An anomaly detection method and device, a terminal device, and a storage medium
By obtaining task configuration parameter sets from network devices and aggregating the data to generate a baseline configuration parameter set, the problem of detecting configuration errors of tasks to be executed synchronously in network devices is solved, and automated anomaly detection is achieved.
Patent Information
- Application Number
- CN202211083008.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-06
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2042-09-06
AI Technical Summary
In existing technologies, it is difficult to effectively detect configuration errors in network devices that are to be executed synchronously, which leads to the inability of tasks to be executed on schedule.
By acquiring task configuration parameter sets from multiple network devices, data aggregation is performed to generate a baseline configuration parameter set. Based on this set, anomaly detection information is determined to indicate whether the task configuration is abnormal.
It enables automated misconfiguration detection of tasks to be executed synchronously in network devices, improving detection efficiency and accuracy.
Smart Images

Figure CN115643172B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of anomaly detection, and particularly relates to an anomaly detection method and device, a terminal device and a storage medium. BACKGROUND
[0002] Enterprises often configure tasks to be executed synchronously for various network devices, for example, configure a computer or a server to execute a pre-configured task (such as backing up data or sending an email) at a certain time point (such as 3 o'clock in the morning every day or a certain time point on Sunday) in a relatively fixed period. However, during the configuration of the task to be executed synchronously, configuration errors may occur due to user input errors and the like, so that the task to be executed synchronously in a certain network device or certain network devices cannot be executed as scheduled. In summary, how to detect whether the task to be executed synchronously configured in each network device is incorrectly configured is a technical problem to be solved urgently. SUMMARY
[0003] The embodiments of the application provide an anomaly detection method and device, a terminal device and a storage medium, which can detect whether the task to be executed synchronously configured in each network device is incorrectly configured.
[0004] In a first aspect, the embodiments of the application provide an anomaly detection method, comprising:
[0005] obtaining a task configuration parameter group from each of a plurality of network devices; the plurality of network devices are configured with a task to be executed synchronously, the task to be executed synchronously corresponds to a plurality of task configuration items, and the task configuration parameter group contains task configuration parameters of each task configuration item;
[0006] performing data aggregation on the task configuration parameter group based on the task configuration item to obtain a baseline configuration parameter set, and the baseline configuration parameter set contains task configuration parameters of each task configuration item that meet a quantity proportion requirement;
[0007] determining anomaly detection information corresponding to the task to be executed synchronously based on the baseline configuration parameter set, and the anomaly detection information is used to indicate whether the task to be executed synchronously configured by each network device is configured abnormally.
[0008] In a second aspect, the embodiments of the application provide an anomaly detection device, comprising:
[0009] a parameter group obtaining module configured to obtain a task configuration parameter group from each of a plurality of network devices; the plurality of network devices are configured with a task to be executed synchronously, the task to be executed synchronously corresponds to a plurality of task configuration items, and the task configuration parameter group contains task configuration parameters of each task configuration item;
[0010] The aggregation module is configured to perform data aggregation on the task configuration parameter set based on the task configuration item, to obtain a baseline configuration parameter set, and the baseline configuration parameter set includes the task configuration parameter in each task configuration item that meets the quantity proportion requirement.
[0011] The information determination module is configured to determine abnormal detection information corresponding to the task to be synchronized and executed based on the baseline configuration parameter set, and the abnormal detection information is used to indicate whether the task to be synchronized and executed of each network device configuration is abnormal.
[0012] In a third aspect, an embodiment of the present application provides a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the abnormal detection method in the first aspect when executing the computer program.
[0013] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, and the computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the abnormal detection method in the first aspect.
[0014] In a fifth aspect, an embodiment of the present application provides a computer program product, and when the computer program product is executed on a terminal device, the terminal device executes the abnormal detection method in the first aspect.
