Anomaly detection method and apparatus

CN115185760BActive Publication Date: 2026-09-25ALIBABA INNOVATION PRIVATE LIMITED
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110355366.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-04-01
Publication Date
2026-09-25
Estimated Expiration
2041-04-01

AI Technical Summary

Technical Problem

由于实际应用场景的差异性大,无法为各监控指标定义较为准确的指标阈值,因此,通过该阈值进行异常监控,容易产生漏报或误报等问题,因此,亟需一种有效的异常检测方法以解决此类问题

Benefits of technology

[0051]本说明书一个实施例通过获取待检测时间区间内待检测对象的日志文件列表以及系统状态数据,根据所述日志文件列表中至少两个业务类别的日志数据生成日志状态分布序列,并根据所述系统状态数据与检测点的对应关系生成系统状态分布序列,将所述日志状态分布序列以及所述系统状态分布序列输入异常检测模型进行异常值打分,生成所述至少两个业务类别及系统状态对应的异常分值,根据所述异常分值、所述至少两个业务类别及所述系统状态分别对应的权重确定所述待检测对象的异常检测结果。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115185760B_ABST
    Figure CN115185760B_ABST
Patent Text Reader

Abstract

Embodiments of the present specification provide an anomaly detection method and device, wherein the anomaly detection method comprises: obtaining a log file list and system state data of a to-be-detected object in a to-be-detected time interval, generating a log state distribution sequence according to log data of at least two business categories in the log file list, and generating a system state distribution sequence according to a correspondence between the system state data and a detection point, inputting the log state distribution sequence and the system state distribution sequence into an anomaly detection model to perform anomaly value scoring, generating anomaly scores corresponding to the at least two business categories and the system state, and determining an anomaly detection result of the to-be-detected object according to weights corresponding to the anomaly scores, the at least two business categories, and the system state, respectively.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of computer technology, and in particular to an anomaly detection method. One or more embodiments of this specification also relate to an anomaly detection device, a computing device, and a computer-readable storage medium. Background Technology

[0002] In the field of large-scale application monitoring, monitoring is mainly carried out at the business dimension (transaction creation success rate, payment success rate, etc.), system dimension, performance dimension, and log dimension. The overall application's normal operation is usually determined by comprehensively assessing the health of monitoring metrics across these dimensions. Among these dimensions, the business dimension, based on logs, directly reflects the service status of the business; however, business logs contain a large amount of information and the scenarios are complex. The system and performance dimensions involve large amounts of time-series data, making it challenging to effectively identify anomalies in the application by combining data from each dimension.

[0003] Traditional monitoring systems for business-level monitoring manually define abnormal states to characterize complex business scenarios into time-series data. This is then combined with system and performance-level monitoring, where users set different thresholds for monitoring metrics based on experience; exceeding these thresholds is considered an anomaly. However, due to the significant differences in real-world application scenarios, it's difficult to define accurate thresholds for each monitoring metric. Therefore, using these thresholds for anomaly monitoring easily leads to missed or false alarms. Thus, an effective anomaly detection method is urgently needed to address these issues. Summary of the Invention

[0004] In view of this, embodiments of this specification provide an anomaly detection method. One or more embodiments of this specification also relate to an anomaly detection device, a computing device, and a computer-readable storage medium, to address the technical deficiencies existing in the prior art.

[0005] According to a first aspect of the embodiments of this specification, an anomaly detection method is provided, comprising:

[0006] Obtain the list of log files and system status data of the objects to be detected within the time interval to be detected;

[0007] A log status distribution sequence is generated based on log data from at least two business categories in the log file list, and a system status distribution sequence is generated based on the correspondence between the system status data and the detection points.

[0008] The log status distribution sequence and the system status distribution sequence are input into the anomaly detection model to score outliers, generating anomaly scores corresponding to the at least two business categories and system statuses.

[0009] The anomaly detection result of the object to be detected is determined based on the anomaly score, the weights corresponding to the at least two business categories and the system status.

[0010] Optionally, generating a log status distribution sequence based on log data from at least two business categories in the log file list includes:

[0011] The number of log status codes is counted based on the log data, wherein the log status codes correspond to at least two business categories contained in the log file list;

[0012] The number of times the business processing interface of the object to be tested is called is determined based on the log data;

[0013] The log status distribution sequence is generated based on the log status codes, the number of log status codes, and the number of times the business processing interface is called.

[0014] Optionally, the step of counting the number of log status codes based on the log data includes:

[0015] Based on the preset statistical dimensions of the log data statistics, the number of log status codes corresponding to the at least two business categories contained in the log file list.

[0016] Optionally, generating the system state distribution sequence based on the correspondence between the system state data and time includes:

[0017] Determine the correspondence between the system status data and the detection points;

[0018] The system state data is aggregated according to a preset fixed-duration time window and the corresponding relationship to generate the system state distribution sequence.

[0019] Optionally, determining the anomaly detection result of the object to be detected based on the anomaly score, the weights corresponding to the at least two business categories, and the system state includes:

[0020] Target business categories and target system states are filtered based on the anomaly scores, and the initial weights of the target business categories and target system states are obtained.

[0021] The abnormal value of the object to be detected is calculated based on the initial weight, the abnormal score of the target business category and the target system state, and the abnormal value is used as the abnormal detection result of the object to be detected.

[0022] Optionally, determining the anomaly detection result of the object to be detected based on the anomaly score, the weights corresponding to the at least two business categories, and the system state includes:

[0023] Target business categories and target system statuses are filtered based on the aforementioned anomaly scores;

[0024] The correlation between the log state distribution sequence of the target business category and the system state distribution sequence of the target system state is determined by a time causal analysis algorithm.

[0025] The initial weights of the target business category and the target system state are determined based on the degree of correlation.

[0026] The abnormal value of the object to be detected is calculated based on the initial weight, the target business category, and the abnormal score of the target system state, and the abnormal value is used as the abnormal detection result of the object to be detected.

[0027] Optionally, the anomaly detection method further includes:

[0028] Obtain the target business category corresponding to the target object whose detection result is abnormal, the reason for the abnormality and the number of abnormalities in the status feedback of the target system for the user;

[0029] The initial weights of the target business category and the target system state are adjusted based on the cause of the anomaly and the number of anomalies.

[0030] Optionally, the step of generating a log status distribution sequence based on log data from at least two business categories in the log file list, and generating a system status distribution sequence based on the correspondence between the system status data and detection points, includes:

[0031] Log data from at least two business categories in the log file list are input into a data profiling model for processing to generate the log status distribution sequence; and,

[0032] The system state data is input into the data profiling model for processing to generate the system state distribution sequence.

