Thread running state classification method and apparatus, computer device, and storage medium
By using hook techniques and conditional random field model training, thread states are automatically labeled and classified, solving the problem of low efficiency in thread running state classification and achieving efficient thread state recognition.
Patent Information
- Application Number
- CN202210592085.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-27
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2042-05-27
AI Technical Summary
Current technologies for classifying thread running states are inefficient and lack effective automation methods, forcing programmers to rely on manual analysis, which is inefficient.
Hook technology is used to label the sample thread data by type, and automatic thread state classification is achieved through conditional random field model training and vector transformation.
While ensuring the accuracy of annotation, it greatly reduces data annotation time, improves data annotation efficiency, and achieves efficient and automated classification of thread running states.
Smart Images

Figure CN114968719B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, and in particular to a thread running state classification method and device, computer equipment and a storage medium. BACKGROUND
[0002] A thread is the smallest unit of operation that can be scheduled by an operating system, representing an execution sequence of a task, and is mainly used to compete for CPU resources in the operating system. In the software of the operating system, a case of CPU resource utilization can be simply divided into CPU-intensive and non-CPU-intensive. CPU-intensive mainly indicates that the thread is using the CPU to perform a large amount of operation, or is performing code control and execution. Non-CPU-intensive indicates that the current thread running and code control and execution account for a small proportion, and the thread may temporarily give up the competition for CPU resources, and is actually not executed and is in a suspended state, for example, is performing file reading and writing, network receiving and sending, etc.
[0003] If each thread running in the software is sampled at a certain time interval, and is distinguished according to the current execution type, a type sequence of the thread execution task can be obtained, and a profile of the software running task can be easily obtained, and then the performance of the software can be adjusted. First, because starting a thread to execute a task needs to occupy certain CPU and memory resources, it is necessary to reduce the number of started threads as much as possible, and reuse the threads to execute different tasks. A certain task is used to execute tasks of similar types to reduce the creation of threads. Then, because the current CPU is multi-core, for tasks that are more CPU-intensive, the number of threads that can be simultaneously run can be determined according to the number of CPU cores to improve the running efficiency. Further, by analyzing the type sequence of each thread executing a task, abnormal analysis can also be performed, such as monitoring the abnormal time consumption of a real-time task, and unreasonable lock waiting, etc.
[0004] At present, due to the complexity of thread running tasks, there is no good method to classify and mark the current execution state of the thread. The programmer generally relies on manual means to analyze the code and check the thread running situation for the above-mentioned tuning and monitoring, and the efficiency is very low. Therefore, the traditional thread running state classification method has the problem of extremely low efficiency. SUMMARY
[0005] The purpose of the embodiments of the present application is to provide a thread running state classification method, device, computer equipment and storage medium to solve the problem of extremely low efficiency of the traditional thread running state classification method.
[0006] In order to solve the above technical problems, the embodiments of the present application provide a thread running state classification method, which adopts the following technical scheme:
[0007] acquire sample thread data, wherein the sample thread data comprises sample stack data;
[0008] perform type annotation on the sample stack data according to a preset hook technology to obtain annotated stack data carrying type information;
[0009] perform vector conversion on the annotated stack data to obtain annotated stack vectors;
[0010] use the annotated stack vectors and type information corresponding to the annotated stack vectors as model training data;
[0011] perform model training on an initial conditional random field model according to the model training data to obtain a target conditional random field model;
[0012] when a thread to be classified is acquired, input the thread to be classified into the target conditional random field model to perform type identification, and obtain a classification result corresponding to the thread to be classified;
[0013] output the classification result.
[0014] To solve the above technical problems, the embodiment of the application further provides a thread running state classification device, which adopts the following technical scheme:
[0015] a sample acquisition module configured to acquire sample thread data, wherein the sample thread data comprises sample stack data;
[0016] a type annotation module configured to perform type annotation on the sample stack data according to a preset hook technology to obtain annotated stack data carrying type information;
[0017] a vector conversion module configured to perform vector conversion on the annotated stack data to obtain annotated stack vectors;
[0018] a training data acquisition module configured to use the annotated stack vectors and type information corresponding to the annotated stack vectors as model training data;
[0019] a model training module configured to perform model training on an initial conditional random field model according to the model training data to obtain a target conditional random field model;
[0020] a model application module configured to, when a thread to be classified is acquired, input the thread to be classified into the target conditional random field model to perform type identification, and obtain a classification result corresponding to the thread to be classified;
[0021] a result output module configured to output the classification result.
[0022] To solve the above technical problems, the embodiment of the present application also provides a computer device which adopts the technical scheme as follows:
[0023] The computer device comprises a memory and a processor, the memory stores computer readable instructions, and the processor implements the steps of the thread running state classification method as described above when executing the computer readable instructions.
[0024] To solve the above technical problems, the embodiment of the present application also provides a computer readable storage medium which adopts the technical scheme as follows:
[0025] The computer readable storage medium stores computer readable instructions, and the computer readable instructions implement the steps of the thread running state classification method as described above when executed by a processor.
