Anomaly detection method, apparatus, device, medium, and product

By calculating the cumulative difference value through a sliding time window on the first-order difference curve, the abrupt change in the index curve is determined, which solves the problem of long time-consuming manual anomaly detection in the existing technology and realizes rapid and accurate anomaly detection.

CN116127270BActive Publication Date: 2026-01-02CHINA UNIONPAY
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310075340.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-18
Publication Date
2026-01-02
Estimated Expiration
2043-01-18

AI Technical Summary

Technical Problem

In existing technologies, as the number of application systems and their indicator curves increases, the time spent manually reviewing indicator curves to check for anomalies is getting longer and longer, resulting in low anomaly detection efficiency.

Method used

By sliding a preset time window on the first-order difference curve, the ordinate and value of the first-order difference curve within the preset time window are calculated to determine multiple mutation quantities. By judging whether the mutation quantities meet preset conditions, the abnormal time points are accurately located.

Benefits of technology

It can quickly and accurately detect abnormal time points without the need for manual viewing of indicator curves, improving the efficiency and accuracy of anomaly detection and reducing the false alarm rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116127270B_ABST
    Figure CN116127270B_ABST
Patent Text Reader

Abstract

The application discloses an abnormality detection method, device, equipment, medium and product, and belongs to the technical field of data processing. The method comprises the following steps: in the case that an index curve of a performance index is acquired, a first-order difference curve of the index curve is determined, the ordinate of the first-order difference curve is a first-order difference value, and the first-order difference value is used for representing the change amount of index values of two adjacent time points in the index curve; a preset time window is slid on the first-order difference curve, and the sum of the ordinates of the first-order difference curve in the preset time window is determined in the sliding process, so that a plurality of mutation values of the performance index are obtained; target mutation values satisfying a preset mutation condition are determined from the plurality of mutation values, and a time point corresponding to the target mutation values is determined as an abnormal time point. According to the embodiment of the application, the index curve can be simply and quickly checked for abnormalities, and the abnormality detection efficiency of the index curve is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of data processing, and particularly relates to an anomaly detection method, device, equipment, medium and product. BACKGROUND

[0002] In the operation and maintenance process of an application system, an operation and maintenance personnel needs to regularly check an index curve of a system performance index to timely investigate abnormal changes of an index value, so as to timely find and solve hidden troubles of the application system.

[0003] In the related art, as the number of application systems and their index curves increases, the time consumed for investigating anomalies by manually reviewing the index curves is longer and longer, and the anomaly detection efficiency is relatively low. Therefore, how to quickly check the index curve of the system performance index and improve the anomaly detection efficiency has become a problem to be solved at present. SUMMARY

[0004] Embodiments of the present application provide an anomaly detection method, device, equipment, medium and product, which can quickly check the index curve of the system performance index and improve the anomaly detection efficiency.

[0005] In a first aspect, an anomaly detection method is provided, which includes:

[0006] In a case where an index curve of a performance index is obtained, a first-order difference curve of the index curve is determined, wherein the index curve is generated based on time series data of the performance index, and a vertical coordinate of the first-order difference curve is a first-order difference value, and the first-order difference value is used to represent a change amount of index values of adjacent two time points in the index curve;

[0007] A preset time window is slid on the first-order difference curve, and a sum value of the vertical coordinates of the first-order difference curve within the preset time window is determined in the sliding process to obtain a plurality of mutation values of the performance index;

[0008] A target mutation value that meets a preset mutation condition is determined from the plurality of mutation values, and a time point corresponding to the target mutation value is determined as an abnormal time point.

[0009] In a second aspect, an anomaly detection device is provided, which includes:

[0010] A determination module is configured to, in a case where an index curve of a performance index is obtained, determine a first-order difference curve of the index curve, wherein the index curve is generated based on time series data of the performance index, and a vertical coordinate of the first-order difference curve is a first-order difference value, and the first-order difference value is used to represent a change amount of index values of adjacent two time points in the index curve;

[0011] The determining module is further configured to slide a preset time window on the first-order difference curve, and determine a sum of the ordinate values of the first-order difference curve in the preset time window during the sliding to obtain a plurality of mutation values of the performance index;

[0012] The detecting module is further configured to determine a target mutation value that meets a preset mutation condition from the plurality of mutation values, and determine a time point corresponding to the target mutation value as the abnormal time point.

[0013] In a third aspect, an embodiment of the present application provides an electronic device, including a processor and a memory storing computer program instructions; the processor implements the steps of the abnormality detection method shown in the first aspect when executing the computer program instructions.

[0014] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, a program or instructions are stored on the computer readable storage medium; the program or instructions are executed by a processor to implement the steps of the abnormality detection method shown in the first aspect.

[0015] In a fifth aspect, an embodiment of the present application provides a computer program product stored in a non-volatile storage medium; the computer program product is executed by at least one processor to implement the steps of the abnormality detection method shown in the first aspect.

[0016] In a sixth aspect, an embodiment of the present application provides a chip, including a processor and a communication interface, the communication interface and the processor are coupled, the processor is used to run a program or instructions to implement the steps of the abnormality detection method shown in the first aspect.

[0017] The embodiment of the present application provides an anomaly detection method, device, equipment, medium and product. In the case that an index curve of a performance index is acquired, a first-order difference curve of the index curve is determined. The index curve is generated based on time series data of the performance index. The ordinate of the first-order difference curve is a first-order difference value. The first-order difference value is used to represent a variation amount of index values of two adjacent time points in the index curve. Therefore, the first-order difference curve can reflect the variation of the variation amount of the index values. On this basis, a preset time window is slid on the first-order difference curve. The sum of the ordinates of the first-order difference curve in the preset time window is determined in the sliding process. The cumulative difference value is calculated by using the sliding time window. A plurality of mutation amounts of the performance index are obtained. The mutation amount is the sum of the variation amounts of the index values in each sliding time window. The mutation amount can accurately reflect the variation degree of the index values in a certain period of time. For example, if the sum is large, it indicates that the plurality of variation amounts of the index values in the sliding time window are large, that is, the index values of the plurality of continuous time points in the sliding time window show a growth trend. Therefore, by judging whether the mutation amount meets a preset mutation condition, whether the index values in the index curve have a mutation anomaly, such as a sudden increase or a sudden decrease, can be effectively measured. Ultimately, the time point corresponding to the target mutation amount meeting the preset mutation condition is determined as an abnormal time point. Manual checking of the index curve is not required. The method is simple and fast, and can effectively improve the anomaly detection efficiency of the index curve. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments of the present application will be briefly introduced. Those skilled in the art can obtain other drawings according to these drawings without creating any creative labor.

[0019] Figure 1 The flowchart of an embodiment of the anomaly detection method provided by the first aspect of the present application;

[0020] Figure 2 The flowchart of another embodiment of the anomaly detection method provided by the first aspect of the present application;

[0021] Figure 3 The flowchart of another embodiment of the anomaly detection method provided by the first aspect of the present application;

[0022] Figure 4 The flowchart of another embodiment of the anomaly detection method provided by the first aspect of the present application;

[0023] Figure 5 The flowchart of another embodiment of the anomaly detection method provided by the first aspect of the present application;

[0024] Figure 6A schematic diagram of an example of the index curve and the reference curve of the abnormality detection method provided by the first aspect of the present application;

[0025] Figure 7 A flowchart of another embodiment of the abnormality detection method provided by the first aspect of the present application;

[0026] Figure 8 A schematic diagram of another example of the index curve and the reference curve of the abnormality detection method provided by the first aspect of the present application;

[0027] Figure 9 A flowchart of another embodiment of the abnormality detection method provided by the first aspect of the present application;

[0028] Figure 10 A structural schematic diagram of an embodiment of the abnormality detection apparatus provided by the second aspect of the present application;

[0029] Figure 11 A structural schematic diagram of an embodiment of the electronic device provided by the third aspect of the present application. DETAILED DESCRIPTION

[0030] The features and exemplary embodiments of the various aspects of the present application will be described in detail below, in order to make the purposes, technical solutions and advantages of the present application more clear and apparent, the present application will be further described in detail below in combination with the drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, but not to limit the present application. The present application can be implemented without some of these specific details by those skilled in the art. The following description of the embodiments is only to provide a better understanding of the present application by showing examples of the present application.

