Log data processing method, device, electronic device and storage medium
By automatically analyzing the firewall log data and identifying and processing malicious IP, the problem of low manual processing efficiency is solved, and efficient log data processing and abnormal IP management is achieved.
Patent Information
- Application Number
- CN202211574693.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-08
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2042-12-08
AI Technical Summary
In the prior art, firewall log data processing requires manual intervention, is inefficient, and cannot efficiently identify and handle malicious IPs.
By obtaining the log data generated by network devices, the log type and sending end identification are automatically determined, and processing operations are automatically performed based on abnormal analysis indicators, including configuring policy blocking or adding to the blacklist.
It improves log data processing efficiency and abnormal IP processing efficiency, reduces dependence on manpower and other equipment, and improves the timeliness and automation of processing.
Smart Images

Figure CN115883317B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular to a log data processing method, device, electronic device, and storage medium. Background Art
[0002] With the development and popularization of computer network technology, large-scale website systems are often accessed by malicious IP addresses, causing bandwidth loss and affecting normal website access. To prevent website systems from being accessed by malicious IP addresses, operation and maintenance engineers usually use firewalls to identify and process these malicious IP addresses to achieve the purpose of defending against attacks. The main function of firewall technology is to promptly detect and address security risks and data transmission issues that may exist during computer network operation. The treatment measures include isolation and protection. At the same time, it can record and detect various operations in computer network security to ensure the security of computer network operation, protect the integrity of user data and information, and provide users with a better and safer computer network experience.
[0003] However, in related technologies, it is often necessary to manually process malicious IP addresses based on firewall log data, which is inefficient. Summary of the Invention
[0004] In order to overcome the above-mentioned problems existing in the related art, the present disclosure provides a log data processing method, device, electronic device and storage medium.
[0005] According to a first aspect of an embodiment of the present disclosure, a log data processing method is provided, the method comprising:
[0006] Obtaining log data generated by a network device; the log data includes a log recording a sender identifier of a sender device, where the sender device is a device that sends a message to the network device or sends a message that flows through the network device;
[0007] Determining a target log type and a sending end identifier corresponding to the log data;
[0008] Determine the abnormality analysis indicator corresponding to the sending end identifier according to the target log type;
[0009] When the abnormality analysis index is greater than or equal to a preset index threshold, the sending end identifier is determined as an abnormal sending end identifier.
[0010] In some embodiments, determining the abnormality analysis indicator corresponding to the sender identifier according to the target log type includes:
[0011] Determine the abnormality analysis adjustment parameter corresponding to the target log type according to the log parameter correspondence relationship; wherein the log parameter correspondence relationship includes the correspondence relationship between the target log type and the abnormality analysis adjustment parameter;
[0012] An abnormality analysis indicator corresponding to the sending end identifier is determined according to the abnormality analysis adjustment parameter.
[0013] In some embodiments, determining the abnormality analysis indicator corresponding to the sender identifier according to the abnormality analysis adjustment parameter includes:
[0014] In the case of obtaining the historical abnormality analysis indicator corresponding to the sender identifier, determining the abnormality analysis indicator according to the historical abnormality analysis indicator and the abnormality analysis adjustment parameter, and using the abnormality analysis indicator as a new historical abnormality analysis indicator; or
[0015] If the historical abnormality analysis indicator corresponding to the sender identifier is not obtained, the abnormality analysis indicator corresponding to the sender identifier is determined according to the abnormality analysis adjustment parameter, and the abnormality analysis indicator is used as the historical abnormality analysis indicator corresponding to the sender identifier.
[0016] In some embodiments, the log parameter correspondence is generated in the following manner:
[0017] Determine multiple candidate log types; the candidate log types include the target log type;
[0018] Obtaining a first amount of data generated by each candidate log type within a first time period; the first time period is a historical time period before the current moment;
[0019] Calculating a first anomaly analysis adjustment parameter corresponding to each candidate log type based on the first data volume; the larger the first data volume, the smaller the calculated first anomaly analysis adjustment parameter;
[0020] The first anomaly analysis adjustment parameter is used as the anomaly analysis adjustment parameter corresponding to the candidate log type to obtain the log parameter correspondence relationship.
[0021] In some embodiments, the log parameter correspondence is updated in the following manner:
[0022] Obtaining the number of logs counted in a second time period and the third data volume in a third time period for each candidate log type; the second time period and the third time period are both time periods before the current moment, and the third time period includes the second time period;
[0023] Determine a second weight corresponding to the third data volume and a first weight corresponding to the number of logs, wherein the first weight is greater than or equal to the second weight;
[0024] Calculate a second anomaly analysis adjustment parameter corresponding to each candidate log type according to the third data volume, the second weight, the number of logs, and the first weight;
[0025] The second abnormality analysis adjustment parameter is used as the abnormality analysis adjustment parameter corresponding to the candidate log type to obtain the log parameter correspondence relationship.
[0026] In some embodiments, the method further comprises
[0027] Obtaining a current amount of sender record information currently stored in the network device; each sender record information includes a sender identifier, a recording time, and a historical anomaly analysis indicator corresponding to the sender identifier, wherein the recording time is the time when the sender record information is first stored in the network device;
[0028] When the current number is greater than or equal to a preset number threshold, determining a target duration according to the current number and the preset number threshold;
[0029] The sending end record information with a storage duration greater than or equal to the target duration is deleted from the network device, and the storage duration is used to represent the time difference between the recording time and the current time.
[0030] In some embodiments, determining the target log type and the sender identifier corresponding to the log data includes:
[0031] Performing text parsing on the log data according to preset type parameters to determine the target log type corresponding to the log data;
[0032] The log data is parsed according to a preset regular expression to obtain the sender identifier.
[0033] In some embodiments, the method further comprises:
[0034] When the abnormality analysis index is greater than or equal to a preset index threshold, an abnormality handling operation is performed according to the sending end identifier.