[0033] Optionally, the data profiling model is trained in the following manner:

[0034] Obtain the list of first historical log files within the first historical time interval and the first historical status data of the system status within the first historical time interval;

[0035] A first historical log sequence is generated based on log data from at least two business categories in the first historical log file list, and a first historical state sequence of the system state is generated based on the correspondence between the first historical state data and the detection points.

[0036] The first historical log sequence and the first historical state sequence are used as sample data to train the data profiling model, thereby obtaining the data profiling model.

[0037] Optionally, the anomaly detection method further includes:

[0038] The log state distribution sequence and the system state distribution sequence are input into the data profiling model for data cleaning to obtain the standard distribution feature sequences corresponding to the at least two business categories and the state thresholds corresponding to the system state.

[0039] Optionally, the step of inputting the log state distribution sequence and the system state distribution sequence into the anomaly detection model for outlier scoring includes:

[0040] Obtain the list of second historical log files within the second historical time interval and the second historical status data of the system status within the second historical time interval;

[0041] The log state distribution sequence, the system state distribution sequence, the standard distribution feature sequence, the state threshold, the second historical log file list, and the second historical state data are input into the anomaly detection model to score outliers.

[0042] According to a second aspect of the embodiments of this specification, an anomaly detection device is provided, comprising:

[0043] The acquisition module is configured to acquire a list of log files and system status data of the objects to be detected within the time interval to be detected.

[0044] The generation module is configured to generate a log status distribution sequence based on log data from at least two business categories in the log file list, and to generate a system status distribution sequence based on the correspondence between the system status data and the detection points;

[0045] The scoring module is configured to input the log state distribution sequence and the system state distribution sequence into the anomaly detection model to score outliers and generate anomaly scores corresponding to the at least two business categories and system states.

[0046] The determination module is configured to determine the anomaly detection result of the object to be detected based on the anomaly score, the weights corresponding to the at least two business categories and the system state, respectively.

[0047] According to a third aspect of the embodiments of this specification, a computing device is provided, comprising:

[0048] Memory and processor;

[0049] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the steps of the anomaly detection method.

[0050] According to a fourth aspect of the embodiments of this specification, a computer-readable storage medium is provided that stores computer-executable instructions, which, when executed by a processor, implement the steps of the anomaly detection method.

[0051] One embodiment of this specification obtains a list of log files and system status data of the object to be detected within a time interval to be detected. A log status distribution sequence is generated based on log data from at least two business categories in the log file list. A system status distribution sequence is generated based on the correspondence between the system status data and detection points. The log status distribution sequence and the system status distribution sequence are input into an anomaly detection model for anomaly scoring, generating anomaly scores corresponding to the at least two business categories and the system status. The anomaly detection result of the object to be detected is determined based on the anomaly scores and the weights corresponding to the at least two business categories and the system status.

[0052] By converting the log data and system status data in the log file list into log status distribution sequences and system status distribution sequences respectively using the above method, and then performing anomaly detection on the object to be detected based on these log status distribution sequences and system status distribution sequences, the complexity of the anomaly detection process can be reduced and the efficiency of anomaly detection can be improved. In addition, after scoring the anomalies of each business category and system status using the anomaly detection model, the anomaly detection result of the object to be detected can be determined by combining the weights corresponding to each business category and system status, which helps to improve the accuracy of the anomaly detection result. Attached Figure Description

[0053] Figure 1 This is a flowchart illustrating an anomaly detection method provided in one embodiment of this specification.

[0054] Figure 2 This is a schematic diagram of an anomaly detection process provided in one embodiment of this specification;

[0055] Figure 3 This is a flowchart illustrating the process of applying an anomaly detection method to a transaction business scenario, as provided in one embodiment of this specification.

[0056] Figure 4 This is a schematic diagram of an anomaly detection device provided in one embodiment of this specification;

[0057] Figure 5 This is a structural block diagram of a computing device provided in one embodiment of this specification. Detailed Implementation

[0058] Many specific details are set forth in the following description to provide a full understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar extensions without departing from the spirit of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.

[0059] The terminology used in one or more embodiments of this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of the one or more embodiments of this specification. The singular forms “a,” “described,” and “the” as used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.

[0060] It should be understood that although the terms first, second, etc., may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first may also be referred to as second without departing from the scope of one or more embodiments of this specification, and similarly, second may also be referred to as first. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."

[0061] First, the terms and concepts used in one or more embodiments of this specification will be explained.

[0062] Application monitoring: System monitoring and operational status monitoring organized from an application perspective.

[0063] Normal state profile: refers to the time-series characteristics of comprehensive application of indicator type monitoring and log type monitoring.

[0064] iForest (Isolation Forest) is a fast anomaly detection method with linear time complexity and high accuracy.

[0065] This specification provides an anomaly detection method, and also relates to an anomaly detection device, a computing device, and a computer-readable storage medium, which will be described in detail in the following embodiments.

[0066] Figure 1 A flowchart of an anomaly detection method according to an embodiment of this specification is shown, including steps 102 to 108.

[0067] Step 102: Obtain the list of log files and system status data of the objects to be detected within the time interval to be detected.

[0068] The anomaly detection method provided in the embodiments of this specification can be applied to a server or terminal. That is, the server or terminal can be used as a monitoring platform to monitor the status of the object to be detected in order to detect whether it is abnormal.

[0069] Specifically, the object to be detected is the object on which anomalies need to be detected. In practical applications, the object to be detected can be a service interface or other business indicators that require anomaly monitoring, or it can be a smart home device such as a smart lock or smart speaker connected to the Internet, an environmental monitoring device, a smart medical device, a transportation management system, or other applications mounted on a server or terminal, such as applications that provide online shopping services or applications that provide same-city delivery services. This specification uses an application as an example to illustrate the embodiment of the object to be detected, but it is not limited to this.

[0070] To maintain normal data access or ensure normal business services for users, it is often necessary to perform anomaly detection on the object to be tested. The embodiments in this specification analyze and process the log file list and system status data of the object to be tested to achieve anomaly detection.

[0071] In practice, before performing anomaly detection on the object to be detected, the server or terminal first needs to determine the anomaly detection time (the time interval to be detected), and then obtain the log file list of the object to be detected corresponding to the anomaly detection time and the status data (system status data) of the server or terminal corresponding to the anomaly detection time based on the identification information of the object to be detected.

[0072] In practical applications, since all log categories, such as application logs, security logs, system logs, and network management logs, can be listed on the log management page of the server or terminal, if the object to be detected is an application, the application log can be viewed on the log management page to obtain a list of log files of the application within the time interval to be detected. In addition, the system status data includes, but is not limited to, status parameters such as CPU, current memory, or system load.