[0031] With the increasing number of application systems and their index curves, the time spent on checking the index curves by manual review is getting longer and longer, and the abnormality detection efficiency is relatively low. Therefore, how to quickly check the index curves of system performance indicators and improve the abnormality detection efficiency has become a problem that needs to be solved at present.

[0032] Based on the above-mentioned problems, the embodiment of the present application provides an anomaly detection method, device, equipment, medium and product. A preset time window is used to slide on a first-order difference curve, and a sum value of the ordinate of the first-order difference curve in the preset time window is determined in the sliding process. A sliding time window is used to calculate a cumulative difference value, and a plurality of mutation variables of the performance index are obtained. The mutation variable is a sum value of the index value change amount in each sliding time window, which can accurately reflect the change degree of the index value in a certain period of time. For example, if the sum value is large, it indicates that the plurality of index value change amounts in the sliding time window are large, that is, the index values of the plurality of continuous time points in the sliding time window show a growth trend. Therefore, by judging whether the mutation variable meets the preset mutation condition, whether the index value in the index curve has a mutation anomaly, such as a sudden increase or a sudden decrease, can be effectively measured, and finally the time point corresponding to the target mutation variable that meets the preset mutation condition is determined as an abnormal time point, without the need for manual checking of the index curve. It is simple and fast, and can effectively improve the anomaly detection efficiency of the index curve.

[0033] The anomaly detection method in the embodiment of the present application can be applied to the scene of anomaly detection of the index curve of the performance index of the application system. The anomaly detection method provided by the embodiment of the present application will be described in detail in combination with the drawings and specific embodiments.

[0034] The first aspect of the present application provides an anomaly detection method, which can be applied to an electronic device, that is, the anomaly detection method can be executed by an electronic device. It should be noted that the above-mentioned execution subject does not constitute a limitation on the present application.

[0035] For example, the electronic device can be a server on the application system side.

[0036] Figure 1 A flowchart of an embodiment of the anomaly detection method provided by the first aspect of the present application is shown in FIG. 1. Figure 1 As shown in FIG. 1, the anomaly detection method can include steps 110-130.

[0037] Step 110, in the case where the index curve of the performance index is acquired, a first-order difference curve of the index curve is determined.

[0038] The index curve is generated based on the time series data of the performance index, and the ordinate of the first-order difference curve is a first-order difference value. The first-order difference value is used to represent the change amount of the index values of two adjacent time points in the index curve.

[0039] Step 120, a preset time window is used to slide on the first-order difference curve, and a sum value of the ordinate of the first-order difference curve in the preset time window is determined in the sliding process. A plurality of mutation variables of the performance index are obtained.

[0040] In step 130, a target mutation variable satisfying a preset mutation condition is determined from the plurality of mutation variables, and a time point corresponding to the target mutation variable is determined as an abnormal time point.

[0041] The abnormality detection method provided by the embodiments of the present application can determine a first-order differential curve of the index curve in the case where the index curve of the performance index is obtained, the index curve is generated based on time series data of the performance index, and the ordinate of the first-order differential curve is a first-order differential value, which is used to represent a variation amount of index values of two adjacent time points in the index curve. Therefore, the first-order differential curve can reflect the variation of the variation amount of the index values. On this basis, the preset time window is used to slide on the first-order differential curve, and a sum of the ordinates of the first-order differential curve in the preset time window is determined in the sliding process. The cumulative differential value is calculated by using the sliding time window, and a plurality of mutation variables of the performance index are obtained. The mutation variable is the sum of the variation amounts of the index values in each sliding time window, which can accurately reflect the variation degree of the index values in a certain period of time. For example, if the sum is large, it indicates that the variation amounts of the index values in the sliding time window are large, that is, the index values of the continuous time points in the sliding time window show a growth trend. Therefore, by judging whether the mutation variable satisfies the preset mutation condition, whether the index value in the index curve has a mutation anomaly, such as a sudden increase or a sudden decrease, can be effectively measured. Ultimately, the time point corresponding to the target mutation variable satisfying the preset mutation condition is determined as the abnormal time point, without the need for manual checking of the index curve, which is simple and fast, and can effectively improve the abnormality detection efficiency of the index curve. Meanwhile, the present application is not limited to the time period in the abnormality positioning, but can be specifically positioned to the time point, effectively improving the abnormality detection accuracy.

[0042] The specific implementation of the above steps will be described in detail in combination with embodiments as follows.

[0043] In step 110, the performance index is an index capable of reflecting the system performance of the application system. The electronic device can obtain time series data of the performance index of the application system, which can include index values corresponding to different time points of a certain performance index of the application system. Therefore, the index curve of the performance index can be generated by the time series data, the abscissa of the index curve is the time point, and the ordinate is the index value of the performance index. The index curve is the to-be-detected curve. The abnormal time point can be determined by analyzing the variation of the index values reflected by the index curve.

[0044] In some examples, the performance indicator can be a number of file handle openings, a number of Transmission Control Protocol (TCP) connections, a file system capacity (i.e., a disk space usage), a central processing unit (CPU) usage, or the like.

[0045] In some examples, the electronic device can obtain time series data of the file system capacity, the time series data having a granularity of 1 minute and a time period of 00:00:00 to 23:59:00 each day, i.e., the file system capacity of the application system is collected every minute, and 1440 file system capacities can be collected at 1440 time points of 00:00:00 to 23:59:00 each day to form the time series data, and an indicator curve of the file system capacity can be obtained based on the time series data, the horizontal coordinate of the indicator curve being a time point and the vertical coordinate being the file system capacity collected at the time point, and thus 1440 coordinate points can be included.

[0046] In some embodiments of the present application, if there is a missing indicator value in the time series data, the indicator value of the adjacent time point can be used to replace it; and for the problem of obviously incorrect indicator values, data deletion and data filling operations can be performed.

[0047] In this way, the requirements for the to-be-detected indicator curve can be reduced, more missing data in the original indicator curve can be tolerated, and thus the application range is wider.

[0048] In some embodiments of the present application, to avoid the influence of too large indicator value difference on the abnormality detection effect, the indicator values in the time series data can be normalized to normalize all the indicator values in the interval [0, 1] after the time series data of the performance indicator is obtained and before the indicator curve is generated based on the time series data.

[0049] In some embodiments of the present application, step 110 can specifically include: calculating a difference between the indicator values of two adjacent time points of the indicator curve to obtain a first-order difference value; and generating a first-order difference curve based on the first-order difference value.

[0050] The two adjacent time points can include a first time point and a second time point, the first time point being earlier than the second time point, the horizontal coordinate of the first-order difference curve being the first time point, and the vertical coordinate being the first-order difference value corresponding to the first time point and the second time point.

[0051] For example, for an indicator curve including 1440 time points, 1339 first-order difference values can be obtained by calculating the difference between the file system capacities of two adjacent time points, and a first-order difference curve including 1339 coordinate points can be generated.

[0052] In step 120, the preset time window can be set according to specific requirements, for example, set to 5 min, 10 min or other values, which are not limited in the present application. The preset time window can slide on the first-order difference curve, from the beginning of the curve to the end of the curve. Each time the sliding occurs, the sum of the ordinate values of the first-order difference curve within the preset time window can be calculated, which is the mutation value of the performance index within the preset time window. The mutation value can be used to represent the degree of change of the index value within the preset time window.

