Domain name alarm information sending method, device, electronic device and computer-readable storage medium

Through the aggregation of domain name alarm data and the combined verification of online and offline data, the problems of untimely alarm and high false alarm rates in existing domain name monitoring are solved, and accurate domain name alarm and efficient inspection process are achieved.

CN115941432BActive Publication Date: 2025-09-02BEIJING ZITIAO NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110665935.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-06-16
Publication Date
2025-09-02
Estimated Expiration
2041-06-16

AI Technical Summary

Technical Problem

The existing domain name monitoring technology has problems such as untimely alarms, high false alarm rates, and low troubleshooting efficiency. Especially in the case of domain names and network fluctuations with low access frequency, it is difficult to accurately and timely discover domain name problems.

Method used

By obtaining domain name alarm data, performing aggregation processing, determining whether to send alarm information based on the dimensional attribute number of aggregated domain name alarm data, and verifying it in combination with online and offline data, eliminating devices with unstable network status, and using online data and offline detection tasks to detect whether CDN and DNS are abnormal, ensuring the accuracy of alarm information.

Benefits of technology

It improves the accuracy and inspection efficiency of domain name alarms, reduces false alarms, can promptly detect and locate domain name problems, and improves the reliability and efficiency of domain name monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115941432B_ABST
    Figure CN115941432B_ABST
Patent Text Reader

Abstract

The embodiments of the present disclosure disclose a method, device, electronic device, and computer-readable storage medium for sending alarm information. The method for sending alarm information includes: obtaining domain name alarm data; aggregating the domain name alarm data to obtain aggregated domain name alarm data; if the aggregated domain name alarm data meets the alarm conditions, sending domain name alarm information; if the aggregated domain name alarm data does not meet the alarm conditions, checking online data based on the domain name alarm data; if the online data is abnormal, sending domain name alarm information; if the online data is normal, checking offline data based on the domain name alarm data; if the offline data is abnormal, sending domain name alarm information. The above method solves the technical problems of low alarm troubleshooting efficiency and large alarm errors by aggregating domain name alarm data and verifying the domain name alarm data through online and offline data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of information transmission, and in particular to a method, device, electronic device and computer-readable storage medium for transmitting domain name alarm information. Background Art

[0002] To ensure application availability and user experience, long-term monitoring of the domain names used by applications is necessary to ensure timely detection of domain name issues. Currently, there are two main methods for domain name monitoring: online monitoring, which extracts data from actual user access and reflects real user access. Offline detection, which simulates active user access through distributed nodes in multiple regions around the world to obtain detailed network detection data.

[0003] However, online monitoring relies on product access. Other products that are not connected to the platform cannot obtain data, so it is impossible to monitor the domain names of external products. There is also the problem of delayed alarms. When the alarm is issued, it usually has affected the use of some users. Especially for domain names with low access frequency, due to insufficient online monitoring data, there may be cases where domain name problems are not discovered until some time later.

[0004] For offline detection, the alarm accuracy may not reach 100% due to unstable detection nodes. Therefore, manual intervention is usually required to determine whether there is a real problem with the alarm domain name.

[0005] In addition, the following problems still exist from alarm to troubleshooting: the alarms are numerous and scattered, and a single alarm can neither clearly reflect the problem nor reduce the efficiency of alarm troubleshooting; the network fluctuations or low network speed of the equipment itself will lead to inaccurate detection results; there may be a problem of too little data, resulting in larger alarm errors; and the problem cannot be reproduced and verified. Summary of the Invention

[0006] This summary is provided to briefly introduce concepts that will be described in detail in the detailed description below. This summary is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0007] In order to at least partially solve the above technical problems, the embodiments of the present disclosure propose the following technical solutions.

[0008] In a first aspect, an embodiment of the present disclosure provides a method for sending domain name alarm information, comprising:

[0009] Obtain domain name alarm data; wherein each domain name alarm data includes multiple dimension attributes;

[0010] Aggregate domain name alarm data with one or more identical dimension attributes to obtain aggregated domain name alarm data;

[0011] If the number of one or more dimension attributes in the aggregated domain name alarm data is greater than a preset threshold, sending a domain name alarm message; wherein the domain name alarm message indicates that the domain name alarm data is true;

[0012] If the number of any dimension attribute in the aggregated domain name alarm data is less than a preset threshold, checking online data based on the domain name alarm data; wherein the online data is data generated based on user use of the product;

[0013] If the online data meets the online data abnormality condition, a domain name alarm message is sent;

[0014] If the online data does not meet the online data abnormality condition, then checking the offline data according to the domain name alarm data; wherein the offline data is data obtained by dialing and testing the product;

[0015] If the offline data meets the offline data abnormality condition, a domain name alarm message is sent.

[0016] Furthermore, before obtaining the domain name alarm data, it also includes:

[0017] Detect the network status of the device generating domain name alarm data;

[0018] If the network status of the domain name alarm data generating device does not meet the preset network conditions, the domain name alarm data generating device is deleted from the domain name alarm data source; wherein, the domain name alarm data source is a collection of domain name alarm data generating devices.

[0019] Furthermore, the aggregating domain name alarm data with the same one or more dimensional attributes to obtain aggregated domain name alarm data includes:

[0020] Obtain at least one aggregate item in the domain name alarm data; the aggregate item includes the one or more dimension attributes;

[0021] Aggregate the domain name alarm data with the same value of one or more dimensions corresponding to each aggregation item to obtain candidate aggregate domain name alarm data;

[0022] The candidate aggregated domain name alarm data with the least number of items is used as the aggregated domain name alarm data.

[0023] Furthermore, the aggregation item includes: one or more dimension attributes of country, city, operator, and domain name.

[0024] Furthermore, if the number of one or more dimension attributes in the aggregated domain name alarm data is greater than a preset threshold, sending domain name alarm information includes:

[0025] When the aggregated item of the aggregated domain name alarm data is a domain name, if the number of countries and / or the number of cities in the aggregated domain name alarm data is greater than a first threshold, sending a domain name alarm message;

[0026] When the aggregation item of the aggregated domain name alarm data is a country, if the number of operators and / or the number of domain names in the aggregated domain name alarm data is greater than a second threshold, domain name alarm information is sent.

