Risk checking method and device, storage medium and electronic equipment

By deploying inspection scripts suitable for different types in a server cluster, the execution and filtering of abnormal results are automated, solving the problem of time-consuming manual screening and sorting in existing technologies, and achieving efficient and accurate risk inspection.

CN115454775BActive Publication Date: 2026-02-13CHINA CONSTRUCTION BANK
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211156253.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-22
Publication Date
2026-02-13
Estimated Expiration
2042-09-22

AI Technical Summary

Technical Problem

The existing risk inspection process requires manual screening and sorting of a large number of inspection results, which is time-consuming, inefficient and prone to errors, especially when dealing with a large number of servers, making it difficult to quickly obtain the effective information that needs to be processed.

Method used

A risk inspection method and apparatus are provided, which automatically executes inspection operations, collects inspection results, and automatically processes abnormal results by deploying inspection scripts applicable to different server types and operating systems in a server cluster.

Benefits of technology

It eliminates the need for manual screening and sorting of inspection results, saving human resources, shortening inspection time, improving the accuracy of risk handling, avoiding human error, and is applicable to various types of servers and operating systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115454775B_ABST
    Figure CN115454775B_ABST
Patent Text Reader

Abstract

The application provides a risk checking method and device, a storage medium and an electronic device. The method comprises the following steps: determining a server cluster, a plurality of checking items and a checking script corresponding to each checking item; deploying the checking script corresponding to each checking item to each server in the server cluster respectively, so that each server executes the checking script corresponding to each checking item; determining a checking result set corresponding to each server, wherein the checking result set corresponding to each server comprises a plurality of checking results; determining a checking result indicating an abnormality in all checking result sets as an abnormal checking result; judging whether each abnormal checking result meets a preset filtering condition, and determining an abnormal checking result not meeting the filtering condition as a target checking result; and performing risk processing on each target checking result. By using the method of the application, the automatic screening of checking results can be realized, the human resources can be saved, and the time consumption of risk checking work can be shortened.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of system health check, in particular to a risk check method and device, a storage medium and an electronic device. BACKGROUND

[0002] A data center is one of important components in an information system of a financial institution and is a cornerstone for the financial institution to provide services externally. A server is one of basic resources of the data center, and guaranteeing safe and stable operation of the server is also an important work in an operation and maintenance process.

[0003] In the operation and maintenance process, risk check on the server is one of main operation and maintenance measures, and the risk check refers to evaluation on some indexes of the server to determine a risk condition, that is, a health state of the server. At present, an operation and maintenance personnel usually runs a check script for the server on the server at regular time, obtains check results of each check item, and manually screens and analyzes the check results to determine which items need to be processed.

[0004] However, in an actual business scenario, due to business expansion, disaster recovery system construction, localization popularization and other reasons, the demand for basic resources of the data center is increasing, and the number of servers faced by the operation and maintenance personnel is very large. Based on the existing risk check mode, the operation and maintenance personnel needs to manually screen and analyze a large number of check results of a large number of servers, which needs to consume a large amount of time and is prone to omissions. In addition, when the check script is changed, it also needs to be manually configured to the corresponding server, which also needs to consume a large amount of human resources. SUMMARY

[0005] Therefore, the embodiments of the present application provide a risk check method to solve the problems that a large number of check results need to be manually screened and analyzed, time-consuming, low efficiency and prone to omissions in the existing risk check process.

[0006] The embodiments of the present application also provide a risk check device to ensure implementation and application of the above method in practice.

[0007] To achieve the above object, the embodiments of the present application provide the following technical scheme:

[0008] A risk check method comprises the following steps:

[0009] In the case of needing to perform risk check, a server cluster is determined, and the server cluster comprises at least one server;

[0010] determine a plurality of check items corresponding to the server cluster and a check script corresponding to each of the check items, wherein the check script corresponding to each of the check items is used to perform a risk checking operation corresponding to the check item according to a server type and an operating system type of a server executing the check script;

[0011] deploy the check script corresponding to each of the check items to each server in the server cluster respectively, so that each of the servers executes the check script corresponding to each of the check items;

[0012] determine a check result set corresponding to each of the servers, wherein the check result set corresponding to each of the servers includes a plurality of check results corresponding to the check items respectively;

[0013] determine an abnormal check result from all the check result sets, wherein the abnormal check result represents an abnormality;

[0014] determine whether each of the abnormal check results meets a preset filtering condition, and determine an abnormal check result that does not meet the filtering condition as a target check result;

[0015] perform a risk processing on each of the target check results, and complete the risk checking process.

[0016] Optionally, the method further includes:

[0017] determine a current daily checking task, wherein the current daily checking task is a pre-created timing checking task;

[0018] determine a server corresponding to the current daily checking task, and group the server corresponding to the current daily checking task into the server cluster.

[0019] Optionally, the method further includes:

[0020] determine a current change checking task, wherein the current change checking task is a checking task created in response to a server change operation;

[0021] determine a server corresponding to the current change checking task, and group the server corresponding to the current change checking task into the server cluster.

[0022] Optionally, the method further includes:

[0023] For each of the abnormal check result, judge whether there is a filtering rule matched with the abnormal check result in a plurality of filtering rules set in advance, if there is no filtering rule matched with the abnormal check result in the plurality of filtering rules, determine that the abnormal check result does not meet the filtering condition.

