Method and device for determining baseline for asset anomaly determination
By sampling and comparing and analyzing the traffic data, the baseline for determining the asset abnormality judgment is solved, and the problem of high frequency of false alarms in the existing technology is achieved, and more effective asset data security is achieved.
Patent Information
- Application Number
- CN202211713698.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-27
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-12-27
AI Technical Summary
When setting the data comparison baseline, the prior art is easy to intercept normal traffic data, resulting in high frequency of false alarms and affecting the normal use of assets.
By obtaining the traffic data within the preset time range, dividing it into multiple traffic quantum data according to the sampling period, and comparing and analyzing it based on the comparison period, the same data interval is determined, thereby determining the baseline for asset abnormality determination.
This method can determine a more effective baseline for asset abnormality determination while reducing false positives and ensure the security of asset data.
Smart Images

Figure CN116016238B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology. Specifically, it relates to a method and device for determining a baseline for asset anomaly determination. Background Art
[0002] In recent years, the number of attacks on terminal assets has generally shown an upward trend, which has made major enterprises and merchants pay more attention to the security of their own assets. In order to protect assets, technical personnel have proposed a method of using a data comparison baseline to determine asset abnormal behaviors. However, in practice, it is found that the data comparison baseline set by the current method will block a lot of normal traffic data, resulting in a high false alarm rate, which in turn affects the normal use of assets. Therefore, how to construct a data comparison baseline and reduce the occurrence of false alarms is an urgent problem to be solved. Summary of the Invention
[0003] The purpose of the embodiments of this application is to provide a method and device for determining a baseline for asset anomaly determination, which can determine a more effective baseline for asset anomaly determination based on the complexity and diversity of the actual network environment, so as to ensure the security of asset data while reducing the occurrence of false alarms.
[0004] The first aspect of the embodiments of this application provides a method for determining a baseline for asset anomaly determination, including:
[0005] Obtain traffic data within a preset time range;
[0006] Divide the traffic data into multiple traffic sub-data according to a preset sampling period;
[0007] Perform comparison and analysis on multiple traffic sub-data based on a preset comparison period to obtain the same data interval;
[0008] Determine a baseline for asset anomaly determination based on the same data interval.
[0009] In the above implementation process, the method can obtain traffic data within a preset time range; it can be seen that the method can collect access data in an extremely long interval range (such as several months) so that the method can determine appropriate traffic data based on the complexity and diversity of the actual network environment, and thus determine a more accurate asset anomaly determination baseline. Then, the method can divide the traffic data into multiple traffic sub-data according to a preset sampling period; it can be seen that the method can evenly divide the extremely long interval range, so that the method can perform comparison and analysis based on the multiple evenly divided traffic sub-data to obtain a more accurate comparison and analysis result. Then, the method can perform comparison and analysis on the multiple traffic sub-data based on a preset comparison period to obtain the same data interval; it can be seen that the method can compare each traffic sub-data on a daily or weekly basis to obtain the change situation within the comparison period and the change situation within the sampling period, and then perform comparison and analysis based on these two change situations to obtain the data interval that best conforms to the actual situation. And finally, based on the same data interval, determine the asset anomaly determination baseline; it can be seen that the method can determine the asset anomaly determination baseline that conforms to the actual situation, thus greatly reducing the possibility of false alarms and facilitating more effective protection of asset security.
[0010] Further, the step of performing comparison and analysis on the multiple traffic sub-data based on a preset comparison period to obtain the same data interval includes:
[0011] Dividing the traffic sub-data based on a preset comparison period to obtain multiple divided data;
[0012] Performing comparison and analysis on the multiple divided data to obtain multiple comparison data intervals;
[0013] Determining the same data interval among the multiple comparison data intervals.