[0027] Furthermore, if the number of any dimension attribute in the aggregated alarm data is less than a preset threshold, checking online data according to the domain name alarm data includes:

[0028] If the number of any dimension attribute in the aggregated alarm data is less than a preset threshold, extract and check online data;

[0029] The online data includes: the average success rate during the alarm time period, the average success rate of the most recent day, the total number of reports during the alarm time period, the total number of reports during the same time period of the previous day, and one or more of the top three errors and their proportions during the alarm time period; wherein the success rate is the access success rate of the target domain name; and the total number of reports is the total number of visits to the target domain name.

[0030] Furthermore, the online data meeting the online data abnormality condition includes one or more of the following situations:

[0031] The average success rate during the alarm period is lower than the first threshold; or

[0032] The average success rate during the alarm period is lower than the average success rate of the most recent day by a second threshold; or

[0033] The total number of reports during the alarm period is higher than the total number of reports during the same period on the previous day by a third threshold; or

[0034] The error rate during the alarm period is higher than the fourth threshold.

[0035] Furthermore, checking offline data according to the domain name alarm data includes:

[0036] A real-time task is issued based on the domain name alarm data to check offline data.

[0037] Furthermore, the issuing of a real-time task to check offline data includes:

[0038] Issue real-time tasks to detect CDN anomalies; and / or,

[0039] Issue real-time tasks to detect DNS anomalies.

[0040] Furthermore, the issuing of a real-time task to detect whether the CDN is abnormal includes:

[0041] Obtaining a first CDN address in an access failure set and a second CDN address in an access success set in the domain name alarm data;

[0042] issuing a real-time task to detect the first CDN address and the second CDN address;

[0043] If the detection of the first CDN address fails and the detection of the second CDN address succeeds, it is determined that the CDN corresponding to the first CDN address is abnormal.

[0044] Furthermore, the issuing of a real-time task to detect whether the DNS is abnormal includes:

[0045] Use the preset DNS to resolve the target domain name;

[0046] If the resolution is successful, it is determined that the DNS is abnormal; otherwise, it is determined that the target domain name is abnormal.

[0047] In a second aspect, an embodiment of the present disclosure provides a domain name alarm information sending device, comprising:

[0048] A domain name alarm data acquisition module is used to acquire domain name alarm data; each domain name alarm data includes multiple dimension attributes;

[0049] Aggregation module, used to aggregate domain name alarm data with the same one or more dimension attributes to obtain aggregated domain name alarm data;

[0050] The checking and alarm module is used to send a domain name alarm message if the number of one or more dimensional attributes in the aggregated domain name alarm data is greater than a preset threshold; wherein, the domain name alarm message indicates that the domain name alarm data is true; if the number of any dimensional attributes in the aggregated domain name alarm data is less than the preset threshold, check the online data according to the domain name alarm data; wherein, the online data is data generated based on the user's use of the product; if the online data meets the online data abnormality condition, send a domain name alarm message; if the online data does not meet the online data abnormality condition, check the offline data according to the domain name alarm data; wherein, the offline data is data obtained by dialing the product; if the offline data meets the offline data abnormality condition, send a domain name alarm message.

[0051] Furthermore, the alarm information sending device further includes:

[0052] A domain name alarm data generating device screening module is used to detect the network status of the domain name alarm data generating device; if the network status of the domain name alarm data generating device does not meet the preset network conditions, the domain name alarm data generating device is deleted from the domain name alarm data source; wherein, the domain name alarm data source is a collection of domain name alarm data generating devices.

[0053] Furthermore, the aggregation module is further configured to:

[0054] Obtain at least one aggregate item in the domain name alarm data; the aggregate item includes the one or more dimension attributes;

[0055] Aggregate the domain name alarm data with the same value of one or more dimensions corresponding to each aggregation item to obtain candidate aggregate domain name alarm data;

[0056] The candidate aggregated domain name alarm data with the least number of items is used as the aggregated domain name alarm data.

[0057] Furthermore, the aggregation item includes: one or more dimension attributes of country, city, operator, and domain name.

[0058] Furthermore, the inspection and alarm module is also used to:

[0059] When the aggregated item of the aggregated domain name alarm data is a domain name, if the number of countries and / or the number of cities in the aggregated domain name alarm data is greater than a first threshold, sending a domain name alarm message;

[0060] When the aggregation item of the aggregated domain name alarm data is a country, if the number of operators and / or the number of domain names in the aggregated domain name alarm data is greater than a second threshold, domain name alarm information is sent.

[0061] Furthermore, the inspection and alarm module is also used to:

[0062] If the number of any dimension attribute in the aggregated alarm data is less than a preset threshold, extract and check online data;

[0063] The online data includes: the average success rate during the alarm time period, the average success rate of the most recent day, the total number of reports during the alarm time period, the total number of reports during the same time period of the previous day, and one or more of the top three errors and their proportions during the alarm time period; wherein the success rate is the access success rate of the target domain name; and the total number of reports is the total number of visits to the target domain name.

[0064] Furthermore, the online data meeting the online data abnormality condition includes one or more of the following situations:

[0065] The average success rate during the alarm period is lower than the first threshold; or

[0066] The average success rate during the alarm period is lower than the average success rate of the most recent day by a second threshold; or

[0067] The total number of reports during the alarm period is higher than the total number of reports during the same period on the previous day by a third threshold; or

[0068] The error rate during the alarm period is higher than the fourth threshold.

[0069] Furthermore, the inspection and alarm module is further configured to: issue a real-time task based on the domain name alarm data to inspect offline data.

[0070] Furthermore, the inspection and alarm module is further configured to: issue a real-time task to detect whether the CDN is abnormal; and / or,

[0071] Issue real-time tasks to detect DNS anomalies.

[0072] Furthermore, the inspection and alarm module is also used to:

[0073] Obtaining a first CDN address in an access failure set and a second CDN address in an access success set in the domain name alarm data;

[0074] issuing a real-time task to detect the first CDN address and the second CDN address;

[0075] If the detection of the first CDN address fails and the detection of the second CDN address succeeds, it is determined that the CDN corresponding to the first CDN address is abnormal.