[0024] The method, optionally, the risk processing of each of the target check result comprises:

[0025] For each of the target check result, judge whether there is a processing task matched with the target check result in a plurality of processing tasks created in advance, if there is no processing task matched with the target check result in the plurality of processing tasks, determine the target check result as a to-be-processed check result;

[0026] Determine the priority corresponding to each of the to-be-processed check result;

[0027] According to the priority corresponding to each of the to-be-processed check result, determine the processing operation corresponding to each of the to-be-processed check result;

[0028] Execute each of the processing operation to create the processing task corresponding to each of the to-be-processed check result.

[0029] The method, optionally, the determination of the priority corresponding to each of the to-be-processed check result comprises:

[0030] For each of the to-be-processed check result, determine the check item corresponding to the to-be-processed check result, and take the preset priority corresponding to the check item as the priority corresponding to the to-be-processed check result.

[0031] The method, optionally, further comprises:

[0032] If there is a processing task matched with the target check result in the plurality of processing tasks, determine the processing task matched with the target check result in the plurality of processing tasks as the processing task corresponding to the target check result.

[0033] A risk check device, comprising:

[0034] A first determination unit is configured to determine a server cluster including at least one server in a case where risk check is needed;

[0035] A second determination unit is configured to determine a plurality of check items corresponding to the server cluster and a check script corresponding to each of the check items; the check script corresponding to each of the check items is configured to perform a risk check operation corresponding to the check item according to a server type and an operating system type of a server executing the check script;

[0036] a deployment unit, configured to deploy each of the inspection scripts corresponding to each of the inspection items to each of the servers in the server cluster respectively, so that each of the servers executes the inspection script corresponding to each of the inspection items;

[0037] a third determination unit, configured to determine a set of inspection results corresponding to each of the servers, wherein the set of inspection results corresponding to each of the servers comprises a plurality of inspection results corresponding to the server, and the plurality of inspection results correspond to each of the inspection items one by one;

[0038] a fourth determination unit, configured to determine, from all the sets of inspection results, an inspection result representing an abnormality as an abnormal inspection result;

[0039] a judgment unit, configured to determine whether each of the abnormal inspection results meets a preset filtering condition, and determine an abnormal inspection result that does not meet the filtering condition as a target inspection result;

[0040] a processing unit, configured to perform risk processing on each of the target inspection results, and complete the current risk inspection process.

[0041] A storage medium, comprising stored instructions, wherein the instructions, when executed, control a device in which the storage medium is located to perform the risk inspection method as described above.

[0042] An electronic device, comprising a memory, and one or more instructions, wherein the one or more instructions are stored in the memory and configured to be executed by one or more processors to perform the risk inspection method as described above.

[0043] Based on the risk checking method provided by the embodiment of the present application, when risk checking is needed, the server cluster, each checking item and the checking script corresponding to each checking item are determined; the checking script corresponding to each checking item is used to perform the risk checking operation corresponding to the checking item according to the server type and the operating system type of the server executing the checking script; the checking script corresponding to each checking item is respectively deployed to each server in the server cluster, so that each server executes the checking script corresponding to each checking item; the checking result set corresponding to each server is determined, and each checking result in each checking result set corresponds to each checking item one by one; the checking result representing an abnormality in all checking result sets is determined as an abnormal checking result; it is judged whether each abnormal checking result meets the preset filtering condition, and the abnormal checking result not meeting the filtering condition is determined as a target checking result; and the risk processing is performed on each target checking result. By applying the method provided by the embodiment of the present application, when the server cluster needs to be checked, the risk checking system can deploy the checking script to each server, so that the server executes the checking script to obtain the checking result. The checking script can be applied to various servers based on different operating systems. When the checking script needs to be changed, the change can be made in the risk checking system, without the need for the operation and maintenance personnel to configure each server, so that the human resources can be saved. After the server completes the risk checking operation, the risk checking system can collect all checking results of all servers, filter the checking result representing an abnormality based on the preset filtering condition, and process the abnormal checking result obtained by filtering. The checking result of the server does not need to be manually screened and sorted, so that the human resources can be saved, the time consumption of the risk checking work is shortened, and the accuracy of the risk processing is improved. BRIEF DESCRIPTION OF DRAWINGS

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only embodiments of the present application, and for those skilled in the art, other drawings can be obtained without creative labor based on the provided drawings.

[0045] Figure 1 A method flowchart of a risk checking method provided by the embodiment of the present application;

[0046] Figure 2 Another method flowchart of a risk checking method provided by the embodiment of the present application;

[0047] Figure 3 An example diagram of a risk checking process provided by the embodiment of the present application;

[0048] Figure 4 A structural schematic diagram of a risk checking device provided by an embodiment of the present application is shown in FIG. 1.

[0049] Figure 5 A structural schematic diagram of an electronic device provided by an embodiment of the present application is shown in FIG. 2. DETAILED DESCRIPTION

[0050] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts fall within the scope of the present application.

[0051] In the present application, the terms “comprising”, “containing” or any other variant thereof are intended to cover non-exclusive containing, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such a process, method, article or device. Without more limitations, the element defined by the sentence “including a…” does not exclude the presence of another identical element in the process, method, article or device including the element.