[0014] In the above implementation process, when the method conducts comparison and analysis on multiple sub-flow data based on a preset comparison period to obtain the same data interval, it first divides the sub-flow data based on the preset comparison period to obtain multiple divided data. It can be seen that the method can divide each sub-flow data into multiple divided data, enabling the method to obtain multiple copies (one for each sub-flow data) of the multiple divided data. Furthermore, the method can conduct horizontal and vertical comparisons based on the multiple divided data, making the comparison and analysis more flexible and targeted. Then, the method conducts comparison and analysis on the multiple divided data to obtain multiple comparison data intervals. It can be seen that the method determines the comparison data interval in a certain situation for a single sub-flow data and further obtains the multiple comparison data intervals corresponding to multiple sub-flow data, thereby achieving comparison and analysis over an extremely long time and improving the accuracy of the comparison and analysis with more comprehensive and accurate data. Finally, the method determines the same data interval among the multiple comparison data intervals. It can be seen that the method can determine a most accurate data interval over an extremely long time, thereby improving the accuracy of obtaining the asset anomaly determination baseline.
[0015] Further, the step of dividing the sub-flow data based on a preset comparison period to obtain multiple divided data includes:
[0016] Dividing the sub-flow data based on a preset comparison period and data type to obtain multiple divided data.
[0017] In the above implementation process, the method can divide the sub-flow data based on a preset comparison period and data type to obtain multiple divided data. It can be seen that the method can divide the sub-flow data based on the data type, enabling the method to more specifically obtain the corresponding data intervals (such as the data intervals for weekdays and non-weekdays, the data intervals for regular video conferences and regular organized activities, etc.), thereby ensuring the pertinence of the asset anomaly determination baseline and facilitating better and more targeted asset protection.
[0018] Further, the step of determining the asset anomaly determination baseline based on the same data interval includes:
[0019] Predicting the same data interval based on a preset confidence level to obtain a confidence data interval;
[0020] Determining the upper boundary value of the confidence data interval as the asset anomaly determination baseline.
[0021] In the above implementation process, when determining the asset anomaly judgment baseline based on the same data range, the method can first predict the same data range based on a preset confidence level to obtain a confidence data range. It can be seen that the method can predict the confidence data range using a 95% confidence level, making the asset anomaly judgment baseline more accurate and effective. Then, the method determines the upper boundary value of the confidence data range as the asset anomaly judgment baseline. It can be seen that the method can take the upper boundary as the asset anomaly judgment baseline, making the asset anomaly judgment baseline close to the maximum value of anomaly judgment, thereby reducing the possibility of false alarms.
[0022] Further, after the step of determining the asset anomaly judgment baseline based on the same data range, the method further includes:
[0023] Performing asset anomaly judgment based on the asset anomaly judgment baseline to obtain an abnormal behavior judgment result;
[0024] Optimizing the asset anomaly judgment baseline based on the abnormal behavior judgment result to obtain an optimized asset anomaly judgment baseline.
[0025] In the above implementation process, after determining the asset anomaly judgment baseline, the method can perform asset anomaly judgment based on the asset anomaly judgment baseline to obtain an abnormal behavior judgment result. It can be seen that the method can put the obtained asset anomaly judgment baseline into actual use after obtaining it, thus achieving the verification effect. Then, the method further optimizes the asset anomaly judgment baseline based on the abnormal behavior judgment result to obtain an optimized asset anomaly judgment baseline. It can be seen that the method can re-optimize the asset anomaly judgment baseline based on the actual usage situation, thereby achieving the dynamic adjustment effect of the asset anomaly judgment baseline and further reducing the possibility of false alarms.
[0026] Further, after the step of optimizing the asset anomaly judgment baseline based on the abnormal behavior judgment result to obtain an optimized asset anomaly judgment baseline, the method further includes:
[0027] Detecting whether there is an anomaly in the optimized asset anomaly judgment baseline;
[0028] When there is no anomaly in the optimized asset anomaly judgment baseline, detecting whether the asset data gradually increases or decreases within the sampling period;
[0029] When the asset data gradually increases or decreases within the sampling period, outputting an asset risk prompt message.