[0015] Compared with the prior art, the embodiment of the present application has the beneficial effects that: the task configuration parameter set corresponding to the task to be synchronized and executed is obtained from multiple network devices; the task to be synchronized and executed corresponds to multiple task configuration items, and the task configuration parameter set includes the task configuration parameter of each task configuration item; data aggregation is performed on the task configuration parameter set based on the task configuration item, to obtain a baseline configuration parameter set including the task configuration parameter in each task configuration item that meets the quantity proportion requirement; and the abnormal detection information corresponding to the task to be synchronized and executed is determined based on the baseline configuration parameter set, and the abnormal detection information is used to indicate whether the task to be synchronized and executed configured by each network device is abnormal. The present application can detect whether the task to be synchronized and executed configured in each network device is error. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0017] Figure 1is a flowchart of an abnormality detection method according to an embodiment of the present application;
[0018] Figure 2 is a flowchart of an abnormality detection method according to another embodiment of the present application;
[0019] Figure 3 is a schematic structural block diagram of an abnormality detection apparatus according to an embodiment of the present application;
[0020] Figure 4 is a structural schematic diagram of a terminal device according to an embodiment of the present application. DETAILED DESCRIPTION
[0021] In the following description, for purposes of explanation and not limitation, specific details are set forth, such as particular sequences of steps, techniques, etc., in order to provide a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application can be practiced in other embodiments that depart from these specific details. In other instances, detailed descriptions of well-known methods, devices, circuits, and
[0022] It is to be understood that the terminology "includes", "has", "holds", "contains" and / or "comprising", when used in this specification and in the following claims, indicates the presence of the described features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0023] It is also to be understood that the terminology "and / or" when used in this specification and in the following claims, refers to at least one of the items, or any combination of one or more of the items, and includes all possible combinations of one or more of the items.
[0024] As used in this specification and in the claims, the term "if" can be interpreted as meaning "when", or "once", or "in response to a determination", or "in response to detecting", as appropriate, depending on the context. Similarly, the phrase "if determined", or "if detected [the described condition or event]" can be interpreted as meaning "once determined", or "in response to a determination", or "once detected [the described condition or event]", or "in response to detecting [the described condition or event]", as appropriate, depending on the context.
[0025] In addition, in the description of the specification and the appended claims, the terms "first", "second", "third", etc. are used only to distinguish descriptions, and cannot be understood as indicating or implying relative importance.
[0026] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0027] Example 1:
[0028] Please see Figure 1 , Figure 1 The illustration shows a schematic flow of an anomaly detection method provided in one embodiment of this application.
[0029] Step 101: Obtain task configuration parameter groups from multiple network devices respectively; each of the multiple network devices is configured with tasks to be executed synchronously, and each task to be executed synchronously corresponds to multiple task configuration items. The task configuration parameter group contains the task configuration parameters for each task configuration item.
[0030] Tasks to be executed synchronously can refer to tasks that will run at the same time, or they can refer to scheduled tasks. Scheduled tasks are a common system function that allows any script, program, or document to be scheduled to run at a convenient time. Specifically, tasks to be executed synchronously / scheduled tasks could be data backup tasks or email sending tasks that will run at a specific time.
[0031] Each network device may be configured with tasks to be executed synchronously at different task execution times. This application needs to obtain the task configuration parameter groups corresponding to the synchronous tasks with the same task execution time in each network device. For example, if network device A and network device B are both configured with a first task to be executed at a first time and a second task to be executed at a second time, this application can obtain the task configuration parameter groups corresponding to the first time and the task configuration parameter groups corresponding to the second time from network device A and network device B, respectively. Then, based on the task configuration parameter groups corresponding to the first time and the task configuration parameter groups corresponding to the second time, step 102 is performed, that is, based on the task configuration items, the task configuration parameter groups corresponding to the first time and the task configuration parameter groups corresponding to the second time are aggregated to obtain the baseline configuration parameter set corresponding to the first time and the baseline configuration parameter set corresponding to the second time.
[0032] In an optional embodiment, the task configuration parameter groups are respectively acquired from the plurality of network devices, including: acquiring a task configuration time of at least one to-be-synchronized execution task contained in each network device, and respectively acquiring, based on the task configuration time, the task configuration parameter group corresponding to the to-be-synchronized execution task with the same task execution time from the plurality of network devices.
[0033] In another optional embodiment, the task configuration parameter groups are respectively acquired from the plurality of network devices, including: acquiring a task index and / or a task identifier of at least one to-be-synchronized execution task contained in each network device, and respectively acquiring, based on the task index and / or the task identifier, the task configuration parameter group corresponding to the to-be-synchronized execution task with the same task execution time from the plurality of network devices. It should be noted that the task index and / or the task identifier corresponding to the same to-be-synchronized execution task executed at different task execution times are different.