[0026] The present application provides a thread running state classification method, comprising: obtaining sample thread data, wherein the sample thread data comprises sample stack data; performing type labeling operation on the sample stack data according to a preset hook technology to obtain labeled stack data carrying type information; performing vector conversion operation on the labeled stack data to obtain labeled stack vector; taking the labeled stack vector and the type information corresponding to the labeled stack vector as model training data; performing model training operation on an initial conditional random field model according to the model training data to obtain a target conditional random field model; when a thread to be classified is obtained, inputting the thread to be classified into the target conditional random field model to perform type identification operation to obtain a classification result corresponding to the thread to be classified; and outputting the classification result. Compared with the prior art, the present application performs data interception and type labeling on the stack in the sample thread through the preset hook technology, without labeling all data one by one, greatly reducing the time of data labeling under the premise of ensuring labeling accuracy, effectively improving the efficiency of data labeling, after completing type labeling, performing vector conversion on the labeled stack data labeled with type information to obtain training data for training the model, and training the conditional random field model according to the training data, when the model training is completed, the trained conditional random field model can be called to automatically classify the obtained thread to be classified, greatly improving the efficiency of classifying the thread running state. BRIEF DESCRIPTION OF DRAWINGS
[0027] In order to more clearly illustrate the schemes in the present application, the drawings needed in the description of the embodiments of the present application will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0028] Figure 1 is an exemplary system architecture diagram in which the present application can be applied;
[0029] Figure 2 is a flow chart of an implementation of the thread running state classification method provided by Embodiment One of the present application;
[0030] Figure 3 is a flow chart of a specific implementation of the target conditional random field model acquisition method provided by Embodiment One of the present application;
[0031] Figure 4 is a specific implementation of the CRF model using a linear chain structure provided by Embodiment One of the present application;
[0032] Figure 5 is a flow chart of a specific implementation of step S303 in Figure 3
[0033] Figure 6 is a flow chart of a specific implementation of step S304 in Figure 3
[0034] Figure 7 is a structural schematic diagram of a thread running state classification apparatus provided by Embodiment Two of the present application;
[0035] Figure 8 is a structural schematic diagram of a specific implementation of the target conditional random field model acquisition apparatus provided by Embodiment Two of the present application;
[0036] Figure 9 is a structural schematic diagram of an embodiment of a computer device according to the present application. DETAILED DESCRIPTION
[0037] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs; the terms used in the specification of the present application are only for the purpose of describing specific embodiments of the present application and are not intended to limit the present application; the terms "include" and "have" and any variations thereof in the specification of the present application and claims and the above description of drawings are intended to cover non-exclusive inclusion. The terms "first", "second" and the like in the specification of the present application and claims are used to distinguish different objects, not to describe a particular order.
[0038] Reference to an "embodiment" herein means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the application. The appearances of the phrase that an "embodiment" in various places in the specification are not necessarily all referring to the same embodiment, nor are they necessarily mutually exclusive or alternative embodiments. It is expressly understood that the embodiments described herein are merely example and that a person skilled in the art would readily recognize items described herein in connection with one embodiment can be incorporated into other embodiments.
[0039] For better understanding of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings.
[0040] As shown in Figure 1 The system architecture 100 can include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is a medium for providing a communication link between the terminal devices 101, 102, 103 and the server 105. The network 104 can include various connection types, such as wired, wireless communication links, or optical fiber cables, and the like.
[0041] A user can use the terminal devices 101, 102, 103 to interact with the server 105 through the network 104 to receive or send messages, and the like. Various communication client applications can be installed on the terminal devices 101, 102, 103, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, and the like.
[0042] The terminal devices 101, 102, 103 can be various electronic devices with display screens and supporting web browsing, including but not limited to smart phones, tablet computers, e-book readers, MP3 (Moving Picture Experts Group Audio Layer III) players, MP4 (Moving Picture Experts Group Audio Layer IV) players, laptop computers, desktop computers, and the like.
[0043] The server 105 can be a server providing various services, such as a background server supporting a page displayed on the terminal devices 101, 102, 103.
[0044] It should be noted that the thread running state classification method provided by the embodiments of the present application is generally executed by a server / terminal device, and accordingly, the thread running state classification apparatus is generally provided in a server / terminal device.
[0045] It should be understood that Figure 1The number of terminal devices, networks and servers in the system is only illustrative. According to the implementation needs, there can be any number of terminal devices, networks and servers.
[0046] Embodiment one
[0047] With reference to the foregoing description Figure 2 , a flow chart of the implementation of the thread running state classification method provided by the embodiment one of the present application is shown. For the convenience of illustration, only the parts related to the present application are shown.
[0048] The thread running state classification method described above comprises the following steps: step S201, step S202, step S203, step S204, step S205, step S206 and step S207.
[0049] In step S201, sample thread data is acquired, wherein the sample thread data comprises sample stack data.
[0050] In the embodiment of the present application, the implementation of acquiring sample thread data can be through starting a monitoring thread to sample the stack of the thread running in the software at a fixed time, wherein the stack of the thread can be collected when the software is online running, and saved locally. When a software ends running, the collected thread stack data is reported to the background server for subsequent processing.
[0051] In step S202, type labeling operation is performed on the sample stack data according to the pre-set hook technology, to obtain labeled stack data carrying type information.
[0052] In the embodiment of the present application, for the Windows system, it is based on the event-driven mechanism, in other words, the whole system is realized through message passing. The hook technology is a special message processing mechanism, which can monitor various event messages in the system or process, intercept the messages sent to the target window and process them. Therefore, we can customize the hook in the system to monitor the occurrence of specific events in the system to complete specific functions, such as screen word taking, monitoring log, intercepting keyboard and mouse input, etc. There are many types of hooks, and each hook can intercept corresponding messages, such as keyboard hook can intercept keyboard messages, shell hook can intercept, start and close application messages, etc. Hooks can be divided into thread hooks and system hooks, thread hooks can monitor event messages of specified threads, and system hooks monitor event messages of all threads in the system. Because the system hook will affect all applications in the system, the hook function must be placed in a separate dynamic link library (DLL). Therefore, hook is a Windows message interception mechanism, which can intercept the messages of a single process (thread hook), intercept the messages of all processes (system hook), and also can customize the processing of intercepted messages. Windows messages carry some useful information for programs, such as Mouse class information, which contains information such as mouse window handle, mouse position, etc. Intercepting these messages can enable functions such as screen word taking of Kingsoft WordPanda.