[0030] In the above implementation process, after obtaining the optimized asset anomaly determination baseline, this method can detect whether there is an anomaly in the optimized asset anomaly determination baseline. It can be seen that this method can detect the optimized asset anomaly determination baseline, thereby avoiding the optimization anomaly of the asset anomaly determination baseline, further ensuring the reliability of automatic optimization, and being conducive to improving the protection effect of assets. When there is no anomaly in the optimized asset anomaly determination baseline, it detects whether the asset data gradually increases or decreases within the sampling period. It can be seen that when there is no anomaly in the optimization of the asset anomaly determination baseline, this method can further determine whether the asset data is slowly increasing or decreasing, so as to further determine whether there is a chronic asset threat, and then ensure the security of the asset data. When the asset data gradually increases or decreases within the sampling period, it outputs an asset risk prompt message. It can be seen that this method can output the corresponding asset risk prompt message in real time when there is a risk, so that relevant staff can know the anomaly risk in real time, and then ensure the security of the assets.
[0031] The second aspect of the embodiments of the present application provides a device for determining an asset anomaly determination baseline. The device for determining an asset anomaly determination baseline includes:
[0032] An acquisition unit, configured to acquire traffic data within a preset time range;
[0033] A division unit, configured to divide the traffic data into multiple traffic sub-data according to a preset sampling period;
[0034] A comparison unit, configured to perform comparison and analysis on the multiple traffic sub-data based on a preset comparison period to obtain the same data interval;
[0035] A determination unit, configured to determine an asset anomaly determination baseline based on the same data interval.
[0036] In the above implementation process, this device can acquire traffic data within a preset time range through the acquisition unit; divide the traffic data into multiple traffic sub-data according to a preset sampling period through the division unit; perform comparison and analysis on the multiple traffic sub-data based on a preset comparison period through the comparison unit to obtain the same data interval; and determine an asset anomaly determination baseline based on the same data interval through the determination unit. It can be seen that this device determines a more effective asset anomaly determination baseline based on the complexity and diversity of the actual network environment, thereby ensuring the security of asset data on the premise of reducing false alarms.
[0037] Further, the comparison unit includes:
[0038] A sub-division unit, configured to divide the traffic sub-data based on a preset comparison period to obtain multiple divided data;
[0039] A comparison subunit, configured to perform comparison and analysis on a plurality of the divided data to obtain a plurality of comparison data intervals;
[0040] A first determination subunit, configured to determine identical data intervals among the plurality of comparison data intervals.
[0041] Further, the division subunit is specifically configured to divide the traffic sub-data based on a preset comparison period and data type to obtain a plurality of divided data.
[0042] Further, the determination unit includes:
[0043] A prediction subunit, configured to predict the identical data intervals based on a preset confidence level to obtain confidence data intervals;
[0044] A second determination subunit, configured to determine the upper boundary value of the confidence data intervals as the asset anomaly determination baseline.
[0045] Further, the apparatus for determining the asset anomaly determination baseline further includes:
[0046] A determination unit, configured to perform asset anomaly determination based on the asset anomaly determination baseline after determining the asset anomaly determination baseline to obtain an abnormal behavior determination result;
[0047] An optimization unit, configured to optimize the asset anomaly determination baseline based on the abnormal behavior determination result to obtain an optimized asset anomaly determination baseline.
[0048] Further, the apparatus for determining the asset anomaly determination baseline further includes:
[0049] A detection unit, configured to detect whether there is an anomaly in the optimized asset anomaly determination baseline after obtaining the optimized asset anomaly determination baseline;
[0050] The detection unit is further configured to detect whether the asset data gradually increases or gradually decreases within the sampling period when the optimized asset anomaly determination baseline has no anomaly;
[0051] An output unit, configured to output an asset risk prompt message when the asset data gradually increases or gradually decreases within the sampling period.
[0052] A third aspect of the embodiments of the present application provides an electronic device, including a memory and a processor, where the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the method for determining the asset anomaly determination baseline according to any one of the first aspects of the embodiments of the present application.
