sliding window length corresponding to the target window category time period.

[0180] Among them, the multiple window category time periods are obtained by dividing the second time period according to a preset rule, the second time period is obtained by dividing the first time period according to natural days, and each window category time period corresponds to a sliding window length. The duration of the window category time period is the same as the duration of the rule time period.

[0181] The preset rule can divide the second time period by hours, or divide the second time period by minutes, or other division methods can be used, which are not limited here.

[0182] If the duration of the window category time period is greater than the duration of one time unit, the window category time period that overlaps with one time unit is used as the target window category time period.

[0183] Step S602: Determine the target sliding window corresponding to one time unit based on the end time point of one time unit and the sliding window length.

[0184] Among them, the end time point of one time unit is the same as the end time point of the target sliding window.

[0185] As Figure 7 shown, the following method can be used to determine the sliding window length corresponding to the target window category time period, including the following steps:

[0186] Step S701: Obtain the total trading volume of the second time period, and determine the lower limit value and upper limit value of the sliding window length based on the total trading volume.

[0187] Specifically, input the total trading volume of the second time period into the first function to obtain the lower limit value and upper limit value of the sliding window length. Among them, the first function is a piecewise function. Different total trading volumes of the second time period result in different lower limit values and upper limit values of the determined sliding window length. The larger the total trading volume of the second time period, the smaller the lower limit value and upper limit value of the determined sliding window length.

[0188] Step S702: Determine the trading ratio corresponding to the target window category time period based on the ratio of the trading volume within the target window category time period to the total trading volume.

[0189] Step S703: Determine the sliding window length corresponding to the target window category time period based on the trading ratio, the lower limit value, and the upper limit value.

[0190] Specifically, input the trading ratio, the lower limit value, and the upper limit value into the second function to obtain the sliding window length corresponding to the target window category time period. Among them, the second function is a piecewise function. The larger the trading ratio, the smaller the determined sliding window length.

[0191] For example, set the first time period to 2 natural days, namely September 1st and September 2nd. The time unit is 15 seconds. Divide the 2 natural days in the first time period to obtain 11,520 time units. At the same time, divide the first time period by natural days to obtain two second time periods, namely the second time period 1 and the second time period 2. Among them, the second time period 1 is September 1st, and the second time period 2 is September 2nd.

[0192] Set the preset rule to divide the second time period by one hour. As Figure 8 shown, divide the second time period 1 (i.e., September 1st) to obtain 24 window category time periods, namely {September 1st 00:00:00 - September 1st 01:00:00}, {September 1st 01:00:00 - September 1st 02:00:00}, …, {September 1st 23:00:00 - September 1st 24:00:00}.

[0193] Divide the second time period 2 (i.e., September 2nd) using the same division method, which will not be elaborated here.

[0194] Set a time unit to be {September 1st 10:30:30 - September 1st 10:30:45}. Since this time unit overlaps with the window category time period {September 1st 10:00:00 - September 1st 11:00:00}, therefore, {September 1st 10:00:00 - September 1st 11:00:00} is used as the target window category time period for a time unit (September 1st 10:30:30 - September 1st 10:30:45).

[0195] Set the total trading volume of the second time period 1 to be 10,000. Input the total trading volume 10,000 into the first function to determine that the lower limit value of the sliding window length is 5s and the upper limit value is 50s.

[0196] The trading volume within the target window category time period (September 1st 10:00:00 - September 1st 11:00:00) is 200. Therefore, determine that the trading ratio corresponding to the target window category time period is Input 5s and 50s into the second function to determine that the sliding window length corresponding to the target window category time period is 30s.

[0197] Finally, the target sliding window corresponding to a determined time unit (September 1st 10:30:30 - September 1st 10:30:45) is as Figure 9 shown, {September 1st 10:30:15 - September 1st 10:30:45} is the target sliding window.

[0198] Optionally, before inputting the multiple cumulative index values and multiple mean index values corresponding to each regular time period into the ensemble learning model to obtain the monitoring rules corresponding to each regular time period in step S204 above, it further includes:

[0199] Perform statistics on the multiple cumulative index values corresponding to each regular time period. If the missing rate meets the preset condition, delete this regular time period.