[0035] According to a second aspect of an embodiment of the present disclosure, a log data processing device is provided, the device comprising:
[0036] A log acquisition module, configured to acquire log data generated by a network device; the log data includes a log recording a sender identifier of a sender device, the sender device being a device that sends a message to the network device or sends a message that passes through the network device;
[0037] A log processing module, configured to determine a target log type and a sender identifier corresponding to the log data;
[0038] An indicator analysis module, configured to determine an abnormality analysis indicator corresponding to the sender identifier according to the target log type;
[0039] The exception handling module is used to perform an exception handling operation according to the sending end identifier when the exception analysis indicator is greater than or equal to a preset indicator threshold.
[0040] In some embodiments, the indicator analysis module is used to determine the abnormality analysis adjustment parameters corresponding to the target log type based on the log parameter correspondence; wherein the log parameter correspondence includes the correspondence between the target log type and the abnormality analysis adjustment parameters; and determine the abnormality analysis indicator corresponding to the sending end identifier based on the abnormality analysis adjustment parameters.
[0041] In some embodiments, the indicator analysis module is used to determine the abnormality analysis indicator based on the historical abnormality analysis indicator and the abnormality analysis adjustment parameter when the historical abnormality analysis indicator corresponding to the sending end identifier is obtained, and use the abnormality analysis indicator as the new historical abnormality analysis indicator; or, when the historical abnormality analysis indicator corresponding to the sending end identifier is not obtained, determine the abnormality analysis indicator corresponding to the sending end identifier based on the abnormality analysis adjustment parameter, and use the abnormality analysis indicator as the historical abnormality analysis indicator corresponding to the sending end identifier.
[0042] In some embodiments, the apparatus further comprises:
[0043] An initialization module is used to determine multiple candidate log types; the candidate log types include the target log type; obtain a first data volume generated by each candidate log type within a first time period; the first time period is a historical time period before the current moment; calculate a first anomaly analysis adjustment parameter corresponding to each candidate log type based on the first data volume; the larger the first data volume, the smaller the calculated first anomaly analysis adjustment parameter; use the first anomaly analysis adjustment parameter as the anomaly analysis adjustment parameter corresponding to the candidate log type to obtain the log parameter correspondence.
[0044] In some embodiments, the apparatus further comprises:
[0045] A dynamic programming module is configured to obtain the number of logs counted in a second time period and a third data volume in a third time period for each candidate log type; the second time period and the third time period are both time periods before a current moment, and the third time period includes the second time period; determine a second weight corresponding to the third data volume and a first weight corresponding to the number of logs, the first weight being greater than or equal to the second weight; calculate a second anomaly analysis adjustment parameter corresponding to each candidate log type based on the third data volume, the second weight, the number of logs, and the first weight; and use the second anomaly analysis adjustment parameter as the anomaly analysis adjustment parameter corresponding to the candidate log type to obtain the log parameter correspondence.
[0046] In some embodiments, the apparatus further comprises:
[0047] A data elimination module is used to obtain the current amount of sender record information currently stored in the network device; each sender record information includes a sender identifier, a recording time, and a historical abnormality analysis indicator corresponding to the sender identifier, and the recording time is the time when the sender record information is first stored in the network device; when the current amount is greater than or equal to a preset amount threshold, a target duration is determined based on the current amount and the preset amount threshold; the sender record information with a storage duration greater than or equal to the target duration is deleted from the network device, and the storage duration is used to represent the time difference between the recording time and the current time.
[0048] In some embodiments, the log processing module is used to perform text parsing on the log data according to preset type parameters to determine the corresponding target log type in the log data; perform text parsing on the log data according to a preset regular expression to obtain the sender identifier.
[0049] According to a third aspect of an embodiment of the present disclosure, an electronic device is provided, comprising: a memory on which a computer program is stored; and a processor for executing the computer program in the memory to implement the steps of the method described in the first aspect of the present disclosure.
[0050] According to a fourth aspect of an embodiment of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method described in the first aspect of the present disclosure are implemented.
[0051] The technical solution provided by the embodiments of the present disclosure may include the following beneficial effects: obtaining log data corresponding to a network device; wherein the log data may include a log recording a sender identifier of a sender device, the sender device being a device that sends messages to the network device or sends messages that flow through the network device; determining the target log type and sender identifier corresponding to the log data; determining the abnormality analysis index corresponding to the sender identifier based on the target log type; and performing an abnormality processing operation based on the sender identifier when the abnormality analysis index is greater than or equal to a preset index threshold. In this way, analysis and statistics of log data can be implemented on the network device, thereby improving the processing efficiency of log data and the processing efficiency of abnormal sender identifiers. In addition, since there is no need to rely on other devices, costs can also be reduced.
[0052] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.
[0054] Figure 1 The figure is a flowchart of a log data processing method according to an exemplary embodiment.
[0055] Figure 2 The figure is a flowchart showing a method for generating a log parameter correspondence relationship according to an exemplary embodiment.
[0056] Figure 3 The figure is a flowchart showing a method for updating a log parameter correspondence relationship according to an exemplary embodiment.
[0057] Figure 4 The figure is a block diagram showing a log data processing device according to an exemplary embodiment.
[0058] Figure 5 It is a block diagram showing another log data processing device according to an exemplary embodiment.
[0059] Figure 6 It is a block diagram of an electronic device according to an exemplary embodiment. DETAILED DESCRIPTION
[0060] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all possible embodiments consistent with the present disclosure. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present disclosure, as detailed in the appended claims.
[0061] It should be noted that all actions of acquiring signals, information or data in the present disclosure are carried out in compliance with the corresponding data protection laws and policies of the country where they are located and with the authorization given by the owner of the corresponding device.
[0062] In the description of the present disclosure, terms such as "first" and "second" are used to distinguish similar objects and are not necessarily to be understood as implying a specific order or precedence. In addition, in the description with reference to the accompanying drawings, the same reference numerals in different drawings represent the same elements unless otherwise indicated.
[0063] In the description of the present disclosure, unless otherwise specified, "multiple" means two or more than two, and other quantifiers are similar thereto; "at least one item(s)", "one item(s) or multiple items(s)" or similar expressions refer to any combination of these items(s), including any combination of single items(s) or plural items(s). For example, at least one item(s) a can represent any number of a's; for another example, one item(s) or multiple items(s) among a, b and c can represent: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or multiple; "and / or" is a type of association relationship that describes associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural.