[0053] In the embodiment of the present application, before the type labeling operation is performed, the type of the thread (i.e., the above-mentioned type information) needs to be defined in advance. As an example, the thread can be divided into: calculation type, control type, lock waiting type, file reading and writing type, network receiving and sending type, etc. It should be understood that the examples of types here are only for easy understanding and do not limit the present application.
[0054] In the embodiment of the present application, considering that the reported thread stack data is very large, the workload of labeling the thread stack data one by one is very large and time-consuming, therefore, the hook method is adopted, and the underlying functions of the lock waiting type, the file reading and writing type, and the network receiving and sending type are hooked and replaced with an implementation function of our own. When these functions are encountered, they can be directly considered as the corresponding labeled types. In this way, the labeled data is reduced.
[0055] In step S203, the labeled stack data is subjected to a vector conversion operation to obtain a labeled stack vector.
[0056] In step S204, the labeled stack vector and the type information corresponding to the labeled stack vector are used as model training data.
[0057] In step S205, a model training operation is performed on the initial conditional random field model according to the model training data, to obtain a target conditional random field model.
[0058] In the embodiments of the present application, the conditional random field model (CRF for short) is a kind of undirected graph structure model. In the undirected graph, any fully connected (any two vertices have edges connected) subgraph is called a clique, and cannot be contained by other cliques to become a maximum clique. Under the condition of a given observation sequence, the CRF model can establish a joint probability model of the observation sequence and the label sequence. When establishing the CRF model, the simplest and most commonly used is the linear chain structure.
[0059] In step S206, when the thread to be classified is obtained, the thread to be classified is input to the target conditional random field model to perform a type recognition operation, to obtain a classification result corresponding to the thread to be classified.
[0060] In the embodiments of the present application, after the model training is completed to obtain the target conditional random field model, the trained model can be used to type mark the running thread every certain period of time. A sequence of type marks is obtained.
[0061] In step S207, the classification result is output.
[0062] In the embodiment of the present application, a thread running state classification method is provided, comprising: obtaining sample thread data, wherein the sample thread data comprises sample stack data; performing type labeling operation on the sample stack data according to a preset hook technology to obtain labeled stack data carrying type information; performing vector conversion operation on the labeled stack data to obtain a labeled stack vector; taking the labeled stack vector and the type information corresponding to the labeled stack vector as model training data; performing model training operation on an initial conditional random field model according to the model training data to obtain a target conditional random field model; when a thread to be classified is obtained, inputting the thread to be classified into the target conditional random field model to perform type identification operation to obtain a classification result corresponding to the thread to be classified; and outputting the classification result. Compared with the prior art, the present application performs data interception and type labeling on the stack in the sample thread through the preset hook technology, without labeling all data one by one, greatly reducing the time for data labeling under the premise of ensuring labeling accuracy, effectively improving the efficiency of data labeling, after completing type labeling, performing vector conversion on the labeled stack data labeled with type information to obtain training data for training a model, and training a conditional random field model according to the training data, when the model training is completed, the trained conditional random field model can be called to automatically classify the obtained thread to be classified, greatly improving the efficiency of classifying the thread running state.
[0063] With reference to Figure 3 , a flow chart of a specific implementation of a method for obtaining a target conditional random field model provided by an embodiment of the present application is shown, and only the parts related to the present application are shown for ease of illustration.
[0064] In some optional implementation modes of the present embodiment, before step S205, steps S301 and S302 are further included, and step S205 specifically comprises steps S303 and S304.
[0065] In step S301, the original conditional random field model is called, and the feature weight parameter λ of the original conditional random field model is initialized to obtain an initial conditional random field model.
[0066] In the embodiment of the present application, before training the model, the CRF model needs to be initialized and set first, and the most important thing is to determine the feature weight parameter λ, wherein the initialization of the feature weight parameter λ can be set according to the specific situation, specifically, in order to ensure the stability of the test result, the initial value of the feature weight parameter λ is set to zero in the present application, and the dimension is determined by the number of training samples and the number of states, and after the initialization of the parameter is set, the model training can be continued.
[0067] In step S302, a convergence precision ε for a model training operation is acquired.
[0068] In step S303, the model training data is input to the initial conditional random field model for an iterative operation, and a parameter is calculated according to a quasi-Newton algorithm until the gradient is less than or equal to the convergence precision ε, and the iterative operation is stopped.
[0069] In the embodiment of the present application, for a given input node x i , the CRF model can calculate the conditional probability of a specified output node y i , and i represents the position of the node in the sequence X={x1, x2, x3, …, x t} and Y={y1, y2, y3, …, y t}.
[0070] In the embodiment of the present application, the CRF model uses a linear chain structure, as shown in Figure 4 , the input node set X={x1, x2, x3, …, x t} represents an observable input sequence, and the output node set Y={y1, y2, y3, …, y t} corresponds to the output state predicted by the reputation model, which is not generated by the model, and thus there is no dependency between them and no need to make an independence assumption.
[0071] In step S304, the feature weight parameter λ of the initial conditional random field model after the iterative operation is determined according to a maximum likelihood estimation method, and a target conditional random field model is obtained.
[0072] Referring to Figure 5 , a flowchart of a specific implementation of step S303 in Figure 3 is shown, and only parts related to the present application are shown for ease of illustration.
[0073] In some optional implementations of the embodiment, step S303 specifically includes step S501 and step S502.
[0074] In step S501, a joint probability model corresponding to an observation sequence and a label sequence is established according to the initial conditional random field model, where the observation sequence is the label stack vector, and the label sequence is the type information.