[0073] After obtaining the list of log files and system status data of the object to be detected within the time interval to be detected, anomaly analysis can be performed on the object to be detected by combining the list of log files and system status data.

[0074] Step 104: Generate a log status distribution sequence based on log data from at least two business categories in the log file list, and generate a system status distribution sequence based on the correspondence between the system status data and the detection points.

[0075] Specifically, after obtaining the list of log files of the objects to be detected within the time interval to be detected, log events can be extracted based on the list of log files, that is, log data of different types of business can be extracted.

[0076] If the object to be detected is an application, since an application can provide one, two or more different services, and different services can contain multiple service categories, for example, a shopping application can provide not only online shopping services, but also utility bill payment and auction services, etc. The service categories contained under the online shopping service can be transaction creation category, payment application category, transaction result category, etc.

[0077] Therefore, the embodiments of this specification can analyze and process log data of different business categories contained in the log file list to generate a log status distribution sequence, and perform anomaly detection on the application based on the log status distribution sequence.

[0078] In practical applications, when users or developers print logs, they can choose to print logs containing specific rules. These specific rules can be based on different log status codes to represent different business categories. For example, one business category under online shopping is the transaction creation category. In this case, the user can print the identifier of the transaction creation category, i.e., the log status code for the transaction creation category, in the logs.

[0079] Therefore, after obtaining log data for different business categories, the log status distribution sequence can be generated using the log status codes for different business categories and the data related to the log status codes.

[0080] In practice, a log status distribution sequence is generated based on log data from at least two business categories in the log file list. This can be achieved in the following ways:

[0081] The number of log status codes is counted based on the log data, wherein the log status codes correspond to at least two business categories contained in the log file list;

[0082] The number of times the business processing interface of the object to be tested is called is determined based on the log data;

[0083] The log status distribution sequence is generated based on the log status codes, the number of log status codes, and the number of times the business processing interface is called.

[0084] Furthermore, based on the log data, the number of log status codes is counted, that is, based on the log data, the number of log status codes corresponding to the at least two business categories contained in the log file list under the preset statistical dimensions.

[0085] Specifically, after extracting log data from different business categories, the time dimension can be used as a preset statistical dimension to count the different log status codes and their quantities within the log file list over a period of X minutes. Additionally, the number of calls to the business processing interface of the object under test can be determined based on the log file list or the log data. The log status distribution sequence is then determined by the log status codes of different business categories under the time dimension, the frequency of occurrence of different log status codes, and the call volume of the business processing interface within the corresponding time period. Specifically, this involves calculating the frequency of occurrence of different log status codes within X minutes under the time dimension (the ratio of the number of times a log status code occurs to the number of times a business interface is called), and integrating each log status code and its corresponding frequency to generate the log status distribution sequence.

[0086] In practical applications, the purpose of counting the number of log status codes for different business categories is to count the number of occurrences of different business categories by counting the number of log status codes. For example, the number of transactions can be determined by counting the number of log status codes corresponding to the transaction creation category.

[0087] Since any business may contain multiple business categories, after a user initiates a business processing request for different business categories, the business processing request can be processed by calling the business processing interface. Therefore, in the embodiments of this specification, the number of times the business processing interface of the object to be detected is called can be the sum of the number of log status codes of different business types.

[0088] After determining the log status code, the number of log status codes, and the number of times the business processing interface is called through the aforementioned process, the log status distribution sequence can be calculated and integrated based on the log status code, the number of log status codes, and the number of times the business processing interface is called.

[0089] In addition, a system state distribution sequence is generated based on the correspondence between the system state data and time. That is, the correspondence between the system state data and the detection points is determined, and the system state data is aggregated according to a preset fixed time window and the correspondence to generate the system state distribution sequence.

[0090] Specifically, as mentioned above, the system status data can be status parameters such as CPU, memory, or load. Since the data acquisition time intervals corresponding to the acquired system status data may differ, that is, the data acquisition durations corresponding to different data acquisition time intervals may differ, in order to ensure the accuracy of the anomaly detection results, the embodiments of this specification can perform aggregation processing on the system status data. Specifically, the correspondence between the system status data and the detection points (time points) within different acquisition time intervals can be determined, and the system status data can be aggregated according to a fixed time window and the correspondence to generate the system status distribution sequence.

[0091] In practical applications, the system status data can be split into status parameters of different system states at the same detection point, and then the splitting results can be aggregated. For example, if the fixed duration is set to 10 minutes, and the acquired system status data includes status parameters of the CPU and memory system states, then the splitting results obtained by splitting the system status data may be the status parameters of the CPU and memory system states at 20 detection points at 10:01, 10:02, ..., 10:20. After obtaining the splitting results, the splitting results are aggregated according to a time window of 10 minutes to generate the system status distribution sequence.

[0092] Furthermore, embodiments of this specification can also generate the log status distribution sequence by inputting log data from at least two business categories in the log file list into the data profiling model for processing; and by inputting the system status data into the data profiling model for processing.

[0093] The data profiling model is trained in the following way:

[0094] Obtain the list of first historical log files within the first historical time interval and the first historical status data of the system status within the first historical time interval;

[0095] A first historical log sequence is generated based on log data from at least two business categories in the first historical log file list, and a first historical state sequence of the system state is generated based on the correspondence between the first historical state data and the detection points.

[0096] The first historical log sequence and the first historical state sequence are used as sample data to train the data profiling model, thereby obtaining the data profiling model.

[0097] Specifically, generating the first historical log sequence and the first historical state sequence involves converting the original log data and system state data into the target format according to a certain processing method. Since directly cleaning the abnormal data (dirty data) in the log data is relatively complicated, converting the original data into a format before cleaning it is beneficial to improve data processing efficiency.

[0098] After generating the first historical log sequence and the first historical state sequence, they can be used as sample data to train the data profiling model. The trained data profiling model can perform data cleaning on the target format sequence, generate standard distribution feature sequences corresponding to at least two business categories, and generate state thresholds corresponding to system states.

[0099] In practical applications, the first historical state sequence is generated based on the log data in the first historical log file list, and the first historical state sequence is also generated based on the correspondence between the first historical state data and the detection points. This is equivalent to using different data to simulate the profiles of different business categories and different system states at different times. The simulation results can be used to characterize the normal distribution range of state parameters of different business categories or different system states.

[0100] Using a data profiling model to generate the log state distribution sequence and the system state distribution sequence not only helps ensure the accuracy of the generated results but also helps shorten the time required for the sequence generation process, thereby improving data processing efficiency.

[0101] Step 106: Input the log status distribution sequence and the system status distribution sequence into the anomaly detection model to score outliers and generate anomaly scores corresponding to the at least two business categories and system statuses.