[0064] Although operations or steps are described in a particular order in the drawings in the embodiments of the present disclosure, this should not be understood as requiring that these operations or steps be performed in the particular order shown or in a serial order, or that all of the operations or steps shown be performed to obtain a desired result. In the embodiments of the present disclosure, these operations or steps may be performed serially; these operations or steps may also be performed in parallel; or some of these operations or steps may be performed.
[0065] The present disclosure is described below with reference to specific embodiments.
[0066] First, the application scenarios of the present disclosure are described. The present disclosure can be applied to abnormal data processing scenarios involving firewalls or other network browsing devices. To address malicious IP addresses, network devices such as firewalls generate large amounts of log data. Manual analysis of this log data can identify problematic IP addresses and develop strategies for addressing them, such as configuring blocking policies or blacklisting them.
[0067] In one implementation of the present disclosure, log data from network devices such as firewalls can be sent to a destination device. The destination device then analyzes historical logs to count the number of problematic IP addresses. A policy can then be configured manually or automatically (blocking or blacklisting IP addresses) on the firewall or other network device. This method requires additional equipment and manual processing, resulting in low efficiency and limited real-time performance.
[0068] Figure 1 This is a flow chart of a log data processing method according to an exemplary embodiment. The method can be applied to network devices, which may include firewalls, routers, computers, servers, etc. Figure 1 As shown, the method may include:
[0069] S101: Obtain log data generated by network devices.
[0070] The log data may include a log recording a sender identifier of a sender device, where the sender device may be a device that sends a message to a network device or sends a message that flows through a network device.
[0071] For example, the destination IP address of the message sent by the sending device may be the IP address of the network device, or an IP address that can be reached by passing through the network device, or other IP addresses, which is not limited in this disclosure.
[0072] The sender identifier may include one or more of an IP address, a port number, a MAC address, and a device identifier of the sender device.
[0073] In some embodiments, the sender identifier may include an IP address of the sender device, for example, it may be a source IP in a message sent by the sender device.
[0074] In other embodiments, the sender identifier may include a MAC (Media Access Control) address of the sender device.
[0075] In some other embodiments, the sender identifier may include a source IP and a source port number in a message sent by the sender device.
[0076] It should be noted that when processing a message sent by a sending device, a network device may directly generate log data, or may generate log data when the message meets certain conditions. For example, if the network device determines that the message is an abnormal message (such as an offensive message or a message determined to be unsafe), the log data may be generated.
[0077] It should also be noted that among the multiple log data generated by the network device, some log data may record the sender identifier, while some log data may not record the sender identifier, and this disclosure does not limit this.
[0078] S102: Determine the target log type and sender identifier corresponding to the log data.
[0079] In some embodiments, text parsing may be performed on the log data according to preset type parameters to determine the corresponding target log type in the log data.
[0080] For example, the preset type parameter may include pre-set "key information for all log types that need to be parsed." The preset type parameter may be key text in the log data, and the target log type may be determined based on the key text. For example, the preset type parameter may include the key text "traffic attack," and the target log type corresponding to log data containing the preset type parameter "traffic attack" may be a traffic attack log.
[0081] In some embodiments, the log data may be parsed according to a preset regular expression to obtain the sender identifier. The preset regular expression may be a regular expression for extracting the sender identifier (eg, IP or MAC).
[0082] In some embodiments, step S102 may be performed by a log processing module. The input of the log processing module may include log data, and the output may include a target log type and a sender identifier corresponding to the log data.
[0083] In some embodiments, the log data obtained by parsing to obtain the target log type and the sender identifier can be treated as abnormal data for subsequent analysis.
[0084] In other embodiments, log data that satisfies a preset abnormality condition can be selected from the log data obtained by parsing the target log type and the sender identifier as abnormal data for subsequent analysis. For example, the preset abnormality condition can include the target log type being a preset abnormality type, that is, log data whose target log type is a preset abnormality type can be used as abnormal data. The preset abnormality type can be a plurality of pre-set types.
[0085] S103: Determine an abnormality analysis indicator corresponding to the sender identifier according to the target log type.
[0086] The abnormality analysis indicator can be used to characterize the abnormal information volume or abnormal impact degree identified by the sending end.
[0087] In some embodiments, the abnormality analysis indicator may be determined based on the data volume of the target log type, which may be the number of log data corresponding to the target log type or the size of the storage space occupied by the log data corresponding to the target log type.
[0088] In other embodiments, the abnormality analysis adjustment parameter corresponding to the target log type may be determined first; and the abnormality analysis indicator corresponding to the sender identifier may be determined based on the abnormality analysis adjustment parameter.
[0089] Among them, the abnormal analysis adjustment parameter can also be called the log score, which can be used to characterize the amount of abnormal information or abnormal impact of each log data corresponding to the target log type. The larger the abnormal analysis adjustment parameter, the greater the amount of abnormal information generated by a log data of the target log type, and the higher the abnormal impact.
[0090] It should be noted that the log data in this embodiment can be one log data or multiple log data. If there are multiple log data, the abnormality analysis adjustment parameter can be multiplied by the number of log data to obtain the abnormality analysis adjustment parameter accumulated by multiple log data.
[0091] The exception analysis adjustment parameters corresponding to different target log types may be the same or different. For example, the exception analysis adjustment parameters corresponding to the target log type may be determined based on a log parameter correspondence relationship, which may include a correspondence relationship between the target log type and the exception analysis adjustment parameters.
[0092] The method for determining the anomaly analysis indicator corresponding to the sender identifier based on the anomaly analysis adjustment parameter may include any of the following:
[0093] Method 1: When a historical anomaly analysis indicator corresponding to the sender identifier is obtained, the anomaly analysis indicator is determined according to the historical anomaly analysis indicator and the anomaly analysis adjustment parameter, and the anomaly analysis indicator is used as a new historical anomaly analysis indicator.
[0094] For example, log statistics information may be stored in a network device, and the log statistics information may include one or more historical sender identifiers and a historical anomaly analysis indicator corresponding to each historical sender identifier.