[0034] Optionally, the plurality of task configuration items corresponding to the to-be-synchronized execution task can include a task execution time configuration item and a task execution instruction configuration item, or can include a task execution time configuration item, a task execution instruction configuration item, and an instruction parameter configuration item. Wherein, the to-be-synchronized execution tasks are different, and the task configuration items corresponding thereto can be different, and each task configuration item corresponds to a task configuration parameter. For example, if the to-be-synchronized execution task is a data resetting task, the task configuration items corresponding thereto include a task execution time configuration item and a task execution instruction configuration item, wherein the task configuration parameter under the task execution instruction configuration item is used to instruct to reset the data; if the to-be-synchronized execution task is a data backup task, the task configuration items corresponding thereto include a task execution time configuration item, a task execution instruction configuration item, and an instruction parameter configuration item, wherein the task configuration parameter under the task execution instruction configuration item is used to instruct to backup the data, and the task configuration parameter under the instruction parameter configuration item is used to instruct to backup the data to where. It should be noted that the instruction parameter configuration item corresponding to the to-be-synchronized execution task can be multiple.
[0035] In step 102, based on the task configuration item, the task configuration parameter groups are data aggregated to obtain a baseline configuration parameter set, and the baseline configuration parameter set contains the task configuration parameter in each task configuration item meeting the quantity proportion requirement.
[0036] Generally, for the to-be-synchronized execution tasks configured in the plurality of network devices, the to-be-synchronized execution tasks configured correctly are the majority, and the to-be-synchronized execution tasks configured abnormally are the minority. Based on this, the task configuration parameter groups are data aggregated based on the task configuration item to obtain the baseline configuration parameter set.
[0037] In step 103, based on the baseline configuration parameter set, the abnormality detection information corresponding to the to-be-synchronized execution task is determined, and the abnormality detection information is used to indicate whether the to-be-synchronized execution task of each network device configuration is configured abnormally.
[0038] The present application considers that each baseline configuration parameter in the baseline configuration parameter set is a task configuration parameter of a correctly configured task configuration item, and therefore, the abnormality detection information can be determined based on the baseline configuration parameter set.
[0039] Optionally, based on the baseline configuration parameter set, the abnormality detection information corresponding to the to-be-synchronized execution task is determined, including: comparing the task configuration parameters in the task configuration parameter group corresponding to the to-be-synchronized execution task with the baseline configuration parameters under the corresponding task configuration item in the baseline configuration parameter set respectively; if the task configuration parameters in the task configuration parameter group are the same as the baseline configuration parameters under the corresponding task configuration item in the baseline configuration parameter set, first abnormality detection information is generated, and the first abnormality detection information is used to indicate that the to-be-synchronized execution task is correctly configured; otherwise, second abnormality detection information is generated, and the second abnormality detection information is used to indicate that the to-be-synchronized execution task is configured abnormally.
[0040] The first abnormality detection information is generated, including: obtaining a task identifier and a correctly configured identifier of the to-be-synchronized execution task; generating the first abnormality detection information according to the task identifier and the correctly configured identifier; and the correctly configured identifier can be a character, a symbol, a pattern, or the like, which can represent that the to-be-synchronized execution task is correctly configured.
[0041] In an optional embodiment, the second abnormality detection information is generated, including: obtaining a task identifier, an abnormal task configuration item, an abnormal task configuration parameter corresponding to the abnormal task configuration item, and a baseline configuration parameter corresponding to the abnormal task configuration item of the to-be-synchronized execution task; and generating the second abnormality detection information based on the task identifier, the abnormal task configuration item, the abnormal task configuration parameter, and the baseline configuration parameter corresponding to the abnormal task configuration item. In this way, the second abnormality detection information is generated, which can enable the user to more intuitively and conveniently understand the configuration error, and facilitate the user to determine to eliminate the configuration error.
[0042] In another optional embodiment, the second abnormality detection information is generated, including: obtaining a task identifier and a configuration error identifier of the to-be-synchronized execution task; and generating the second abnormality detection information according to the task identifier and the configuration error identifier; and the configuration error identifier can be a character, a symbol, a pattern, or the like, which can represent that the to-be-synchronized execution task is configured abnormally.
[0043] Optionally, after the second abnormality detection information is generated, the device identifier of the network device corresponding to the to-be-synchronized execution task is obtained, and the device identifier and the second abnormality detection information are sent to the user. The device identifier includes a device ID and / or a device location of the network device.
[0044] It should be noted that after the first abnormality detection information is generated, the device identifier and the first abnormality detection information can be sent to the user, or the device identifier and the first abnormality detection information can not be sent to the user.