[0076] Furthermore, the inspection and alarm module is also used to:

[0077] Use the preset DNS to resolve the target domain name;

[0078] If the resolution is successful, it is determined that the DNS is abnormal; otherwise, it is determined that the target domain name is abnormal.

[0079] In a third aspect, an embodiment of the present disclosure provides an electronic device, including:

[0080] a memory for storing computer-readable instructions; and

[0081] A processor is configured to execute the computer-readable instructions so that the electronic device implements the method according to any one of the first aspects above.

[0082] In a fourth aspect, an embodiment of the present disclosure provides a non-transitory computer-readable storage medium for storing computer-readable instructions. When the computer-readable instructions are executed by a computer, the computer implements the method described in any one of the first aspects above.

[0083] The embodiments of the present disclosure disclose a method, device, electronic device, and computer-readable storage medium for sending domain name alarm information. The method for sending domain name alarm information includes: obtaining domain name alarm data; aggregating the domain name alarm data to obtain aggregated domain name alarm data; if the aggregated domain name alarm data meets the domain name alarm conditions, sending domain name alarm information; if the aggregated domain name alarm data does not meet the domain name alarm conditions, checking online data based on the domain name alarm data; if the online data is abnormal, sending domain name alarm information; if the online data is normal, checking offline data based on the domain name alarm data; if the offline data is abnormal, sending domain name alarm information. The above method solves the technical problems of low efficiency in troubleshooting domain name alarms and large errors in domain name alarms by aggregating domain name alarm data and verifying the domain name alarm data through online and offline data.

[0084] The above description is only an overview of the technical solution of the present disclosure. In order to more clearly understand the technical means of the present disclosure, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present disclosure more obvious and easy to understand, the following specifically cites preferred embodiments and describes them in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0085] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that the originals and elements are not necessarily drawn to scale.

[0086] Figure 1 A flowchart of a method for sending domain name alarm information provided by an embodiment of the present disclosure;

[0087] Figure 2 A further flowchart of the method for sending domain name alarm information provided by an embodiment of the present disclosure;

[0088] Figure 3 A schematic diagram of the structure of an embodiment of a domain name alarm information sending device provided by an embodiment of the present disclosure;

[0089] Figure 4 The figure is a schematic structural diagram of an electronic device provided according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0090] The following describes embodiments of the present disclosure in more detail with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.

[0091] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.

[0092] As used herein, the term "including" and its variations are open-ended, i.e., "including but not limited to." The term "based on" means "based, at least in part, on." The term "one embodiment" means "at least one embodiment," the term "another embodiment" means "at least one additional embodiment," and the term "some embodiments" means "at least some embodiments." Other terms are defined in the following description.

[0093] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0094] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".

[0095] Figure 1 This is a flowchart of an embodiment of a domain name alarm information sending method provided by an embodiment of the present disclosure. The domain name alarm information sending method provided by this embodiment can be executed by a domain name alarm information sending device. The domain name alarm information sending device can be implemented as software, or as a combination of software and hardware. The domain name alarm information sending device can be integrated into a device in a domain name alarm information sending system, such as a domain name alarm information sending terminal or server. Figure 1 As shown, the method includes the following steps:

[0096] Step S101: Acquire domain name alarm data; wherein each domain name alarm data includes multiple dimensional attributes;

[0097] The domain name alarm data is candidate domain name alarm data obtained by a domain name alarm data generating device. Exemplarily, the domain name alarm data generating device is a dialing device, which is deployed in various regions and by various operators and is used to periodically send detection information to the target domain name to be tested to determine the connectivity of the target domain name. The domain name alarm information sending terminal or server obtains the domain name alarm data from a domain name alarm data source, which is a collection of domain name alarm data generating devices, such as the collection of dialing devices.

[0098] In order to obtain more accurate alarm data, before step S101, the following steps are further included:

[0099] Step S201, detecting the network status of the domain name alarm data generating device;

[0100] Step S202: If the network status of the domain name alarm data generating device does not meet the preset network conditions, the domain name alarm data generating device is deleted from the domain name alarm data source; wherein the domain name alarm data source is a collection of domain name alarm data generating devices.

[0101] For example, since the domain name alarm data generating device is located in a certain network environment, the stability of the network environment may affect the accuracy of the domain name alarm data. For example, a domain name alarm data generating device cannot connect to the target domain name and generates domain name alarm data. However, the reason why the domain name alarm data generating device cannot connect to the target domain name is not necessarily due to a problem with the target domain name, but may also be due to an issue with the network environment in which the domain name alarm data generating device is located. Therefore, before obtaining domain name alarm data, some domain name alarm data can be excluded by excluding problematic domain name alarm data generating devices.

[0102] As described in the above steps, in step S201, the network status of the domain name alarm data generating device is detected. Exemplarily, whether the network status of the domain name alarm data generating device is stable is detected by accessing some stable domain names. Typical stable domain names include domain names of large portal websites, domain names of well-known services, etc. The domain name alarm data generating device accesses the stable domain names. If the access success rate is greater than a preset threshold, it is determined that the network status of the network where the domain name alarm data generating device is located is stable. If the access success rate is lower than the preset threshold, it is determined that the network status of the network is unstable.

[0103] In step S201, if it is determined that the network status of the domain name alarm data generating device does not meet the preset network conditions, such as if the success rate of accessing a stable domain name is lower than a preset threshold, the domain name alarm data generating device is removed from the domain name alarm data source. In other words, when obtaining domain name alarm data, devices whose network status does not meet the preset conditions are eliminated.

[0104] Optionally, the domain name alarm data includes multiple dimension attributes, which are used to describe the source of the domain name alarm data, network conditions, domain name, etc. For example, the domain name alarm data includes dimension attributes such as country, city, operator, domain name, access error type, etc.

[0105] Return to Attachment Figure 1 The domain name alarm information sending method further includes step S102: aggregating domain name alarm data with the same one or more dimensional attributes to obtain aggregated domain name alarm data.

[0106] To eliminate bias caused by individual domain name alarm data and to prevent subsequent multiple investigations of the same issue, in step S102, the acquired domain name alarm data is aggregated to obtain aggregated domain name alarm data. It is understood that the number of aggregated domain name alarm data obtained may vary depending on the aggregation method, and the number of aggregated domain name alarm data may be one or more.