[0102] Specifically, the anomaly detection model described in the embodiments of this specification is an unsupervised model, which may be based on statistical short-term month-on-month and year-on-year amplitude, iForest based on tree model, or Long Short-Term Memory Network + Autoencoder Network based on deep learning, etc.

[0103] The log state distribution sequence and the system state distribution sequence are input into the anomaly detection model, which scores the two state distribution sequences for anomalies and outputs the scores. After generating anomaly scores for the log state distribution sequence and the system state distribution sequence, the anomaly detection model can output the anomaly scores corresponding to all or part of the generated state distribution sequences (sequences with anomaly scores higher than a preset threshold).

[0104] In practice, this can be achieved by acquiring a list of historical log files and historical system state data of the object to be detected, generating a historical log sequence based on the log data in the historical file list, generating a historical state sequence based on the correspondence between the historical system state data and detection points, and training the anomaly detection model based on the historical log sequence, the historical state sequence, and an unsupervised anomaly detection algorithm (such as moving average, Laida criterion, or isolated forest algorithm). The anomaly detection model is then used to subsequently determine whether the object to be detected is abnormal based on the log state distribution sequence and the system state distribution sequence.

[0105] In practical applications, since the historical state sequence and the historical state sequence can be used to characterize the normal distribution range of state parameters for different business categories or different system states, the anomaly detection model trained using the historical log sequence and the historical state sequence can learn the normal distribution range of state parameters for different business categories or different system states.

[0106] After obtaining a new list of log files and / or system status data, the frequency of occurrence of status codes for different business categories (such as transaction volume, transaction results, etc.) can be calculated based on the log status codes in the log file list and the number of calls to business processing interfaces. The correspondence between different system statuses and time points can be determined based on the system status data. Then, each status code, the frequency of occurrence of each status code, and the correspondence between different system statuses and time points are input into the anomaly detection model. The anomaly detection model can then score the status codes and system statuses for outliers based on the learning results and the input data.

[0107] In practice, after generating the log status distribution sequence and the system status distribution sequence, the log status distribution sequence and the system status distribution sequence can be input into the data profiling model for data cleaning to obtain the standard distribution feature sequence corresponding to the at least two business categories and the status threshold corresponding to the system status.

[0108] Specifically, since the log data or system status data in the obtained log file list may contain abnormal data, a data profiling model can be used to clean the log data or system status data to determine the standard distribution characteristics and system status thresholds corresponding to at least two business categories. The standard distribution characteristics and the status thresholds can be used as reference values ​​to score outliers in the log status distribution sequence and the system status distribution sequence.

[0109] However, since the process of directly cleaning the abnormal data (dirty data) in the log data is quite complicated, the embodiments of this specification first convert the log data into a log status distribution sequence and the system status data into a system status distribution sequence. Then, the log status distribution sequence and the system status distribution sequence are input into the data profiling model for data cleaning. The cleaned data is then processed to generate the standard distribution feature sequence (the distribution ratio of log status codes at different detection points) corresponding to the at least two business categories and the status threshold corresponding to the system status (the distribution threshold of the system status at different detection points).

[0110] Furthermore, the log state distribution sequence and the system state distribution sequence are input into the anomaly detection model for outlier scoring, which can be achieved in the following ways:

[0111] Obtain the list of second historical log files within the second historical time interval and the second historical status data of the system status within the second historical time interval;

[0112] The log state distribution sequence, the system state distribution sequence, the standard distribution feature sequence, the state threshold, the second historical log file list, and the second historical state data are input into the anomaly detection model to score outliers.

[0113] Specifically, after obtaining the standard distribution feature sequence and the state threshold, unlike the usual anomaly detection methods of comparing the log state distribution sequence with the standard distribution feature sequence to determine whether the corresponding business category is abnormal, and comparing the system state distribution sequence with the state threshold to determine whether the corresponding system state is abnormal, the embodiments of this specification can also combine historical data within the historical time interval to comprehensively determine whether the business category or system state is abnormal.

[0114] Combining historical data corresponding to each business category and system status to comprehensively determine the anomaly detection results of the object to be detected is beneficial to improving the accuracy of the anomaly detection results.

[0115] Step 108: Determine the anomaly detection result of the object to be detected based on the anomaly score, the weights corresponding to the at least two business categories and the system status.

[0116] Specifically, after the anomaly detection model outputs the log state distribution sequence and the anomaly score corresponding to the system state distribution sequence, it can also combine the weights of each sequence to comprehensively judge the anomaly detection result of the object to be detected.

[0117] In practice, the anomaly detection result of the object to be detected is determined based on the anomaly score, the weights corresponding to the at least two business categories, and the system status, which can be achieved in the following ways:

[0118] Target business categories and target system states are filtered based on the anomaly scores, and the initial weights of the target business categories and target system states are obtained.

[0119] The abnormal value of the object to be detected is calculated based on the initial weight, the abnormal score of the target business category and the target system state, and the abnormal value is used as the abnormal detection result of the object to be detected.

[0120] Specifically, after the anomaly detection model outputs anomaly scores corresponding to at least two business categories and system states, the target business category and target system state can be filtered based on the anomaly scores. Specifically, the business category or system state with an anomaly score greater than a preset score threshold can be used as the target business category or the target system state.

[0121] After filtering and obtaining the target business category and target system status, the initial weights corresponding to the target business category and the target system status can be obtained respectively. The abnormal scores of the target business category and the target system indicators can be calculated by weighted average based on the initial weights to generate anomaly values. The anomaly values ​​are then used as the anomaly detection results of the object to be detected.

[0122] In addition, determining the anomaly detection result of the object to be detected based on the anomaly score, the weights corresponding to the at least two business categories and the system state can also be achieved in the following ways:

[0123] Target business categories and target system statuses are filtered based on the aforementioned anomaly scores;

[0124] The correlation between the log state distribution sequence of the target business category and the system state distribution sequence of the target system state is determined by a time causal analysis algorithm.

[0125] The initial weights of the target business category and the target system state are determined based on the degree of correlation.

[0126] The abnormal value of the object to be detected is calculated based on the initial weight, the target business category, and the abnormal score of the target system state, and the abnormal value is used as the abnormal detection result of the object to be detected.

[0127] Specifically, after the anomaly detection model outputs anomaly scores corresponding to at least two business categories and system states, the target business category and target system state can be filtered based on the anomaly scores. Specifically, the business category or system state with an anomaly score greater than a preset score threshold can be used as the target business category or the target system state.

[0128] After obtaining the target business category and target system status through screening, the degree of correlation between the target log status distribution sequence corresponding to the target business category and the target system status distribution sequence corresponding to the target system status and the abnormal event can be determined by temporal causal analysis. Then, the initial weights of the target business category and the target system status can be determined based on the degree of correlation.

