An operation method of an intelligent auxiliary decision-making and maintenance system

By conducting real-time monitoring and abnormal analysis of the system, the problem of unstable search results in the existing intelligent auxiliary decision-making system is solved, timely discovery and accurate handling of system abnormalities is achieved, and the efficiency and accuracy of system maintenance are improved.

CN116192675BActive Publication Date: 2025-08-19BEIJING TONGTECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211460371.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-17
Publication Date
2025-08-19
Estimated Expiration
2042-11-17

AI Technical Summary

Technical Problem

When facing complex unstructured data, the existing intelligent auxiliary decision-making system has unstable correlation accuracy of the search results, resulting in untimely maintenance and poor application, making it difficult to detect and deal with system abnormalities in time.

Method used

By monitoring the operation of the target system, obtaining the monitoring data of the system login address, login website and operation information, analyzing these data in real time to determine whether there is an abnormal state, and dealing with it according to the corresponding decision matching the abnormal type, so as to achieve timely maintenance of the system.

Benefits of technology

Improve the timeliness and accuracy of system operation and maintenance to ensure the stable operation of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116192675B_ABST
    Figure CN116192675B_ABST
Patent Text Reader

Abstract

The present invention provides an operation method for an intelligent decision-making support and maintenance system, comprising: monitoring the operation of a target system to determine the operation monitoring data of the target system; analyzing the operation monitoring data in real time to determine whether the target system is in an abnormal state during operation; when an abnormal state occurs in the target system during operation, obtaining the abnormality type of the abnormal state, matching a corresponding target decision according to the abnormality type, and handling the abnormal state in the target system based on the target decision to achieve operation maintenance of the target system. By analyzing the operation monitoring data in real time, it is effectively determined whether the target system is in an abnormal state during operation, and thus the operation maintenance of the target system is achieved by determining the abnormality type and then matching the target decision, thereby improving the timeliness and accuracy of the operation maintenance of the target system, thereby ensuring the smooth operation of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of big data technology, and in particular to an operating method of an intelligent auxiliary decision-making and maintenance system. Background Art

[0002] At present, system monitoring is conducive to ensuring the safe operation of the system. System monitoring includes: system login address monitoring, system login website monitoring, and system operation information monitoring. In the process of monitoring the system login address, system login website, and system operation information, an intelligent decision-making support system combines AI with other relevant scientific achievements. Through artificial intelligence, human knowledge is more fully applied to solve problems through reasoning knowledge. Through logical reasoning, an auxiliary decision-making system helps solve complex decision-making problems.

[0003] However, most intelligent decision-making support systems rely on complex retrieval and analysis algorithms to extract knowledge similar to the problem being solved from large amounts of unstructured data. This approach is not only complex to implement and calculate, but also suffers from unstable correlation accuracy of retrieval results for different input conditions, resulting in limited applicability. Furthermore, due to the need to analyze large amounts of data during system maintenance, system anomalies cannot be discovered in a timely manner, leading to missed opportunities for maintenance.

[0004] Therefore, the present invention provides an operation method of an intelligent auxiliary decision-making and maintenance system. Summary of the Invention

[0005] The present invention provides an operation method of an intelligent auxiliary decision-making and maintenance system, which is used to determine the operation monitoring data of the system login address, system login website and system operation information in the target system by monitoring the operation of the target system, and effectively judge whether there is an abnormal state in the target system during operation through real-time analysis of the operation monitoring data, so as to realize the operation maintenance of the target system by determining the abnormality type and then matching the target decision, thereby improving the timeliness and accuracy of the operation maintenance of the target system and ensuring the smooth operation of the system.

[0006] The present invention provides an operation method of an intelligent auxiliary decision-making and maintenance system, comprising:

[0007] Step 1: Monitor the operation of the target system and determine the operation monitoring data of the target system;

[0008] Step 2: Analyze the operation monitoring data in real time to determine whether the target system has any abnormal status during operation;

[0009] Step 3: When an abnormal state occurs in the target system during operation, the abnormal type of the abnormal state is obtained, and the corresponding target decision is matched according to the abnormal type. The abnormal state in the target system is handled based on the target decision to achieve operation maintenance of the target system.

[0010] Preferably, a method for operating an intelligent decision-making support and maintenance system, in step 1, monitoring the operation of a target system and determining the operation monitoring data of the target system, includes:

[0011] Obtain N monitoring indicators for abnormal monitoring of the target system, and set N sub-data recording terminals according to the N monitoring indicators;

[0012] Based on the sub-data recording end, the monitoring data corresponding to the monitoring indicator is recorded in sequence according to the time frame, and the sub-operation monitoring data corresponding to each sub-data recording end is determined;

[0013] A data summary database is obtained, and the sub-operation monitoring data corresponding to the N sub-data recording terminals are uploaded to the data summary database, and the operation monitoring data of the target system is determined in the data summary database.

[0014] Preferably, an operation method of an intelligent auxiliary decision-making and maintenance system, uploading sub-operation monitoring data corresponding to N sub-data recording terminals into a data summary database, includes:

[0015] Acquire multiple first addresses corresponding to each sub-data recording end, and determine the second address corresponding to the data aggregation library. At the same time, establish data upload links between the multiple first addresses and the second addresses, wherein there are multiple data upload links, and the data upload links correspond one-to-one to the sub-data recording ends;

[0016] A corresponding data storage package is set for each data upload link in the data summary library, and the sub-operation monitoring data is uploaded to the corresponding data storage package in the data summary library.