[0200] Perform statistics on the multiple mean index values corresponding to each regular time period. If the missing rate meets the preset condition, delete this regular time period.

[0201] Optionally, in step S204 above, input the multiple cumulative index values and multiple mean index values corresponding to each regular time period into the ensemble learning model to obtain the monitoring rules corresponding to each regular time period, which specifically includes the following steps:

[0202] As Figure 10 shown, for multiple regular time periods, the following steps are respectively executed:

[0203] Step S1001, input the multiple cumulative index values corresponding to a regular time period into the ensemble learning model to obtain multiple first monitoring thresholds.

[0204] Specifically, the ensemble learning model includes multiple sub-learning models, and the sub-learning model can be any one of Isolation Forest, Local Outlier Factor algorithm, and Median Absolute Deviation.

[0205] Input the multiple cumulative index values corresponding to this regular time period into multiple sub-learning models respectively to obtain the first monitoring thresholds output by each sub-learning model.

[0206] Assume that the ensemble learning model includes Isolation Forest, Local Outlier Factor algorithm, and Median Absolute Deviation. Input the multiple cumulative index values corresponding to this regular time period into Isolation Forest. After removing the abnormal cumulative index values, select the maximum cumulative index value from the remaining multiple cumulative index values as the first monitoring threshold.

[0207] At the same time, input the multiple cumulative index values corresponding to this regular time period into the Local Outlier Factor algorithm. After removing the abnormal cumulative index values, select the maximum cumulative index value from the remaining multiple cumulative index values as the first monitoring threshold. Input the multiple cumulative index values corresponding to this regular time period into the Median Absolute Deviation. After removing the abnormal cumulative index values, select the maximum cumulative index value from the remaining multiple cumulative index values as the first monitoring threshold.

[0208] Finally, after inputting the multiple cumulative index values corresponding to this regular time period into the ensemble learning model, 3 first monitoring thresholds are obtained.

[0209] For example, when the ensemble learning model includes Isolation Forest, Local Outlier Factor algorithm, and Median Absolute Deviation, and the cumulative metric value is the consecutive failed transaction volume, input the multiple consecutive failed transaction volumes corresponding to a regular time period into the Isolation Forest. After removing the abnormal consecutive failed transaction volumes, among the remaining multiple consecutive failed transaction volumes, select the maximum consecutive failed transaction volume as the first monitoring threshold.

[0210] Meanwhile, input the multiple consecutive failed transaction volumes corresponding to this regular time period into the Local Outlier Factor algorithm. After removing the abnormal consecutive failed transaction volumes, among the remaining multiple consecutive failed transaction volumes, select the maximum consecutive failed transaction volume as the first monitoring threshold. Input the multiple consecutive failed transaction volumes corresponding to this regular time period into the Median Absolute Deviation. After removing the abnormal consecutive failed transaction volumes, among the remaining multiple consecutive failed transaction volumes, select the maximum consecutive failed transaction volume as the first monitoring threshold.

[0211] Finally, after inputting the multiple consecutive failed transaction volumes corresponding to this regular time period into the said ensemble learning model, 3 first monitoring thresholds are obtained.

[0212] Step S1002: Take the maximum monitoring threshold among the multiple first monitoring thresholds as the cumulative metric monitoring threshold corresponding to the multiple cumulative metric values in a regular time period.

[0213] Step S1003: Input the multiple mean metric values corresponding to a regular time period into the ensemble learning model to obtain multiple second monitoring thresholds.

[0214] Specifically, input the multiple mean metric values corresponding to this regular time period into multiple sub - learning models respectively to obtain the second monitoring thresholds output by each of the multiple sub - learning models.

[0215] Suppose the ensemble learning model includes Isolation Forest, Local Outlier Factor algorithm, and Median Absolute Deviation. Input the multiple mean metric values corresponding to this regular time period into the Isolation Forest. After removing the abnormal mean metric values, among the remaining multiple mean metric values, select the maximum mean metric value as the second monitoring threshold.

[0216] Meanwhile, input the multiple mean metric values corresponding to this regular time period into the Local Outlier Factor algorithm. After removing the abnormal mean metric values, among the remaining multiple mean metric values, select the maximum mean metric value as the second monitoring threshold. Input the multiple mean metric values corresponding to this regular time period into the Median Absolute Deviation. After removing the abnormal mean metric values, among the remaining multiple mean metric values, select the maximum mean metric value as the second monitoring threshold.