[0045] The application obtains a task configuration parameter group corresponding to a to-be-synchronized execution task from each of a plurality of network devices; the to-be-synchronized execution task corresponds to a plurality of task configuration items, and the task configuration parameter group contains task configuration parameters of each task configuration item; based on the task configuration items, data aggregation is performed on the task configuration parameter group to obtain a baseline configuration parameter set containing task configuration parameters in each task configuration item that meet a quantity proportion requirement; and based on the baseline configuration parameter set, abnormality detection information corresponding to the to-be-synchronized execution task is determined to indicate whether the to-be-synchronized execution task configured by each network device is abnormal. The application can detect whether the to-be-synchronized execution task configured in each network device is incorrectly configured.
[0046] It should be understood that the size of the serial number of each step in the above embodiments does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the application.
[0047] Embodiment two:
[0048] Please refer to Figure 2 , Figure 2 The embodiment of the application provides an abnormality detection method.
[0049] Step 201, obtaining a task configuration parameter group from each of a plurality of network devices.
[0050] The related content in step 201 can be referred to the related description in step 101.
[0051] Step 202, based on the first task configuration item, selecting a target task configuration parameter group with the same task configuration parameters and the number of task configuration parameters in the target task configuration parameter group meeting a first proportion requirement from the task configuration parameter group, and determining the task configuration parameters of the first task configuration item in the target task configuration parameter group as the first target task configuration parameter.
[0052] Optionally, based on the first task configuration item, a target task configuration parameter group is selected from the task configuration parameter groups, the task configuration parameters of which are the same and the number proportion of which in the task configuration parameter groups meets the first proportion requirement, including: dividing the task configuration parameter groups with the same task configuration parameters under the first task configuration item into at least one parameter group set; and selecting the task configuration parameter groups contained in the parameter group set, the number proportion of which in all the task configuration parameter groups meets the first proportion requirement, as the target task configuration parameter group.
[0053] If the task configuration items corresponding to the tasks to be synchronously executed are two, the first task configuration item is any one of the two task configuration items; if the task configuration items corresponding to the tasks to be synchronously executed are N, N is an integer greater than 2, the first task configuration item is any N-1 of the N task configuration items.
[0054] Step 203, based on the target task configuration parameter group, a second target task configuration parameter under a second task configuration item is obtained, the task configuration parameters of which are the same and the number proportion of which in the target task configuration parameter group meets a second proportion requirement.
[0055] If the task configuration items corresponding to the tasks to be synchronously executed are two, the second task configuration item is the remaining task configuration item in the two task configuration items, i.e., the task configuration item other than the first task configuration item in the two task configuration items; if the task configuration items corresponding to the tasks to be synchronously executed are N, the second task configuration item is the remaining task configuration item in the N task configuration items, i.e., the task configuration item other than the first task configuration item in the N task configuration items.
[0056] Step 204, a baseline configuration parameter set containing the first target task configuration parameter and the second target task configuration parameter is obtained.
[0057] If multiple tasks to be synchronously executed are configured in each network device, a baseline configuration parameter set can be obtained based on each target task configuration parameter group, i.e., each task to be synchronously executed corresponds to a baseline configuration parameter set, and the baseline configuration parameter set contains the task configuration parameters meeting the number proportion requirement in each task configuration item corresponding to the task to be synchronously executed; or a baseline configuration parameter set can be obtained based on all target task configuration parameter groups, i.e., all target task configuration parameter groups correspond to a baseline configuration parameter set, and the baseline configuration parameter set contains the task configuration parameters meeting the number proportion requirement in each task configuration item corresponding to each task to be synchronously executed.
[0058] The following illustrates the process of obtaining the baseline configuration parameter set:
[0059] Taking the data backup task as an example, the corresponding task configuration items include the task execution time configuration item, the task execution instruction configuration item and the instruction parameter configuration item. Assuming that the first task configuration item is the task execution time configuration item and the task execution instruction configuration item, and the second task configuration item is the instruction parameter configuration item, the baseline configuration parameter set includes:
[0060] The task configuration parameter groups are aggregated based on the task execution time configuration item and the task execution instruction configuration item, that is, the task configuration parameter groups with the same task configuration parameters of the task execution time configuration item and the task execution instruction configuration item are set divided to obtain at least one parameter group set; the number ratio corresponding to each parameter group set is calculated according to the number of the task configuration parameter groups contained in each parameter group set and the number of all task configuration parameter groups, the parameter group set with the number ratio meeting the first ratio requirement is determined as the target parameter group set, the task configuration parameter groups contained in the target parameter group set are the target task configuration parameter groups, and the task configuration parameters of the task execution time configuration item and the task execution instruction configuration item in the target task configuration parameter groups are determined as the first target task configuration parameters.