[0075] In step S502, the initial conditional random field model is parameter trained according to the label stack vector, a value of each parameter of the conditional random field model is obtained, and a target conditional random field model corresponding to different type information is established.
[0076] In some optional implementations of the embodiment, the joint probability model is represented as:
[0077]
[0078] where Y * represents the probability that Y tends to satisfy the maximum global condition in the initial conditional random field model (X, Y) given X; λ represents the feature weight parameter; F represents the global feature of the input data sequence X and the label sequence Y in the conditional random field; x and y represent values in the input data sequence X and the label sequence Y, respectively.
[0079] In the embodiment of the application, the global feature of the conditional random field for the input data sequence X and the label sequence Y is represented as:
[0080]
[0081] where x and y are values in the input data sequence X and the label sequence Y, respectively, i traverses all positions in the input sequence, and f(y, x, i) represents a feature vector composed of various features at the i position.
[0082] In the embodiment of the application, according to the random field basic theorem, if Figure 4 the label sequence Y = {y1, y2, …, yt} is a tree structure (linear chain is a special case of the tree structure), then given the observed sequence X = {x1, x2, …, xt}, the conditional probability of the label sequence Y is as follows:
[0083] F λ (Y|X)∝exp[λ·F(Y,X)]
[0084] where F λ (Y|X) represents the global conditional probability after introducing the feature weight parameter λ; λ represents the feature weight parameter that needs to be estimated and can be estimated from the training sample data; a large, non-negative λ parameter value means that the corresponding feature event is preferentially selected, and a negative value corresponds to a feature event that is less likely to occur.
[0085] In the embodiment of the application, under the condition that the observed sequence X is given, the normalization factor Z λ (x) is introduced, and the conditional probability of the label sequence Y can be obtained as:
[0086]
[0087] In the embodiment of the application, the normalization factor Z λ (x) can be represented as:
[0088]
[0089] In the embodiments of this application, the model inference of chained CRF refers to finding the most likely label sequence Y = {y1,y2,…,yt} corresponding to an observation sequence X = {x1,x2,…,xt}.
[0090] In this embodiment of the application, F is established using CRF. λ When looking at the probability model of (Y|X), we need to find F. λ Maximize (Y|X), and label y that satisfies this condition. * That is, the best label, where Z λ (x) and y are uncorrelated, therefore y * It can be represented as:
[0091]
[0092] In this embodiment, the optimal label y can be determined using dynamic programming algorithms such as Viterbi. * .
[0093] In this embodiment, estimating the feature weight parameters λ = (λ1, λ2...λt) is an important aspect of CRF modeling. Currently, there are two main methods for parameter estimation: maximum likelihood estimation and Bayesian estimation. Maximum likelihood estimation is generally more common, and this invention employs maximum likelihood estimation for the solution.
[0094] In this embodiment of the application, given a complete marked wear training set {x} i ,y i Given i = 1, 2, ..., t, the feature weight parameter λ can be obtained by optimizing the conditional log-likelihood of the training set.
[0095] Continue reading Figure 6 , showed Figure 3 The flowchart of a specific embodiment of step S304 is shown. For ease of explanation, only the parts relevant to this application are shown.
[0096] In some optional implementations of this embodiment, step S304 specifically includes: step S601.
[0097] In step S601, the feature weight parameter λ is differentiated according to the derivative formula to obtain the feature weight parameter λ of the initial conditional random field model after the iterative operation, wherein the derivative formula is expressed as:
[0098]
[0099] where x and y represent values in the input data sequence X and the label sequence Y respectively; i traverses all positions in the input sequence; F (Y, x i ) represents global features of the conditional random field for the input data sequence X and the label sequence Y; and P (Y|X) represents a global conditional probability.
[0100] In the embodiment of the present application, the given training data sample set is and the samples are independent of each other. The task of the log-likelihood estimation is to estimate λi (i represents a position in the λ sequence) from the independent training data, so as to obtain the value of the feature weight parameter λ.
[0101] In the embodiment of the present application, the likelihood function of the conditional probability F λ (Y|X) is:
[0102]
[0103] where x i represents a value at the i position in the input data sequence X; and y i represents a value at the i position in the label sequence Y.
[0104] In the embodiment of the present application, L (λ) can be regarded as a function of λ, and the task of the maximum likelihood estimation is to obtain that satisfies:
[0105]
[0106] where λ represents the final feature weight parameter value.
[0107] In the embodiment of the present application, according to the above derivation, the derivative of the parameter λ is zero at the maximum point, and the derivative formula is: The derivative of the parameter λ is zero at the maximum point, and the derivative formula is:
[0108]
[0109] where x and y represent values in the input data sequence X and the label sequence Y respectively; i traverses all positions in the input sequence; F (Y, x i ) represents global features of the conditional random field for the input data sequence X and the label sequence Y; and P (Y|X) represents a global conditional probability.
[0110] In the embodiment of the present application, the mathematical expectation can be quickly calculated by a variant of the forward-backward algorithm.
[0111] It is emphasized that, in order to further ensure the privacy and security of the above classification result, the above classification result can also be stored in a node of a block chain.
[0112] The blockchain referred to in the present application is a new application mode of distributed data storage, peer-to-peer transmission, consensus mechanism, encryption algorithm and other computer technologies. The blockchain is essentially a decentralized database, which is a series of data blocks associated using cryptographic methods, each data block containing information of a batch of network transactions, for verifying the validity (anti-fake) of the information and generating the next block. The blockchain can include a blockchain underlying platform, a platform product service layer, and an application service layer, etc.
[0113] The present application can be used in a variety of general-purpose or special-purpose computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments that include any of the above systems or devices, etc. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in a distributed computing environment, in which tasks are performed by remote processing devices connected by a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media, including storage devices.