[0053] For example, in the index curve of the file system capacity, the index values corresponding to 00:01 to 00:06 are 0.25, 0.27, 0.33, 0.40, 0.55 and 0.57 respectively, and the first-order difference values corresponding to 00:01 to 00:05 are 0.02, 0.06, 0.07, 0.15 and 0.02 respectively. If the preset time window is 5 min, the mutation value in the time window of 00:01 to 00:05 is the sum of the five first-order difference values, which is 0.32. In this way, by sliding the time window, the mutation values of the file system capacity in the sliding time windows of 00:05 to 00:09 and 00:09 to 00:13 can be obtained.

[0054] In step 130, the preset mutation condition can include that the mutation value is greater than a first mutation threshold or the mutation value is less than a second mutation threshold, the first mutation threshold and the second mutation threshold are opposite numbers, and the first mutation threshold and the second mutation threshold can be set according to specific requirements, for example, the first mutation threshold is set to 0.3 and the second mutation threshold is set to -0.3, or the first mutation threshold is set to 0.35 and the second mutation threshold is set to -0.35, which are not limited in the present application.

[0055] In some embodiments of the present application, step 130 can specifically include the following steps: in the case that the target mutation value is greater than the first mutation threshold, determining that the time point corresponding to the target mutation value is an abnormal time point of sudden increase of the index value; in the case that the target mutation value is less than the second mutation threshold, determining that the time point corresponding to the target mutation value is an abnormal time point of sudden decrease of the index value.

[0056] Wherein, the target mutation value is the mutation value greater than the first mutation threshold, or the target mutation value is the mutation value less than the second mutation threshold.

[0057] In the embodiments of the present application, if the target mutation variable is greater than the first mutation threshold, it indicates that the index value continuously increases in the time period in which the target mutation variable is generated, and the increase range is large, and thus it can be considered that the index value suddenly increases in the time period, so as to accurately determine the time point corresponding to the target mutation variable as the abnormal time point of the sudden increase of the index value. If the target mutation variable is less than the second mutation threshold, it indicates that the index value continuously decreases in the time period in which the target mutation variable is generated, and the decrease range is large, and thus it can be considered that the index value suddenly decreases in the time period, so as to accurately determine the time point corresponding to the target mutation variable as the abnormal time point of the sudden decrease of the index value. In this way, in the mutation anomaly detection process, the present application can determine the position of the abnormal point, accurately locate the abnormal time point, and identify whether it is a sudden increase anomaly or a sudden decrease anomaly, and give a specific abnormal type, which has a strong explanatory nature for the abnormal time point. Compared with the related art which can only determine whether the curve is abnormal as a whole, the present application effectively improves the anomaly detection accuracy. Compared with the method of using two-point difference and using mean and standard deviation to calculate the mutation index for mutation anomaly detection, the present application innovatively uses the cumulative difference method and uses the sliding time window to calculate the cumulative difference value (i.e. the mutation variable) to measure the mutation and check the anomaly. This method is simple and fast, has a low false positive rate, and is very suitable for the preliminary screening of abnormal points.

[0058] In some embodiments, the time point can be at least one, and step 130 can specifically include any one of the following: determining the initial time point in the abnormal time period corresponding to the target mutation variable as the abnormal time point; determining the end time point in the abnormal time period corresponding to the target mutation variable as the abnormal time point; determining the initial time point and the end time point in the abnormal time period corresponding to the target mutation variable as the abnormal time point; and determining all time points in the abnormal time period corresponding to the target mutation variable as the abnormal time point.

[0059] Referring to the above example, the first-order difference values corresponding to 00:01 to 00:05 are 0.02, 0.06, 0.07, 0.15, and 0.02, respectively. If the preset time window is 5 min, then in the time window of 00:01 to 00:05, the mutation variable is the sum of the five first-order difference values, which is 0.32. If the first mutation threshold is 0.3, then the mutation variable in the sliding time window of 00:01 to 00:05 is the target mutation variable, at this time, the initial time point 00:01 of 00:01 to 00:05 can be taken as the abnormal time point, or the end time point 00:05 can be taken as the abnormal time point, or the initial time point 00:01 and the end time point 00:05 can be taken as the abnormal time point, or 00:01, 00:02, 00:03, 00:04, and 00:05 can all be taken as the abnormal time point.

[0060] In some embodiments of the present application, after step 130, the method can further specifically include: filtering the abnormal time points according to preset filtering conditions, and displaying the filtered abnormal time points.

[0061] Specifically, according to manual research and judgment, some expected abnormal inspection results can be further customized and set filtering conditions, such as host, abnormal type, abnormal time, etc. to avoid excessive display of abnormal results.

[0062] For example, the distributed database UPProxy connection number has a large fluctuation at about 23 o'clock, which is obviously different from the historical curve, so 23 o'clock is determined as an abnormal time point. However, after consulting the system manager, the application system was in the state of implementing changes at 23 o'clock that night, so 23 o'clock is not displayed as an abnormal time point.

[0063] In some embodiments of the present application, in order to reduce the false positive rate of abnormal time points on the basis of mutation anomaly detection, Figure 2 The flowchart of another embodiment of the abnormal detection method provided by the first aspect of the present application can specifically include steps 110-130. Figure 2 The steps 210-230 shown.

[0064] Step 210, in the case of a flat curve, determine a first-order difference curve based on the index curve.

[0065] Step 220, in the case of a fluctuating curve, determine the maximum translation amount of the index curve relative to the reference curve.

[0066] Wherein, the reference curve is generated based on the historical time series curve of the performance index, and the historical time series curve is generated based on the historical time series data in the first preset time period. The first preset time period can be set according to specific requirements, which is not limited in the present application.

[0067] Step 230, in the case where the maximum translation amount is greater than the preset translation threshold, reverse translation is performed on the index curve, and a first-order difference curve is determined based on the index curve after reverse translation.

[0068] Wherein, the preset translation threshold can be set according to specific requirements, which is not limited in the present application. If the index curve is left translated relative to the reference curve, the index curve is right translated, and if the index curve is right translated relative to the reference curve, the index curve is left translated.

[0069] In the embodiments of the present application, for the fluctuation type curve, abnormal time point misjudgment may occur due to curve translation. Based on this, before the mutation anomaly detection, the present application calculates the maximum translation amount of the index curve relative to the reference curve to determine whether the index curve is translated, for example, the peak value of the index curve is translated due to the change of the business logic of the application system, in this scenario, the index curve can be inversely translated, and the mutation anomaly detection is performed based on the inversely translated index curve, thereby reducing the abnormal false alarm caused by curve translation in the mutation anomaly detection, and further reducing the false alarm rate.

[0070] It should be noted that the present application does not specifically limit the execution order of steps 210 and 220, and step 210 can be performed before step 220 or after step 220.

[0071] In some embodiments of the present application, in order to accurately determine the curve type of the index curve, Figure 3 The flow chart of another embodiment of the anomaly detection method provided by the first aspect of the present application is shown in FIG. 3. Figure 3 As shown in FIG. 3, before step 210 of determining the first difference curve of the index curve, the method can further include steps 310-350.

[0072] Step 310, dividing the index curve into N time intervals, and obtaining the interval maximum value and the interval minimum value of each time interval.

[0073] Wherein, N is a positive integer, which can be set according to specific requirements, for example, 30min, 1h or other numerical values, etc., which is not specifically limited by the present application. Among all the time points in each time interval, the maximum index value is the interval maximum value, and the minimum index value is the interval minimum value.