[0129] In practical applications, the sensitivity of each monitored object to different business categories or system states can be analyzed based on the log file list and system status data of the monitored objects within a historical time interval. First, a data profiling model is used to obtain the log file list and system status data, including log status distribution sequences and system status distribution sequences. Then, abnormal events within the time window are collected, and temporal causal analysis is used to determine the correlation between abnormal events and the log status distribution sequences and system status distribution sequences, forming a weight matrix for each monitored object in different sequences. This weight matrix contains the initial weights of the monitored objects in different business categories or different system states.

[0130] The anomaly scores of the target business category and the target system indicator are calculated by weighting the initial weights, and the calculation result is used as the anomaly detection result of the object to be detected.

[0131] Furthermore, after obtaining the anomaly detection results of the object to be detected, the weights of each business category and system status can be adjusted based on user feedback. This can be achieved in the following ways:

[0132] Obtain the target business category corresponding to the target object whose detection result is abnormal, the reason for the abnormality and the number of abnormalities in the status feedback of the target system for the user;

[0133] The initial weights of the target business category and the target system state are adjusted based on the cause of the anomaly and the number of anomalies.

[0134] Specifically, after obtaining the anomaly detection results of the object to be detected by combining the weights, the anomaly detection results can be fed back to the user. The user can then provide feedback on the impact of the abnormal business categories and / or system states on the business, or the user can use the inverse document frequency (IDF) algorithm to evaluate the importance of the anomaly detection results of different business categories or different system states on the object to be detected. Specifically, the user can provide feedback on the causes and frequency of anomalies in the abnormal business categories and system states, so that the terminal or server can adjust the weights corresponding to each business category and system state based on the feedback information. In practical applications, the weights of business categories can be adjusted according to the inverse relationship between the weight and the frequency of anomalies. For example, the weight of a business category with fewer anomalies can be increased, or the weight of a business category with more anomalies can be decreased.

[0135] In one embodiment of this specification, the granularity of weight adjustment can also be differentiated based on the business type, and this application does not limit this.

[0136] Since the embodiments in this specification are applied to servers or terminals, after the server or terminal performs anomaly detection on the object to be detected and obtains the anomaly detection results, it can display the anomaly detection results to the user through the display interface of the server or terminal, or integrate the anomaly detection results over a period of time and display them to the user through the display interface. Similarly, the user can click on the clickable controls of the display interface to view the anomaly detection results or the integrated results of the anomaly detection, to statistically analyze the causes and frequency of anomalies based on the anomaly detection results, or to view the causes and frequency of anomalies included in the integrated results, and determine whether it is a false alarm based on the causes and frequency of anomalies. Then, through the display interface, the weights of different business categories or different system states can be adjusted according to the determination of whether it is a false alarm (if it is determined not to be a false alarm, the initial weight corresponding to the business category or system state where anomalies are detected is increased by a certain amount; if it is determined to be a false alarm, the initial weight of the business category or system state where anomalies are detected is decreased by a certain amount).

[0137] Furthermore, after adjusting the weights of different business categories and / or system states, users can redeploy the corresponding monitoring items based on the adjustment results. For example, if the terminal currently has multiple monitoring items deployed (CPU, memory, and load monitoring), and the weight adjustment results determine that CPU and load have higher weights while memory has a lower weight, then only CPU and load monitoring can be deployed, and memory monitoring can be removed. The embodiments in this specification are merely illustrative of the above-described monitoring deployment and adjustment methods. In actual applications, the specific deployment method can be determined according to actual needs and is not limited here.

[0138] This method adjusts the weights of each business category and system status, thereby making the detection results generated by subsequent anomaly detection of the target object more accurate.

[0139] A schematic diagram of an anomaly detection process provided in the embodiments of this specification is shown below. Figure 2 As shown, firstly, the log file list of the object to be detected (corresponding to the log in the figure) and the status data of the system status (corresponding to the system indicators in the figure) are obtained from the log. Then, the log file list and the status data are preprocessed, that is, the log file list and the status data are cleaned. Then, the cleaning result is input into the profiling module (equivalent to the data profiling model) to generate at least two log status distribution sequences corresponding to business categories and system status distribution sequences corresponding to system status.

[0140] The log state distribution sequence and the system state distribution sequence are input into the anomaly detection model for anomaly detection (outlier scoring);

[0141] The weight processing module determines the weights of the business category and system status, calculates the anomaly detection result of the object to be detected based on the anomaly scoring result output by the anomaly detection model and the weights, and sends the anomaly detection result to the user.

[0142] Users provide feedback on the reasons for and frequency of anomalies in target business categories and system states that are flagged as abnormal by anomaly detection. The weights of the business categories and system states are then adjusted based on this feedback. Specifically, the system acquires the data to be detected for the target object, performs anomaly detection processing on it, and obtains a corresponding anomaly score. The weighting module then combines the anomaly score with the weights corresponding to each business category and system state to perform a weighted summation, resulting in an anomaly score for the target object. This anomaly score is sent to the user, who then adjusts the weights of the business categories and system states based on the anomaly score.

[0143] In practical applications, the data to be detected can be acquired, and the log file list and system status data contained in the data to be detected can be preprocessed (data cleaning). Then, based on the processing results, at least two log status distribution sequences corresponding to business categories and system status distribution sequences corresponding to system status can be generated. The log status distribution sequences and system status distribution sequences are then input into the profile model to be trained for training to obtain the profile model (profile module).

[0144] Furthermore, as mentioned earlier, the objects to be detected can be service interfaces, business metrics, smart home devices such as smart locks and smart speakers connected to the internet, environmental monitoring devices, smart medical devices, transportation management systems, or other applications installed on servers or terminals, such as applications providing online shopping services or applications providing same-city delivery services. Therefore, to ensure the accuracy of anomaly detection results for different objects to be detected, in practical applications, different objects to be detected can be classified. For example, smart locks, smart speakers, and other smart home devices can be grouped into one category, and applications that can provide different services can be grouped into another category. Different anomaly detection methods can be used for different categories of objects to be detected. For example, for smart home devices, anomaly detection can be mainly based on data such as device usage time and device power consumption; while for applications, anomaly detection can be mainly based on log data and system status data.

[0145] In addition to classifying the objects to be tested, the system can also classify the causes of anomalies in different objects within the same category. Users can perform anomaly diagnosis based on the classification results, which helps improve the accuracy of the diagnostic results. For example, if the anomaly detected in a smart speaker in a smart home device is that it cannot connect to the network, without classifying the causes of anomalies in other smart home devices, users cannot quickly and accurately determine whether the problem lies with the smart speaker itself or the network. However, if the causes of anomalies in other smart home devices are classified, and it is determined that other devices have also experienced the problem of not being able to connect to the network over a period of time, users can then determine that the problem lies with the network.