[0114] Those of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiments can be completed by computer-readable instructions instructing relevant hardware, and the computer-readable instructions can be stored in a computer-readable storage medium. When the computer-readable instructions are executed, they can include the processes of the above-mentioned embodiments. The storage medium can be a non-volatile storage medium such as a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).
[0115] It should be understood that although each step in the flowchart of the accompanying drawings is shown in sequence according to the direction of the arrow, these steps are not necessarily executed in sequence according to the direction of the arrow. Unless explicitly stated herein, the execution of these steps is not strictly limited in sequence, and they can be executed in other sequences. Moreover, at least part of the steps in the flowchart of the accompanying drawings can include multiple sub-steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence is not necessarily sequential, but can be alternately executed with at least part of other steps or sub-steps or stages of other steps.
[0116] Embodiment Two
[0117] Further reference Figure 7 , as an implementation of the method shown above Figure 2 , the application provides an embodiment of a thread running state classification device, which corresponds to the method embodiment shown in Figure 2 , and the device can be specifically applied to various electronic devices.
[0118] As shown in Figure 7 , the thread running state classification device 200 described in the embodiment includes a sample acquisition module 210, a type labeling module 220, a vector conversion module 230, a training data acquisition module 240, a model training module 250, a model application module 260, and a result output module 270. Among them:
[0119] The sample acquisition module 210 is configured to acquire sample thread data, wherein the sample thread data includes sample stack data;
[0120] The type labeling module 220 is configured to perform type labeling on the sample stack data according to a pre-set hook technology, to obtain labeled stack data carrying type information;
[0121] The vector conversion module 230 is configured to perform vector conversion on the labeled stack data, to obtain a labeled stack vector;
[0122] The training data acquisition module 240 is configured to take the labeled stack vector and type information corresponding to the labeled stack vector as model training data;
[0123] The model training module 250 is configured to perform model training on an initial conditional random field model according to the model training data, to obtain a target conditional random field model;
[0124] The model application module 260 is configured to, when a thread to be classified is acquired, input the thread to be classified into the target conditional random field model to perform type identification, to obtain a classification result corresponding to the thread to be classified;
[0125] The result output module 270 is configured to output the classification result.
[0126] In the embodiment of the present application, the implementation manner of acquiring the thread data of the sample can be that a monitoring thread is started to sample the stack of the thread running in the software at a time interval. In this way, the stack of the thread can be collected when the software is running online, and saved locally. When a software ends running, the collected thread stack data is reported to the background server for subsequent processing.
[0127] In the embodiment of the present application, for the Windows system, it is built on the event-driven mechanism, which means that the whole system is realized by message passing. The hook technology is a special message processing mechanism, which can monitor various event messages in the system or process, intercept the messages sent to the target window and process them. Therefore, we can customize the hook in the system to monitor the occurrence of specific events in the system and complete specific functions, such as screen word taking, monitoring logs, intercepting keyboard and mouse inputs, etc. There are many types of hooks, and each hook can intercept corresponding messages. For example, the keyboard hook can intercept keyboard messages, the shell hook can intercept, start and close application messages, etc. Hooks can be divided into thread hooks and system hooks. The thread hook can monitor the event messages of a specified thread, and the system hook monitors the event messages of all threads in the system. Because the system hook affects all applications in the system, the hook function must be placed in a separate dynamic link library (DLL). Therefore, the hook is a message interception mechanism of Windows, which can intercept the messages of a single process (thread hook) or all processes (system hook), and can also perform custom processing on the intercepted messages. Windows messages carry some useful information for programs, such as Mouse class information, which carries information such as the handle of the window where the mouse is located and the position of the mouse. By intercepting these messages, functions such as screen word taking of Kingsoft Wudaba can be realized.
[0128] In the embodiment of the present application, before the type labeling operation is performed, the type of the thread (i.e., the type information) needs to be defined in advance. As an example, the thread can be divided into: calculation type, control type, lock waiting type, file reading and writing type, network receiving and sending type, etc. It should be understood that the examples of types herein are only for convenience of understanding and do not limit the present application.
[0129] In the embodiment of the present application, considering that the reported thread stack data is very large, the workload of marking the thread stack data one by one is very large and very time-consuming, therefore, the hook means is adopted, the underlying functions such as lock waiting type, file reading and writing type, network receiving and sending type are hooked and replaced by an implementation function of our own. When these functions are encountered, it can be directly considered as the corresponding marking type. In this way, the marked data is reduced.
[0130] In the embodiment of the present application, after the target conditional random field model is obtained through model training, the trained model can be used to mark the type of the running thread every certain period of time. A sequence of type marking is obtained.
[0131] In the embodiment of the present application, a thread running state classification device 200 is provided, comprising: a sample acquisition module 210, configured to acquire sample thread data, wherein the sample thread data comprises sample stack data; a type marking module 220, configured to perform type marking operation on the sample stack data according to a preset hook technology, to obtain marked stack data carrying type information; a vector conversion module 230, configured to perform vector conversion operation on the marked stack data, to obtain a marked stack vector; a training data acquisition module 240, configured to take the marked stack vector and the type information corresponding to the marked stack vector as model training data; a model training module 250, configured to perform model training operation on an initial conditional random field model according to the model training data, to obtain a target conditional random field model; a model application module 260, configured to input a to-be-classified thread into the target conditional random field model to perform type recognition operation when the to-be-classified thread is acquired, to obtain a classification result corresponding to the to-be-classified thread; and a result output module 270, configured to output the classification result. Compared with the prior art, the present application performs data interception and type marking on the stack in the sample thread through the preset hook technology, without marking all data one by one, greatly reduces the time for data marking under the premise of ensuring the accuracy of marking, effectively improves the efficiency of data marking, after completing the type marking, performs vector conversion on the marked stack data carrying type information, to obtain training data for training the model, and trains the conditional random field model according to the training data, after completing the model training, the trained conditional random field model can be called to automatically classify the acquired to-be-classified thread, greatly improving the efficiency of classifying the thread running state.