[0074] Step 320, calculating the difference between the interval maximum value and the interval minimum value of each time interval to obtain N difference values corresponding to N time intervals.

[0075] Wherein, the difference value can be used to represent the maximum variation amplitude of the index value in the time interval.

[0076] Step 330, determining the first number of target time intervals in the N time intervals, wherein the difference value corresponding to the target time interval is greater than the first preset threshold.

[0077] Wherein, the first number is the number of target time intervals, and the first preset threshold can be set according to specific requirements, for example, 0.5, 0.6 or other numerical values, etc., which is not specifically limited by the present application.

[0078] Step 340, in the case that the ratio of the first quantity and N is less than or equal to the first ratio, determining that the index curve is a gentle type curve.

[0079] The first ratio can be set according to specific requirements, for example, set to 0.7, 0.8 or other values, which is not limited in the present application.

[0080] Step 350, in the case that the ratio of the first quantity and N is greater than the first ratio, determining that the index curve is a fluctuant type curve.

[0081] Exemplarily, the abscissa of the index curve is a time point, the ordinate is the file system capacity collected at the time point, and the index curve includes 1440 time points. If the time interval is 40 min, the index curve can be divided into 36 time intervals. The first preset threshold can be 0.5, and the first ratio is 0.8. If there are more than 28 target time intervals whose difference values are greater than 0.5 in the 36 difference values corresponding to the 36 time intervals, the index curve is a fluctuant type curve, otherwise it is a gentle type curve.

[0082] In the embodiments of the present application, by calculating the difference between the interval maximum value and the interval minimum value of each time interval, the difference value which can represent the maximum variation amplitude of the index value in the time interval can be obtained. If the ratio of the first quantity and N of the target time interval is greater than the first ratio, it means that the number of target intervals is relatively large, that is, there are many time intervals with large difference values, the variation amplitude of the index value of the performance index in most time intervals is large, and the fluctuation frequency of the index value is large, so it can be accurately judged that the index curve is a fluctuant type curve. Compared with the industry which uses the standard deviation of the whole curve to measure the fluctuation of the curve, the first preset threshold and the first ratio in the present application can be flexibly adjusted, so the curve type discrimination method based on the first preset threshold and the first ratio is also more flexible.

[0083] In some embodiments of the present application, in order to obtain the reference curve, before step 220 determines the maximum translation amount of the index curve relative to the reference curve, the method can further include the following steps: obtaining historical time series data of the performance index in a first preset time period; generating P historical time series curves of the performance index based on the historical time series data in the first preset time period, wherein the abscissa of the historical time series curve is a time point, and the ordinate is the index value of the performance index; calculating the average value of the P index values corresponding to each time point in the P historical time series curves; generating the reference curve by taking the average value of the P index values as the ordinate.

[0084] P is a positive integer, the index curve can be generated based on time series data in the third preset time period, the first preset time period can be before the third preset time period, the first preset time period can be set according to specific requirements, for example, set to 7 days before the third preset time period, the present application does not make specific limitation.

[0085] Exemplarily, the index curve can be generated based on the time series data in the eighth, and the first preset time period can be from the first to the seventh, so based on the seven-day historical time series data of the application system from the first to the seventh, P=7 historical time series curves can be generated. Calculate the average value of the 7 index values corresponding to each day at the same time point in the 7 historical time series curves, for example, get the index value at 00:10:00 of each day in the historical time series curve, get 7 index values, and calculate the average value. Based on the average value of the 7 index values corresponding to all time points, the baseline curve is obtained.

[0086] In the embodiment of the present application, after generating a plurality of historical time series curves based on historical time series data, the average value of the index values corresponding to the same time point in the plurality of historical time series curves is calculated to obtain the baseline curve. Since the baseline curve can reflect the historical change rule of the index value, that is, the normal fluctuation rule, when the baseline curve is used to detect the curve translation amount of the index curve, the translation amount of the index curve relative to the normal fluctuation baseline curve can be calculated, so that the maximum translation amount calculated is more convincing and has higher accuracy.

[0087] In some embodiments of the present application, in order to accurately calculate the maximum translation amount of the index curve relative to the baseline curve, Figure 4 The flowchart of another embodiment of the anomaly detection method provided by the first aspect of the present application is shown in step 220, which determines the maximum translation amount of the index curve relative to the baseline curve, which can specifically include Figure 4 Steps 410 and 420 are shown.

[0088] Step 410, based on dynamic time warping (DTW) algorithm, calculate the similarity of the index curve and the baseline curve, get the shortest distance of the index curve and the baseline curve, and the mapping path between the index curve and the baseline curve.

[0089] Wherein, the mapping path is used to represent the shortest distance on the whole index curve and the baseline curve, and the mapping path is used to represent the mapping relationship between the coordinate points in the index curve and the coordinate points in the baseline curve to achieve the shortest distance.

[0090] Dynamic time warping (DTW) algorithm is a method for measuring the similarity between two time series, which can be used to calculate the similarity between the index curve and the baseline curve here.

[0091] Step 420, based on the mapping path, calculating the maximum translation amount of the index curve relative to the reference curve.

[0092] In the embodiments of the present application, considering that the DTW algorithm can be used to calculate the shortest distance, which can be used to measure the similarity between two curves, after obtaining the shortest distance, the present application determines the mapping path between the index curve and the reference curve based on the shortest distance, so as to accurately calculate the maximum translation amount of the index curve relative to the reference curve according to the mapping path, and realize the abnormal translation amount detection of the fluctuation type index curve. In this way, in the case that the index curve is relatively translated to the reference curve, the index curve can be inversely translated, and the mutation anomaly detection can be performed based on the inversely translated index curve, so as to reduce the abnormal false alarm caused by curve translation in the mutation anomaly detection, and further reduce the false alarm rate.

[0093] In some embodiments of the present application, the mapping path is used to represent the mapping relationship between the first coordinate point and the second coordinate point, the first coordinate point is a coordinate point in the index curve, and the second coordinate point is a coordinate point in the reference curve, Figure 5 The flowchart of another embodiment of the anomaly detection method provided by the first aspect of the present application is shown in the figure, and the above step 420 can specifically include Figure 5 Steps 510-540 shown in the figure.

[0094] Step 510, in the case that at least two first coordinate points have a mapping relationship with the same second coordinate point, determining that the index curve is translated relative to the reference curve.

[0095] Specifically, in order to make the index curve and the reference curve achieve the shortest distance as a whole, the first coordinate point and the second coordinate point need to establish a mapping relationship, and each second coordinate point can have a mapping relationship with at least one first coordinate point. If the vertical coordinates of the continuous multiple first coordinate points are close, the continuous multiple first coordinate points can establish a mapping relationship with the same second coordinate point.

[0096] Step 520, obtaining the number of first coordinate points having a mapping relationship with each second coordinate point in the plurality of second coordinate points corresponding to the reference curve, to obtain a second number corresponding to each second coordinate point.

[0097] Wherein, the second number is the number of first coordinate points having a mapping relationship with the second coordinate point.

[0098] In some examples, the first coordinate points in the index curve include a1, a2…a1440, and the second coordinate points in the baseline curve include b1, b2…b1440. The mapping path between the index curve and the baseline curve is [(a1, b1), (a2, b2), (a3, b3), (a4, b3), (a5, b3), (a6, b3), (a7, b3), (a8, b4), (a9, b5)...(a1440, b1440)]. Since the second coordinate point b3 has a mapping relationship with all five first coordinate points a3, a4, a5, a6, and a7, the second quantity corresponding to the second coordinate point b3 is 5.

[0099] Step 530: Determine the second target coordinate point among multiple second coordinate points.

[0100] Among them, the second target coordinate point has the largest number of corresponding second coordinate points, that is, the second coordinate point that has the most mapping relationship with the first coordinate point is the second target coordinate point.