[0095] In this way, it is possible to first determine whether the historical sender identifiers in the log statistical information include the sender identifier. If so, the historical anomaly analysis indicator corresponding to the sender identifier can be obtained. The anomaly analysis indicator corresponding to the sender identifier can then be calculated based on the historical anomaly analysis indicator and the anomaly analysis adjustment parameter. For example, the sum of the historical anomaly analysis indicator and the anomaly analysis adjustment parameter can be used as the anomaly analysis indicator, and this anomaly analysis indicator can be stored as a new historical anomaly analysis indicator in the log statistical information.
[0096] Method 2: When the historical anomaly analysis indicator corresponding to the sender identifier is not obtained, the anomaly analysis indicator corresponding to the sender identifier is determined according to the anomaly analysis adjustment parameter, and the anomaly analysis indicator is used as the historical anomaly analysis indicator corresponding to the sender identifier.
[0097] Similarly, it is possible to first determine whether the historical sender identifier in the above-mentioned log statistical information includes the sender identifier. If not, it can be determined that the historical anomaly analysis indicator corresponding to the sender identifier has not been obtained. In this way, the anomaly analysis indicator corresponding to the sender identifier can be determined based on the anomaly analysis adjustment parameter. For example, the anomaly analysis adjustment parameter can be used as the anomaly analysis indicator, or the anomaly analysis adjustment parameter can be multiplied by a preset coefficient to obtain the anomaly analysis indicator.
[0098] Furthermore, the abnormality analysis indicator may be used as a historical abnormality analysis indicator corresponding to the sender identifier and stored in the log statistical information.
[0099] Furthermore, the current time may be used as the first recording time of the sender identifier, and the first recording time may be stored in the log statistical information.
[0100] S104: When the abnormality analysis indicator is greater than or equal to a preset indicator threshold, perform an abnormality handling operation according to the sending end identifier.
[0101] The preset indicator threshold may be any preset value.
[0102] In some embodiments, the exception handling operation may include: determining the sender identifier as an abnormal sender identifier.
[0103] When the abnormal analysis index of the sending end identifier is greater than or equal to the preset index threshold, it can be determined that the accumulated abnormal information amount or abnormal impact of the sending end identifier has exceeded the preset level. Therefore, the sending end identifier can be determined as an abnormal sending end identifier.
[0104] For example, when the sending end is identified as the source IP, the target source IP may be determined as an abnormal IP.
[0105] Furthermore, when the sender identifier is determined to be an abnormal sender identifier, abnormal prompt information including the sender identifier may be displayed to the user. The abnormal prompt information may be used to prompt the user to perform an abnormal processing operation on the sender identifier.
[0106] In other embodiments, the exception handling operation may include: executing a target instruction according to the sender identifier, where the target instruction may be an instruction generated according to a preset basic instruction and the sender identifier.
[0107] For example, the preset basic instruction may be a basic instruction for performing exception handling. After combining the sender identifier and the preset basic instruction, an executable target instruction may be obtained. Executing the target instruction may implement the exception handling operation.
[0108] For example, the sending end identifier can be the source IP, and the preset basic instruction can be a basic command for adding the IP to the blacklist or configuring a policy to block the IP. After combining the source IP and the basic command, an executable command (target instruction) can be obtained. Executing the command can achieve the operation of adding the source IP to the blacklist or configuring a policy to block the source IP.
[0109] In this way, this method can further improve timeliness and save labor costs by automatically performing exception handling operations.
[0110] The above method is used to obtain log data corresponding to a network device; wherein the log data may include a log recording a sender identifier of a sender device, where the sender device is a device that sends messages to or through the network device; determine the target log type and sender identifier corresponding to the log data; determine the abnormality analysis index corresponding to the sender identifier based on the target log type; and, if the abnormality analysis index is greater than or equal to a preset index threshold, perform an abnormality handling operation based on the sender identifier. In this way, log data analysis and statistics can be implemented on the network device, thereby improving the efficiency of log data processing and the efficiency of handling abnormal sender identifiers. In addition, since it does not require reliance on other devices, it can also reduce costs.
[0111] In some embodiments of the present disclosure, the above-mentioned log parameter correspondence may be a pre-set correspondence. For example, the user may pre-set the abnormality analysis adjustment parameters corresponding to each candidate log type based on experience. The candidate log type may include a target log type.
[0112] In other embodiments of the present disclosure, the log parameter correspondence may be generated based on historical statistical data.
[0113] Figure 2FIG. 1 is a flow chart showing a method for generating a log parameter correspondence relationship according to an exemplary embodiment. Figure 2 As shown, the method may include:
[0114] S201: Determine multiple candidate log types.
[0115] The candidate log type may include the target log type. For example, the candidate log type may be any pre-set log type.
[0116] S202: Obtain a first data volume generated by each candidate log type within a first time period.
[0117] The first time period may be a historical time period before the current moment. For example, it may be a complete historical time period from power-on of the network device to the current moment, or it may be a historical time period within a first preset time period before the current moment. The first preset time period may be any preset time period, such as 1 day, 10 days, 1 month, 2 months, 1 quarter, or 1 year.
[0118] The first data volume may be the number of log data counted for the candidate log type within the first time period, or the size of the storage space occupied by the log data counted for the candidate log type within the first time period, which is not limited in the present disclosure.
[0119] S203: Calculate a first anomaly analysis adjustment parameter corresponding to each candidate log type according to the first data volume.
[0120] The larger the first data volume is, the smaller the calculated first abnormality analysis adjustment parameter is.
[0121] For example, it is assumed that n candidate log types are determined, and the first data volumes generated by each candidate log type in the first time period are [d1, d2, d3, ..., d n ], we can first calculate the first proportion of each candidate log type [p1,p2,p3,…,p n ]:
[0122]
[0123] Among them, p i represents the first proportion of the i-th candidate log type, d i represents the first data volume generated by the i-th candidate log type in the first time period, n represents the total number of candidate log types, and the value of i can range from 1 to n.
[0124] In some embodiments, the inverse of the first ratio may be used as the first abnormality analysis adjustment parameter.
[0125] In other embodiments, a difference obtained by subtracting the first ratio from 1 may be used as the first abnormality analysis adjustment parameter.