[0052] As known from the background, currently, an operation and maintenance personnel needs to deploy a checking script for checking a server to the server to perform risk checking and obtain a checking result. In an actual risk checking scenario, due to the fact that the checking script is difficult to cover all special situations, not all checking results of abnormal checking items are required to be processed, and for some servers in some scenarios, the system state corresponding to an abnormal checking result is actually not really abnormal. Therefore, the operation and maintenance personnel usually needs to manually sort and screen a large number of checking results to determine the checking results that need to be processed, which consumes a large amount of time, and when the operation and maintenance personnel faces tens of thousands of abnormal checking results of hundreds of servers, it is difficult to quickly obtain effective information required to be processed from the tens of thousands of abnormal checking results, and high-risk items are likely to be ignored, and it is difficult to distinguish which checking abnormalities are caused by normal system changes.

[0053] Therefore, the embodiments of the present application provide a risk checking method, which can realize unified deployment and execution of checking scripts through checking scripts suitable for multiple types of servers and multiple types of operating systems, and automatically screen all checking results, thereby saving a large amount of human resources and improving efficiency.

[0054] The embodiment of the present application provides a risk checking method, which can be applied to a risk checking system, a subject of execution of the method can be a server of the system, a method flowchart of the method is as shown in Figure 1

[0055] S101: in the case of needing to perform risk checking, determining a server cluster, the server cluster comprising at least one server;

[0056] In the method provided by the embodiment of the present application, the risk checking system can be constructed in advance, used for storing the pre-set checking script and the configuration checking task, and when the checking task is triggered, it is considered that the risk checking is needed. The checking task can be a timing checking task deployed in the daily inspection scene, or a checking task deployed for performing the risk checking in some special scene, for example, after some servers are changed, the risk checking needs to be performed on the servers, and the server subjected to the change operation can call the system service to create the corresponding checking task.

[0057] In the method provided by the embodiment of the present application, when the risk checking is needed, the server currently needing to perform the risk checking can be determined according to the current checking task, and the server currently needing to perform the risk checking is composed into a server cluster. The server cluster can only comprise one server, or can comprise multiple servers, which is determined by the server needing to perform the risk checking in the actual checking scene.

[0058] S102: determining a plurality of checking items corresponding to the server cluster and a checking script corresponding to each checking item; the checking script corresponding to each checking item is used for performing the risk checking operation corresponding to the checking item according to the server type and the operating system type of the server performing the checking script;

[0059] ​The method provided by the embodiment of the present application can define the check items related to system check in the risk check system in advance, and the dimensions of the check items include cluster, file system, network, disk, log, process, system security and the like. A corresponding check script is written for each check item, and the check script is stored in the risk check system, and the check script can be configured by shell language. According to the check requirement, a plurality of check items corresponding to the server cluster can be determined, that is, the check items related to the system check of each server in the server cluster. The check script corresponding to each check item is obtained. The check script corresponding to each check item is used for performing the risk check operation corresponding to the check item. Each check script can be applied to different server types and different operating system types, that is, when the check script is executed on the server to be checked, the risk check operation corresponding to the check item can be performed according to the server type and the operating system type of the server. The server types to which the check script is applicable include physical machines, virtual machines, bare metals and various server types, and the operating system types to which the check script is applicable include Redhat, OracleLinux, Centos, Kylin, UOS and various domestic operating systems (such as Kylin and UOS) and the like.

[0060] It should be noted that in the method provided by the embodiment of the present application, the check items related to each server in the server cluster are the same, and in the actual application scenario, the check items related to the servers deployed in the network can be different. In the scenario in which risk check is required, a check task can be created for the servers related to the same check items, so as to divide the servers related to the same check items into a server cluster, and the processing flow provided by the embodiment of the present application can be applied to each server cluster.

[0061] S103: The check script corresponding to each check item is respectively deployed to each server in the server cluster, so that each server executes the check script corresponding to each check item;

[0062] In the method provided by the embodiment of the present application, the check script corresponding to each check item is respectively deployed to each server through the proxy server, and the check script corresponding to each check item is executed in each server. When each server executes the check script, the operating system and the server type of the current server can be judged in the execution process of the check script, and the corresponding operation is executed according to the judgment result. After the risk check operation corresponding to the check item is completed, each server can obtain the check result corresponding to each check item.

[0063] S104: A check result set corresponding to each server is determined, and the check result set corresponding to each server includes a plurality of check results corresponding to the server, and the plurality of check results correspond to each check item one by one.

[0064] In the method provided by the embodiment of the present application, the risk checking system can collect the checking result corresponding to each checking item obtained in each server to form a checking result set by collecting the checking result of each server. Each checking result set contains the checking result of each checking item corresponding to the server. Each checking result contains a state parameter representing the good or bad state of the system corresponding to the checking item. The specific content can be that the system state is abnormal or normal. The checking result also contains some checking-related data content.

[0065] S105: Determine the checking result representing the abnormality in all the checking result sets as an abnormal checking result;

[0066] In the method provided by the embodiment of the present application, all the checking results in all the collected checking result sets can be screened, and the checking result representing the abnormality is regarded as an abnormal checking result. The abnormal checking result is the checking result representing the abnormality of the system state corresponding to the server and the checking item.