[0101] In other examples, such as Figure 6 As shown, curve 601 is the indicator curve, and curve 602 is the baseline curve. The horizontal axis represents time points, and the vertical axis represents the indicator values ​​corresponding to those time points. In indicator curve 601, the indicator value corresponding to multiple consecutive time points between 00:00:00 and 06:00:00 is 0.45. Therefore, multiple first coordinate points between 00:00:00 and 06:00:00 can be mapped to the same second coordinate point A1. Figure 6 In the diagram, A1 is the second coordinate point that has the most mapping relationships with the first coordinate point. Therefore, A1 has the largest number of second coordinate points, and A1 is the second target coordinate point.

[0102] Step 540: Calculate the maximum translation amount based on the second quantity corresponding to the second target coordinate point.

[0103] In some embodiments of this application, calculating the maximum translation amount based on the second quantity corresponding to the second target coordinate point may specifically include: determining the difference between the second quantity corresponding to the second target coordinate point and 1 as the maximum translation amount.

[0104] For example, the second coordinate point b3 has a mapping relationship with all five first coordinate points a3, a4, a5, a6, and a7. Therefore, the second quantity corresponding to the second coordinate point b3 is 5. It can be considered that compared with the baseline curve, the index curve has shifted 4 units to the right at a3, that is, the shift amount is 4. If b3 is the second target coordinate point, then the maximum shift amount is 4.

[0105] In the embodiments of the present application, if the plurality of first coordinate points have a mapping relationship with the same second coordinate point, it indicates that the index values of the plurality of first coordinate points are similar, that is, the index values in the index curve are in a constant state, and the index curve is translated relative to the reference curve. Therefore, the number of the first coordinate points having a mapping relationship with the second coordinate point, that is, the second number, can accurately reflect the size of the translation of the index curve relative to the reference curve, and the maximum translation of the index curve relative to the reference curve can be accurately determined based on the second number.

[0106] In some embodiments of the present application, in order to reduce the false negative rate of the abnormal time point, Figure 7 The flow chart of another embodiment of the abnormality detection method provided by the first aspect of the present application is shown in FIG. 7. Figure 7 As shown in FIG. 7, after step 530, the method can further include steps 710 and 720.

[0107] In step 710, a first target coordinate point in the plurality of first coordinate points corresponding to the index curve is obtained.

[0108] The first target coordinate point is a first coordinate point having a mapping relationship with the second target coordinate point.

[0109] In step 720, in the case that the maximum translation is greater than a preset translation threshold, the first target time point in the index curve is determined as an abnormal time point.

[0110] The preset translation threshold can be set according to specific requirements, which is not limited in the present application, and the first target time point is the horizontal coordinate of the first target coordinate point.

[0111] Continuing to refer to Figure 6 , the second coordinate point A1 in the reference curve 602 is the second target coordinate point, so the first coordinate point having a mapping relationship with A1 in the index curve 601 is the first target coordinate point, and therefore the horizontal coordinate of the first target coordinate point, that is, the time point between 00:00:00 and 06:00:00, is the first target time point with abnormality.

[0112] In the embodiments of the present application, if the maximum translation of the index curve relative to the reference curve is small, it can be considered as a normal phenomenon, and if the maximum translation of the index curve relative to the reference curve is greater than a preset translation threshold, that is, exceeds the limit value, it can be considered that the application system causes a large translation of the index curve relative to the reference curve due to the change of business logic, that is, the application system is abnormal, and therefore the plurality of time points with unchanged index values, that is, the first target time point, can be determined as an abnormal time point, avoiding the omission of the abnormal time point and reducing the false negative rate of the abnormal time point.

[0113] In some embodiments of the present application, the number of the first target coordinate points is M, M is a positive integer, the M first target coordinate points correspond to M first target time points, the abscissa of the second target coordinate point is the second target time point, and the reverse translation of the index curve in step 230 can specifically include the following steps: in the case that the M first target time points are greater than or equal to the second target time point, it is determined that the index curve is right translated relative to the reference curve, and then the index curve is left translated by the maximum translation amount; in the case that the M first target time points are less than or equal to the second target time point, it is determined that the index curve is left translated relative to the reference curve, and then the index curve is right translated by the maximum translation amount.

[0114] Continuing to refer to Figure 6 , the second coordinate point A1 in the reference curve 602 is the second target coordinate point, and the abscissa 00:00:00 of A1 is the second target time point. In the index curve 601, the first coordinate point having a mapping relationship with A1 is the first target coordinate point, and therefore the abscissa of the first target coordinate point, that is, the time point between 00:00:00 and 06:00:00, is the first target time point with an abnormality. Since the time points between 00:00:00 and 06:00:00 are all greater than or equal to the second target time point 00:00:00, it can be determined that the index curve 601 is right translated relative to the reference curve, and the index curve needs to be reverse translated, that is, left translated. As shown in Figure 8 , 801 is the index curve after reverse translation.

[0115] In the embodiments of the present application, by comparing the size relationship between the first target time point and all the second target time points, it can be accurately determined whether the index curve is left translated or right translated relative to the reference curve, so that the index curve is reverse translated based on the maximum translation amount, the abnormality of the index value in the index curve is solved, and the mutation abnormality detection is performed on the basis of the normal index curve, thereby reducing the false positive rate in the mutation abnormality detection.

[0116] In some embodiments of the present application, in order to reduce the false positive rate of the abnormal time point, Figure 9 the flowchart of still another embodiment of the abnormality detection method provided by the first aspect of the present application is shown in Figure 9 After the time point corresponding to the target mutation variable is determined as the abnormal time point in step 130, the method can further include steps 910-950.

[0117] In step 910, historical time series data of the performance index in a second preset time period is acquired.

[0118] The second preset time period and the first preset time period can be the same or different, and the present application does not make a specific limitation in this regard.

[0119] At step 920, Q historical time series curves of the performance indicator are generated based on historical time series data in a second preset time period.

[0120] wherein Q is a positive integer, the abscissa of the historical time series curve and the abscissa of the indicator curve are time points, and the ordinate of the historical time series curve and the ordinate of the indicator curve are indicator values of the performance indicator.

[0121] At step 930, the average value and the standard deviation of the Q indicator values corresponding to each time point in the Q historical time series curves are calculated.

[0122] At step 940, the upper interval value and the lower interval value corresponding to each time point are calculated based on the average value and the standard deviation of the Q indicator values corresponding to each time point, to obtain the reference interval corresponding to each time point.

[0123] Specifically, the upper interval value can be the sum of the average value of the Q indicator values and a first numerical value, and the lower interval value can be the difference between the average value of the Q indicator values and the first numerical value, wherein the first numerical value is the product of the standard deviation and a preset coefficient, which can be set according to specific requirements, for example, set to 3, 5 or other numerical values, which are not limited in the present application.

[0124] For example, the second preset time period is 7 days in the past, Q is 7, the indicator values at 00:10:00 every day in the historical time series curve are 7 in total, the average value avg and the standard deviation sigma are calculated, the upper interval value is avg+3*sigma, the lower interval value is avg-3*sigma, and the reference interval corresponding to 00:10:00 is avg-3*sigma to avg+3*sigma.

[0125] In some embodiments of the present application, after step 940, the method can further specifically include: generating an upper interval reference curve based on the upper interval value corresponding to each time point, and generating a lower interval reference curve based on the lower interval value corresponding to each time point; and if the indicator value in the indicator curve is not between the upper interval reference curve and the lower interval reference curve, determining that the indicator value is not in the reference interval.

[0126] At step 950, if the indicator values of the consecutive R time points in the indicator curve are not in the reference interval, and R is greater than a preset number, the consecutive R time points are determined as abnormal points.