[0132] With reference to Figure 8 , a structure schematic diagram of a specific implementation manner of the target conditional random field model acquisition device provided in the embodiment two of the present application is shown, only the parts related to the present application are shown for the convenience of description.
[0133] In some optional implementations of the embodiment, the thread running state classification apparatus 200 further comprises the initialization module 280 and the precision obtaining module 290, and the model training module 250 comprises an iteration operator module 251 and a parameter determination sub-module 252, wherein:
[0134] The initialization module 280 is configured to call an original conditional random field model, and initialize a feature weight parameter λ of the original conditional random field model to obtain the initial conditional random field model.
[0135] The precision obtaining module 290 is configured to obtain a convergence precision ε used for the model training operation.
[0136] The iteration operator module 251 is configured to input the model training data into the initial conditional random field model to perform an iteration operation, and calculate a parameter according to a quasi-Newton algorithm until a gradient is less than or equal to the convergence precision ε, and then stop the iteration operation.
[0137] The parameter determination sub-module 252 is configured to determine the feature weight parameter λ of the initial conditional random field model after the iteration operation according to a maximum likelihood estimation method to obtain the target conditional random field model.
[0138] In the embodiment of the application, before training the model, the CRF model needs to be initialized and set first, and the most important thing is to determine the feature weight parameter λ. The initialization of the feature weight parameter λ can be set according to specific conditions. Specifically, in order to ensure the stability of the test result, the initial value of the feature weight parameter λ is set to zero in the application, and the dimension is determined by the number of training samples and the number of states. After the parameter is initialized and set, the model training can be continued.
[0139] In the embodiment of the application, for a given input node x i , the CRF model can calculate the conditional probability of a specified output node y i , and i represents the position of the node in the sequence X={x1,x2,x3,…,x t} and Y={y1,y2,y3,…,y t}.
[0140] In the embodiment of the application, the CRF model uses a linear chain structure, as shown in Figure 4 , the input node set X={x1,x2,x3,…,x t} represents an observable input sequence, and the output node set Y={y1,y2,y3,…,y tCorresponding to the output state predicted by the reputation model, they are not generated by the model, so there is no dependency between them, and no independence assumption is needed.
[0141] In some optional implementations of the embodiment, the iteration operator module 251 includes a first iteration operation unit and a second iteration operation unit, wherein:
[0142] The first iteration operation unit is configured to establish a joint probability model corresponding to an observation sequence and a label sequence according to the initial conditional random field model, wherein the observation sequence is the label stack vector, and the label sequence is the type information.
[0143] The second iteration operation unit is configured to perform parameter training on the initial conditional random field model according to the label stack vector, to obtain values of parameters of the conditional random field model, thereby establishing a target conditional random field model corresponding to different type information.
[0144] In some optional implementations of the embodiment, the joint probability model is represented as:
[0145]
[0146] wherein Y * represents a probability that Y tends to satisfy the maximum global condition in the initial conditional random field model (X, Y) with X as the condition; λ represents the feature weight parameter; F represents the global feature of the input data sequence X and the label sequence Y in the conditional random field; x and y respectively represent values in the input data sequence X and the label sequence Y.
[0147] In the embodiment of the application, for the input data sequence X and the label sequence Y, the global feature of the conditional random field is represented as:
[0148]
[0149] wherein x and y are values in the input data sequence X and the label sequence Y, i traverses all positions in the input sequence, and f(y, x, i) represents a feature vector composed of various features at the i position.
[0150] In the embodiment of the application, according to the basic theorem of the random field, if Figure 4 the label sequence Y = {y1, y2, …, yt} in the formula is a tree structure (linear chain is a special case of tree structure), then given the observation sequence X = {x1, x2, …, xt}, the conditional probability of the label sequence Y is as follows:
[0151] F λ (Y|X)∝exp[λ·F(Y,X)]
[0152] where F λ (Y|X) represents the global conditional probability after introducing the feature weight parameter λ; λ represents a feature weight parameter to be estimated, which can be estimated from training sample data; a large, non-negative λ parameter value means that the corresponding feature event is preferentially selected, and a negative value corresponds to a feature event that is less likely to occur.
[0153] In the embodiment of the present application, under the condition of a given observation sequence X, a normalization factor Z λ (x) is introduced, and the conditional probability of the label sequence Y can be obtained as:
[0154]
[0155] In the embodiment of the present application, the normalization factor Z λ (x) can be expressed as:
[0156]
[0157] In the embodiment of the present application, the model inference of the chain CRF refers to finding a most likely label sequence Y = {y1, y2,..., yt} corresponding to an observation sequence X = {x1, x2,..., xt} under the condition of the given X.
[0158] In the embodiment of the present application, when the probability model of F λ (Y|X) is established by using the CRF, the maximization of F λ (Y|X) is sought, and the label y * that satisfies this condition is the best label, where Z λ (x) is irrelevant to y, and thus y * can be expressed as:
[0159]
[0160] In the embodiment of the present application, the best label y * can be obtained by using dynamic programming algorithms such as Viterbi.
[0161] In the embodiment of the present application, the estimation of the feature weight parameter λ = (λ1, λ2,..., λt) is an important work of the CRF model, and currently there are two main parameter estimation methods: maximum likelihood estimation and Bayesian estimation. Generally, the maximum likelihood estimation is more common, and the present application adopts the maximum likelihood estimation for solution.