[0067] S106: Determine whether each abnormal checking result meets a preset filtering condition, and determine the abnormal checking result not meeting the filtering condition as a target checking result;

[0068] In the method provided by the embodiment of the present application, the filtering condition can be set in advance according to the actual filtering requirement, and the filtering condition is used to indicate under which condition the abnormal checking result needs to be filtered, that is, does not need to be processed. For each abnormal checking result, it is determined whether the abnormal checking result meets the preset filtering condition, that is, whether the abnormal checking result needs to be filtered. If the abnormal checking result does not need to be filtered, the abnormal checking result is regarded as a target checking result.

[0069] S107: Perform risk processing on each target checking result to complete the current risk checking process.

[0070] In the method provided by the embodiment of the present application, each target checking result can be processed based on a preset risk processing mode. The risk processing on the target checking result means that the abnormal system state represented by the target checking result is excluded. The specific processing mode is, for example, sending a risk prompt corresponding to the target checking result in the front end to prompt the user to process immediately, or generating a processing work order corresponding to the target checking result and sending the processing work order to a designated operation and maintenance personnel to instruct the designated operation and maintenance personnel to process the target checking result.

[0071] Based on the method provided in the embodiments of the present application, in the case of needing to perform risk checking, the server cluster is determined; a plurality of checking items corresponding to the server cluster and a checking script corresponding to each checking item are determined; the checking script corresponding to each checking item is used to perform a risk checking operation corresponding to the checking item according to the server type and the operating system type of the server executing the checking script; the checking script corresponding to each checking item is respectively deployed to each server in the server cluster, so that each server executes the checking script corresponding to each checking item; a checking result set corresponding to each server is determined, and the checking result set corresponding to each server includes a plurality of checking results corresponding to the server; in all checking result sets, the checking result representing an abnormality is determined as an abnormal checking result; it is judged whether each abnormal checking result meets a preset filtering condition, and the abnormal checking result not meeting the filtering condition is determined as a target checking result; each target checking result is subjected to risk processing, and the current risk checking process is completed. When the server cluster needs to be subjected to risk checking, the method provided in the embodiments of the present application can deploy the checking script to each server through the risk checking system, so that the server executes the checking script to obtain the checking result. The checking script can be applied to various servers based on different operating systems. When the checking script needs to be changed, the change can be made in the risk checking system, without the need for an operation and maintenance personnel to configure each server, so that human resources can be saved. After the server completes the risk checking operation, the risk checking system can collect all checking results of all servers, filter the checking result representing an abnormality based on a preset filtering condition, and process the abnormal checking result obtained by filtering. The checking result of the server does not need to be manually screened and sorted, so that human resources can be saved, the time consumption of the risk checking work is shortened, and it is beneficial to avoid human errors and improve the accuracy of risk processing.

[0072] In Figure 1 Based on the method shown, in the method provided in the embodiments of the present application, the process of determining the server cluster in step S101 includes:

[0073] The current routine checking task is determined, and the current routine checking task is a pre-created timing checking task;

[0074] In the method provided in the embodiments of the present application, the risk checking is performed in the scene of routine inspection, that is, the risk checking is performed on all servers deployed in the network. Specifically, a routine checking task can be pre-created, and the task is a timing checking task. When a predetermined time point is reached, the checking process corresponding to the routine checking task is executed. In the routine checking task, the object (that is, the server) performing the checking, the checking item, and the time can be configured. When the risk checking needs to be performed, the current routine checking task that needs to be executed can be determined.

[0075] Determine the servers corresponding to the current routine check task, and form the server cluster by the servers corresponding to the current routine check task.

[0076] In the method provided by the embodiment of the present application, the servers that need to perform the check are determined according to the task content of the current routine check task, and the servers that need to perform the check set in the current routine check task are formed into the server cluster.

[0077] Further, in the method shown in the figure, the process of determining the server cluster in step S101 comprises: Figure 1 In the method provided by the embodiment of the present application, the process of determining the server cluster in step S101 comprises:

[0078] Determine the current change check task, wherein the current change check task is a check task created in response to a server change operation;

[0079] In the method provided by the embodiment of the present application, the server can be configured in advance to trigger the risk check actively after the change operation is performed, that is, to call the service of the risk check system. The change operation refers to an operation that changes the server, such as changing the system configuration, installing new software, restarting, etc. When a server in the network performs the change operation, the service can be called to create the change check task.

[0080] In the method provided by the embodiment of the present application, the risk check is performed in the scenario where the server changes, and the check task created in response to the server change operation is determined as the current change check task when the risk check is needed.

[0081] Determine the servers corresponding to the current change check task, and form the server cluster by the servers corresponding to the current change check task.

[0082] In the method provided by the embodiment of the present application, the server that has performed the change operation is formed into the server cluster.

[0083] In the method shown in the figure, the process of determining the server cluster in step S101 comprises: Figure 1 In the method provided by the embodiment of the present application, the process of determining the server cluster in step S101 comprises:

[0084] For each of the abnormal check results, it is determined whether there is a filtering rule matched with the abnormal check result in the plurality of filtering rules set in advance. If there is no filtering rule matched with the abnormal check result in the plurality of filtering rules, it is determined that the abnormal check result does not meet the filtering condition.