[0127] wherein R is a positive integer, and the preset number can be set according to requirements, for example, set to 6, 8 or other numerical values, which are not limited in the present application.

[0128] In the industry, when performing interval anomaly detection, if the index value at a certain time point is not in the reference interval, it is determined as an abnormal time point, and the false positive rate is high. In the embodiments of the present application, on the basis of the interval anomaly detection scheme in the industry, it is considered that there is an anomaly only when the index values of a preset number of continuous time points are all not in the reference interval, and the continuous multiple time points are confirmed as abnormal time points. The standard of interval anomaly detection is improved, the misjudgment is reduced, the false positive rate is reduced, and the accuracy of interval anomaly detection is improved. At the same time, different types of curves are classified, and multiple anomaly checking algorithms are combined to check the volatility curve according to the characteristics that different checking algorithms are suitable for different types of curves, so as to ensure the accuracy and reduce the false positive rate. If subsequent curves are of types other than the flat type and the volatility type, a measurement index can be introduced to classify the curves, and a new checking algorithm can be customized for the classified curves, which has strong expandability.

[0129] In some embodiments of the present application, the method can further include: training the anomaly detection model with historical time series data as training sample data to obtain a trained target anomaly detection model; inputting the index curve of the performance index into the target anomaly detection model, so that the target anomaly detection model classifies the index curve, and in the case that the index curve is a flat curve, performs mutation anomaly detection on the index curve to obtain an abnormal time point; and in the case that the index curve is a volatility curve, performing shift anomaly detection, mutation anomaly detection and interval anomaly detection on the index curve in sequence to obtain an abnormal time point.

[0130] In the embodiments of the present application, the sample data for training the anomaly detection model does not need to be labeled, and the model is simple. In addition to detecting abnormal time points, the target anomaly detection model can also perform large data volume parallel automatic anomaly labeling, and provide labeled training sample data for more complex supervised models and multi-index anomaly checking models.

[0131] Based on the same inventive concept, the second aspect of the present application provides an anomaly detection device. Figure 10 An embodiment of the anomaly detection device provided by the second aspect of the present application is shown in a structural schematic diagram.

[0132] As shown in Figure 10 The anomaly detection device 1000 can specifically include a determination module 1010 and a detection module 1020.

[0133] The determination module 1010 is configured to determine a first-order difference curve of the index curve when the index curve of the performance index is obtained, wherein the index curve is generated based on time series data of the performance index, and the ordinate of the first-order difference curve is a first-order difference value, and the first-order difference value is used to represent the change amount of the index values of adjacent two time points in the index curve.

[0134] The determining module 1010 is further configured to slide a preset time window on the first-order differential curve, and determine a sum of the ordinate of the first-order differential curve in the preset time window during the sliding to obtain a plurality of mutation values of the performance index.

[0135] The detecting module 1020 is further configured to determine a target mutation value that meets a preset mutation condition from the plurality of mutation values, and determine a time point corresponding to the target mutation value as an abnormal time point.

[0136] The abnormality detection apparatus provided in the embodiments of the present application, in the case where the index curve of the performance index is obtained, determines a first-order differential curve of the index curve, the index curve is generated based on time series data of the performance index, and the ordinate of the first-order differential curve is a first-order differential value, which is used to represent the index value variation amount of adjacent two time points in the index curve, and thus the first-order differential curve can reflect the change of the index value variation amount. On this basis, the preset time window is slid on the first-order differential curve, and the sum of the ordinate of the first-order differential curve in the preset time window is determined during the sliding to calculate the cumulative differential value using the sliding time window, and a plurality of mutation values of the performance index are obtained, the mutation value is the sum of the index value variation amount in each sliding time window, and can accurately reflect the change degree of the index value in a certain period of time. For example, if the sum is large, it means that the plurality of index value variation amounts located in the sliding time window are large, that is, the index values of the continuous plurality of time points located in the sliding time window show a growth trend. Therefore, by judging whether the mutation value meets the preset mutation condition, whether the index value in the index curve is abnormal, such as sudden increase or sudden decrease, can be effectively measured, and finally the time point corresponding to the target mutation value that meets the preset mutation condition is determined as the abnormal time point, without the need for manual checking of the index curve, which is simple and fast, and can effectively improve the abnormality detection efficiency of the index curve.

[0137] In some embodiments of the present application, the determining module 1010 includes a determining sub-module configured to, in the case where the index curve is a gentle curve, determine the first-order differential curve based on the index curve; the determining sub-module is further configured to, in the case where the index curve is a fluctuant curve, determine a maximum translation amount of the index curve relative to a reference curve, the reference curve being generated based on a historical time series curve of the performance index; and a translation sub-module configured to, in the case where the maximum translation amount is greater than a preset translation threshold, inversely translate the index curve, and determine the first-order differential curve based on the inversely translated index curve.

[0138] In some embodiments of the present application, the device further comprises: a division module configured to divide the index curve into N time intervals before determining the first difference curve of the index curve, and obtain the interval maximum value and the interval minimum value of each time interval; a calculation module configured to calculate the difference between the interval maximum value and the interval minimum value of each time interval to obtain N difference values corresponding to the N time intervals; the determination module 1010 is further configured to determine a first number of target time intervals in the N time intervals, wherein the target time intervals correspond to the difference values greater than a first preset threshold; the determination module 1010 is further configured to determine that the index curve is a gentle curve when the ratio of the first number to N is less than or equal to a first ratio; and the determination module 1010 is further configured to determine that the index curve is a fluctuating curve when the ratio of the first number to N is greater than the first ratio.

[0139] In some embodiments of the present application, the device further comprises: an acquisition module configured to acquire historical time series data of the performance index in a first preset time period before determining the maximum translation of the index curve relative to the reference curve; a generation module configured to generate P historical time series curves of the performance index based on the historical time series data in the first preset time period, wherein the abscissa of the historical time series curve is a time point, and the ordinate is an index value of the performance index; a calculation module configured to calculate the average value of P index values corresponding to each time point in the P historical time series curves; and the generation module is further configured to generate the reference curve by taking the average value of the P index values as the ordinate.

[0140] In some embodiments of the present application, the determination sub-module comprises: a calculation unit configured to calculate the similarity between the index curve and the reference curve based on a dynamic time warping (DTW) algorithm, to obtain the shortest distance between the index curve and the reference curve, and a mapping path between the index curve and the reference curve; and the calculation unit is further configured to calculate the maximum translation of the index curve relative to the reference curve based on the mapping path.

[0141] In some embodiments of the present application, the mapping path is used to represent the mapping relationship between the first coordinate point and the second coordinate point, the first coordinate point is a coordinate point in the index curve, and the second coordinate point is a coordinate point in the reference curve. The calculation unit is specifically configured to: determine that the index curve is translated relative to the reference curve when at least two first coordinate points and the same second coordinate point have a mapping relationship; obtain the number of first coordinate points having a mapping relationship with each second coordinate point from a plurality of second coordinate points corresponding to the reference curve, to obtain a second number corresponding to each second coordinate point; determine a second target coordinate point in the plurality of second coordinate points, wherein the second target coordinate point corresponds to the maximum second number; and calculate the maximum translation based on the second number corresponding to the second target coordinate point.

[0142] In some embodiments of the present application, the device further comprises an acquisition module, further configured to acquire a first target coordinate point in the plurality of first coordinate points corresponding to the index curve, wherein the first target coordinate point is a first coordinate point having a mapping relationship with the second target coordinate point; and the determination module 1010 is further configured to determine the first target time point in the index curve as an abnormal time point in a case where the maximum translation amount is greater than a preset translation threshold.