[0146] Whether classifying the objects to be detected or classifying the causes of anomalies in the same category, the anomaly detection results and classification results of the objects to be detected can be fed back to the user. The user can then adjust the weights of different business categories and different system states based on the causes and frequency of anomalies in the feedback results, so as to further improve the accuracy of anomaly detection results using the feedback data.

[0147] This specification uses an example of application A, which provides online shopping services, to further illustrate the anomaly detection method by performing anomaly detection on transaction transactions within a specified time interval in application A.

[0148] First, obtain the log file list and system status data of application A within the time interval to be tested (09:59-10:01 on XX / XX / XXXX). Based on the log data in the log file list, count the number of each log status code, and determine the number of times the transaction business processing interface of application A is called according to the log data. Then, based on the statistical results, determine the frequency of occurrence of status codes corresponding to different business categories under the transaction business within the time interval to be tested, and generate a log status sequence.

[0149] Then, based on the system status data, the correspondence between the status parameters of different system states and the detection points is determined. The status parameters of the system states are aggregated according to the correspondence to generate a system status distribution sequence. Next, the log status distribution sequence and the system status distribution sequence are input into the anomaly detection model to score outliers and generate anomaly scores corresponding to the at least two transaction business categories and system states. Then, the initial weights of different business categories and different system states under the transaction business are used to perform a weighted summation operation on the aforementioned anomaly scores to obtain the anomaly detection results of the transaction business of application A.

[0150] In addition, if it is determined that there is an anomaly in the transaction business based on the anomaly detection results, the anomaly detection results can also be fed back to the user so that the user can determine whether it is a false alarm.

[0151] For example, based on the historical log file list and historical status data, the simulation model depicts the profiles of different business categories and system states under the transaction business at different times. Based on the simulation results, the normal distribution range for the transaction volume value under the business category is determined to be 100-150 within the time interval of 09:59-10:01. However, the anomaly detection model, based on the input log status sequence, determines that the transaction volume value under the business category is 300 within the time interval of 09:59-10:01, which is much larger than the normal distribution range. Therefore, the anomaly score generated by scoring the log status distribution sequence is high. This results in a weighted calculation using the anomaly score and the weights of different business categories and system states under the transaction business to obtain the anomaly detection result. The result indicates that anomalies exist in the transaction business within the time interval of 09:59-10:01 on [Date].

[0152] After this anomaly detection result is fed back to the user, since the user has determined that the application added special transaction activities, such as flash sales, during the time interval of 09:59-10:01 on XX / XX / XXXX, the user determines that this anomaly detection result is a false alarm. Based on this anomaly detection result, the weight of different business categories and / or system states under the transaction business can be adjusted to reduce the anomaly sensitivity of business categories or system states with high alarm frequency and low importance, and increase the anomaly sensitivity of high-risk anomaly indicators (business categories or system states). Furthermore, by combining the historical anomaly linkage relationship between anomaly indicators, the accuracy of the anomaly detection result can be further improved.

[0153] This specification provides an anomaly detection method. It involves acquiring a list of log files and system status data of the object to be detected within a specified time interval. A log status distribution sequence is generated based on log data from at least two business categories in the log file list. A system status distribution sequence is generated based on the correspondence between the system status data and detection points. The log status distribution sequence and the system status distribution sequence are input into an anomaly detection model for anomaly scoring, generating anomaly scores corresponding to the at least two business categories and the system status. The anomaly detection result of the object to be detected is determined based on the anomaly scores and the weights corresponding to the at least two business categories and the system status.

[0154] By converting the log data and system status data in the log file list into log status distribution sequences and system status distribution sequences respectively using the above method, and then performing anomaly detection on the object to be detected based on these log status distribution sequences and system status distribution sequences, the complexity of the anomaly detection process can be reduced and the efficiency of anomaly detection can be improved. In addition, after scoring the anomalies of each business category and system status using the anomaly detection model, the anomaly detection result of the object to be detected can be determined by combining the weights corresponding to each business category and system status, which helps to improve the accuracy of the anomaly detection result.

[0155] The following is in conjunction with the appendix Figure 3 Taking the anomaly detection method provided in this specification as an example in transaction business, the anomaly detection method will be further explained. Among other things, Figure 3 The flowchart of an anomaly detection method provided in one embodiment of this specification is shown, which is applied to a transaction business scenario. The specific steps include steps 302 to 322.

[0156] Step 302: Obtain the list of log files and system status data of the application to be tested within the time interval to be tested.

[0157] Step 304: Count the number of log status codes based on the log data.

[0158] The log status code corresponds to the at least two transaction business categories included in the log file list.

[0159] Step 306: Determine the number of times the transaction processing interface of the application to be tested is called based on the log data.

[0160] Step 308: Generate the log status distribution sequence based on the log status code, the number of log status codes, and the number of times the transaction business processing interface is called.

[0161] Step 310: Determine the correspondence between the system status data and the detection points.

[0162] Step 312: Aggregate the system state data according to a preset fixed-duration time window and the corresponding relationship to generate the system state distribution sequence.

[0163] Step 314: Input the log status distribution sequence and the system status distribution sequence into the anomaly detection model to score outliers and generate anomaly scores corresponding to the at least two transaction business categories and system statuses.

[0164] Step 316: Filter the target transaction business category and target system status based on the anomaly score.

[0165] Step 318: Determine the degree of correlation between the log state distribution sequence of the target transaction business category and the system state distribution sequence of the target system state using a time causal analysis algorithm.

[0166] Step 320: Determine the initial weights of the target transaction business category and the target system state based on the degree of correlation.

[0167] Step 322: Calculate the anomaly value of the application to be tested based on the initial weight, the target transaction business category, and the anomaly score of the target system state, and use the anomaly value as the anomaly detection result of the application to be tested.

[0168] This embodiment of the specification converts the log data and system status data in the log file list into log status distribution sequences and system status distribution sequences, respectively. Anomaly detection is then performed on the object to be detected based on these log status distribution sequences and system status distribution sequences. This helps reduce the complexity of the anomaly detection process and improves the efficiency of anomaly detection. In addition, after scoring each business category and system status for anomalies using the anomaly detection model, the anomaly detection result of the object to be detected is determined by combining the weights corresponding to each business category and system status. This helps improve the accuracy of the anomaly detection result.

[0169] Corresponding to the above method embodiments, this specification also provides embodiments of anomaly detection devices. Figure 4 A schematic diagram of an anomaly detection device according to one embodiment of this specification is shown. Figure 4 As shown, the device includes:

[0170] The acquisition module 402 is configured to acquire a list of log files of the objects to be detected within the time interval to be detected and system status data.