[0217] Finally, after inputting the multiple mean metric values corresponding to this regular time period into the said ensemble learning model, 3 second monitoring thresholds are obtained.

[0218] For example, when the integrated learning model includes Isolation Forest, Local Outlier Factor algorithm, and Median Absolute Deviation, and the mean metric value is the average trading volume, multiple average trading volumes corresponding to a regular time period are input into the Isolation Forest. After removing the abnormal average trading volumes, among the remaining multiple average trading volumes, the maximum average trading volume is selected as the second monitoring threshold.

[0219] Meanwhile, multiple average trading volumes corresponding to the regular time period are input into the Local Outlier Factor algorithm. After removing the abnormal average trading volumes, among the remaining multiple average trading volumes, the maximum average trading volume is selected as the second monitoring threshold. Multiple average trading volumes corresponding to the regular time period are input into the Median Absolute Deviation. After removing the abnormal average trading volumes, among the remaining multiple average trading volumes, the maximum average trading volume is selected as the second monitoring threshold.

[0220] Finally, multiple average trading volumes corresponding to the regular time period are input into the integrated learning model, and 3 second monitoring thresholds are obtained.

[0221] When the mean metric value is the average successful trading volume, negative volatility value, or average response time, the process is similar to the above and will not be elaborated here.

[0222] Step S1004: Use the maximum monitoring threshold among the multiple second monitoring thresholds as the mean metric monitoring threshold corresponding to multiple mean metric values in a regular time period.

[0223] Step S1005: Use the obtained cumulative metric monitoring threshold and mean metric monitoring threshold as the monitoring rules corresponding to a regular time period.

[0224] Specifically, within a regular time period, for the cumulative metric value, use the cumulative metric monitoring threshold as the monitoring rule; for the mean metric value, use the mean metric value and the sliding window length as the monitoring rule.

[0225] For the monitoring rules corresponding to each regular time period, perform rule backtesting. If the rule backtesting result meets the monitoring standard, output the monitoring rules corresponding to each regular time period; if the rule backtesting result does not meet the monitoring standard, conduct manual review and perform targeted processing.

[0226] To better explain the embodiments of the present application, the following describes a method for generating monitoring rules provided by the embodiments of the present application in combination with a specific implementation scenario. This method is executed by Figure 1 the monitoring rule generation system 102 in Figure 11As shown in the figure, the monitoring rule generation system 102 includes a data conversion and derivation module 1101, a rule calculation module 1102, and a rule integration module 1103. Among them, the data conversion and derivation module 1101 includes a data correction module 11011, a cumulative index value calculation module 11012, an average index value calculation module 11013, and a data regularization module 11014. The rule calculation module 1102 includes a filtering module 11021 and an integrated learning module 11022. The rule integration module 1103 includes a rule generation module 11031, a rule backtesting module 11032, and a manual review module 11033.

[0227] The data correction module 11011 divides the first time period into multiple time units, and respectively corrects the original transaction data corresponding to each of the multiple time units to obtain the corrected transaction data corresponding to each of the multiple time units. The data correction module 11011 respectively sends the corrected data to the cumulative index value calculation module 11012 and the average index value calculation module 11013.

[0228] The cumulative index value calculation module 11012 respectively determines the cumulative index values corresponding to each of the multiple time units based on the corrected transaction data corresponding to each of the multiple time units. Specifically, the cumulative index values include the consecutive failed transaction volume, etc. The cumulative index value calculation module 11012 sends the obtained cumulative index values to the data regularization module 11014.

[0229] The average index value calculation module 11013 respectively determines the average index values corresponding to each of the multiple time units based on the corrected transaction data corresponding to each of the multiple time units. Specifically, the average index values include the average transaction volume, the average successful transaction volume, the negative volatility value, the average response time, etc. The average index value calculation module 11013 sends the average index values to the data regularization module 11014.

[0230] The data regularization module 11014 judges the cumulative index values. If the cumulative index value is of the upward trigger index type, the cumulative index value remains unchanged; if the cumulative index value is of the downward trigger index type, the cumulative index value is inverted.