[0143] In some embodiments of the present application, the number of first target coordinate points is M, the M first target coordinate points correspond to M first target time points, and the translation submodule is specifically configured to: in a case where the M first target time points are greater than or equal to the second target time point, determine that the index curve produces a right translation relative to the reference curve, and then translate the index curve to the left by the maximum translation amount; and in a case where the M first target time points are less than or equal to the second target time point, determine that the index curve produces a left translation relative to the reference curve, and then translate the index curve to the right by the maximum translation amount.

[0144] In some embodiments of the present application, the device further comprises: an acquisition module, further configured to acquire historical time series data of the performance index in a second preset time period after determining the time point corresponding to the target mutation variable as an abnormal time point; a generation module, configured to generate Q historical time series curves of the performance index based on the historical time series data in the second preset time period, wherein the horizontal coordinates of the historical time series curves and the index curve are time points, and the vertical coordinates are index values of the performance index; a calculation module, configured to calculate the average value and the standard deviation of Q index values corresponding to each time point in the Q historical time series curves; and the calculation module is further configured to calculate the upper interval value and the lower interval value corresponding to each time point based on the average value and the standard deviation of the Q index values corresponding to each time point, to obtain a reference interval corresponding to each time point; and the determination module 1010 is further configured to determine the continuous R time points as abnormal points in a case where the index values of the continuous R time points in the index curve are all not in the reference interval, and R is greater than a preset number.

[0145] In some embodiments of the present application, the preset mutation condition includes that the mutation variable is greater than a first mutation threshold or the mutation variable is less than a second mutation threshold, and the determination module 1010 is specifically configured to: in a case where the target mutation variable is greater than the first mutation threshold, determine that the time point corresponding to the target mutation variable is an abnormal time point of sudden increase of the index value; and in a case where the target mutation variable is less than the second mutation threshold, determine that the time point corresponding to the target mutation variable is an abnormal time point of sudden decrease of the index value; wherein the first mutation threshold and the second mutation threshold are opposite numbers.

[0146] The third aspect of the present application further provides an electronic device. Figure 11An embodiment of the electronic device provided by the third aspect of the present application is shown in a structural schematic diagram. As shown in Figure 11 The electronic device 1100 includes a memory 1101, a processor 1102, and a computer program stored in the memory 1101 and executable on the processor 1102.

[0147] In one example, the processor 1102 can include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or can be configured as one or more integrated circuits that implement embodiments of the present application.

[0148] The memory 1101 can include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage medium device, an optical storage medium device, a flash memory device, an electrical, optical, or other physical / tangible memory storage device. Therefore, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions and when the software is executed (e.g., by one or more processors), it is operable to perform operations described with reference to the method of detecting an anomaly according to the embodiments of the first aspect of the present application.

[0149] The processor 1102 runs a computer program corresponding to the executable program code stored in the memory 1101 by reading the executable program code, for implementing the method of detecting an anomaly in the embodiments of the first aspect described above.

[0150] In some examples, the electronic device 1100 can also include a communication interface 1103 and a bus 1104. As shown in Figure 11 The memory 1101, the processor 1102, and the communication interface 1103 are connected through the bus 1104 and complete communication among each other.

[0151] The communication interface 1103 is mainly used to realize communication among modules, devices, units, and / or equipment in embodiments of the present application. Input devices and / or output devices can also be accessed through the communication interface 1103.

[0152] Bus 1104 includes hardware, software, or both, to couple components of electronic device 1100 to each other and to couple electronic device 1100 to other systems or devices. While Fig. 1 illustrates a bus as the mechanism for communicating between electronic components, other mechanisms for communicating or transferring information between electronic components are also possible. For example, electronic device 1100 could be communicatively coupled to another device or system via wireless communications, wireline communications, optical communications, or other form of communication. In some embodiments, electronic device 1100 can include a plurality of busses. Although this application describes and illustrates a particular bus, this application contemplates any suitable bus or interconnect.

[0153] The fourth aspect of the present application provides a computer readable storage medium, which stores a program or instructions, and the program or instructions are executed by a processor to implement the abnormality detection method of the first aspect, and achieve the same technical effects. To avoid repetition, details are not described here. The computer readable storage medium can include a non-transitory computer readable storage medium, such as a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and the like, which is not limited here.

[0154] The fifth aspect of the present application provides a computer program product stored in a non-volatile storage medium, and the computer program product is executed by at least one processor to implement the steps of the abnormality detection method of the first aspect. The specific content of the abnormality detection method can be referred to the related description in the above embodiments, and details are not described here.

[0155] The sixth aspect of the present application provides a chip, which comprises a processor and a communication interface, the communication interface is coupled with the processor, the processor is configured to run programs or instructions, and each process of the embodiment of the anomaly detection method shown in the first aspect is implemented, and the same technical effects are achieved. To avoid repetition, details are not described here.

[0156] It should be understood that the chip mentioned in the embodiments of the present application can also be referred to as a system-level chip, a system chip, a chip system, or a system-on-chip, etc.

[0157] It should be noted that each embodiment in the present specification is described in a progressive manner, and the same or similar parts of each embodiment can be referred to each other. Each embodiment focuses on the difference from other embodiments. For the device embodiment, the user terminal embodiment, the equipment embodiment, the system embodiment and the computer readable storage medium embodiment, the relevant parts can be referred to the description of the method embodiment. The present application is not limited to the specific steps and structures described above and shown in the drawings. Those skilled in the art can make various changes, modifications and additions, or change the order of steps, after understanding the spirit of the present application. Moreover, in order to be brief, the detailed description of the known method technology is omitted.

[0158] The aspects of the present application are described above with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each block in the flowcharts and / or block diagrams, and the combination of blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus, to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing apparatus enable the implementation of the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field programmable logic circuit. It should also be understood that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can also be implemented by special hardware to perform the specified functions or acts, or can be implemented by a combination of special hardware and computer instructions.

[0159] It should be understood by those skilled in the art that the above embodiments are exemplary but not limiting. Different technical features appearing in different embodiments can be combined to achieve beneficial effects. Other changed embodiments of the disclosed embodiments can be understood and implemented by those skilled in the art based on the drawings, the specification and the claims. In the claims, the term "comprising" does not exclude other devices or steps; the numerical term "one" does not exclude a plurality; the terms "first", "second" are used to designate names and not to indicate any particular order. Any reference signs in the claims should not be understood as limiting the scope of protection. The functions of multiple parts appearing in the claims can be implemented by a single hardware or software module. The fact that certain technical features appear in different dependent claims does not mean that these technical features cannot be combined to achieve beneficial effects.

Claims

1. An anomaly detection method characterized by, The method comprises: In the case of obtaining an index curve of a performance index, a first-order difference curve of the index curve is determined, wherein the index curve is generated based on time series data of the performance index, and the ordinate of the first-order difference curve is a first-order difference value, which is used to represent the change amount of index values of adjacent two time points in the index curve; A preset time window is used to slide on the first-order difference curve, and the sum of the ordinates of the first-order difference curve within the preset time window is determined during the sliding process to obtain a plurality of mutation values of the performance index; A target mutation value that meets a preset mutation condition is determined from the plurality of mutation values, and a time point corresponding to the target mutation value is determined as an abnormal time point; The determination of the first-order difference curve of the index curve comprises: In the case of a gentle curve of the index curve, the first-order difference curve is determined based on the index curve; In the case of a fluctuating curve of the index curve, a maximum translation amount of the index curve relative to a reference curve is determined, and the reference curve is generated based on a historical time series curve of the performance index; In the case that the maximum translation amount is greater than a preset translation threshold, the index curve is inversely translated, and the first-order difference curve is determined based on the inversely translated index curve; The determination of the maximum translation amount of the index curve relative to the reference curve comprises: Based on a dynamic time warping (DTW) algorithm, the similarity between the index curve and the reference curve is calculated to obtain the shortest distance between the index curve and the reference curve, and a mapping path between the index curve and the reference curve; Based on the mapping path, the maximum translation amount of the index curve relative to the reference curve is calculated; The mapping path is used to represent the mapping relationship between a first coordinate point and a second coordinate point, the first coordinate point is a coordinate point in the index curve, and the second coordinate point is a coordinate point in the reference curve. Based on the mapping path, the maximum translation amount of the index curve relative to the reference curve is calculated, which comprises: In the case that at least two first coordinate points have a mapping relationship with the same second coordinate point, it is determined that the index curve is translated relative to the reference curve; The number of first coordinate points having a mapping relationship with each second coordinate point is obtained from a plurality of second coordinate points corresponding to the reference curve to obtain a second number corresponding to each second coordinate point; A second target coordinate point is determined from the plurality of second coordinate points, wherein the second target coordinate point corresponds to the maximum second number; Based on the second number corresponding to the second target coordinate point, the maximum translation amount is calculated; The inverse translation comprises: if the index curve is left translated relative to the reference curve, the index curve is right translated, and if the index curve is right translated relative to the reference curve, the index curve is left translated.