[0085] The method provided by the embodiment of the present application can set multiple filtering rules according to actual filtering requirements, and the dimensions involved can include an operating system, a server host (i.e., a specific server), a check item and a check result. Specifically, all hosts of certain application systems can be filtered, hosts with problems in certain checks but needing time window processing or being about to be offline can be filtered, a certain check item of a certain host can be filtered, and check results containing certain keywords can be filtered. For example, filtering rule 1 is to filter all check results of servers of application operating system A, filtering rule 2 is to filter check results of check item C of server B, and filtering rule 3 is to filter check results containing keyword D.

[0086] In order to better illustrate the method provided by the embodiment of the present application, the embodiment of the present application provides another risk checking method, which is based on the method shown in Figure 1 Figure 2 The flowchart shown in the embodiment of the present application, in the method provided by the embodiment of the present application, the process of performing risk processing on each target check result in step S107 includes:

[0087] S201: For each target check result, it is judged whether there is a processing task matching the target check result in the multiple pre-created processing tasks, and if there is no processing task matching the target check result in the multiple processing tasks, the target check result is determined as a to-be-processed check result.

[0088] In the method provided by the embodiment of the present application, in the daily routine inspection scenario, a risk check can be performed on all servers at a predetermined time point every day, and when an abnormal check result corresponding to a certain check item is processed for the first time, a processing task corresponding to the abnormal check result is created, so there are multiple pre-created processing tasks in the risk checking system.

[0089] In the method provided by the embodiment of the present application, in the current risk checking process, each target check result can be matched with each pre-created processing task, and if each processing task does not match the current check result, the check result is taken as a to-be-processed check result. Matching the target check result with the processing task means judging whether the target check result and the check result corresponding to the processing task are the same, that is, judging whether the same check result (the same conclusion is obtained for the same server and the same check item) as the target check result has been checked in the previous risk checking process and has been processed.

[0090] S202: Determine the priority corresponding to each to-be-processed check result.

[0091] ​In the method provided by this invention, the priority of each inspection result to be processed can be determined according to a preset priority setting method. For example, the priority can be set according to the server type, the application's operating system, and so on.

[0092] S203: Determine the processing operation corresponding to each of the pending inspection results based on the priority of each of the pending inspection results;

[0093] In the method provided by this invention, various priority levels and their corresponding processing methods can be pre-set. For example, a high priority level corresponds to a direct reminder processing method, while a low priority level corresponds to a transfer to a designated person for processing. The processing method for each pending inspection result can be determined based on its priority, thereby determining the specific processing operation. For example, pending inspection result A corresponds to a high priority, and pending inspection result B corresponds to a low priority. The processing method for pending inspection result A is direct reminder processing, and the processing method for pending inspection result B is transfer to a designated person for processing. Therefore, the processing operation for pending inspection result A can be determined as issuing a risk handling prompt for pending inspection result A at the front end, and the processing operation for pending inspection result B can be determined as generating a processing work order for pending inspection result B and sending the work order to the designated person.

[0094] S204: Execute each of the aforementioned processing operations to create a processing task corresponding to each of the pending inspection results.

[0095] In the method provided by the embodiments of the present invention, a processing operation corresponding to each inspection result to be processed can be executed. After the processing operation is executed, a processing task corresponding to the inspection result to be processed can be automatically created in the system, and relevant operation and maintenance personnel can update the progress of the processing task.

[0096] Based on the method provided in the above embodiments, the method provided in this embodiment of the invention, wherein the process of determining the priority corresponding to each of the inspection results to be processed mentioned in step S202 includes:

[0097] For each inspection result to be processed, the inspection item corresponding to the inspection result to be processed is determined, and the preset priority corresponding to the inspection item is used as the priority corresponding to the inspection result to be processed.

[0098] In the method provided by this embodiment of the invention, the priority of each inspection item is preset. The priority of the inspection item corresponding to each inspection result to be processed is used as the priority of each result to be processed.

[0099] Furthermore, in Figure 2 Based on the method shown, the method provided in this embodiment of the invention further includes:

[0100] If there is a processing task matching the target check result in the plurality of processing tasks, the processing task matching the target check result in the plurality of processing tasks is determined as the processing task corresponding to the target check result.

[0101] In the method provided by the embodiment of the present application, if a processing task matching a target check result exists in the processing tasks created in advance during the judgment in step S201, the processing task is used as the processing task corresponding to the target check result, and the processing progress of the processing task is used as the processing progress of the target check result.

[0102] In order to better illustrate the method provided by the embodiment of the present application, another risk check method is provided in combination with an actual application scenario. The method provided by the embodiment of the present application can be implemented by a risk check system, which is an instantiation of the method shown in the figure, and mainly includes a definition module, a check module, a filtering module and a processing module. Figure 1 The definition module is mainly used for defining system check related index items (check items), including a cluster, a file system, a network, a disk, a log, a process, system security and the like, and corresponding scripts are written for each check item. The check script is implemented by a shell, is adapted to different types of servers and operating systems, is uploaded to a management platform, and is subjected to version management, that is, storage and modification of the check script rely on the management platform. Meanwhile, the check items are divided into priorities for subsequent disposal.