[0061] The task configuration parameters of the instruction parameter configuration item in the target task configuration parameter groups are grouped, that is, the task configuration parameters of the same instruction parameter configuration item are grouped, the number ratio of the number of the task configuration parameters contained in each group to the number of the target task configuration parameter groups is calculated, and the task configuration parameters contained in the group with the number ratio meeting the second ratio requirement are the second target task configuration parameters.
[0062] The baseline configuration parameter set is obtained based on the first target task configuration parameters and the second target task configuration parameters.
[0063] The process of obtaining a baseline configuration parameter set based on all target task configuration parameter groups in each network device in which multiple tasks to be synchronously executed are configured will be described below:
[0064] For example, each network device is configured with a mail sending task and a data backup task performed at the same task execution time, the task configuration item corresponding to the mail sending task also includes the task execution time configuration item, the task execution instruction configuration item and the instruction parameter configuration item, the baseline configuration parameter set contains the task configuration parameters in the task execution time configuration item, the task execution instruction configuration item and the instruction parameter configuration item corresponding to the mail sending task that meet the quantity proportion requirement, and the task configuration parameters in the task execution time configuration item, the task execution instruction configuration item and the instruction parameter configuration item corresponding to the data backup task that meet the quantity proportion requirement. Among them, the mail sending task and the data backup task are to-be-synchronized execution tasks, therefore, the task configuration parameters of the task execution time configuration item corresponding to the mail sending task and the task configuration parameters of the task execution time configuration item corresponding to the data backup task are the same.
[0065] It should be noted that the task configuration parameters of the task execution instruction configuration item corresponding to the mail sending task can be mail sending instructions respectively, and the task configuration parameters of the instruction parameter configuration item corresponding thereto can be recipient mailboxes; the task configuration parameters of the task execution instruction configuration item corresponding to the data backup task can be data backup instructions respectively, and the task configuration parameters of the instruction parameter configuration item corresponding thereto can be backup addresses.
[0066] In an optional implementation, the baseline configuration parameter set can also be obtained in the following manner:
[0067] Based on the task configuration parameter groups obtained from the plurality of network devices, based on each task configuration item, the same task configuration parameter groups are aggregated to obtain at least one aggregation set; the aggregation set in which the quantity proportion of the task configuration parameter groups in all task configuration parameter groups meets the set proportion requirement is determined as a target aggregation set; and the baseline configuration parameter set is obtained based on the task configuration parameter groups contained in the target aggregation set.
[0068] In step 205, the abnormality detection information corresponding to the to-be-synchronized execution task is determined based on the baseline configuration parameter set.
[0069] The related content in step 205 can be referred to the related description in step 103.
[0070] If one baseline configuration parameter set is obtained based on each target task configuration parameter group: based on each task configuration item, the task configuration parameters in the to-be-synchronized execution task corresponding to the task configuration parameter group are compared with each baseline configuration parameter set; if the task configuration parameters in the task configuration parameter group are completely the same as the baseline configuration parameters in any baseline configuration parameter set, first abnormality detection information is generated, otherwise, second abnormality detection information is generated.
[0071] If a baseline configuration parameter set is obtained based on all target task configuration parameter groups, the task configuration parameters in the task configuration parameter group corresponding to the task to be synchronized and executed are compared with the baseline configuration parameters under the corresponding task configuration item in the baseline configuration parameter set respectively; if each task configuration parameter in the task configuration parameter group is included in the baseline configuration parameter set, first abnormality detection information is generated, otherwise, second abnormality detection information is generated.
[0072] The application obtains a task configuration parameter group corresponding to a task to be synchronized and executed from each network device; determines a first target task configuration parameter based on a first task configuration item and a second target task configuration parameter based on a second task configuration item, and obtains a baseline configuration parameter set containing the first target task configuration parameter and the second target task configuration parameter; and determines abnormality detection information corresponding to the task to be synchronized and executed based on the baseline configuration parameter set. The application not only can detect whether the task to be synchronized and executed configured in each network device has an error configuration, but also can automatically determine the baseline configuration parameter set according to the actual configuration of the task to be synchronized and executed in each network device, without the user giving the baseline configuration parameter set manually, so as to realize automatic detection of abnormality of the task to be synchronized and executed and improve the abnormality detection efficiency.