[0126] In some other embodiments, the first anomaly analysis adjustment parameter corresponding to each candidate log type can be calculated according to the following formula (2):
[0127]
[0128] Among them, b i represents the first anomaly analysis adjustment parameter corresponding to the i-th candidate log type, p i represents the first ratio of the i-th candidate log type, k represents a first preset optimization base number, and the first preset optimization base number can be any preset value greater than 1.
[0129] In this way, the first anomaly analysis adjustment parameter corresponding to each candidate log type can be calculated based on the first data volume and the first preset optimization base number.
[0130] S204: Use the first abnormality analysis adjustment parameter as the abnormality analysis adjustment parameter corresponding to the candidate log type to obtain a log parameter correspondence relationship.
[0131] In this way, through the above method, a log parameter correspondence relationship can be generated.
[0132] In some embodiments, the steps of generating log parameter correspondences shown in S201 to S204 above may be performed by an initialization module.
[0133] In some embodiments of the present disclosure, the log parameter correspondence may also be updated through an updating step. Figure 3 FIG. 1 is a flow chart showing a method for updating log parameter correspondence according to an exemplary embodiment. Figure 3 As shown, the update method may include:
[0134] S301: Obtain the number of logs counted in a second time period and the third data volume in a third time period for each candidate log type.
[0135] The second time period and the third time period are both time periods before the current moment, and the third time period includes the second time period.
[0136] For example, the second time period may be a historical time period within a second preset time period before the current moment, and the second preset time period may be any preset time period, such as 1 day, 10 days, 1 month, or 2 months.
[0137] The third time period may be a historical time period before the current moment. For example, it may be a complete historical time period from when the network device is powered on to the current moment, or it may be a historical time period within a third preset time period before the current moment. The third preset time period may be any preset time period, such as 10 days, 1 month, 2 months, 1 quarter, or 1 year.
[0138] In some embodiments, the third preset duration may be greater than the second preset duration.
[0139] The number of logs can be the number of log data counted by the candidate log type in the second time period, or the size of the storage space occupied by the newly counted log data of the candidate log type in the second time period; the third data volume can be the number of log data counted by the candidate log type in the third time period, or the size of the storage space occupied by the newly counted log data of the candidate log type in the third time period. This disclosure does not limit this.
[0140] In some embodiments, the number of logs in the second time period is the number of logs that have obtained the log type and the sender identifier for each candidate log type. The third data volume in the third time period may include the data volume of log data that has obtained the log type. For example, the third data volume may include the total data volume of log data that has obtained the log type and the sender identifier, and log data that has obtained the log type but not the sender identifier.
[0141] It should be noted that the method for obtaining the third data volume of the third time period can be the same as the method for obtaining the first data volume of the first time period. For details, please refer to the description in the aforementioned embodiments of the present disclosure, which will not be repeated here.
[0142] S302: Determine a first weight corresponding to the number of logs and a second weight corresponding to the third data volume.
[0143] The first weight may be greater than or equal to the second weight.
[0144] In some embodiments, the first weight and the second weight may be any pre-set parameters. In one implementation, the sum of the first weight and the second weight is 1, and the first weight may be greater than or equal to the second weight. For example, the first weight may be 0.6 and the second weight may be 0.4; for another example, the first weight may be 0.8 and the second weight may be 0.2.
[0145] In other embodiments, the first weight may be calculated based on the number of logs, and the second weight may be calculated based on the third data volume.
[0146] In some implementations, a method for calculating the second weight based on the third data volume is as follows:
[0147] Assume that n candidate log types are determined, and the third data volume generated by each candidate log type in the third time period is [e1, e2, e3, …, e n ], the first information value of each candidate log type can be calculated according to the following formula (3):
[0148] e′ i =Max(e x )-e i +Δ(x=1,2,3,…,n) (3)
[0149] Among them, e′ i represents the first information value corresponding to the i-th candidate log type, Max(e x ) represents the maximum value among n third data quantities, e i represents the third data volume corresponding to the i-th candidate log type, Δ represents the preset fault tolerance parameter, which can be a small positive number set in advance to avoid e′ i For example, the preset fault tolerance parameter may be 0.01 or 0.001.
[0150] Then, the second weight k2 can be calculated according to the following formula (4):
[0151]
[0152] Among them, k2 represents the second weight, Max(e′ i ) represents the maximum value of the first information of n candidate log types, Represents the sum of the first information values of n candidate log types.
[0153] In this way, the second weight can be calculated.
[0154] In some implementations, the first weight is calculated based on the number of logs as follows:
[0155] Also assume that n candidate log types are determined, and the number of logs counted for each candidate log type in the second time period is [c1, c2, c3, …, c n ], the second information value of each candidate log type can be calculated according to the following formula (5):
[0156] c′ i =Max(c x )-c i +Δ(x=1,2,3,…,n) (5)
[0157] Among them, c′ i represents the second information value corresponding to the i-th candidate log type, Max(c x ) represents the maximum value among n log numbers, c i represents the number of logs corresponding to the i-th candidate log type, Δ represents the preset fault tolerance parameter, which can be a small positive number set in advance to avoid e′ i For example, the preset fault tolerance parameter may be 0.01 or 0.001.
[0158] Then, the first weight k1 can be calculated according to the following formula (6):
[0159]
[0160] Among them, k1 represents the first weight, Max(c′ i ) represents the maximum value of the second information of n candidate log types, Represents the sum of the second information values of n candidate log types.
[0161] In this way, the first weight k1 can be calculated.
[0162] Furthermore, if the calculated first weight is less than the second weight, the first weight can be set to a value greater than or equal to the second weight. For example, the second weight calculated above can be used as the value of the first weight. This ensures that the weight of data closer to the current moment is greater than the weight of data farther away.
[0163] In some embodiments, after the first weight is calculated, the number of logs may be reset to zero and statistics may be restarted.
[0164] S303: Calculate a second anomaly analysis adjustment parameter corresponding to each candidate log type according to the number of logs, the third data volume, the first weight, and the second weight.