[0171] The generation module 404 is configured to generate a log status distribution sequence based on log data of at least two business categories in the log file list, and to generate a system status distribution sequence based on the correspondence between the system status data and the detection points.

[0172] The scoring module 406 is configured to input the log state distribution sequence and the system state distribution sequence into the anomaly detection model to score anomalies and generate anomaly scores corresponding to the at least two business categories and system states.

[0173] The determination module 408 is configured to determine the anomaly detection result of the object to be detected based on the anomaly score, the weights corresponding to the at least two business categories and the system state.

[0174] Optionally, the generation module 404 includes:

[0175] The statistics submodule is configured to count the number of log status codes based on the log data, wherein the log status codes correspond to the at least two business categories contained in the log file list;

[0176] The call count determination submodule is configured to determine the call count of the business processing interface of the object to be detected based on the log data;

[0177] The log status distribution sequence generation submodule is configured to generate the log status distribution sequence based on the log status code, the number of log status codes, and the number of times the business processing interface is called.

[0178] Optionally, the statistics submodule includes:

[0179] The statistics unit is configured to count the number of log status codes corresponding to the at least two business categories contained in the log file list under a preset statistical dimension based on the log data.

[0180] Optionally, the generation module 404 includes:

[0181] The correspondence determination submodule is configured to determine the correspondence between the system status data and the detection points;

[0182] The system state distribution sequence generation submodule is configured to aggregate the system state data according to a preset fixed-duration time window and the corresponding relationship to generate the system state distribution sequence.

[0183] Optionally, the determining module 408 includes:

[0184] The initial weight acquisition submodule is configured to filter target business categories and target system states based on the anomaly scores, and acquire the initial weights of the target business categories and the target system states;

[0185] The first calculation submodule is configured to calculate the abnormal value of the object to be detected based on the initial weight, the abnormal score of the target business category and the target system state, and use the abnormal value as the abnormal detection result of the object to be detected.

[0186] Optionally, the determining module 408 includes:

[0187] The filtering submodule is configured to filter target business categories and target system states based on the anomaly scores;

[0188] The correlation degree determination submodule is configured to determine the correlation degree between the log state distribution sequence of the target business category and the system state distribution sequence of the target system state through a time causal analysis algorithm;

[0189] The initial weight determination submodule is configured to determine the initial weights of the target business category and the target system state based on the degree of correlation.

[0190] The second calculation submodule is configured to calculate the abnormal value of the object to be detected based on the initial weight, the target business category, and the abnormal score of the target system state, and use the abnormal value as the abnormal detection result of the object to be detected.

[0191] Optionally, the anomaly detection device further includes:

[0192] The feedback information acquisition module is configured to acquire the abnormal reason and the number of abnormalities reported by the user for the target business category corresponding to the target system status of the object to be detected with an abnormal detection result;

[0193] The weight adjustment module is configured to adjust the initial weights of the target business category and the target system state based on the cause of the anomaly and the number of anomalies.

[0194] Optionally, the step of generating a log status distribution sequence based on log data from at least two business categories in the log file list, and generating a system status distribution sequence based on the correspondence between the system status data and detection points, includes:

[0195] Log data from at least two business categories in the log file list are input into a data profiling model for processing to generate the log status distribution sequence; and,

[0196] The system state data is input into the data profiling model for processing to generate the system state distribution sequence.

[0197] Optionally, the data profiling model is trained in the following manner:

[0198] Obtain the list of first historical log files within the first historical time interval and the first historical status data of the system status within the first historical time interval;

[0199] A first historical log sequence is generated based on log data from at least two business categories in the first historical log file list, and a first historical state sequence of the system state is generated based on the correspondence between the first historical state data and the detection points.

[0200] The first historical log sequence and the first historical state sequence are used as sample data to train the data profiling model, thereby obtaining the data profiling model.

[0201] Optionally, the anomaly detection device further includes:

[0202] The data cleaning module is configured to input the log state distribution sequence and the system state distribution sequence into the data profiling model for data cleaning, and obtain the standard distribution feature sequence corresponding to the at least two business categories and the state threshold corresponding to the system state.

[0203] Optionally, the scoring module 406 includes:

[0204] The second historical status data acquisition submodule is configured to acquire the list of second historical log files within the second historical time interval and the second historical status data of the system status within the second historical time interval.

[0205] The outlier scoring module is configured to input the log state distribution sequence, the system state distribution sequence, the standard distribution feature sequence, the state threshold, the second historical log file list, and the second historical state data into the anomaly detection model to score outliers.

[0206] The above is a schematic scheme of an anomaly detection device according to this embodiment. It should be noted that the technical solution of this anomaly detection device and the technical solution of the above-described anomaly detection method belong to the same concept. For details not described in detail in the technical solution of the anomaly detection device, please refer to the description of the technical solution of the above-described anomaly detection method.

[0207] Figure 5 A structural block diagram of a computing device 500 according to one embodiment of this specification is shown. The components of the computing device 500 include, but are not limited to, a memory 510 and a processor 520. The processor 520 is connected to the memory 510 via a bus 530, and a database 550 is used to store data.

[0208] The computing device 500 also includes an access device 540, which enables the computing device 500 to communicate via one or more networks 560. Examples of these networks include a Public Switched Telephone Network (PSTN), a Local Area Network (LAN), a Wide Area Network (WAN), a Personal Area Network (PAN), or a combination of communication networks such as the Internet. The access device 540 may include one or more of any type of wired or wireless network interface (e.g., a Network Interface Card (NIC)), such as an IEEE 802.11 Wireless Local Area Network (WLAN) interface, a Wi-MAX interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a Near Field Communication (NFC) interface, and so on.

[0209] In one embodiment of this specification, the above-described components of the computing device 500 and Figure 5 Other components, not shown, can also be connected to each other, for example, via a bus. It should be understood that... Figure 5 The block diagram of the computing device shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art can add or replace other components as needed.

[0210] The computing device 500 can be any type of stationary or mobile computing device, including mobile computers or mobile computing devices (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smartphones), wearable computing devices (e.g., smartwatches, smart glasses, etc.) or other types of mobile devices, or stationary computing devices such as desktop computers or PCs. The computing device 500 can also be a mobile or stationary server.

[0211] The memory 510 is used to store computer-executable instructions, and the processor 520 is used to execute the following computer-executable instructions to implement the steps of the anomaly detection method.

[0212] The above is an illustrative scheme of a computing device according to this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the above-described anomaly detection method belong to the same concept. For details not described in detail in the technical solution of the computing device, please refer to the description of the technical solution of the above-described anomaly detection method.

[0213] An embodiment of this specification also provides a computer-readable storage medium storing computer instructions that, when executed by a processor, are used to implement the steps of the anomaly detection method.