[0073] In addition, in the application, when the baseline configuration parameter set is obtained, first, the target task configuration parameter group is obtained based on the first task configuration item, and the task configuration parameter of the first task configuration item in the target task configuration parameter group is determined as the first target task configuration parameter; second, the second target task configuration parameter is obtained based on the target task configuration parameter group, which has the same task configuration parameter under the second task configuration item and the number of which in the target task configuration parameter group accounts for the second proportion requirement; and finally, the baseline configuration parameter set containing the first target task configuration parameter and the second target task configuration parameter is obtained. The process of obtaining the target task configuration parameter group based on part of the task configuration items is the process of screening the task configuration parameter group, so that the application can obtain the baseline configuration parameter set based on part of the task configuration parameter groups, without comparing each task configuration parameter in each task configuration parameter group, thereby improving the speed of obtaining the baseline configuration parameter set.
[0074] Embodiment Three
[0075] Please refer to Figure 3 , Figure 3 The schematic structure of an abnormality detection device provided by the application is shown. For the convenience of description, only the parts related to the embodiments of the application are shown in the figure.
[0076] Referring to Figure 3 , the device includes a parameter group obtaining module 31, an aggregation module 32 and an information determining module 33; and the specific functions of each module are as follows:
[0077] The parameter group obtaining module 31 is configured to obtain a task configuration parameter group from each of a plurality of network devices, wherein the plurality of network devices are configured to execute a task to be synchronized, the task to be synchronized corresponds to a plurality of task configuration items, and the task configuration parameter group contains a task configuration parameter of each task configuration item;
[0078] The aggregation module 32 is configured to aggregate the task configuration parameter groups based on the task configuration items to obtain a baseline configuration parameter set, wherein the baseline configuration parameter set contains a task configuration parameter of each task configuration item that meets a quantity proportion requirement.
[0079] The information determination module 33 is configured to determine abnormal detection information corresponding to the task to be synchronized based on the baseline configuration parameter set, wherein the abnormal detection information is used to indicate whether the task to be synchronized configured by each network device is abnormal.
[0080] Optionally, the aggregation module 32 further includes a parameter group selection unit, a parameter obtaining unit and a set obtaining unit, wherein the functions of the units are as follows:
[0081] The parameter group selection unit is configured to select, based on a first task configuration item, a target task configuration parameter group from the task configuration parameter groups, wherein the target task configuration parameter group contains the same task configuration parameter and the quantity proportion of the target task configuration parameter group in the task configuration parameter groups meets a first proportion requirement, and the task configuration parameter of the first task configuration item in the target task configuration parameter group is determined as a first target task configuration parameter.
[0082] The parameter obtaining unit is configured to obtain, based on the target task configuration parameter group, a second target task configuration parameter that contains the same task configuration parameter and the quantity proportion of the second target task configuration parameter in the target task configuration parameter group meets a second proportion requirement.
[0083] The set obtaining unit is configured to obtain a baseline configuration parameter set containing the first target task configuration parameter and the second target task configuration parameter.
[0084] Optionally, the parameter group selection unit is specifically configured to:
[0085] perform set division on the task configuration parameter groups containing the same task configuration parameter under the first task configuration item to obtain at least one parameter group set;
[0086] select, as the target task configuration parameter group, a task configuration parameter group contained in a parameter group set, wherein the parameter group set contains the same task configuration parameter and the quantity proportion of the parameter group set in all the task configuration parameter groups meets the first proportion requirement.
[0087] Optionally, the information determination module 33 includes a comparison unit, a first generation unit and a second generation unit, wherein the functions of the units are as follows:
[0088] The comparison unit is used to compare the task configuration parameters in the task configuration parameter group corresponding to the task to be synchronized with the baseline configuration parameters under the corresponding task configuration item in the baseline configuration parameter set.
[0089] The first generation unit is configured to generate first anomaly detection information when the task configuration parameter in the task configuration parameter group is the same as the baseline configuration parameter under the corresponding task configuration item in the baseline configuration parameter set. The first anomaly detection information is used to indicate that the configuration of the task to be synchronized is correct.
[0090] The second generation unit is used to generate second anomaly detection information when any one of the task configuration parameters in the task configuration parameter group is different from the baseline configuration parameter under the corresponding task configuration item in the baseline configuration parameter set. The second anomaly detection information is used to indicate that the configuration of the task to be synchronized is abnormal.