[0162] In the embodiment of the present application, under the condition of a given complete label wear training set {x i , y iUnder the condition of i = 1, 2...t, the feature weight parameter λ can be solved by optimizing the conditional log-likelihood of the training set.
[0163] In some optional implementation of the embodiment, the parameter determination sub-module 252 comprises a derivation unit, wherein:
[0164] The derivation unit is configured to perform derivation operation on the feature weight parameter λ according to a derivative formula to obtain the feature weight parameter λ of the initial conditional random field model after the iterative operation, and the derivative formula is represented as:
[0165]
[0166] Wherein, x and y represent values in the input data sequence X and the label sequence Y respectively; i traverses all positions in the input sequence; F(Y, x i represents the global feature of the conditional random field for the input data sequence X and the label sequence Y; and P(Y|X) represents the global conditional probability.
[0167] In the embodiment of the present application, the given training data sample set is and the samples are independent of each other. The task of log-likelihood estimation is to estimate λi (i represents the position in the λ sequence) from the independent training data, so as to obtain the value of the feature weight parameter λ.
[0168] In the embodiment of the present application, the likelihood function of the conditional probability F λ (Y|X) is:
[0169]
[0170] Wherein, x i represents the value at the i position in the input data sequence X; and y i represents the value at the i position in the label sequence Y.
[0171] In the embodiment of the present application, L(λ) can be regarded as a function of λ, and the task of maximum likelihood estimation is to obtain satisfying:
[0172]
[0173] Wherein, represents the final feature weight parameter value.
[0174] In the embodiment of the present application, according to the above derivation, The point where the derivative of the parameter λ is zero is the maximum point, and the derivative formula is:
[0175]
[0176] where x and y represent values in the input data sequence X and the label sequence Y, respectively; i traverses all positions in the input sequence; F(Y, x i ) represents global features of the conditional random field for the input data sequence X and the label sequence Y; and P(Y|X) represents a global conditional probability.
[0177] In the embodiments of the present application, the mathematical expectation can be quickly calculated by a variant of the forward-backward algorithm.
[0178] To solve the above technical problems, the embodiments of the present application further provide a computer device. For details, please refer to Figure 9 , Figure 9 which is a basic structure block diagram of the computer device in the embodiments.
[0179] The computer device 300 comprises a memory 310, a processor 320, and a network interface 330 which are connected to each other through a system bus. It should be noted that only the computer device 300 with components 310-330 is shown in the figure, but it should be understood that all the shown components are not required to be implemented, and more or fewer components can be alternatively implemented. Among them, those skilled in the art can understand that the computer device herein is a device capable of automatically performing numerical calculation and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.
[0180] The computer device can be a desktop computer, a notebook computer, a palm computer, a cloud server, and other computing devices. The computer device can interact with the user through a keyboard, a mouse, a remote controller, a touchpad, a voice control device, and other ways.
[0181] The memory 310 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 310 can be an internal storage unit of the computer device 300, such as a hard disk or a memory of the computer device 300. In other embodiments, the memory 310 can also be an external storage device of the computer device 300, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device 300. Of course, the memory 310 can also include both an internal storage unit and an external storage device of the computer device 300. In this embodiment, the memory 310 is generally used to store an operating system and various application software installed on the computer device 300, such as computer readable instructions of the thread running state classification method, etc. In addition, the memory 310 can also be used to temporarily store various data that has been output or will be output.
[0182] The processor 320 can be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip in some embodiments. The processor 320 is generally used to control the overall operation of the computer device 300. In this embodiment, the processor 320 is used to run computer readable instructions or process data stored in the memory 310, such as computer readable instructions of the thread running state classification method.
[0183] The network interface 330 can include a wireless network interface or a wired network interface, and is generally used to establish a communication connection between the computer device 300 and other electronic devices.
[0184] The computer device provided in the application performs data interception and type information labeling on the stack in the sample thread through the preset hook technology, does not need to label all data one by one, greatly reduces the data labeling time under the premise of ensuring the labeling accuracy, effectively improves the data labeling efficiency, converts the labeled stack data with type information into a vector after completing the type labeling, obtains training data for training a model, trains a conditional random field model according to the training data, and after completing the model training, can call the trained conditional random field model to automatically classify the obtained threads to be classified, and greatly improves the efficiency of classifying the thread running state.
[0185] The application further provides another implementation, namely providing a computer readable storage medium, the computer readable storage medium stores computer readable instructions, the computer readable instructions can be executed by at least one processor, so that the at least one processor executes the steps of the thread running state classification method as described above.
[0186] The computer readable storage medium provided in the application performs data interception and type information labeling on the stack in the sample thread through the preset hook technology, does not need to label all data one by one, greatly reduces the data labeling time under the premise of ensuring the labeling accuracy, effectively improves the data labeling efficiency, converts the labeled stack data with type information into a vector after completing the type labeling, obtains training data for training a model, trains a conditional random field model according to the training data, and after completing the model training, can call the trained conditional random field model to automatically classify the obtained threads to be classified, and greatly improves the efficiency of classifying the thread running state.
[0187] Through the description of the above implementation, those skilled in the art can clearly understand that the above-mentioned example method can be realized by means of software and necessary general hardware platform, of course, it can also be realized by hardware, but in many cases, the former is a better implementation. Based on such understanding, the technical solutions of the application can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disc, optical disc), and includes a plurality of instructions for making a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device) execute the method described in each embodiment of the application.