[0214] The above is an illustrative embodiment of a computer-readable storage medium. It should be noted that the technical solution of this storage medium and the technical solution of the above-described anomaly detection method belong to the same concept. Details not described in detail in the technical solution of the storage medium can be found in the description of the technical solution of the above-described anomaly detection method.

[0215] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0216] The computer instructions include computer program code, which may be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium may be appropriately added to or subtracted according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media may not include electrical carrier signals and telecommunication signals.

[0217] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments in this specification are not limited to the described order of actions, because according to the embodiments in this specification, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments in this specification.

[0218] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0219] The preferred embodiments disclosed above are merely illustrative of this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the embodiments described herein. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the embodiments, thereby enabling those skilled in the art to better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.

Claims

1. An anomaly detection method, comprising: Obtain the list of log files and system status data of the objects to be detected within the time interval to be detected; A log status distribution sequence is generated based on log data from at least two business categories in the log file list, and a system status distribution sequence is generated based on the correspondence between the system status data and the detection points. The log status distribution sequence is generated based on the log status codes determined from the log data of at least two business categories in the log file list, the number of log status codes, and the number of times the business processing interface is called. The log status distribution sequence and the system status distribution sequence are input into the anomaly detection model to score outliers, generating anomaly scores corresponding to the at least two business categories and system statuses. The anomaly detection result of the object to be detected is determined based on the anomaly score, the weights corresponding to the at least two business categories and the system status.

2. The anomaly detection method according to claim 1, wherein generating a log status distribution sequence based on log data of at least two business categories in the log file list includes: The number of log status codes is counted based on the log data, wherein the log status codes correspond to at least two business categories contained in the log file list; The number of times the business processing interface of the object to be tested is called is determined based on the log data; The log status distribution sequence is generated based on the log status codes, the number of log status codes, and the number of times the business processing interface is called.

3. The anomaly detection method according to claim 2, wherein counting the number of log status codes based on the log data includes: Based on the preset statistical dimensions of the log data statistics, the number of log status codes corresponding to the at least two business categories contained in the log file list.

4. The anomaly detection method according to claim 1 or 2, wherein generating the system state distribution sequence based on the correspondence between the system state data and time includes: Determine the correspondence between the system status data and the detection points; The system state data is aggregated according to a preset fixed-duration time window and the corresponding relationship to generate the system state distribution sequence.

5. The anomaly detection method according to claim 1, wherein determining the anomaly detection result of the object to be detected based on the anomaly score, the weights corresponding to the at least two business categories and the system state respectively, includes: Target business categories and target system states are filtered based on the anomaly scores, and the initial weights of the target business categories and target system states are obtained. The abnormal value of the object to be detected is calculated based on the initial weight, the abnormal score of the target business category and the target system state, and the abnormal value is used as the abnormal detection result of the object to be detected.

6. The anomaly detection method according to claim 1, wherein determining the anomaly detection result of the object to be detected based on the anomaly score, the weights corresponding to the at least two business categories and the system state respectively, includes: Target business categories and target system statuses are filtered based on the aforementioned anomaly scores; The correlation between the log state distribution sequence of the target business category and the system state distribution sequence of the target system state is determined by a time causal analysis algorithm. The initial weights of the target business category and the target system state are determined based on the degree of correlation. The abnormal value of the object to be detected is calculated based on the initial weight, the target business category, and the abnormal score of the target system state, and the abnormal value is used as the abnormal detection result of the object to be detected.

7. The anomaly detection method according to claim 5 or 6 further includes: Obtain the target business category corresponding to the target object whose detection result is abnormal, the reason for the abnormality and the number of abnormalities in the status feedback of the target system for the user; The initial weights of the target business category and the target system state are adjusted based on the cause of the anomaly and the number of anomalies.

8. The anomaly detection method according to claim 1, wherein generating a log state distribution sequence based on log data of at least two business categories in the log file list, and generating a system state distribution sequence based on the correspondence between the system state data and detection points, comprises: Log data from at least two business categories in the log file list are input into the data profiling model for processing to generate the log status distribution sequence; as well as, The system state data is input into the data profiling model for processing to generate the system state distribution sequence.

9. The anomaly detection method according to claim 8, wherein the data profiling model is trained in the following manner: Obtain the list of first historical log files within the first historical time interval and the first historical status data of the system status within the first historical time interval; A first historical log sequence is generated based on log data from at least two business categories in the first historical log file list, and a first historical state sequence of the system state is generated based on the correspondence between the first historical state data and the detection points. The first historical log sequence and the first historical state sequence are used as sample data to train the data profiling model, thereby obtaining the data profiling model.

10. The anomaly detection method according to claim 1 or 8, further comprising: The log state distribution sequence and the system state distribution sequence are input into the data profiling model for data cleaning to obtain the standard distribution feature sequences corresponding to the at least two business categories and the state thresholds corresponding to the system state.

11. The anomaly detection method according to claim 10, wherein inputting the log state distribution sequence and the system state distribution sequence into the anomaly detection model for anomaly scoring includes: Obtain the list of second historical log files within the second historical time interval and the second historical status data of the system status within the second historical time interval; The log state distribution sequence, the system state distribution sequence, the standard distribution feature sequence, the state threshold, the second historical log file list, and the second historical state data are input into the anomaly detection model to score outliers.

12. An anomaly detection device, comprising: The acquisition module is configured to acquire a list of log files and system status data of the objects to be detected within the time interval to be detected. The generation module is configured to generate a log status distribution sequence based on log data from at least two business categories in the log file list, and to generate a system status distribution sequence based on the correspondence between the system status data and the detection points. The log status distribution sequence is generated based on the log status codes determined from the log data of at least two business categories in the log file list, the number of log status codes, and the number of times the business processing interface is called. The scoring module is configured to input the log state distribution sequence and the system state distribution sequence into the anomaly detection model to score outliers and generate anomaly scores corresponding to the at least two business categories and system states. The determination module is configured to determine the anomaly detection result of the object to be detected based on the anomaly score, the weights corresponding to the at least two business categories and the system state, respectively.

13. A computing device, comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the steps of the anomaly detection method according to any one of claims 1 to 11.

14. A computer-readable storage medium storing computer instructions that, when executed by a processor, implement the steps of the anomaly detection method according to any one of claims 1 to 11.

15. A computer program product, characterized in that, It includes computer instructions that, when executed by a processor, implement the steps of the anomaly detection method according to any one of claims 1 to 11.

Citation Information

Patent Citations

  • Log-based system fault prediction method, apparatus and device

    CN110955586A

  • System anomaly detection method and system based on depth log sequence analysis

    CN111930903A