[0053] A fourth aspect of the embodiments of the present application provides a computer-readable storage medium storing computer program instructions, which, when read and executed by a processor, execute the method for determining the asset anomaly determination baseline according to any one of the first aspects of the embodiments of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] To more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0055] Figure 1 A flowchart showing a method for determining an asset anomaly determination baseline provided by an embodiment of the present application;
[0056] Figure 2 A flowchart showing another method for determining an asset anomaly determination baseline provided by an embodiment of the present application;
[0057] Figure 3 A schematic structural diagram of a device for determining an asset anomaly determination baseline provided by an embodiment of the present application;
[0058] Figure 4 A schematic structural diagram of another device for determining an asset anomaly determination baseline provided by an embodiment of the present application;
[0059] Figure 5 An example flowchart of a method for determining an asset anomaly determination baseline provided by an embodiment of the present application;
[0060] Figure 6 A system architecture diagram of an application of a method for determining an asset anomaly determination baseline provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0061] The following will describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application.
[0062] It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, the terms "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0063] Embodiment 1
[0064] Please refer to Figure 1 , Figure 1This embodiment provides a schematic flow diagram of a method for determining an asset anomaly determination baseline. Among them, the method for determining the asset anomaly determination baseline includes:
[0065] S101. Obtain traffic data within a preset time range.
[0066] S102. Divide the traffic data into multiple traffic sub-data according to a preset sampling period.
[0067] S103. Perform comparison and analysis on multiple traffic sub-data based on a preset comparison period to obtain the same data interval.
[0068] S104. Determine the asset anomaly determination baseline based on the same data interval.
[0069] Implementing this implementation method can focus on eliminating the error influence caused by a single standardized judgment of abnormal behavior, and mine more concealed abnormal behaviors based on the data display of asset behavior. At the same time, it can also focus on solving the accuracy problem of other baseline calculation methods (such as eliminating or reducing the error influence caused by mean calculation when the sample values vary greatly).
[0070] Specifically, the key technical points involved in this method are as follows:
[0071] (1) Optimize the calculation of the behavior baseline for assets based on the confidence interval, and can more accurately predict the behavior activity range of normal traffic data and the highest point of traffic data.
[0072] (2) Judge the results of assets and baselines to determine whether the abnormal behaviors confirmed by the system are false alarms, and whether the normal behavior baselines not confirmed by the system need to be optimized to reduce the false alarm rate.
[0073] (3) Taking the baseline as a reference point, participate in the tolerance calculation method to dynamically divide the abnormal range to reduce the error of judging abnormal behaviors.
[0074] In this embodiment, the execution subject of this method can be a computing device such as a computer or a server, and no limitation is made in this embodiment.
[0075] In this embodiment, the execution subject of this method can also be a smart device such as a smart phone or a tablet computer, and no limitation is made in this embodiment.
[0076] It can be seen that implementing the method for determining the asset anomaly determination baseline described in this embodiment can be applied to a complex network environment. Based on the divided intervals, a probabilistic algorithm is used to predict the behavior baseline, which greatly improves the accuracy of determining the asset determination baseline. At the same time, it can also perform secondary optimization on the asset determination baseline based on the data verification results, thereby further reducing the occurrence of data false alarms, and thus facilitating the improvement of the work efficiency of operation and maintenance personnel.
[0077] Embodiment 2
[0078] Please refer to Figure 2 , Figure 2 which provides a schematic flowchart of a method for determining an asset anomaly determination baseline. Among them, the method for determining the asset anomaly determination baseline includes:
[0079] S201. Obtain traffic data within a preset time range.
[0080] In this embodiment, the preset time range can be an ultra-long interval range, such as three months.
[0081] S202. Divide the traffic data into multiple traffic sub-data according to a preset sampling period.
[0082] In this embodiment, the method can pre-set a sampling period for the asset that needs to perform traffic analysis. For example, the sampling period can be set to 30 days.
[0083] In this embodiment, the method can also pre-initialize the timer. Specifically, the timer can be scaled in days and read the traffic data values in the historical time period including the current time (collected in advance by the apl interface and stored in the database) for the specified network asset at 0:00 every day, and then trigger the subsequent relevant baseline calculation process.
[0084] In this embodiment, the method can obtain new samples and remove old samples through a sliding time slice by the day timer, so as to ensure that the measured values obtained are the latest historical behaviors. Since the asset sampling period is set to 30 days, that is, the sliding time slice is 30 days, the traffic data within the selected time slice participates in the calculation.