[0107] Optionally, step S102 further includes:

[0108] Obtain at least one aggregate item in the domain name alarm data; the aggregate item includes the one or more dimension attributes;

[0109] Aggregate the domain name alarm data with the same value of one or more dimensions corresponding to each aggregation item to obtain candidate aggregate domain name alarm data;

[0110] The candidate aggregated domain name alarm data with the least number of items is used as the aggregated domain name alarm data.

[0111] In step S102, aggregation refers to combining domain name alarm data according to a specific dimensional attribute. For example, the aggregation item is a dimensional attribute of the domain name alarm data, such as one or more of country, city, operator, and domain name. After obtaining the aggregation items, the domain name alarm data is aggregated according to each aggregation item. Aggregation using each aggregation item may result in one or more aggregated domain name alarm data.

[0112] For example, there are 5 domain name alarm data items obtained in step S101, as shown in Table 1 below:

[0113] nation City Operator domain name Country1 City1 Operator1 domain1 Country1 City1 Operator2 domain1 Country1 City2 Operator1 domain2 Country2 City3 Operator3 domain2 Country2 City4 Operator4 domain1

[0114] Table 1

[0115] For example, the five domain name alarm data are aggregated using country, operator, and domain name as aggregation items. Aggregating using country as the aggregation item yields two candidate aggregated data items, as shown in Table 2 below:

[0116]

[0117] Table 2 is aggregated with operator as the aggregation item, and three candidate aggregation data are obtained, as shown in Table 3 below:

[0118]

[0119] Table 3

[0120] Aggregating with domain name as the aggregation item, we get two candidate aggregation data, as shown in Table 4 below:

[0121]

[0122] Table 4

[0123] It can be determined that the aggregation item with the least number of candidate aggregated domain name alarm data is the candidate aggregated domain name alarm data obtained with the domain name as the aggregation item or the country as the aggregation item, and the aggregation data in Table 2 or Table 4 is used as the final aggregated domain name alarm data.

[0124] Through the aggregation operation, domain name alarm data with common characteristics can be aggregated into one domain name alarm data, so that there is no need to repeatedly troubleshoot the same problem in the future. For example, if the domain name alarm data of Country1 is aggregated into one, then when troubleshooting the problem later, you can conduct a single investigation on that country to improve the troubleshooting efficiency.

[0125] Return to Attachment Figure 1 The domain name alarm information sending method also includes step S103: if the number of one or more dimensional attributes in the aggregated domain name alarm data is greater than a preset threshold, domain name alarm information is sent; wherein, the domain name alarm information indicates that the domain name alarm data is true.

[0126] In this step, if the number of one or more dimension attributes in the aggregated domain name alarm data is greater than the preset threshold, it means that the data is obviously aggregated, which means that the problem is more concentrated. At this time, the domain name alarm information can be sent directly.

[0127] Optionally, step S103 includes:

[0128] When the aggregated item of the aggregated domain name alarm data is a domain name, if the number of countries and / or the number of cities in the aggregated domain name alarm data is greater than a first threshold, sending a domain name alarm message;

[0129] When the aggregation item of the aggregated domain name alarm data is a country, if the number of operators and / or the number of domain names in the aggregated domain name alarm data is greater than a second threshold, domain name alarm information is sent.

[0130] As shown in the example above, Table 4 shows the aggregation results using domain names as the aggregation item. In the aggregated data for domain1, the number of countries is 2, and the number of cities is 2. When the first threshold is 1, a domain name alarm message is directly sent, indicating that domain1 is abnormal. In the aggregated data for domain2, the number of countries is 2, and the number of cities is 2. When the first threshold is 1, a domain name alarm message is directly sent, indicating that domain2 is abnormal.

[0131] As shown in the example above, Table 2 shows the aggregation results based on country. In the aggregated data for Country 1, the number of operators and domain names is 2, so a domain name alarm message is sent directly, indicating an abnormality in Country 1. In the aggregated data for Country 1, the number of operators and domain names is 2, so a domain name alarm message is sent directly, indicating an abnormality in Country 2.

[0132] Return to Attachment Figure 1 The domain name alarm information sending method also includes step S104: if the number of any dimensional attributes in the aggregated domain name alarm data is less than a preset threshold, checking the online data based on the domain name alarm data; wherein, the online data is data generated based on the user's use of the product.

[0133] If the number of any dimension attribute in the aggregated domain name alarm data is less than a preset threshold, the accuracy of the domain name alarm data is verified using online data. The online data is data generated based on user usage of the product, such as data actually generated when users use the app.

[0134] Exemplarily, the online data is online data related to a target domain name. For example, the target domain name is the domain name used by a service of a specific application, such as the domain name of a video service provided by a video application. When a video application installed on a terminal device requests a video, it needs to access the target domain name. When a user actually uses the video service, corresponding online data is generated. Certain indicators of this online data can be used to verify whether the target domain name is abnormal.

[0135] Optionally, step S104 includes:

[0136] If the number of any dimension attribute in the aggregated alarm data is less than a preset threshold, extract and check online data;

[0137] The online data includes: the average success rate during the alarm period, the average success rate of the most recent day, the total number of reports during the alarm period, the total number of reports during the same period of the previous day, and one or more of the access errors and their proportions during the alarm period; wherein the success rate is the access success rate of the target domain name; and the total number of reports is the total number of visits to the target domain name.

[0138] Optionally, the average success rate within the alarm time period is the average access success rate of the target domain name in a certain alarm country and / or alarm operator within the alarm time period, wherein the alarm time period is the time period from the alarm moment to a preset time period before the alarm moment. For example, if the preset time period is 5 hours and the alarm time is 10 o'clock, the alarm period is defined as the time period between 5 o'clock and 10 o'clock; the total reporting volume includes the overall reporting volume of the target domain name in the alarm country and / or alarm operator, including the reporting volume of successful access and the reporting volume of failed access; the error is the error type when the access fails, typical error types include connection timeout, DNS resolution timeout, SSL handshake failure, etc. The proportion of access errors refers to the proportion of the number of a certain error or several errors to the total number of errors.