[0188] Obviously, the above-described embodiments are only some embodiments but not all the embodiments of the present application, the preferred embodiments of the present application are shown in the drawings, but do not limit the patent scope of the present application. The present application can be implemented in many different forms, and conversely, the purpose of providing these embodiments is to make the disclosure of the present application more thorough and comprehensive. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or make equivalent replacements to some technical features therein. Any equivalent structure made by using the content of the specification and drawings, directly or indirectly applied to other related technical fields, is also within the patent protection scope of the present application.
Claims
1. A method of classifying thread run states, characterized by, The method comprises the following steps: acquiring sample thread data, wherein the sample thread data comprises sample stack data; performing type labeling on the sample stack data according to a preset hook technology to obtain labeled stack data carrying type information; performing vector conversion on the labeled stack data to obtain a labeled stack vector; taking the labeled stack vector and type information corresponding to the labeled stack vector as model training data; performing model training on an initial conditional random field model according to the model training data to obtain a target conditional random field model; when a thread to be classified is acquired, inputting the thread to be classified into the target conditional random field model to perform type recognition to obtain a classification result corresponding to the thread to be classified; and outputting the classification result.
2. The thread running state classification method according to claim 1, characterized by, Before the step of performing model training on an initial conditional random field model according to the model training data to obtain a target conditional random field model, the method further comprises the following steps: calling an original conditional random field model and initializing feature weight parameters λ of the original conditional random field model to obtain the initial conditional random field model; acquiring a convergence precision ε used for the model training operation; the step of performing model training on an initial conditional random field model according to the model training data to obtain a target conditional random field model specifically comprises the following steps: inputting the model training data into the initial conditional random field model to perform iterative operation and calculating parameters according to a quasi-Newton algorithm until the gradient is less than or equal to the convergence precision ε, and stopping the iterative operation; determining the feature weight parameters λ of the initial conditional random field model after the iterative operation according to a maximum likelihood estimation method to obtain the target conditional random field model.
3. The thread run state classification method of claim 2, wherein, the step of inputting the model training data into the initial conditional random field model to perform iterative operation and calculating parameters according to a quasi-Newton algorithm until the gradient is less than or equal to the convergence precision ε, and stopping the iterative operation specifically comprises the following steps: establishing a joint probability model corresponding to an observation sequence and a label sequence according to the initial conditional random field model, wherein the observation sequence is the labeled stack vector and the label sequence is the type information; performing parameter training on the initial conditional random field model according to the labeled stack vector to obtain values of parameters of the conditional random field model, thereby establishing a target conditional random field model corresponding to different type information.
4. The thread run state classification method of claim 3, wherein, the joint probability model is expressed as: wherein y * represents the probability that y tends to satisfy the maximum global condition in the initial conditional random field model (X, Y) with X as the condition; λ represents the feature weight parameter; F represents the global feature of the input data sequence X and the label sequence Y in the conditional random field; and x and y represent the values in the input data sequence X and the label sequence Y, respectively.
5. The thread run state classification method of claim 2, wherein, the step of determining the feature weight parameters λ of the initial conditional random field model after the iterative operation according to a maximum likelihood estimation method to obtain the target conditional random field model specifically comprises the following steps: performing derivation on the feature weight parameters λ according to a derivative formula to obtain the feature weight parameters λ of the initial conditional random field model after the iterative operation, wherein the derivative formula is expressed as: where x and y represent values in the input data sequence X and the label sequence Y, respectively; i iterates over all positions in the input sequence; F(Y, x i ) represents global features of the conditional random field for the input data sequence X and the label sequence Y; and P(Y|X) represents the global conditional probability.
6. The thread run state classification method of claim 1, wherein, After the step of inputting the thread to be classified into the target conditional random field model for type identification operation to obtain a classification result corresponding to the thread to be classified when the thread to be classified is acquired, the method further comprises the following steps: The classification result is stored in a blockchain.
7. A thread state classification apparatus characterized by comprising: The method comprises: a sample acquisition module configured to acquire sample thread data, wherein the sample thread data comprises sample stack data; a type labeling module configured to perform type labeling operation on the sample stack data according to a preset hook technology to obtain labeled stack data carrying type information; a vector conversion module configured to perform vector conversion operation on the labeled stack data to obtain labeled stack vectors; a training data acquisition module configured to use the labeled stack vectors and type information corresponding to the labeled stack vectors as model training data; a model training module configured to perform model training operation on an initial conditional random field model according to the model training data to obtain a target conditional random field model; a model application module configured to input a thread to be classified into the target conditional random field model for type identification operation to obtain a classification result corresponding to the thread to be classified when the thread to be classified is acquired; a result output module configured to output the classification result.
8. The thread state classification apparatus according to claim 7, wherein The device further comprises an initialization module and a precision acquisition module, and the model training module comprises an iteration operator module and a parameter determination submodule, wherein: the initialization module is configured to call an original conditional random field model, initialize feature weight parameters λ of the original conditional random field model, and obtain the initial conditional random field model; the precision acquisition module is configured to acquire convergence precision ε used for the model training operation; the iteration operator module is configured to input the model training data into the initial conditional random field model for iteration operation, and calculate parameters according to a quasi-Newton algorithm until the gradient is less than or equal to the convergence precision ε, and then stop the iteration operation; the parameter determination submodule is configured to determine the feature weight parameters λ of the initial conditional random field model after the iteration operation according to a maximum likelihood estimation method to obtain the target conditional random field model.
9. A computer device, comprising: The computer readable storage medium stores computer readable instructions, and the computer readable instructions are executed by the processor to realize the steps of the thread running state classification method according to any one of claims 1 to 6.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer readable instructions, and the computer readable instructions are executed by the processor to realize the steps of the thread running state classification method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Task statistics method and device
CN108681805A
Identifying message thread state
US20210241134A1