[0085] In this embodiment, the method can divide the data values obtained within an ultra-long time range (the recent three months) into multiple traffic sub-data of the same length based on the sampling period as the unit.
[0086] S203. Divide the traffic sub-data based on a preset comparison period and data type to obtain multiple divided data.
[0087] S204. Perform comparison analysis on the multiple divided data to obtain multiple comparison data intervals.
[0088] S205. Determine the same data intervals among multiple comparison data intervals.
[0089] In this embodiment, the method can compare the data of each equal part on a daily or weekly basis. The comparison content includes data such as the size of the traffic received and sent for each asset and the number of access times. The data with the fluctuation amplitude and actual value within the specified range in each equal part is divided into the same interval.
[0090] S206. Predict the same data intervals based on a preset confidence level to obtain confidence data intervals.
[0091] In this embodiment, the method can predict the confidence data intervals at a 95% confidence level within this interval.
[0092] S207. Determine the upper boundary value of the confidence data interval as the asset anomaly determination baseline.
[0093] In this embodiment, the method can use the upper boundary value of the confidence interval as the asset anomaly determination baseline.
[0094] S208. Perform asset anomaly determination based on the asset anomaly determination baseline to obtain an abnormal behavior determination result.
[0095] S209. Optimize the asset anomaly determination baseline based on the abnormal behavior determination result to obtain an optimized asset anomaly determination baseline.
[0096] S210. Detect whether there is an anomaly in the optimized asset anomaly determination baseline. If so, execute step S212; if not, execute step S211.
[0097] In this embodiment, since the vast majority of attack behaviors, such as DDOS attacks, scanning attacks, and botnets, will cause abnormal increases in asset access traffic, a percentage floating range is divided with the baseline as the reference point as a fluctuation interval for normal traffic communication. The traffic generated in a certain direction of the asset within this interval is regarded as normal communication, and if it exceeds this range value, it is determined as abnormal, providing more effective reference bases and directional guidance for security event tracing for operation and maintenance personnel.
[0098] S211. Detect whether the asset data gradually increases or decreases within the sampling period. If so, execute step S212; if not, end this process.
[0099] S212. Output an asset risk warning message.
[0100] In this embodiment, if an asset is determined to have abnormal behavior for most of the sampling period or every day, after manual verification determines that the data belongs to normal business traffic, the baseline amplitude can be manually adjusted downward or the system can re - formulate the behavior baseline through self - learning.
[0101] In this embodiment, if an asset does not exceed the baseline value within the sampling period, but both the baseline value and the actual behavior traffic are increasing day by day, the method will give a warning.
[0102] In this embodiment, the method can collect and analyze access data in an ultra - long interval range, divide multiple data category intervals based on data similarity comparison before calculating the baseline, and perform secondary optimization and adjustment of the baseline according to the baseline and data results after calculating the baseline value.
[0103] Please refer to Figure 5 , Figure 5 which specifically shows a flowchart for calculating the determination baseline of abnormal assets based on confidence intervals. Among them, based on Figure 5 For example:
[0104] Step 1: Set the sampling period;
[0105] Step 2: Initialize the timer;
[0106] Step 3: Obtain the traffic data within the sampling period;
[0107] Step 4: Interval division and baseline calculation;
[0108] Step 5: Abnormal behavior judgment and result presentation;
[0109] Step 6: Baseline optimization;
[0110] Step 7: Determine whether the baseline is normal. If it is, execute Step 4; if not, execute Step 5:
[0111] Step 8: Detect whether the asset data is gradually increasing or decreasing. If it is, execute Step 9; if not, end;
[0112] Step 9: Prompt asset risk information.
[0113] For example, this method can be applied to the design of forming an asset portrait and detecting abnormal behavior in the behavior baseline module of a fully self - defined next - generation firewall. Specifically, using the method of calculating the baseline and marking the behavior portrait by dividing data category intervals proposed in this application, it can dynamically detect abnormal behavior of asset access and perform secondary optimization of the baseline according to the baseline, thereby achieving an improvement in security protection capabilities. Its system architecture diagram is as Figure 6 shown. Among them, the example process based on Figure 6 is as follows:
[0114] (1) The asset management module defines network assets by device IP addresses.