[0231] The data regularization module 11014 judges the average index values. If the average index value is of the upward trigger index type, the average index value remains unchanged; if the average index value is of the downward trigger index type, the average index value is inverted.

[0232] Among them, the consecutive failed transaction volume and the average response time are of the upward trigger index type, and the average transaction volume, the average successful transaction volume, and the negative volatility value are of the downward trigger index type.

[0233] The data regularization module 11014 sends the cumulatively index values and average index values after data regularization to the filtering module 11021.

[0234] The filtering module 11021 divides the first time period according to the regular time slice to obtain multiple regular time periods. Then, for the multiple cumulative index values corresponding to each regular time period, if the missing rate meets the preset condition, the regular time period is deleted. For the multiple average index values corresponding to each regular time period, if the missing rate meets the preset condition, the regular time period is deleted.

[0235] The filtering module 11021 inputs the multiple cumulative index values and multiple average index values corresponding to the filtered regular time periods into the integrated learning module 11022.

[0236] The integrated learning module 11022 performs the following steps for multiple regular time periods respectively:

[0237] Input the multiple cumulative index values corresponding to a regular time period into the integrated learning model to obtain multiple first monitoring thresholds. Take the maximum monitoring threshold among the multiple first monitoring thresholds as the cumulative index monitoring threshold corresponding to the multiple cumulative index values in a regular time period.

[0238] Input the multiple average index values corresponding to a regular time period into the integrated learning model to obtain multiple second monitoring thresholds. Take the maximum monitoring threshold among the multiple second monitoring thresholds as the average index monitoring threshold corresponding to the multiple average index values in a regular time period.

[0239] The integrated learning module 11022 sends the cumulative index monitoring threshold corresponding to each regular time period to the rule generation module 11031.

[0240] The integrated learning module 11022 sends the average index monitoring threshold and the sliding window length corresponding to each regular time period to the rule generation module 11031.

[0241] The rule generation module 11031 takes the cumulative index monitoring threshold, the average index monitoring threshold and the sliding window length corresponding to each regular time period as the monitoring rules. The rule generation module 11031 sends the generated monitoring rules to the rule backtesting module 11032.

[0242] The rule backtesting module 11032 performs rule backtesting for the monitoring rules corresponding to each regular time period. If the rule backtesting result meets the monitoring standard, the monitoring rules corresponding to each regular time period are output; if the rule backtesting result does not meet the monitoring standard, it is sent to the manual review module 11033.

[0243] The manual review module 11033 conducts manual review on the monitoring rules that do not meet the monitoring standard and performs targeted processing.

[0244] Based on the same technical concept, an embodiment of the present application provides a device for generating monitoring rules, as follows Figure 12 As shown, the device 1200 for generating monitoring rules includes:

[0245] A correction module 1201, configured to divide a first time period into multiple time units, and respectively correct the original transaction data corresponding to each of the multiple time units to obtain the corrected transaction data corresponding to each of the multiple time units;

[0246] A calculation module 1202, configured to respectively determine the cumulative index value corresponding to each of the multiple time units and the average index value corresponding to each of the multiple time units based on the corrected transaction data corresponding to each of the multiple time units;

[0247] A division module 1203, configured to divide the first time period according to a regular time slice to obtain multiple regular time periods;

[0248] A rule acquisition module 1204, configured to respectively input the multiple cumulative index values and multiple average index values corresponding to each regular time period into an integrated learning model to obtain the monitoring rule corresponding to each regular time period.

[0249] Optionally, the correction module 1201 is specifically configured to:

[0250] For each of the multiple time units, respectively perform the following steps:

[0251] Based on the business type, correct the original transaction data corresponding to one time unit to obtain corrected transaction data.

[0252] Optionally, the cumulative index value includes the consecutive failed transaction volume;

[0253] The calculation module 1202 is specifically configured to:

[0254] For each of the multiple time units, respectively perform the following steps:

[0255] If the failed transaction volume of the corrected transaction data within one time unit is 0, determine that the consecutive failed transaction volume corresponding to the one time unit is 0;

[0256] If the failed transaction volume of the corrected transaction data within one time unit is not 0, determine the consecutive failed transaction volume corresponding to the one time unit based on the consecutive failed transaction volume corresponding to the previous time unit of the one time unit and the failed transaction volume.