[0139] It is understandable that the above online data is only an example and does not constitute a limitation to the present disclosure. In fact, any indicator that can represent the online access status of the target domain name can be used as online data, which will not be repeated here.

[0140] Return to Attachment Figure 1 The alarm information sending method also includes step S105: if the online data meets the online data abnormality condition, domain name alarm information is sent.

[0141] The fact that the online data meets the online data abnormality condition indicates that an abnormality has indeed occurred and an alarm needs to be issued.

[0142] Optionally, the online data meeting the online data abnormality condition includes one or more of the following situations:

[0143] The average success rate during the alarm period is lower than the first threshold; or

[0144] The average success rate during the alarm period is lower than the average success rate of the most recent day by a second threshold; or

[0145] The total number of reports during the alarm period is higher than the total number of reports during the same period on the previous day by a third threshold; or

[0146] The error rate during the alarm period is higher than the fourth threshold.

[0147] Among them, the average success rate during the alarm time period is lower than the first threshold, which means that in the alarm country and / or alarm operator and / or alarm city, the success rate of accessing the target domain name is lower than the first threshold, wherein the first threshold is a preset value or a dynamically calculated value. Exemplarily, the first threshold is 50%, that is, the access success rate is lower than 50%. At this time, it is judged that an abnormal situation has occurred and an alarm is required. However, whether the cause of the abnormality is the target domain name or the alarm country requires further judgment. For example, if the success rate of accessing the target domain name in only one country is lower than 50%, there may be a problem with the network exit of that country; if the success rate of accessing the target domain name in multiple countries is lower than 50%, there may be a problem with the target domain name itself.

[0148] If the average success rate during the alarm period is lower than the average success rate of the most recent day by a second threshold, it indicates a sudden drop in the success rate. For example, if the average success rate during the alarm period is 10% lower than the average success rate of the most recent day, it indicates a sudden drop in the access success rate. This condition is helpful for identifying recent problems. For example, problems that occurred suddenly in the last few hours may not be reflected in the average access success rate, but they will definitely cause a sudden drop in the average access success rate, thus allowing for more accurate problem detection.

[0149] The total number of reports during the alarm period is higher than the total number of reports during the same period the previous day by a third threshold. An increase in total reports indicates an increase in access volume. Given a certain number of terminals accessing the target domain, an increase in total reports is only caused by access failures. Because failed accesses trigger re-access attempts, an increase in total reports is likely due to access failures to the target domain. For example, the third threshold is 20%, meaning a 20% increase in access reports indicates a potential anomaly and requires an alarm.

[0150] The error rate during the alarm period is higher than the fourth threshold. In this case, during the alarm period, the error rate of one or more errors exceeds the fourth threshold. This means that one or more errors are concentrated, such as DNS resolution timeouts. If the number of these errors accounts for more than 30% of the total number of errors, it indicates that there is a high probability of a DNS problem and an alarm is required.

[0151] By checking this online data, we can identify and locate problems, and then send domain name alerts. These alerts include anomaly information, indicating the location of the anomaly, such as a specific country, operator, or domain name. Because they're verified with online data, domain name alerts are more accurate and can eliminate false positives.

[0152] However, since online data is historical data, there will be a certain lag, and domain name alarm data is periodic offline detection data, which is newer than online data. Therefore, if the problem of accessing the target domain name occurs after the above-mentioned online data is generated, it is impossible to verify whether the problem actually occurred using only online data; and online data is generally only for domain names accessed by the platform, and online data of domain names accessed by third parties cannot be obtained. Therefore, in this disclosure, offline data is used to further verify the domain name alarm data.

[0153] Return to Attachment Figure 1 The domain name alarm information sending method also includes step S106: if the online data does not meet the online data abnormality condition, checking the offline data according to the domain name alarm data; wherein, the offline data is data obtained by dialing the product.

[0154] As mentioned above, the absence of abnormalities in online data does not necessarily mean that there are no abnormalities. In this case, you can verify whether there is a problem by checking offline data. The offline data is the data obtained by real-time dialing of the product through the dialing task.

[0155] Optionally, the checking offline data according to the domain name alarm data includes:

[0156] A real-time task is issued based on the domain name alarm data to check offline data.

[0157] As mentioned above, due to the lag of online data, a real-time task is issued to check offline data to determine whether a domain alarm has occurred. Domain alarm data includes the source of the domain alarm, such as the country and city, the network environment of the domain alarm, such as the carrier, and the target domain of the domain alarm. Based on this domain alarm data, a real-time task is configured and issued to the dial-up test device for detection.

[0158] Optionally, issuing a real-time task to check offline data includes:

[0159] Issue real-time tasks to detect CDN anomalies; and / or,

[0160] Issue real-time tasks to detect DNS anomalies.

[0161] CDN (Content Delivery Network) is a distributed network built and covered on the bearer network, consisting of edge node server clusters distributed in different regions. CDN is widely used and supports content acceleration in various industries and scenarios, such as: small image files, large file downloads, video and audio on demand, live streaming, full-site acceleration, and security acceleration. That is, when a user requests to access the target domain name, they will be redirected to the corresponding CDN and the desired resources will be obtained through the CDN cache. This process is imperceptible to the user. When a problem occurs with the CDN, it may cause access failure to the target domain name. Therefore, by issuing real-time tasks to detect whether the corresponding CDN is abnormal, it is possible to determine whether the problem is with the CDN or the target domain name.

[0162] DNS (Domain Name System) is used to resolve domain names into corresponding IP addresses, allowing computing devices to access the services corresponding to the domain names. If the DNS is abnormal, it may not be able to resolve the IP address corresponding to the target domain name, or it may resolve the wrong IP address, resulting in a failure to access the target domain name.

[0163] Therefore, by detecting whether CDN and DNS are abnormal, it is possible to locate whether the problem actually exists and determine the cause of the failure to access the target domain name.

[0164] Furthermore, it is possible to determine whether to prioritize CDN or DNS detection based on the error code in the domain name alarm data. The error code is used to indicate the reason for the failure to access the domain name. For example, if the reason for the failure is request timeout, priority is given to detecting whether the CDN is abnormal; if the reason for the failure is DNS timeout or failure, priority is given to detecting whether the DNS is abnormal.