[0115] (2) The statistics module obtains the asset objects for which statistical access data needs to be collected from the asset management module, collects the raw traffic data in the access receiving direction of the specified assets through the firewall interface, and at the same time the API interface confirms the asset access count data based on the obtained TCP / UDP connection information.
[0116] (3) The behavior baseline module selects the network assets that need to be analyzed for behavior from the asset management module, sets the baseline dimension to monthly or weekly as needed, and reads the access receiving traffic, access sending traffic, and access count data of the assets within the sampling period into the memory through the time timer.
[0117] (4) Before calculating the baseline of the asset using the confidence interval algorithm, the time timer needs to first divide the stored data for 3 months into 3 samples by month, perform data-level analysis and comparison between each sample in units of weeks and days, and then divide into multiple different intervals through the regular differences in traffic size, such as the data intervals between weekdays and non-weekdays, the data intervals for regular video conferences and regular organized activities, etc.; calculate the behavior baseline values for the data within the sampling period according to the divided sample intervals respectively.
[0118] (5) Display baselines of different dimensions in different intervals, and supplement with static threshold baselines or tolerance baselines (create dynamic percentage increase ranges based on the baseline) according to the actual situation of the user to assist in determining the deviation of the behavior of the four dimensions of internal-to-external access, external-to-internal access, horizontal active access, and horizontal passive access of the asset from the baseline within the interval, so as to detect abnormalities in a timely manner and corroborate with the security events and logs generated during the same period.
[0119] (6) When the system prompts a high frequency of abnormal traffic for an asset, the behavior baseline will judge by comparing the data difference between the historical period and the current period whether there is a possibility of false alarm. When the system does not generate an abnormal prompt but the daily traffic of the asset slowly increases with the baseline and does not exceed the baseline value, there may be a situation where the asset is under a slowly increasing network attack volume but the system does not recognize it. At this time, the abnormal amplitude of the judgment baseline can be manually adjusted or the baseline self-learning operation can be executed to re-adjust the baseline value to make the asset behavior baseline value increasingly accurate.
[0120] In this embodiment, the execution subject of this method can be a computing device such as a computer or a server, and no limitation is made in this embodiment.
[0121] In this embodiment, the execution subject of this method can also be a smart device such as a smart phone or a tablet computer, and no limitation is made in this embodiment.
[0122] It can be seen that implementing the method for determining the asset anomaly determination baseline described in this embodiment can be applied to a complex network environment. Based on the divided intervals, a probabilistic algorithm is used to predict the behavior baseline, which can greatly improve the accuracy of determining the asset determination baseline. At the same time, it can also perform secondary optimization on the asset determination baseline based on the data verification results, thereby further reducing the occurrence of data false alarms, and thus facilitating the improvement of the work efficiency of operation and maintenance personnel.
[0123] Embodiment 3
[0124] Please refer to Figure 3 , Figure 3 which is a schematic structural diagram of a device for determining an asset anomaly determination baseline provided in this embodiment. As Figure 3 shown, the device for determining the asset anomaly determination baseline includes:
[0125] An acquisition unit 310, configured to acquire traffic data within a preset time range;
[0126] A division unit 320, configured to divide the traffic data into multiple traffic sub-data according to a preset sampling period;
[0127] A comparison unit 330, configured to perform comparison and analysis on the multiple traffic sub-data based on a preset comparison period to obtain the same data interval;
[0128] A determination unit 340, configured to determine the asset anomaly determination baseline based on the same data interval.
[0129] In this embodiment, the explanation of the device for determining the asset anomaly determination baseline can refer to the description in Embodiment 1 or Embodiment 2, and will not be elaborated herein.
[0130] It can be seen that implementing the device for determining the asset anomaly determination baseline described in this embodiment can be applied to a complex network environment. Based on the divided intervals, a probabilistic algorithm is used to predict the behavior baseline, which can greatly improve the accuracy of determining the asset determination baseline. At the same time, it can also perform secondary optimization on the asset determination baseline based on the data verification results, thereby further reducing the occurrence of data false alarms, and thus facilitating the improvement of the work efficiency of operation and maintenance personnel.