[0091] Optionally, the first generating unit is specifically used for:
[0092] Get the task identifier, abnormal task configuration item, abnormal task configuration parameter corresponding to the abnormal task configuration item, and baseline configuration parameter corresponding to the abnormal task configuration item of the task to be synchronized;
[0093] Based on the task identifier, abnormal task configuration items, abnormal task configuration parameters, and the baseline configuration parameters corresponding to the abnormal task configuration items, a second abnormality detection information is generated.
[0094] Optionally, the device further includes a sending module, which is used to obtain the device identifier of the network device corresponding to the task to be synchronized and execute; and send the device identifier and second anomaly detection information to the user.
[0095] Optionally, the device identifier includes the network device's device ID and / or device location.
[0096] The anomaly detection device provided in this application embodiment can be applied in the aforementioned method embodiment one. For details, please refer to the description of the aforementioned method embodiment one, which will not be repeated here.
[0097] Example 4:
[0098] Please see Figure 4 , Figure 4 This illustration shows a schematic structure of a terminal device according to an embodiment of the present application. The terminal device 4 of this embodiment includes: at least one processor 40 ( Figure 4 Only one is shown in the diagram), memory 41, and computer program 42 stored in the memory 41 and executable on the at least one processor 40, wherein the processor 40 executes the computer program 42 to implement the steps of the anomaly detection method in the above embodiment 1.
[0099] The terminal device 4 can be a desktop computer, a notebook computer, a palm computer, a cloud server and the like. The terminal device can include, but is not limited to, a processor 40 and a memory 41. Those skilled in the art can understand that, Figure 4 The terminal device 4 is only an example and is not limited to the terminal device 4, and can include more or less components, or combine some components, or different components, for example, can also include an input / output device, a network access device and the like.
[0100] The processor 40 can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or can also be any conventional processor.
[0101] The memory 41 can be an internal storage unit of the terminal device 4 in some embodiments, for example, a hard disk or a memory of the terminal device 4. The memory 41 can also be an external storage device of the terminal device 4 in other embodiments, for example, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card and the like equipped on the terminal device 4. Further, the memory 41 can include both the internal storage unit and the external storage device of the terminal device 4. The memory 41 is used to store an operating system, application programs, a boot loader, data and other programs, for example, program codes of the computer program and the like. The memory 41 can also be used to temporarily store data that has been output or will be output.
[0102] It should be noted that the information interaction, execution process and the like between the above apparatuses / units are based on the same concept as the method embodiments of the present application, and the specific functions and the technical effects brought by the specific functions can be referred to the method embodiments part, which will not be described here.
[0103] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above-mentioned division of each functional unit and module is exemplified, and in actual application, the above-mentioned functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or software functional unit. In addition, the specific name of each functional unit and module is only for easy distinction, and does not limit the protection scope of the application. The specific working process of the unit and module in the above system can refer to the corresponding process in the foregoing method embodiment, which will not be described here.
[0104] The computer readable storage medium stores a computer program, and the computer program is executed by a processor to realize the steps in each of the above method embodiments.
[0105] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, all or part of the processes in the above embodiment methods can be completed by a computer program instructing related hardware, and the computer program can be stored in a computer readable storage medium. The computer program can realize the steps of each of the above method embodiments when executed by a processor. The computer program includes computer program code, which can be in the form of source code, object code, executable file, or some intermediate form. The computer readable medium at least includes any entity or device capable of carrying the computer program code to the terminal device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium. For example, U disk, mobile hard disk, magnetic disk or optical disk, etc. In some jurisdictions, according to legislation and patent practice, the computer readable medium cannot be an electrical carrier signal and a telecommunication signal.
[0106] In the above embodiments, the description of each embodiment has its own emphasis, and the parts not described or recorded in detail in a certain embodiment can be referred to the related description of other embodiments.
[0107] Those skilled in the art can understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0108] In the embodiments provided by the present application, it should be understood that the disclosed apparatus / terminal device and method can be implemented in other ways. For example, the division of the described apparatus / terminal device embodiments is merely a logical function division, and there can be another division manner in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between the units can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or in other forms.
[0109] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e. can be located in one place, or can be distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.
[0110] The above-described embodiments are only used to illustrate the technical solutions of the present application, but not limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.