[0103] The check module is mainly used for implementing check task deployment and check result acquisition. The check task deployment needs to clearly indicate the object, check item and time of performing the check, and the check result acquisition mainly includes script deployment, script execution and then collection of the check result on the corresponding host (server) through a proxy server. In a daily inspection scene, the management platform will regularly issue scripts to all hosts to perform tasks. The system collects the results from the management platform, filters and performs subsequent processing operations on all host check results. In a change scene, the current check operation is added in the change process, and the check script is issued after the change is completed. The check item result of each check item of the current changed host is obtained by executing the script, and it is judged whether processing is needed, that is, after the change operation, the check module can be directly called to evaluate the system state after the change, and the risk is directly processed.

[0104] The check module is mainly used for implementing check task deployment and check result acquisition. The check task deployment needs to clearly indicate the object, check item and time of performing the check, and the check result acquisition mainly includes script deployment, script execution and then collection of the check result on the corresponding host (server) through a proxy server. In a daily inspection scene, the management platform will regularly issue scripts to all hosts to perform tasks. The system collects the results from the management platform, filters and performs subsequent processing operations on all host check results. In a change scene, the current check operation is added in the change process, and the check script is issued after the change is completed. The check item result of each check item of the current changed host is obtained by executing the script, and it is judged whether processing is needed, that is, after the change operation, the check module can be directly called to evaluate the system state after the change, and the risk is directly processed.

[0105] Filtering module, mainly used for setting n filtering rules according to actual demand, application system, host individual, checking item and output result of the host. After obtaining the checking result, filtering is carried out through regular matching, if the checking result matches the mth rule, the checking result is directly filtered without processing. The remaining result after filtering is continuously processed.

[0106] Processing module, which saves the previous abnormal item into the database, firstly judges whether the abnormal item in this time is new or not, if it is the existing abnormal item, the previous processing progress is synchronized, if it is the new abnormal item, according to the priority set in the definition module, the abnormal item with high priority is listed for processing, and the abnormal item without high priority is assigned to the designated person for processing.

[0107] Reference Figure 3 As shown in the example diagram, the risk processing process provided by the embodiment of the application mainly includes:

[0108] Starting risk checking;

[0109] Deploying checking task;

[0110] Obtaining checking result;

[0111] Judging whether the result is abnormal or not, if the result is not the checking result indicating abnormality, filtering is carried out;

[0112] For each checking result indicating abnormality, judging whether the system to which the checking result corresponds triggers rule 1 or not, that is, judging whether the system is the system defined in rule 1 which needs to filter the result, if yes, the checking result is filtered, if no, the matching of the subsequent rule is entered;

[0113] Judging whether the host to which the checking result corresponds triggers rule 2 or not, that is, judging whether the host is the host defined in rule 2 which needs to filter the result, if yes, the checking result is filtered, if no, the matching of the subsequent rule is entered;

[0114] Similarly, the checking result is matched with each rule in the preset n rules, if the checking result matches a rule, the checking result is filtered;

[0115] For the checking result left after filtering, judging whether the checking result is the new abnormal item or not, that is, judging whether the checking item represented by the checking result is the new abnormal checking item or not, if not, the previous processing progress is synchronized;

[0116] For the new abnormal checking item, the priority of the checking item is determined, and whether the checking item is the high priority is judged, for the abnormal checking item with high priority, the user is prompted to process immediately through the front end, for the abnormal checking item without high priority, the designated person is assigned to process.

[0117] The method provided by the embodiments of the present application can perform risk checking on multi-version operating systems, and can actively and efficiently find a large number of risks that need to be solved in servers and perform disposal, thereby improving the automatic processing capability. For operations such as change operations that may cause risks, risk checking tasks can be performed after the change to judge the health degree of the current system.

[0118] With Figure 1 Corresponding to the risk checking method shown in Figure 1 The specific implementation of the method shown in Figure 4 The structure diagram is as shown in

[0119] The first determination unit 301 is configured to determine a server cluster in the case of needing to perform risk checking, wherein the server cluster includes at least one server.

[0120] The second determination unit 302 is configured to determine a plurality of checking items corresponding to the server cluster and a checking script corresponding to each checking item, wherein the checking script corresponding to each checking item is used to perform a risk checking operation corresponding to the checking item according to a server type and an operating system type of a server executing the checking script.

[0121] The deployment unit 303 is configured to deploy the checking script corresponding to each checking item to each server in the server cluster respectively, so that each server executes the checking script corresponding to each checking item.

[0122] The third determination unit 304 is configured to determine a checking result set corresponding to each server, wherein the checking result set corresponding to each server includes a plurality of checking results corresponding to the server, and the plurality of checking results correspond to each checking item one by one.

[0123] The fourth determination unit 305 is configured to determine a checking result indicating an abnormality in all the checking result sets as an abnormal checking result.

[0124] The judgment unit 306 is configured to judge whether each abnormal checking result meets a preset filtering condition, and determine an abnormal checking result that does not meet the filtering condition as a target checking result.

[0125] The processing unit 307 is configured to perform risk processing on each target checking result, and complete the current risk checking process.