[0165] In some embodiments, the third abnormality analysis adjustment parameter corresponding to each candidate log type can be first calculated based on the number of logs, and the fourth abnormality analysis adjustment parameter corresponding to each candidate log type can be calculated based on the third data volume; then, the second abnormality analysis adjustment parameter can be calculated based on the third abnormality analysis adjustment parameter, the fourth abnormality analysis adjustment parameter, the second weight and the first weight.
[0166] For example, suppose there are n candidate log types, and the third data volume generated by each candidate log type in the third time period is [e1, e2, e3, ..., e n], we can first calculate the third ratio [r1, r2, r3, …, r n ]:
[0167]
[0168] Among them, r i represents the third proportion of the i-th candidate log type, e i represents the third data volume generated by the i-th candidate log type in the third time period, n represents the total number of candidate log types, and the value of i can range from 1 to n.
[0169] Then, a fourth abnormality analysis adjustment parameter may be calculated according to the third ratio.
[0170] In some embodiments, the inverse of the third ratio may be used as the fourth abnormality analysis adjustment parameter.
[0171] In other embodiments, a difference obtained by subtracting the third ratio from 1 may be used as the fourth abnormality analysis adjustment parameter.
[0172] In some other embodiments, the fourth anomaly analysis adjustment parameter corresponding to each candidate log type can be calculated according to the following formula (8):
[0173]
[0174] Among them, w i represents the fourth anomaly analysis adjustment parameter corresponding to the i-th candidate log type, r i represents the third ratio of the i-th candidate log type, k represents a first preset optimization base number, and the first preset optimization base number can be any preset value greater than 1.
[0175] In this way, the fourth abnormality analysis adjustment parameter can be calculated.
[0176] Also assume that n candidate log types are determined, and the number of logs counted for each candidate log type in the second time period is [c1, c2, c3, …, c n ], the second ratio of each candidate log type [t1, t2, t3, …, t n ]:
[0177]
[0178] Among them, t i represents the second proportion of the i-th candidate log type, c iIt represents the number of logs of the i-th candidate log type counted in the second time period, n represents the total number of candidate log types, and the value of i can range from 1 to n.
[0179] Then, a third abnormality analysis adjustment parameter may be calculated based on the second ratio.
[0180] In some embodiments, the inverse of the second ratio may be used as the third abnormality analysis adjustment parameter.
[0181] In other embodiments, a difference obtained by subtracting the second ratio from 1 may be used as the third abnormality analysis adjustment parameter.
[0182] In some other embodiments, the third anomaly analysis adjustment parameter corresponding to each candidate log type can be calculated according to the following formula (10):
[0183]
[0184] Among them, u i represents the third anomaly analysis adjustment parameter corresponding to the i-th candidate log type, t i represents the second ratio of the i-th candidate log type, w represents the second preset optimization base, and the second preset optimization base can be any preset value greater than 1. The second preset optimization base can be the same as or different from the first preset optimization base.
[0185] In this way, the third abnormality analysis adjustment parameter can be calculated.
[0186] Furthermore, the second abnormality analysis adjustment parameter can be calculated by the following formula (11):
[0187] s i =(k1*w i +k2*u i ) / (k1+k2) (i=1, 2, 3,..., n) (11)
[0188] Among them, s i represents the second anomaly analysis adjustment parameter corresponding to the i-th candidate log type, k1 represents the second weight, k2 represents the first weight, and w i Indicates the fourth anomaly analysis adjustment parameter corresponding to the i-th candidate log type, u i Indicates the third anomaly analysis adjustment parameter corresponding to the i-th candidate log type.
[0189] In this way, the second abnormality analysis adjustment parameter can be calculated.
[0190] S304: Use the second abnormality analysis adjustment parameter as the abnormality analysis adjustment parameter corresponding to the candidate log type to obtain a log parameter correspondence relationship.
[0191] Through the above method, the log parameter correspondence relationship can be generated or updated.
[0192] In some embodiments of the present disclosure, the above steps S301 to S304 may be performed periodically. For example, a preset period may be set and the steps are performed once every preset period. The preset period may be any preset duration.
[0193] In some implementations, the second time period may be a time period within the current cycle, that is, the second preset duration used to determine the second time period is equal to the duration of the preset cycle.
[0194] In some embodiments, the steps of updating the log parameter correspondence shown in S301 to S304 above may be performed by a dynamic programming module.
[0195] In some embodiments of the present disclosure, a network device may store one or more sender record information, each sender record information may include a sender identifier, a recording time, and a historical anomaly analysis indicator corresponding to the sender identifier, and the recording time is the time when the sender record information is first stored in the network device. The sender identifiers recorded in different sender record information may be different. The sender record information may also include a recording time, which may be used to represent the time when the sender record information is first stored in the network device. For example, it may be the time when the sender identifier is first parsed and the sender record information is recorded.
[0196] In some embodiments, the sender record information currently stored in the network device may also be reasonably deleted to reduce resource usage.
[0197] In some implementations, the current amount of sender record information currently stored in the network device can be obtained. When the current amount is greater than or equal to a preset amount threshold, the target duration is determined based on the current amount and the preset amount threshold; the sender record information with a storage duration greater than or equal to the target duration is deleted from the network device.
[0198] The storage duration can be used to represent the time difference between the time when the sender record information is recorded in the network device and the current time; the recording time can be used to represent the time when the sender record information is first stored in the network device. For example, the time when the sender identifier is first parsed and the sender record information is recorded can be used as the recording time of the sender record information.
[0199] In some embodiments, the target duration may be any pre-set duration, for example, 1 day, 7 days, or 1 month.
[0200] In some embodiments, the target duration can be calculated using the following formula (12):
[0201]
[0202] in, represents the target duration, f represents the preset data removal coefficient, which can be any positive number less than 1, dl represents the current amount of sender record information currently stored in the network device, db represents the preset number threshold, and t1 represents the preset data removal interval.
[0203] In this way, the larger the current amount of the currently stored sender record information is, the smaller the calculated target duration is, and the more sender record information is eliminated.
[0204] In some embodiments, the above-mentioned step of reasonably removing the sender record information currently stored in the network device can be executed based on the triggering of the target event, or can be executed periodically.