[0257] Optionally, the calculation module 1202 is specifically configured to:

[0258] For each of the multiple time units, respectively perform the following steps:

[0259] Obtain the corrected transaction data corresponding to each of the multiple time units within the target sliding window corresponding to one time unit;

[0260] Based on the obtained multiple corrected transaction data, determine the mean index value corresponding to the one time unit.

[0261] Optionally, the target sliding window corresponding to the one time unit is determined in the following manner, including:

[0262] From multiple window category time periods, determine the target window category time period that matches the one time unit, and obtain the sliding window length corresponding to the target window category time period. The multiple window category time periods are obtained by dividing the second time period according to a preset rule, where each window category time period corresponds to a sliding window length;

[0263] Based on the end time point of the one time unit and the sliding window length, determine the target sliding window corresponding to the one time unit, where the end time point of the one time unit is the same as the end time point of the target sliding window.

[0264] Optionally, the sliding window length corresponding to the target window category time period is determined in the following manner, including:

[0265] Obtain the total trading volume of the second time period, and determine the lower limit value and the upper limit value of the sliding window length based on the total trading volume;

[0266] Based on the ratio of the trading volume within the target window category time period to the total trading volume, determine the trading ratio corresponding to the target window category time period;

[0267] Based on the trading ratio, the lower limit value, and the upper limit value, determine the sliding window length corresponding to the target window category time period.

[0268] Optionally, the mean index value includes a negative volatility value;

[0269] The calculation module 1202 is specifically configured to:

[0270] Based on the obtained multiple corrected transaction data, determine the total trading volume corresponding to the target sliding window;

[0271] Based on the total trading volume corresponding to the target sliding window and the total trading volume corresponding to the previous sliding window of the target sliding window, determine the negative volatility value corresponding to the one time unit.

[0272] Optionally, the calculation module 1202 is specifically configured to:

[0273] Use the difference between the total trading volume corresponding to the previous sliding window and the total trading volume corresponding to the target sliding window as the trading growth volume corresponding to the target sliding window;

[0274] Use the ratio of the trading growth volume corresponding to the target sliding window to the total trading volume corresponding to the target sliding window as the negative fluctuation value corresponding to one time unit.

[0275] Optionally, the rule acquisition module 1204 is specifically configured to:

[0276] For the multiple rule time periods, respectively perform the following steps:

[0277] Input the multiple cumulative index values corresponding to one rule time period into the integrated learning model to obtain multiple first monitoring thresholds;

[0278] Use the maximum monitoring threshold among the multiple first monitoring thresholds as the cumulative index monitoring threshold corresponding to the multiple cumulative index values in the one rule time period;

[0279] Input the multiple mean index values corresponding to one rule time period into the integrated learning model to obtain multiple second monitoring thresholds;

[0280] Use the maximum monitoring threshold among the multiple second monitoring thresholds as the mean index monitoring threshold corresponding to the multiple mean index values in the one rule time period;

[0281] Use the obtained cumulative index monitoring threshold and mean index monitoring threshold as the monitoring rule corresponding to the one rule time period.

[0282] Optionally, the integrated learning model includes multiple sub - learning models;

[0283] The rule acquisition module 1204 is specifically configured to:

[0284] Input the multiple cumulative index values corresponding to one rule time period into the multiple sub - learning models respectively to obtain the first monitoring thresholds output by the multiple sub - learning models respectively;

[0285] The rule acquisition module 1204 is specifically configured to:

[0286] Input the multiple mean index values corresponding to one rule time period into the multiple sub - learning models respectively to obtain the second monitoring thresholds output by the multiple sub - learning models respectively.

[0287] Based on the same technical concept, an embodiment of the present application provides a computer device. The computer device can be a terminal or a server, such as Figure 13As shown, it includes at least one processor 1301 and a memory 1302 connected to the at least one processor. In the embodiments of the present application, the specific connection medium between the processor 1301 and the memory 1302 is not limited. Figure 13 Take the case where the processor 1301 and the memory 1302 are connected through a bus. The bus can be divided into an address bus, a data bus, a control bus, etc.