[0126] The device provided by the embodiment of the present application can deploy the check script to each server through the risk checking system when the server cluster needs to be checked, so that the server executes the check script to obtain the check result. The check script can be applied to various servers based on different operating systems. When the check script needs to be changed, the change can be made in the risk checking system, and the operation and maintenance personnel do not need to configure each server, which can save human resources. After the server completes the risk checking operation, the risk checking system can collect all the check results of all the servers, filter the check results representing the exception based on the preset filtering condition, and process the abnormal check result obtained by filtering. The check result of the server does not need to be screened and combed manually, which can save human resources, shorten the time consumption of the risk checking work, and is beneficial to avoiding human errors and improving the accuracy of risk processing.

[0127] On the basis of the device provided by the above embodiment, the device provided by the embodiment of the present application comprises the first determination unit 301, which comprises:

[0128] The first determination subunit is configured to determine the current routine checking task, and the current routine checking task is a pre-created timing checking task.

[0129] The second determination subunit is configured to determine the servers corresponding to the current routine checking task, and group the servers corresponding to the current routine checking task into the server cluster.

[0130] On the basis of the device provided by the above embodiment, the device provided by the embodiment of the present application comprises the first determination unit 301, which comprises:

[0131] The third determination subunit is configured to determine the current change checking task, and the current change checking task is a checking task created in response to a server change operation.

[0132] The fourth determination subunit is configured to determine the server corresponding to the current change checking task, and group the server corresponding to the current change checking task into the server cluster.

[0133] On the basis of the device provided by the above embodiment, the device provided by the embodiment of the present application comprises the judgment unit 306, which comprises:

[0134] The first judgment subunit is configured to determine, for each abnormal check result, whether there is a filtering rule matched with the abnormal check result in the plurality of pre-set filtering rules. If there is no filtering rule matched with the abnormal check result in the plurality of filtering rules, it is determined that the abnormal check result does not meet the filtering condition.

[0135] On the basis of the device provided in the above embodiment, the device provided in the embodiment of the present application comprises the processing unit 307, which comprises:

[0136] The second judging sub-unit is configured to judge, for each target inspection result, whether there is a processing task matching the target inspection result in the plurality of processing tasks, and determine the target inspection result as a to-be-processed inspection result if there is no processing task matching the target inspection result in the plurality of processing tasks.

[0137] The fifth determining sub-unit is configured to determine the priority corresponding to each to-be-processed inspection result.

[0138] The sixth determining sub-unit is configured to determine the processing operation corresponding to each to-be-processed inspection result according to the priority corresponding to each to-be-processed inspection result.

[0139] The executing sub-unit is configured to execute each processing operation to create a processing task corresponding to each to-be-processed inspection result.

[0140] On the basis of the device provided in the above embodiment, the device provided in the embodiment of the present application comprises the fifth determining sub-unit, which comprises:

[0141] The seventh determining sub-unit is configured to determine, for each to-be-processed inspection result, the inspection item corresponding to the to-be-processed inspection result, and take the preset priority corresponding to the inspection item as the priority corresponding to the to-be-processed inspection result.

[0142] On the basis of the device provided in the above embodiment, the device provided in the embodiment of the present application further comprises:

[0143] The eighth determining sub-unit is configured to determine, if there is a processing task matching the target inspection result in the plurality of processing tasks, the processing task matching the target inspection result in the plurality of processing tasks as the processing task corresponding to the target inspection result.

[0144] The embodiment of the present application further provides a storage medium, which comprises stored instructions, wherein the instructions are used to control the device where the storage medium is located to perform the risk inspection method as described above when the instructions are executed.

[0145] The embodiment of the present application further provides an electronic device, a structure diagram of which is shown in FIG. 4. Figure 5 The electronic device specifically comprises a memory 401 and one or more than one instruction 402, wherein the one or more than one instruction 402 is stored in the memory 401 and is configured to perform the one or more than one instruction 402 by the one or more than one processor 403 to perform the following operations:

[0146] In the case that the risk check needs to be performed, a server cluster is determined, the server cluster including at least one server;

[0147] A plurality of check items corresponding to the server cluster are determined, and a check script corresponding to each of the check items is determined, the check script corresponding to each of the check items being used to perform a risk check operation corresponding to the check item according to a server type and an operating system type of a server performing the check script;

[0148] The check script corresponding to each of the check items is respectively deployed to each of the servers in the server cluster, so that each of the servers performs the check script corresponding to each of the check items;

[0149] A check result set corresponding to each of the servers is determined, the check result set corresponding to each of the servers including a plurality of check results corresponding to the check items respectively;

[0150] An abnormal check result is determined from all the check result sets, the abnormal check result indicating an abnormality;

[0151] It is determined whether each of the abnormal check results meets a preset filtering condition, and an abnormal check result that does not meet the filtering condition is determined as a target check result;

[0152] A risk processing is performed on each of the target check results, and the risk check process is completed.

[0153] Each of the embodiments in the specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each of the embodiments mainly describes the difference from other embodiments. Especially, the system or the system embodiment is basically similar to the method embodiment, and thus is described more simply. The system and the system embodiment described above are merely illustrative, and the units described as separate components can be or can not be physically separated, and the components displayed as units can be or can not be physical units, that is, can be located in one place or can be distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiment according to actual needs. Those skilled in the art can understand and implement without creative labor.