[0205] In this way, the sender record information currently stored in the network device can be reasonably eliminated according to the above target duration to reduce resource usage.
[0206] Figure 4 is a block diagram of a log data processing device 1100 according to an exemplary embodiment. Figure 4 As shown, the apparatus 1100 may include:
[0207] The log acquisition module 1101 is configured to acquire log data generated by a network device; the log data includes a log recording a sender identifier of a sender device, where the sender device is a device that sends a message to the network device or sends a message passing through the network device;
[0208] The log processing module 1102 is used to determine the target log type corresponding to the log data and the sender identifier;
[0209] An indicator analysis module 1103 is configured to determine an abnormality analysis indicator corresponding to the sender identifier according to the target log type;
[0210] The exception handling module 1104 is configured to perform an exception handling operation according to the sender identifier when the exception analysis indicator is greater than or equal to a preset indicator threshold.
[0211] In some embodiments, the indicator analysis module 1103 is used to determine the abnormality analysis adjustment parameters corresponding to the target log type based on the log parameter correspondence; wherein the log parameter correspondence includes the correspondence between the target log type and the abnormality analysis adjustment parameters; and determine the abnormality analysis indicator corresponding to the sending end identifier based on the abnormality analysis adjustment parameters.
[0212] In some embodiments, the indicator analysis module 1103 is used to determine the abnormality analysis indicator based on the historical abnormality analysis indicator and the abnormality analysis adjustment parameter when the historical abnormality analysis indicator corresponding to the sending end identifier is obtained, and use the abnormality analysis indicator as the new historical abnormality analysis indicator; or, when the historical abnormality analysis indicator corresponding to the sending end identifier is not obtained, determine the abnormality analysis indicator corresponding to the sending end identifier based on the abnormality analysis adjustment parameter, and use the abnormality analysis indicator as the historical abnormality analysis indicator corresponding to the sending end identifier.
[0213] In some embodiments, the apparatus further comprises:
[0214] Figure 5 is a block diagram of another log data processing device 1100 according to an exemplary embodiment. Figure 5 As shown, the apparatus 1100 may further include:
[0215] Initialization module 1105 is used to determine multiple candidate log types; the candidate log types include the target log type; obtain the first data volume generated by each candidate log type in a first time period; the first time period is a historical time period before the current moment; calculate the first anomaly analysis adjustment parameter corresponding to each candidate log type based on the first data volume; the larger the first data volume, the smaller the calculated first anomaly analysis adjustment parameter; use the first anomaly analysis adjustment parameter as the anomaly analysis adjustment parameter corresponding to the candidate log type to obtain the log parameter correspondence.
[0216] In some embodiments, as Figure 5 As shown, the apparatus 1100 may further include:
[0217] The dynamic planning module 1106 is used to obtain the number of logs counted in the second time period and the third data volume in the third time period for each candidate log type; the second time period and the third time period are both time periods before the current moment, and the third time period includes the second time period; determine the second weight corresponding to the third data volume and the first weight corresponding to the number of logs, and the first weight is greater than or equal to the second weight; calculate the second anomaly analysis adjustment parameter corresponding to each candidate log type based on the third data volume, the second weight, the number of logs and the first weight; use the second anomaly analysis adjustment parameter as the anomaly analysis adjustment parameter corresponding to the candidate log type to obtain the log parameter correspondence.
[0218] In some embodiments, as Figure 5 As shown, the apparatus 1100 may further include:
[0219] The data elimination module 1107 is used to obtain the current amount of sender record information currently stored in the network device; each sender record information includes a sender identifier, a recording time, and a historical anomaly analysis indicator corresponding to the sender identifier, and the recording time is the time when the sender record information is first stored in the network device; when the current amount is greater than or equal to a preset amount threshold, the target duration is determined based on the current amount and the preset amount threshold; the sender record information with a storage duration greater than or equal to the target duration is deleted from the network device, and the storage duration is used to represent the time difference between the recording time and the current time.
[0220] In some embodiments, the log processing module 1102 is used to perform text parsing on the log data according to preset type parameters to determine the corresponding target log type in the log data; perform text parsing on the log data according to a preset regular expression to obtain the sender identifier.
[0221] Regarding the apparatus in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.
[0222] Figure 6 FIG. 2 is a block diagram of an electronic device 2000 according to an exemplary embodiment. Figure 6 As shown, the electronic device 2000 may include: a processor 2001 and a memory 2002. The electronic device 2000 may also include one or more of a multimedia component 2003, an input / output (I / O) interface 2004, and a communication component 2005.
[0223] The processor 2001 is used to control the overall operation of the electronic device 2000 to complete all or part of the steps in the log data processing method described above. The memory 2002 is used to store various types of data to support the operation of the electronic device 2000. For example, these data may include instructions for any application or method operating on the electronic device 2000, as well as application-related data, such as contact information, sent and received messages, pictures, audio, video, etc. The memory 2002 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The multimedia component 2003 may include a screen and an audio component. The screen may be, for example, a touch screen, and the audio component is used to output and / or input audio signals. For example, the audio component may include a microphone for receiving external audio signals. The received audio signals may be further stored in the memory 2002 or transmitted via the communication component 2005. The audio component also includes at least one speaker for outputting audio signals. The input / output interface 2004 provides an interface between the processor 2001 and other interface modules. The aforementioned other interface modules may be a keyboard, a mouse, buttons, etc. These buttons may be virtual buttons or physical buttons. The communication component 2005 is used for wired or wireless communication between the electronic device 2000 and other devices. Wireless communication, such as Wi-Fi, Bluetooth, Near Field Communication (NFC), 2G, 3G, 4G, 5G, NB-IOT, eMTC, or other 6G, etc., or a combination of one or more thereof, is not limited here. Therefore, the corresponding communication component 2005 may include: a Wi-Fi module, a Bluetooth module, an NFC module, etc.
[0224] In an exemplary embodiment, the electronic device 2000 can be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to execute the above-mentioned log data processing method.