Claims
1. An anomaly detection method characterized by, The method comprises the steps of: obtaining a task configuration parameter group from each of a plurality of network devices; a plurality of network devices are configured to execute a task to be synchronized, the task to be synchronized corresponds to a plurality of task configuration items, and the task configuration parameter group contains task configuration parameters of each task configuration item; based on the task configuration item, the task configuration parameter group is data aggregated to obtain a baseline configuration parameter set, and the baseline configuration parameter set contains task configuration parameters that are the same in each task configuration item and meet the quantity proportion requirement in the task configuration parameter group; based on the baseline configuration parameter set, determining the abnormal detection information corresponding to the task to be synchronized, the abnormal detection information is used to indicate whether the task to be synchronized configured by each network device is abnormal.
2. The method of claim 1, wherein, The method comprises the steps of: based on the task configuration item, the task configuration parameter group is data aggregated to obtain a baseline configuration parameter set, and the baseline configuration parameter set contains task configuration parameters that are the same in each task configuration item and meet the quantity proportion requirement in the task configuration parameter group; based on the first task configuration item, the target task configuration parameter group with the same task configuration parameters and the quantity proportion meeting the first proportion requirement in the task configuration parameter group is selected from the task configuration parameter group, and the task configuration parameters of the first task configuration item in the target task configuration parameter group are determined as the first target task configuration parameter; based on the target task configuration parameter group, the second target task configuration parameter with the same task configuration parameters and the quantity proportion meeting the second proportion requirement in the target task configuration parameter group under the second task configuration item is obtained; 3. The method of claim 2, wherein, the baseline configuration parameter set containing the first target task configuration parameter and the second target task configuration parameter is obtained. The method comprises the steps of: the task configuration parameter group with the same task configuration parameters is divided into at least one parameter group set based on the first task configuration item; 4. The method of claim 1, wherein, the task configuration parameter group contained in the parameter group set with the quantity proportion meeting the first proportion requirement in all task configuration parameter groups is selected as the target task configuration parameter group. The method comprises the steps of: the task configuration parameters in the task configuration parameter group corresponding to the task to be synchronized are compared with the baseline configuration parameters under the corresponding task configuration item in the baseline configuration parameter set, respectively; if the task configuration parameters in the task configuration parameter group are the same as the baseline configuration parameters under the corresponding task configuration item in the baseline configuration parameter set, first abnormal detection information is generated, and the first abnormal detection information is used to indicate that the task to be synchronized is configured correctly; 5. The method of claim 4, wherein, otherwise, the second abnormal detection information is generated, and the second abnormal detection information is used to indicate that the task to be synchronized is configured abnormally. The method comprises the steps of: Obtain a task identifier of the task to be synchronously executed, an abnormal task configuration item, an abnormal task configuration parameter corresponding to the abnormal task configuration item, and a baseline configuration parameter corresponding to the abnormal task configuration item; Generate the second abnormality detection information based on the task identifier, the abnormal task configuration item, the abnormal task configuration parameter, and the baseline configuration parameter corresponding to the abnormal task configuration item.
6. The method of claim 4, wherein, After the second abnormality detection information is generated, the method further includes: Obtain a device identifier of the network device corresponding to the task to be synchronously executed; Send the device identifier and the second abnormality detection information to a user.
7. The method of claim 6, wherein, The device identifier includes a device ID and / or a device location of the network device.
8. An abnormality detection device characterized by comprising: The method includes: A parameter group obtaining module, configured to obtain a task configuration parameter group from each of a plurality of network devices; The plurality of network devices are configured with a task to be synchronously executed, the task to be synchronously executed corresponds to a plurality of task configuration items, and the task configuration parameter group includes a task configuration parameter of each of the task configuration items; An aggregation module, configured to perform data aggregation on the task configuration parameter group based on the task configuration items to obtain a baseline configuration parameter set, the baseline configuration parameter set including a task configuration parameter that is the same in each of the task configuration items and meets a quantity proportion requirement in the task configuration parameter group; An information determining module, configured to determine abnormality detection information corresponding to the task to be synchronously executed based on the baseline configuration parameter set, the abnormality detection information being used to indicate whether the task to be synchronously executed configured by each of the network devices is abnormal.
9. A terminal device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, The processor executes the computer program to implement the method of any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, the computer program comprising instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1 to 9. The computer program is executed by the processor to implement the method of any one of claims 1 to 7.
Citation Information
Patent Citations
Abnormal login behavior detection method and device, storage medium and computer equipment
CN113518058A
Vehicle configuration state monitoring method and device, storage medium and computer equipment
CN114677779A