[0154] Those skilled in the art will further realize that the mechanisms of the various examples described herein are capable of being implemented using any number of combinations of the described features. Accordingly, these examples are not limited to the mechanisms described herein, but rather, the intent is to cover all modifications and alternatives equivalent thereto. The preceding description of the examples is illustrative, and not restrictive. Many other examples will be apparent to those of skill in the art upon reviewing the above description. The scope of the examples should, therefore, be determined not with reference to the above description, but instead should be given to the appended claims, along with their full scope of equivalents.

[0155] The above description of disclosed examples is intended to be illustrative, and not restrictive. Many other examples will be apparent to those of skill in the art upon reviewing the above description. The scope of the examples should, therefore, be determined not with reference to the above description, but instead should be given to the appended claims, along with their full scope of equivalents.

Claims

1. A risk inspection method, characterized in that, include: When a risk check is required, determine the current change check task, which is a check task created in response to a server change operation, including modifying system configuration, installing new software, or restarting. Identify the server corresponding to the current change check task, and form a server cluster consisting of the servers corresponding to the current change check task, wherein the server cluster includes at least one server; Determine multiple check items corresponding to the server cluster and the check script corresponding to each check item; The inspection script corresponding to each inspection item is used to perform risk inspection operations corresponding to that inspection item based on the server type and operating system type of the server executing the inspection script; The inspection script corresponding to each inspection item is deployed to each server in the server cluster, so that each server executes the inspection script corresponding to each inspection item. Determine the set of inspection results corresponding to each server. The set of inspection results corresponding to each server includes multiple inspection results corresponding to that server. Each of the multiple inspection results corresponds to each of the inspection items. From the set of all the inspection results, the inspection results that indicate anomalies are identified as abnormal inspection results; Determine whether each of the anomaly check results meets the preset filtering conditions, and identify the anomaly check results that do not meet the filtering conditions as the target check results; Risk processing is performed on each of the target inspection results to complete this risk inspection process.

2. The method according to claim 1, characterized in that, The method further includes: Determine the current daily inspection task, which is a pre-created scheduled inspection task; Identify the servers corresponding to the current daily inspection task, and form the server cluster together with the servers corresponding to the current daily inspection task.

3. The method according to claim 1, characterized in that, The determination of whether each of the anomaly check results meets the preset filtering conditions includes: For each anomaly check result, it is determined whether there is a filter rule that matches the anomaly check result among the multiple preset filter rules. If there is no filter rule that matches the anomaly check result among the multiple filter rules, it is determined that the anomaly check result does not meet the filter conditions.

4. The method according to claim 1, characterized in that, The risk handling for each of the target inspection results includes: For each target inspection result, determine whether there is a processing task that matches the target inspection result among the multiple pre-created processing tasks. If there is no processing task that matches the target inspection result among the multiple processing tasks, then the target inspection result is determined as an inspection result to be processed. Determine the priority of each of the pending inspection results; Based on the priority of each pending inspection result, determine the corresponding processing operation for each pending inspection result; Perform each of the aforementioned processing operations to create a processing task corresponding to each of the aforementioned pending inspection results.

5. The method according to claim 4, characterized in that, Determining the priority of each of the pending inspection results includes: For each inspection result to be processed, the inspection item corresponding to the inspection result to be processed is determined, and the preset priority corresponding to the inspection item is used as the priority corresponding to the inspection result to be processed.

6. The method according to claim 4, characterized in that, Also includes: If among the plurality of processing tasks, there is a processing task that matches the target inspection result, then the processing task that matches the target inspection result among the plurality of processing tasks is determined as the processing task corresponding to the target inspection result.

7. A risk inspection device, characterized in that, include: The first determining unit is configured to determine the current change check task when a risk check is required, wherein the current change check task is a check task created in response to a server change operation, the change operation including modifying system configuration, installing new software, or restarting; determine the server corresponding to the current change check task, and form a server cluster consisting of the servers corresponding to the current change check task, wherein the server cluster includes at least one server. The second determining unit is used to determine multiple check items corresponding to the server cluster and check scripts corresponding to each check item. The inspection script corresponding to each inspection item is used to perform risk inspection operations corresponding to that inspection item based on the server type and operating system type of the server executing the inspection script; The deployment unit is used to deploy the inspection script corresponding to each inspection item to each server in the server cluster, so that each server executes the inspection script corresponding to each inspection item. The third determining unit is used to determine the inspection result set corresponding to each of the servers. The inspection result set corresponding to each server includes multiple inspection results corresponding to that server, and the multiple inspection results correspond one-to-one with each of the inspection items. The fourth determining unit is used to determine the inspection results that indicate the presence of anomalies from all the inspection result sets as abnormal inspection results; The judgment unit is used to determine whether each of the anomaly check results meets the preset filtering conditions, and to determine the anomaly check results that do not meet the filtering conditions as the target check results; The processing unit is used to perform risk processing on each of the target inspection results to complete the current risk inspection process.

8. A storage medium, characterized in that, The storage medium includes stored instructions, wherein, when the instructions are executed, the device in which the storage medium is located is controlled to perform the risk check method as described in any one of claims 1 to 6.

9. An electronic device, characterized in that, It includes a memory, and one or more instructions, wherein one or more instructions are stored in the memory and configured to be executed by one or more processors as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Cluster inspection system and method

    CN107395379A

  • Cloud server batch detection method, device and equipment and storage medium

    CN112433899A