[0225] In another exemplary embodiment, there is also provided a computer-readable storage medium, which stores a computer program or program instructions, and the steps of the above-mentioned log data processing method are implemented when the computer program or program instructions are executed by the processor. For example, the computer-readable storage medium can be the above-mentioned memory 2002 including program instructions, and the above-mentioned program instructions can be executed by the processor 2001 of the electronic device 2000 to complete the above-mentioned log data processing method. For example, the computer-readable storage medium can be a non-temporary computer-readable storage medium, for example, the non-temporary computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.
[0226] In another exemplary embodiment, a computer program product is further provided. The computer program product includes a computer program that can be executed by a programmable device, and the computer program has a code portion for executing the above-mentioned log data processing method when executed by the programmable device.
[0227] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the present disclosure. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the following claims.
[0228] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.
Claims
1. A log data processing method, characterized in that: The method comprises: Obtaining log data generated by a network device; the log data includes a sender identifier of a sender device, the sender device being a device that sends a message to the network device or sends a message that flows through the network device; Determining a target log type and a sending end identifier corresponding to the log data; Determine the abnormality analysis adjustment parameter corresponding to the target log type according to the log parameter correspondence relationship; wherein the log parameter correspondence relationship includes the correspondence relationship between the target log type and the abnormality analysis adjustment parameter; Determining an abnormality analysis index corresponding to the sender identifier according to the abnormality analysis adjustment parameter, wherein a larger abnormality analysis adjustment parameter is, a larger abnormality analysis index corresponding to the determined sender identifier is, and the abnormality analysis index corresponding to the sender identifier is used to characterize the amount of abnormal information or the degree of abnormal impact of the sender identifier; When the abnormality analysis indicator is greater than or equal to a preset indicator threshold, performing an abnormality handling operation according to the sending end identifier; The log parameter correspondence is generated in the following manner: Determine multiple candidate log types; the candidate log types include the target log type; Obtaining a first amount of data generated by each candidate log type within a first time period; the first time period is a historical time period before the current moment; Calculating a first anomaly analysis adjustment parameter corresponding to each candidate log type based on the first data volume; the larger the first data volume, the smaller the calculated first anomaly analysis adjustment parameter; The first anomaly analysis adjustment parameter is used as the anomaly analysis adjustment parameter corresponding to the candidate log type to obtain the log parameter correspondence relationship.
2. The method according to claim 1, characterized in that Determining the abnormality analysis indicator corresponding to the sender identifier according to the abnormality analysis adjustment parameter includes: In the case of obtaining the historical abnormality analysis indicator corresponding to the sender identifier, determining the abnormality analysis indicator according to the historical abnormality analysis indicator and the abnormality analysis adjustment parameter, and using the abnormality analysis indicator as a new historical abnormality analysis indicator; or If the historical abnormality analysis indicator corresponding to the sender identifier is not obtained, the abnormality analysis indicator corresponding to the sender identifier is determined according to the abnormality analysis adjustment parameter, and the abnormality analysis indicator is used as the historical abnormality analysis indicator corresponding to the sender identifier.
3. The method according to claim 1, characterized in that The log parameter correspondence is updated in the following way: Obtaining the number of logs counted in a second time period and the third data volume in a third time period for each candidate log type; the second time period and the third time period are both time periods before the current moment, and the third time period includes the second time period; Determine a second weight corresponding to the third data volume and a first weight corresponding to the number of logs, wherein the first weight is greater than or equal to the second weight; Calculate a second anomaly analysis adjustment parameter corresponding to each candidate log type according to the third data volume, the second weight, the number of logs, and the first weight; The second abnormality analysis adjustment parameter is used as the abnormality analysis adjustment parameter corresponding to the candidate log type to obtain the log parameter correspondence relationship.
4. The method according to claim 2, characterized in that The method further comprises: Obtaining a current amount of sender record information currently stored in the network device; each sender record information includes a sender identifier, a recording time, and a historical anomaly analysis indicator corresponding to the sender identifier, wherein the recording time is the time when the sender record information is first stored in the network device; When the current number is greater than or equal to a preset number threshold, determining a target duration according to the current number and the preset number threshold; The sending end record information with a storage duration greater than or equal to the target duration is deleted from the network device, and the storage duration is used to represent the time difference between the recording time and the current time.
5. The method according to any one of claims 1 to 4, characterized in that Determining the target log type and the sender identifier corresponding to the log data includes: Performing text parsing on the log data according to preset type parameters to determine the target log type corresponding to the log data; The log data is parsed according to a preset regular expression to obtain the sender identifier.
6. A log data processing device, characterized in that: The device comprises: A log acquisition module, configured to acquire log data generated by a network device; the log data includes a log recording a sender identifier of a sender device, the sender device being a device that sends a message to the network device or sends a message that passes through the network device; A log processing module, configured to determine a target log type and a sender identifier corresponding to the log data; An indicator analysis module is configured to determine, based on a log parameter correspondence, an anomaly analysis adjustment parameter corresponding to the target log type; wherein the log parameter correspondence includes a correspondence between the target log type and the anomaly analysis adjustment parameter; and determine, based on the anomaly analysis adjustment parameter, an anomaly analysis indicator corresponding to the sender identifier; wherein, a larger anomaly analysis adjustment parameter is, a larger anomaly analysis indicator corresponding to the determined sender identifier is, and the anomaly analysis indicator corresponding to the sender identifier is used to characterize an amount of anomaly information or anomaly impact of the sender identifier; An exception handling module, configured to perform an exception handling operation according to the sending end identifier when the exception analysis indicator is greater than or equal to a preset indicator threshold; An initialization module is used to determine multiple candidate log types; the candidate log types include the target log type; obtain a first data volume generated by each candidate log type within a first time period; the first time period is a historical time period before the current moment; calculate a first anomaly analysis adjustment parameter corresponding to each candidate log type based on the first data volume; the larger the first data volume, the smaller the calculated first anomaly analysis adjustment parameter; use the first anomaly analysis adjustment parameter as the anomaly analysis adjustment parameter corresponding to the candidate log type to obtain the log parameter correspondence.
7. An electronic device, characterized in that: include: a memory having a computer program stored thereon; A processor, configured to execute the computer program in the memory to implement the steps of the method according to any one of claims 1 to 5.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Network attack source identification method and device, computer equipment and storage medium
CN112953917A