[0165] Optionally, the issuing of a real-time task to detect whether the CDN is abnormal includes:

[0166] Obtain the first CDN address in the access failure set and the second CDN address in the access success set in the domain name alarm data;

[0167] issuing a real-time task to detect the first CDN address and the second CDN address;

[0168] If the detection of the first CDN address fails and the detection of the second CDN address succeeds, it is determined that the CDN corresponding to the first CDN address is abnormal.

[0169] In this optional embodiment, the domain name alarm data includes the address of the CDN that was successfully or unsuccessfully accessed, such as the CDN's IP address. When determining whether a CDN is abnormal, first obtain the first CND address in the access failure set and the second CDN address in the access success set. For example, if a certain CDN address fails to access in a certain country, it is used as the first CDN address. If another CND address is successfully accessed in the same country, it is used as the second CDN address. Afterwards, a real-time task is issued to the two CDN addresses through the dialing test equipment in the dialing test platform to detect the connectivity of the two addresses. If the detection of the first CDN address fails and the detection of the second CDN address succeeds, it proves that the data in the domain name alarm data is correct and the CND corresponding to the first CND address is abnormal.

[0170] For example, the dial-up test platform implements real-time task delivery through the curl command, creates a curl real-time task to access the target domain name of the domain name alarm, and forcibly resolves the target domain name to the CDN node to be verified, so as to determine the connectivity of the target domain name under the node.

[0171] For example, curl is:

[0172] curl <domain>-v--resolve <domain>:443:<IP of the First CND>

[0173] curl <domain>-v--resolve <domain>:443:<IP address of the second CND>

[0174] If the detection of the IP designated to the first CND succeeds and the detection of the IP designated to the second CND fails, it can be determined that there is a problem with the first CND node.

[0175] That is, in the above steps, a real-time task is used to verify whether the abnormal CDN in the domain name alarm data is indeed abnormal. During the verification, in order to rule out problems with the dial-up testing platform itself, when verifying the CDN that failed to be accessed, the CDN that was successfully accessed is also verified. By comparison, it is determined whether the CDN that failed to be accessed is really abnormal.

[0176] In the process of detecting CDN anomalies through offline data, online data can also be used to determine whether the access success rate of the target domain name under the first CDN node is abnormal. The abnormality can refer to the above-mentioned online data standards and will not be repeated here.

[0177] Optionally, the issuing of a real-time task to detect whether the DNS is abnormal includes:

[0178] Use the preset DNS to resolve the target domain name;

[0179] If the resolution is successful, it is determined that the DNS is abnormal; otherwise, it is determined that the target domain name is abnormal.

[0180] Failure to access the target domain name may also be due to an abnormality in the DNS used by the device accessing the target domain name, resulting in the domain name not being correctly resolved. Therefore, in order to determine whether the target domain name is abnormal or the DNS is abnormal, a real-time task is issued to detect the DNS to determine whether the DNS used by the device is abnormal. Among them, the preset DNS in the above steps is a stable DNS, such as the DNS service provided by some large platforms. It can generally be considered that there is no abnormality in the DNS. The target domain name is resolved through the preset DNS. If the resolution is successful, it means that there is no abnormality in the target domain name, which means that the DNS used by the device contained in the domain name alarm information is abnormal; if the resolution fails, it is determined that the target domain name is abnormal.

[0181] For example, the connectivity of the domain name can be determined by creating a dig real-time task on the dial-up test platform. For example, the dig command is as follows:

[0182] dig<domain_name> @8.8.8.8

[0183] 8.8.8.8 is the preset DNS server address. If the target domain name resolution through 8.8.8.8 times out or fails, it is considered that there is a problem with the target domain name itself. If the resolution is successful, it is considered that the DNS used by the device is abnormal.

[0184] Optionally, before checking offline data, you can determine the inspection target based on the error code in the domain name alarm data. For example, if the error code shows that the reason for the access failure is a request timeout, prioritize checking whether the CDN is abnormal. If the reason for the access failure is a DNS timeout / failure, prioritize checking whether the DNS is abnormal.

[0185] Return to Attachment Figure 1 The alarm information sending method also includes step S107: if the offline data meets the offline data abnormality condition, domain name alarm information is sent.

[0186] Through the inspection in the above step S106, if it is found that the offline data meets the offline data abnormality condition, a domain name alarm message is sent. If there is no abnormality, it means that the domain name alarm data is a false alarm after investigation and can be filtered out through the verification of the above steps.

[0187] Through the steps in the above embodiment, the acquired domain name alarm data is aggregated to reduce the amount of data to be checked and the error rate. Verification of the domain name alarm data is then performed online and offline to ensure its accuracy. Furthermore, through online data indicators or real-time verification of offline data, the cause and location of the problem can be located. In one embodiment, because domain name alarm data is a periodic detection result, problems can be discovered using domain name alarm data before online data, allowing them to be fixed before they occur online.

[0188] In the above, although the various steps in the above method embodiment are described in the above order, those skilled in the art should be aware that the steps in the embodiments of the present disclosure are not necessarily executed in the above order, and they can also be executed in other orders such as reverse order, parallel order, and cross order. Moreover, based on the above steps, those skilled in the art can also add other steps. These obvious variations or equivalent replacement methods should also be included in the scope of protection of the present disclosure and will not be repeated here.

[0189] Figure 3 This is a schematic diagram of the structure of an embodiment of the alarm information sending device provided in the embodiment of the present disclosure. Figure 3 As shown, the device 300 includes: a domain name alarm data acquisition module 301, an aggregation module 302, and a check and alarm module 303.

[0190] The domain name alarm data acquisition module 301 is used for the domain name alarm data acquisition module to acquire domain name alarm data; acquire domain name alarm data; wherein each domain name alarm data includes multiple dimension attributes;

[0191] Aggregation module 302, configured to aggregate domain name alarm data with the same one or more dimensional attributes to obtain aggregated domain name alarm data;

[0192] The checking and alarm module 303 is used to send a domain name alarm message if the number of one or more dimensional attributes in the aggregated domain name alarm data is greater than a preset threshold; wherein, the domain name alarm message indicates that the domain name alarm data is true; if the number of any dimensional attributes in the aggregated domain name alarm data is less than the preset threshold, then check the online data according to the domain name alarm data; wherein, the online data is data generated based on the user's use of the product; if the online data meets the online data abnormality condition, then send a domain name alarm message; if the online data does not meet the online data abnormality condition, then check the offline data according to the domain name alarm data; wherein, the offline data is data obtained by dialing the product; if the offline data meets the offline data abnormality condition, then send a domain name alarm message.