[0288] In the embodiments of the present application, the memory 1302 stores instructions executable by the at least one processor 1301. By executing the instructions stored in the memory 1302, the at least one processor 1301 can execute the steps included in the above data query method.

[0289] Among them, the processor 1301 is the control center of the computer device. It can use various interfaces and lines to connect to various parts of the computer device. By running or executing the instructions stored in the memory 1302 and calling the data stored in the memory 1302, data query can be performed. Optionally, the processor 1301 may include one or more processing units. The processor 1301 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above modem processor may not be integrated into the processor 1301. In some embodiments, the processor 1301 and the memory 1302 can be implemented on the same chip. In some embodiments, they can also be separately implemented on independent chips.

[0290] The processor 1301 can be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application specific integrated circuit (ASIC), a field programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, which can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.

[0291] The memory 1302 serves as a non-volatile computer-readable storage medium and can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 1302 may include at least one type of storage medium. For example, it may include flash memory, hard disks, multimedia cards, card-type memories, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memories, magnetic disks, optical discs, and so on. The memory 1302 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 1302 in the embodiments of the present application may also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.

[0292] Based on the same inventive concept, embodiments of the present application provide a computer-readable storage medium storing a computer program executable by a computer device. When the program runs on the computer device, the computer device is caused to execute the steps of the above data query method.

[0293] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0294] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, so that the instructions executed by the processors of the computer or other programmable data processing devices generate for implementing in the process Figure 1 one process or multiple processes and / or blocksFigure 1 means for the functions specified in one or more boxes.

[0295] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction means that implements the functions specified in one Figure 1 or more processes and / or boxes Figure 1 means for the functions specified in one or more boxes.

[0296] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus, such that a series of operational steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one Figure 1 or more processes and / or boxes Figure 1 means for the functions specified in one or more boxes.

[0297] It is apparent that those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims

1. A method for generating monitoring rules, characterized in that, Including: Dividing a first time period into multiple time units, and respectively correcting the original transaction data corresponding to each of the multiple time units to obtain the corrected transaction data corresponding to each of the multiple time units; For each of the multiple time units, respectively perform the following steps: If the failed transaction volume of the corrected transaction data within a time unit is 0, determine that the continuous failed transaction volume corresponding to the time unit is 0; If the failed transaction volume of the corrected transaction data within the time unit is not 0, determine the continuous failed transaction volume corresponding to the time unit based on the continuous failed transaction volume corresponding to the previous time unit of the time unit and the failed transaction volume; Obtain the corrected transaction data corresponding to each of the multiple time units within the target sliding window corresponding to the time unit; Based on the obtained multiple corrected transaction data, determine the total transaction volume corresponding to the target sliding window; Based on the total transaction volume corresponding to the target sliding window and the total transaction volume corresponding to the previous sliding window of the target sliding window, determine the negative fluctuation value corresponding to the time unit; Divide the first time period according to regular time slices to obtain multiple regular time periods; Respectively input the multiple continuous failed transaction volumes and multiple negative fluctuation values corresponding to each regular time period into an integrated learning model to obtain the monitoring rules corresponding to each regular time period.

2. The method according to claim 1, characterized in that, The respectively correcting the original transaction data corresponding to each of the multiple time units to obtain the corrected transaction data corresponding to each of the multiple time units includes: For each of the multiple time units, respectively perform the following steps: Based on the business type, correct the original transaction data corresponding to a time unit to obtain corrected transaction data.

3. The method according to claim 1, characterized in that, The following method is used to determine the target sliding window corresponding to the time unit, including: Determine a target window category time period matching the time unit from multiple window category time periods, and obtain the sliding window length corresponding to the target window category time period. The multiple window category time periods are obtained by dividing a second time period according to a preset rule, where each window category time period corresponds to a sliding window length; Based on the end time point of the time unit and the sliding window length, determine the target sliding window corresponding to the time unit, where the end time point of the time unit is the same as the end time point of the target sliding window.