[0131] Embodiment 4
[0132] Please refer to Figure 4 , Figure 4 which is a schematic structural diagram of a device for determining an asset anomaly determination baseline provided in this embodiment. As Figure 4 shown, the device for determining the asset anomaly determination baseline includes:
[0133] An acquisition unit 310, configured to acquire traffic data within a preset time range;
[0134] A division unit 320, configured to divide the traffic data into multiple traffic sub-data according to a preset sampling period;
[0135] A comparison unit 330, configured to perform comparison and analysis on multiple traffic sub-data based on a preset comparison period to obtain the same data interval;
[0136] A determination unit 340, configured to determine an asset anomaly determination baseline based on the same data interval.
[0137] As an optional implementation manner, the comparison unit 330 includes:
[0138] A sub-division unit 331, configured to divide the traffic sub-data based on a preset comparison period to obtain multiple divided data;
[0139] A sub-comparison unit 332, configured to perform comparison and analysis on multiple divided data to obtain multiple comparison data intervals;
[0140] A first determination sub-unit 333, configured to determine the same data interval among multiple comparison data intervals.
[0141] As an optional implementation manner, the sub-division unit 331 is specifically configured to divide the traffic sub-data based on a preset comparison period and data type to obtain multiple divided data.
[0142] As an optional implementation manner, the determination unit 340 includes:
[0143] A prediction sub-unit 341, configured to predict the same data interval based on a preset confidence level to obtain a confidence data interval;
[0144] A second determination sub-unit 342, configured to determine the upper boundary value of the confidence data interval as the asset anomaly determination baseline.
[0145] As an optional implementation manner, the device for determining the asset anomaly determination baseline further includes:
[0146] A determination unit 350, configured to perform asset anomaly determination based on the asset anomaly determination baseline after determining the asset anomaly determination baseline to obtain an abnormal behavior determination result;
[0147] An optimization unit 360, configured to optimize the asset anomaly determination baseline based on the abnormal behavior determination result to obtain an optimized asset anomaly determination baseline.
[0148] As an optional implementation manner, the device for determining the asset anomaly determination baseline further includes:
[0149] A detection unit 370, configured to detect whether there is an abnormality in the optimized asset anomaly determination baseline after obtaining the optimized asset anomaly determination baseline;
[0150] The detection unit 370 is further configured to detect whether the asset data gradually increases or decreases within the sampling period when there is no abnormality in the optimized asset anomaly determination baseline;
[0151] An output unit 380, configured to output an asset risk prompt message when the asset data gradually increases or decreases within the sampling period.
[0152] In this embodiment, the explanation of the device for determining the asset anomaly determination baseline may refer to the description in Embodiment 1 or Embodiment 2, and will not be elaborated herein.
[0153] It can be seen that the device for determining the asset anomaly determination baseline described in this embodiment can be applied to a complex network environment, predict the behavior baseline using a probabilistic algorithm on the basis of dividing intervals, and improve the accuracy of determining the asset determination baseline to a greater extent; at the same time, it can also perform secondary optimization on the asset determination baseline based on the data verification result, thereby further reducing the occurrence of data false alarms, and thus facilitating the improvement of the work efficiency of operation and maintenance personnel.
[0154] An embodiment of the present application provides an electronic device, including a memory and a processor, where the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the method for determining the asset anomaly determination baseline in Embodiment 1 or Embodiment 2 of the present application.
[0155] An embodiment of the present application provides a computer-readable storage medium, which stores computer program instructions, and when the computer program instructions are read and run by a processor, the method for determining the asset anomaly determination baseline in Embodiment 1 or Embodiment 2 of the present application is executed.
[0156] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0157] In addition, each functional module in various embodiments of this application can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.
[0158] If the described functions are implemented in the form of software functional modules and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0159] The above are only the embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, the present application may have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application. It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0160] As described above, this is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, and all should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0161] It should be noted that in this text, relative terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.