[0193] Furthermore, the alarm information sending device 300 further includes:

[0194] A domain name alarm data generating device screening module is used to detect the network status of the domain name alarm data generating device; if the network status of the domain name alarm data generating device does not meet the preset network conditions, the domain name alarm data generating device is deleted from the domain name alarm data source; wherein, the domain name alarm data source is a collection of domain name alarm data generating devices.

[0195] Furthermore, the aggregation module 302 is further configured to:

[0196] Obtain at least one aggregate item in the domain name alarm data; the aggregate item includes the one or more dimension attributes;

[0197] Aggregate the domain name alarm data with the same value of one or more dimensions corresponding to each aggregation item to obtain candidate aggregate domain name alarm data;

[0198] The candidate aggregated domain name alarm data with the least number of items is used as the aggregated domain name alarm data.

[0199] Furthermore, the aggregation item includes: one or more dimension attributes of country, city, operator, and domain name.

[0200] Furthermore, the inspection and alarm module 303 is further configured to:

[0201] When the aggregated item of the aggregated domain name alarm data is a domain name, if the number of countries and / or the number of cities in the aggregated domain name alarm data is greater than a first threshold, sending a domain name alarm message;

[0202] When the aggregation item of the aggregated domain name alarm data is a country, if the number of operators and / or the number of domain names in the aggregated domain name alarm data is greater than a second threshold, domain name alarm information is sent.

[0203] Furthermore, the inspection and alarm module 303 is further configured to:

[0204] If the number of any dimension attribute in the aggregated alarm data is less than a preset threshold, extract and check online data;

[0205] The online data includes: the average success rate during the alarm time period, the average success rate of the most recent day, the total number of reports during the alarm time period, the total number of reports during the same time period of the previous day, and one or more of the top three errors and their proportions during the alarm time period; wherein the success rate is the access success rate of the target domain name; and the total number of reports is the total number of visits to the target domain name.

[0206] Furthermore, the online data meeting the online data abnormality condition includes one or more of the following situations:

[0207] The average success rate during the alarm period is lower than the first threshold; or

[0208] The average success rate during the alarm period is lower than the average success rate of the most recent day by a second threshold; or

[0209] The total number of reports during the alarm period is higher than the total number of reports during the same period on the previous day by a third threshold; or

[0210] The error rate during the alarm period is higher than the fourth threshold.

[0211] Furthermore, the checking and alarm module 303 is further configured to issue a real-time task to check offline data according to the domain name alarm data.

[0212] Furthermore, the inspection and alarm module 303 is further configured to: issue a real-time task to detect whether the CDN is abnormal; and / or,

[0213] Issue real-time tasks to detect DNS anomalies.

[0214] Furthermore, the inspection and alarm module 303 is further configured to:

[0215] Obtaining a first CDN address in an access failure set and a second CDN address in an access success set in the domain name alarm data;

[0216] issuing a real-time task to detect the first CDN address and the second CDN address;

[0217] If the detection of the first CDN address fails and the detection of the second CDN address succeeds, it is determined that the CDN corresponding to the first CDN address is abnormal.

[0218] Furthermore, the inspection and alarm module 303 is further configured to:

[0219] Use the preset DNS to resolve the target domain name;

[0220] If the resolution is successful, it is determined that the DNS is abnormal; otherwise, it is determined that the target domain name is abnormal.

[0221] Figure 3 The device shown can perform Figure 1 and 2 For the method of the embodiment shown in FIG. 1 , reference may be made to the description of the part not described in detail in the embodiment. Figure 1 and 2 The implementation process and technical effects of this technical solution can be found in Figure 1 and 2 The description in the illustrated embodiment will not be repeated here.

[0222] Reference below Figure 4 , which shows a schematic structural diagram of an electronic device 400 suitable for implementing the embodiments of the present disclosure. The terminal devices in the embodiments of the present disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 4 The electronic device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.

[0223] like Figure 4 As shown, the electronic device 400 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 401, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 402 or a program loaded from a storage device 408 into a random access memory (RAM) 403. Various programs and data required for the operation of the electronic device 400 are also stored in the RAM 403. The processing device 401, the ROM 402, and the RAM 403 are connected to each other via a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.

[0224] Typically, the following devices may be connected to the I / O interface 405: an input device 406 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 407 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 408 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 409. The communication device 409 may allow the electronic device 400 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 4 The electronic device 400 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead.

[0225] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 409, or installed from the storage device 408, or installed from the ROM 402. When the computer program is executed by the processing device 401, the above-mentioned functions defined in the method of the embodiment of the present disclosure are performed.

[0226] It should be noted that the computer-readable medium mentioned above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. In the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.

[0227] In some embodiments, the client and server can communicate using any currently known or future developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.

[0228] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.

[0229] The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device is enabled to execute the alarm information sending method in the above embodiment.

[0230] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages, or a combination thereof, including, but not limited to, object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0231] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0232] The units involved in the embodiments described in this disclosure may be implemented in software or hardware, wherein the name of a unit does not necessarily limit the unit itself.

[0233] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0234] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0235] According to one or more embodiments of the present disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any of the domain name alarm information sending methods described in the first aspect above.

[0236] According to one or more embodiments of the present disclosure, a non-transitory computer-readable storage medium is provided, characterized in that the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute any domain name alarm information sending method described in the first aspect.