4. The method according to claim 3, wherein The following method is used to determine the sliding window length corresponding to the target window category time period, including: Obtain the total transaction volume of the second time period, and determine the lower limit value and upper limit value of the sliding window length based on the total transaction volume; Based on the ratio of the transaction volume within the target window category time period to the total transaction volume, determine the transaction ratio corresponding to the target window category time period; Based on the transaction ratio, the lower limit value, and the upper limit value, determine the sliding window length corresponding to the target window category time period.

5. The method according to claim 1, characterized in that, Determining the negative fluctuation value corresponding to one time unit based on the total trading volume corresponding to the target sliding window and the total trading volume corresponding to the previous sliding window of the target sliding window includes: Taking the difference between the total trading volume corresponding to the previous sliding window and the total trading volume corresponding to the target sliding window as the trading growth volume corresponding to the target sliding window; Taking the ratio of the trading growth volume corresponding to the target sliding window to the total trading volume corresponding to the target sliding window as the negative fluctuation value corresponding to one time unit.

6. The method according to claim 1, wherein Respectively inputting the multiple consecutive failed trading volumes and multiple negative fluctuation values corresponding to each rule time period into the integrated learning model to obtain the monitoring rules corresponding to each rule time period respectively, includes: For the multiple rule time periods, respectively perform the following steps: Inputting the multiple consecutive failed trading volumes corresponding to one rule time period into the integrated learning model to obtain multiple first monitoring thresholds; Taking the maximum monitoring threshold among the multiple first monitoring thresholds as the cumulative index monitoring threshold corresponding to the multiple consecutive failed trading volumes in the one rule time period; Inputting the multiple negative fluctuation values corresponding to one rule time period into the integrated learning model to obtain multiple second monitoring thresholds; Taking the maximum monitoring threshold among the multiple second monitoring thresholds as the mean index monitoring threshold corresponding to the multiple negative fluctuation values in the one rule time period; Taking the obtained cumulative index monitoring threshold and mean index monitoring threshold as the monitoring rules corresponding to the one rule time period.

7. The method according to claim 6, wherein The integrated learning model includes multiple sub - learning models; The inputting the multiple consecutive failed trading volumes corresponding to one rule time period into the integrated learning model to obtain multiple first monitoring thresholds includes: Respectively inputting the multiple consecutive failed trading volumes corresponding to one rule time period into the multiple sub - learning models to obtain the first monitoring thresholds output by the multiple sub - learning models respectively; The inputting the multiple negative fluctuation values corresponding to one rule time period into the integrated learning model to obtain multiple second monitoring thresholds includes: Respectively inputting the multiple negative fluctuation values corresponding to one rule time period into the multiple sub - learning models to obtain the second monitoring thresholds output by the multiple sub - learning models respectively.

8. An apparatus for generating monitoring rules, characterized in that, Includes: A correction module, configured to divide the first time period into multiple time units, and respectively correct the original transaction data corresponding to the multiple time units to obtain the corrected transaction data corresponding to the multiple time units; A calculation module is configured to perform the following steps respectively for the multiple time units: if the number of failed transaction volumes of the corrected transaction data within a time unit is 0, determine that the continuous failed transaction volume corresponding to the time unit is 0; if the number of failed transaction volumes of the corrected transaction data within the time unit is not 0, determine the continuous failed transaction volume corresponding to the time unit based on the continuous failed transaction volume corresponding to the previous time unit of the time unit and the failed transaction volume; obtain the corrected transaction data corresponding to each of the multiple time units within the target sliding window corresponding to the time unit; determine the total transaction volume corresponding to the target sliding window based on the obtained multiple corrected transaction data. Determine the negative fluctuation value corresponding to the time unit based on the total transaction volume corresponding to the target sliding window and the total transaction volume corresponding to the previous sliding window of the target sliding window. A division module is configured to divide the first time period according to regular time slices to obtain multiple regular time periods. A rule acquisition module is configured to input the multiple continuous failed transaction volumes and multiple negative fluctuation values corresponding to each regular time period into an ensemble learning model respectively to obtain the monitoring rules corresponding to each regular time period.

9. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, It stores a computer program executable by a computer device. When the program runs on the computer device, the computer device is caused to execute the steps of the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • A data monitoring method and device

    CN106991145A

  • Risk assessment method and device for target transaction

    CN110414845A