Claims
1. A method for determining an asset anomaly judgment baseline, characterized in that, it includes: Obtain traffic data within a preset time range; According to a preset sampling period, divide the traffic data into multiple traffic sub-data; Based on a preset comparison period, perform comparison and analysis on multiple traffic sub-data to obtain the same data interval; Based on the same data interval, determine the asset anomaly judgment baseline; Among them, the step of performing comparison and analysis on multiple traffic sub-data based on a preset comparison period to obtain the same data interval includes: Based on a preset comparison period, divide the traffic sub-data to obtain multiple divided data; Perform comparison and analysis on multiple divided data to obtain multiple comparison data intervals; Among multiple comparison data intervals, determine the same data interval; Among them, the step of determining the asset anomaly judgment baseline based on the same data interval includes: Based on a preset confidence level, predict the same data interval to obtain a confidence data interval; Determine the upper boundary value of the confidence data interval as the asset anomaly judgment baseline; Among them, determining the same data interval among multiple comparison data intervals specifically includes dividing data with a fluctuation amplitude and an actual value within a specified range in each equal part into the same interval.
2. The method for determining an asset anomaly judgment baseline according to claim 1, characterized in that, The step of dividing the traffic sub-data based on a preset comparison period to obtain multiple divided data includes: Based on a preset comparison period and data type, divide the traffic sub-data to obtain multiple divided data.
3. The method for determining an asset anomaly judgment baseline according to claim 1, characterized in that, After the step of determining the asset anomaly judgment baseline based on the same data interval, the method further includes: Based on the asset anomaly judgment baseline, perform asset anomaly judgment to obtain an abnormal behavior judgment result; Based on the abnormal behavior judgment result, optimize the asset anomaly judgment baseline to obtain an optimized asset anomaly judgment baseline.
4. The method for determining an asset anomaly judgment baseline according to claim 3, characterized in that, After the step of optimizing the asset anomaly judgment baseline based on the abnormal behavior judgment result to obtain an optimized asset anomaly judgment baseline, the method further includes: Detect whether there is an anomaly in the optimized asset anomaly judgment baseline; When there is no anomaly in the optimized asset anomaly judgment baseline, detect whether the asset data gradually increases or gradually decreases within the sampling period; When the asset data gradually increases or gradually decreases within the sampling period, output an asset risk prompt message.
5. An apparatus for determining an asset anomaly judgment baseline, characterized in that, The apparatus for determining an asset anomaly judgment baseline includes: An acquisition unit for acquiring traffic data within a preset time range; A division unit for dividing the traffic data into multiple traffic sub-data according to a preset sampling period; A comparison unit for performing comparison and analysis on multiple traffic sub-data based on a preset comparison period to obtain the same data interval; A determination unit, configured to determine an asset anomaly determination baseline based on the same data interval; Wherein, the comparison unit includes: A division sub-unit, configured to divide the traffic sub-data based on a preset comparison period to obtain a plurality of divided data; A comparison sub-unit, configured to perform comparison and analysis on the plurality of divided data to obtain a plurality of comparison data intervals; A first determination sub-unit, configured to determine the same data interval among the plurality of comparison data intervals; Wherein, the determination unit includes: A prediction sub-unit, configured to predict the same data interval based on a preset confidence level to obtain a confidence data interval; A second determination sub-unit, configured to determine the upper boundary value of the confidence data interval as the asset anomaly determination baseline; Wherein, the first determination sub-unit is specifically configured to divide the data with a fluctuation amplitude and an actual value within a specified range in each equal part into the same interval.
6. An electronic device, Characterized in that The electronic device includes a memory and a processor, the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the method for determining the asset anomaly determination baseline according to any one of claims 1 to 4.
7. A readable storage medium, Characterized in that The readable storage medium stores computer program instructions, and when the computer program instructions are read and run by a processor, the method for determining the asset anomaly determination baseline according to any one of claims 1 to 4 is executed.
Citation Information
Patent Citations
Optical module fault diagnosis and early warning method, device and system
CN110611531A
Gene copy number variation detection method and device, equipment and storage medium
CN115273971A