[0237] The above description is merely a preferred embodiment of the present disclosure and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but also includes other technical solutions formed by any combination of the above-mentioned technical features or their equivalents without departing from the above-mentioned disclosed concepts. For example, a technical solution formed by replacing the above-mentioned features with (but not limited to) technical features with similar functions disclosed in this disclosure.< / domain> < / domain> < / domain> < / domain>

Claims

1. A method for sending domain name alarm information, characterized in that: include: Obtain domain name alarm data; wherein each domain name alarm data includes multiple dimension attributes; Aggregate domain name alarm data with one or more identical dimension attributes to obtain aggregated domain name alarm data; If the number of one or more dimension attributes in the aggregated domain name alarm data is greater than a preset threshold, sending a domain name alarm message; wherein the domain name alarm message indicates that the domain name alarm data is true; If the number of any dimension attribute in the aggregated domain name alarm data is less than a preset threshold, checking online data based on the domain name alarm data; wherein the online data is data generated based on user use of the product; If the online data meets the online data abnormality condition, a domain name alarm message is sent; If the online data does not meet the online data abnormality condition, then checking the offline data according to the domain name alarm data; wherein the offline data is data obtained by dialing and testing the product; If the offline data meets the offline data abnormality condition, a domain name alarm message is sent; If the number of one or more dimension attributes in the aggregated domain name alarm data is greater than a preset threshold, sending domain name alarm information includes: When the aggregated item of the aggregated domain name alarm data is a domain name, if the number of countries and / or cities in the aggregated domain name alarm data is greater than a first threshold, a domain name alarm message is sent; the aggregated item includes: one or more dimension attributes of country, city, operator, and domain name; When the aggregation item of the aggregated domain name alarm data is a country, if the number of operators and / or the number of domain names in the aggregated domain name alarm data is greater than a second threshold, domain name alarm information is sent.

2. The method according to claim 1, wherein Before obtaining domain name alarm data, it also includes: Detect the network status of the device generating domain name alarm data; If the network status of the domain name alarm data generating device does not meet the preset network conditions, the domain name alarm data generating device is deleted from the domain name alarm data source; wherein, the domain name alarm data source is a collection of domain name alarm data generating devices.

3. The method according to claim 1, wherein The step of aggregating domain name alarm data having the same one or more dimension attributes to obtain aggregated domain name alarm data includes: Obtain at least one aggregate item in the domain name alarm data; the aggregate item includes the one or more dimension attributes; Aggregate the domain name alarm data with the same value of one or more dimensions corresponding to each aggregation item to obtain candidate aggregate domain name alarm data; The candidate aggregated domain name alarm data with the least number of items is used as the aggregated domain name alarm data.

4. The method according to claim 1, wherein If the number of any dimension attribute in the aggregated domain name alarm data is less than a preset threshold, checking online data according to the domain name alarm data includes: If the number of any dimension attribute in the aggregated domain name alarm data is less than a preset threshold, extract and check online data; The online data includes: the average success rate during the alarm time period, the average success rate of the most recent day, the total number of reports during the alarm time period, the total number of reports during the same time period of the previous day, and one or more of the top three errors and their proportions during the alarm time period; wherein the success rate is the access success rate of the target domain name; and the total number of reports is the total number of visits to the target domain name.

5. The method according to claim 4, wherein The online data meeting the online data abnormality condition includes one or more of the following situations: The average success rate during the alarm period is lower than the first threshold; or The average success rate during the alarm period is lower than the average success rate of the most recent day by a second threshold; or The total number of reports during the alarm period is higher than the total number of reports during the same period on the previous day by a third threshold; or The error rate during the alarm period is higher than the fourth threshold.

6. The method according to claim 1, wherein The checking of offline data according to the domain name alarm data includes: A real-time task is issued based on the domain name alarm data to check offline data.

7. The method according to claim 6, wherein The issuing of real-time tasks to check offline data includes: Issue real-time tasks to detect CDN anomalies; and / or, Issue real-time tasks to detect DNS anomalies.

8. The method according to claim 7, wherein The real-time task is issued to detect whether the CDN is abnormal, including: Obtaining a first CDN address in an access failure set and a second CDN address in an access success set in the domain name alarm data; issuing a real-time task to detect the first CDN address and the second CDN address; If the detection of the first CDN address fails and the detection of the second CDN address succeeds, it is determined that the CDN corresponding to the first CDN address is abnormal.

9. The method according to claim 7, wherein The real-time task of sending a DNS error detection task includes: Use the preset DNS to resolve the target domain name; If the resolution is successful, it is determined that the DNS is abnormal; otherwise, it is determined that the target domain name is abnormal.

10. A domain name alarm information sending device, characterized in that: include: Domain name alarm data acquisition module, used to obtain domain name alarm data; Obtain domain name alarm data; wherein each domain name alarm data includes multiple dimension attributes; Aggregation module, used to aggregate domain name alarm data with the same one or more dimension attributes to obtain aggregated domain name alarm data; A checking and alarm module, configured to send a domain name alarm message if the number of one or more dimensional attributes in the aggregated domain name alarm data is greater than a preset threshold; wherein the domain name alarm message indicates that the domain name alarm data is true; if the number of any dimensional attribute in the aggregated domain name alarm data is less than a preset threshold, check online data based on the domain name alarm data; wherein the online data is data generated based on user use of the product; if the online data meets an online data anomaly condition, send a domain name alarm message; if the online data does not meet the online data anomaly condition, check offline data based on the domain name alarm data; wherein the offline data is data obtained by dialing the product; if the offline data meets the offline data anomaly condition, send a domain name alarm message; If the number of one or more dimension attributes in the aggregated domain name alarm data is greater than a preset threshold, sending domain name alarm information includes: When the aggregated item of the aggregated domain name alarm data is a domain name, if the number of countries and / or cities in the aggregated domain name alarm data is greater than a first threshold, a domain name alarm message is sent; the aggregated item includes: one or more dimension attributes of country, city, operator, and domain name; When the aggregation item of the aggregated domain name alarm data is a country, if the number of operators and / or the number of domain names in the aggregated domain name alarm data is greater than a second threshold, domain name alarm information is sent.

11. An electronic device comprising: a memory for storing computer-readable instructions; as well as A processor, configured to execute the computer-readable instructions, so that the processor implements the method according to any one of claims 1 to 9 when executed.

12. A non-transitory computer-readable storage medium for storing computer-readable instructions, which, when executed by a computer, causes the computer to perform the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Alarming restraining method based on distributed clustering of historical alarming

    CN105069115A

  • Method and device for clustering phishing webpages

    WO2015014279A1