2. The method of claim 1, wherein, Before the determination of the first-order difference curve of the index curve, the method further comprises: The index curve is divided into N time intervals, and the interval maximum value and the interval minimum value of each time interval are obtained. calculate a difference between the interval maximum value and the interval minimum value of each time interval, to obtain N difference values corresponding to the N time intervals; determine a first number of target time intervals in the N time intervals, wherein the target time intervals correspond to a difference value greater than a first preset threshold value; in a case where a ratio of the first number to N is less than or equal to a first ratio, determine that the index curve is a flat curve; in a case where the ratio of the first number to N is greater than the first ratio, determine that the index curve is a fluctuating curve.

3. The method of claim 1, wherein, Before the determining the maximum translation amount of the index curve relative to the reference curve, the method further comprises: obtaining historical time series data of the performance index in a first preset time period; generating P historical time series curves of the performance index based on the historical time series data in the first preset time period, wherein the horizontal coordinate of the historical time series curve is a time point, and the vertical coordinate is an index value of the performance index; calculating an average value of P index values corresponding to each time point in the P historical time series curves; generating the reference curve by taking the average value of the P index values as the vertical coordinate.

4. The method of claim 1, wherein, The method further comprises: obtaining a first target coordinate point in a plurality of first coordinate points corresponding to the index curve, wherein the first target coordinate point is a first coordinate point having a mapping relationship with the second target coordinate point; in a case where the maximum translation amount is greater than a preset translation threshold value, determining that a first target time point in the index curve is an abnormal time point, wherein the first target time point is a horizontal coordinate of the first target coordinate point.

5. The method of claim 4, wherein, The number of the first target coordinate points is M, and M first target coordinate points correspond to M first target time points, the horizontal coordinate of the second target coordinate point is a second target time point, and the inversely translating the index curve comprises: in a case where the M first target time points are greater than or equal to the second target time point, determining that the index curve produces a right translation relative to the reference curve, and then translating the index curve to the left by the maximum translation amount; in a case where the M first target time points are less than or equal to the second target time point, determining that the index curve produces a left translation relative to the reference curve, and then translating the index curve to the right by the maximum translation amount.

6. The method of claim 1, wherein, After the determining the time point corresponding to the target mutation variable as an abnormal time point, the method further comprises: obtaining historical time series data of the performance index in a second preset time period; generating Q historical time series curves of the performance index based on the historical time series data in the second preset time period, wherein the horizontal coordinates of the historical time series curves and the index curve are time points, and the vertical coordinates are index values of the performance index; calculating an average value and a standard deviation of Q index values corresponding to each time point in the Q historical time series curves; based on the average value and the standard deviation of the Q index values corresponding to each time point, calculating an upper interval value and a lower interval value corresponding to each time point to obtain a reference interval corresponding to each time point; In a case where the index values of R consecutive time points in the index curve are all not in the reference interval, and R is greater than a preset number, the R consecutive time points are determined as abnormal points.

7. The method of claim 1, wherein, The preset mutation condition includes that the mutation quantity is greater than a first mutation threshold or the mutation quantity is less than a second mutation threshold, and the time point corresponding to the target mutation quantity is determined as an abnormal time point, including: In a case where the target mutation quantity is greater than the first mutation threshold, the time point corresponding to the target mutation quantity is determined as an abnormal time point of index value sudden increase; In a case where the target mutation quantity is less than the second mutation threshold, the time point corresponding to the target mutation quantity is determined as an abnormal time point of index value sudden decrease; The first mutation threshold and the second mutation threshold are opposite numbers.

8. An abnormality detection device characterized by comprising: The apparatus includes: A determination module is configured to, in a case where an index curve of a performance index is acquired, determine a first-order difference curve of the index curve, wherein the index curve is generated based on time series data of the performance index, and a vertical coordinate of the first-order difference curve is a first-order difference value used to represent a variation amount of index values of two adjacent time points in the index curve. The determination module is further configured to slide a preset time window on the first-order difference curve, and determine a sum of the vertical coordinates of the first-order difference curve within the preset time window in the sliding process to obtain a plurality of mutation quantities of the performance index. A detection module is configured to determine a target mutation quantity that satisfies a preset mutation condition from the plurality of mutation quantities, and determine a time point corresponding to the target mutation quantity as an abnormal time point. The determination module includes a determination sub-module configured to, in a case where the index curve is a gentle curve, determine the first-order difference curve based on the index curve, and the determination sub-module is further configured to, in a case where the index curve is a fluctuant curve, determine a maximum translation amount of the index curve relative to a reference curve, and the reference curve is generated based on a historical time series curve of the performance index; and a translation sub-module configured to, in a case where the maximum translation amount is greater than a preset translation threshold, perform reverse translation on the index curve, and determine the first-order difference curve based on the index curve after reverse translation. The determination sub-module includes a calculation unit configured to calculate a similarity between the index curve and the reference curve based on a dynamic time warping (DTW) algorithm to obtain a shortest distance between the index curve and the reference curve and a mapping path between the index curve and the reference curve, and the calculation unit is further configured to calculate the maximum translation amount of the index curve relative to the reference curve based on the mapping path. The mapping path is used to represent a mapping relationship between a first coordinate point and a second coordinate point, the first coordinate point is a coordinate point in the index curve, and the second coordinate point is a coordinate point in the reference curve. The calculation unit is specifically configured to: in the case that at least two first coordinate points have a mapping relationship with the same second coordinate point, determine that the index curve produces a translation relative to the reference curve; obtain the number of first coordinate points having a mapping relationship with each second coordinate point in a plurality of second coordinate points corresponding to the reference curve, to obtain a second number corresponding to each second coordinate point; determine a second target coordinate point in the plurality of second coordinate points, wherein the second target coordinate point corresponds to the maximum second number; and calculate the maximum translation amount based on the second number corresponding to the second target coordinate point. The reverse translation includes: if the index curve is left translation relative to the reference curve, right translation is performed on the index curve; and if the index curve is right translation relative to the reference curve, left translation is performed on the index curve.

9. An electronic device, comprising: The device comprises a processor and a memory storing computer program instructions; The processor executes the computer program instructions to implement the anomaly detection method of any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores programs or instructions, and the programs or instructions are executed by the processor to implement the anomaly detection method of any one of claims 1 to 7.

11. A computer program product, characterised in that, The computer program product is stored in a non-volatile storage medium, and the computer program product is executed by at least one processor to implement the anomaly detection method of any one of claims 1 to 7.

Citation Information

Patent Citations

  • Service index abnormity detection method and device based on time sequence and electronic device

    CN110008080A