[0017] Preferably, in a method for operating an intelligent decision-making support and maintenance system, in step 2, the operation monitoring data is analyzed in real time to determine whether the target system has an abnormal state during operation, including:

[0018] Obtain the monitoring types for the target system's operation monitoring, learn the monitoring types and their corresponding features, and construct a data classification model based on the learning results, using each monitoring type as a classification node;

[0019] Input the operation monitoring data into the data classification model for category analysis, and output the target operation category corresponding to the operation monitoring data in the data classification model based on the analysis results;

[0020] Based on the target operation type corresponding to the operation monitoring data, the corresponding abnormality analysis conditions are matched in the abnormality management library, and the operation monitoring data corresponding to the target operation type is judged to be abnormal based on the abnormality analysis conditions.

[0021] Preferably, a method for operating an intelligent decision-making support and maintenance system includes:

[0022] The types of monitoring for target system operation monitoring include: system login address monitoring, system login website monitoring, and system operation information monitoring;

[0023] Abnormal analysis conditions correspond to monitoring types one by one, and abnormal analysis conditions include: system login address abnormal analysis conditions, system login website violation analysis conditions, and system illegal information analysis conditions;

[0024] Based on the abnormality analysis conditions, the operation monitoring data corresponding to the target operation type is judged to be abnormal.

[0025] Preferably, an operation method of an intelligent auxiliary decision-making and maintenance system performs abnormality determination on operation monitoring data corresponding to a target operation type based on abnormality analysis conditions, including:

[0026] When the target operation type is system login address monitoring, the system login abnormality analysis condition is retrieved from the abnormality management library, and a first abnormality determination is performed on the first operation monitoring data corresponding to the system login address monitoring based on the abnormality analysis condition;

[0027] When the target operation type is system login website monitoring, the system login website violation analysis condition is retrieved from the exception management library, and a second exception determination is performed on the second operation monitoring data corresponding to the system login website monitoring based on the system login website violation analysis condition;

[0028] When the target operation type is system operation information monitoring, the system illegal information analysis condition is retrieved from the abnormality management library, and a third abnormality determination is performed on the second monitoring data corresponding to the system operation information monitoring based on the system illegal information analysis condition.

[0029] Preferably, a method for operating an intelligent decision-making support and maintenance system includes:

[0030] When the first abnormality is determined to be abnormal, a first alarm operation is performed;

[0031] When the second abnormality is determined to be abnormal, a second alarm operation is performed;

[0032] When the third abnormality is determined to be abnormal, a third alarm operation is performed.

[0033] Preferably, in a method for operating an intelligent auxiliary decision-making and maintenance system, in step 3, when an abnormal state occurs in the target system during operation, the abnormal type of the abnormal state is obtained, and the corresponding target decision is matched according to the abnormal type, including:

[0034] Read the abnormal state, determine the abnormal type corresponding to the abnormal state and the target abnormal operation data corresponding to the abnormal state;

[0035] Read the target abnormal operation data to determine the abnormality level of the target system when an abnormal state occurs during operation;

[0036] Match the target-related node in the preset decision network according to the anomaly type, and match the corresponding target-related sub-node in the target-related node according to the degree of anomaly;

[0037] Read the decision data corresponding to the target associated sub-node and generate the target decision based on the decision data.

[0038] Preferably, in a method for operating an intelligent auxiliary decision-making and maintenance system, in step 3, the abnormal state in the target system is handled based on the target decision to achieve operation and maintenance of the target system, including:

[0039] Determine a disposal strategy for abnormal states in the target system based on the target decision, and convert the disposal strategy into a policy text;

[0040] Read the policy text, determine the logical keywords, and determine the target execution process of the disposal policy according to the logical keywords. At the same time, generate the target execution instruction according to the target execution process, wherein the target execution instruction includes: a first execution instruction and a second execution instruction;

[0041] Dealing with abnormal conditions in the target system in real time based on the first execution instruction, and monitoring the execution process based on the second instruction and obtaining monitoring results;

[0042] Among them, when the monitoring results reach the target standard, the operation and maintenance of the target system are completed.

[0043] Preferably, a method for operating an intelligent decision-making support and maintenance system includes:

[0044] The monitoring results include: the execution steps for handling the abnormal state in the target system and the execution progress of handling the abnormal state in the target system;

[0045] The target standards include: the first target standard and the second target standard;

[0046] The first target standard is that when the execution steps for handling the abnormal state in the target system are consistent with the target execution steps, it is determined that the first target standard is met;

[0047] The second target standard is that when the execution progress of handling the abnormal state in the target system reaches the target progress, it is determined that the second target standard is met.

[0048] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purposes and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings.

[0049] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0051] Figure 1 This is a flow chart of an operating method of an intelligent auxiliary decision-making and maintenance system according to an embodiment of the present invention;

[0052] Figure 2 This is a flowchart of step 1 in a method for operating an intelligent decision-making support and maintenance system according to an embodiment of the present invention;

[0053] Figure 3 This is a flowchart of step 2 in a method for operating an intelligent auxiliary decision-making and maintenance system in an embodiment of the present invention. DETAILED DESCRIPTION

[0054] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.

[0055] Example 1:

[0056] This embodiment provides an operation method of an intelligent auxiliary decision-making and maintenance system, such as Figure 1 Shown, including:

[0057] Step 1: Monitor the operation of the target system and determine the operation monitoring data of the target system;

[0058] Step 2: Analyze the operation monitoring data in real time to determine whether the target system has any abnormal status during operation;

[0059] Step 3: When an abnormal state occurs in the target system during operation, the abnormal type of the abnormal state is obtained, and the corresponding target decision is matched according to the abnormal type. The abnormal state in the target system is handled based on the target decision to achieve operation maintenance of the target system.

[0060] In this embodiment, the operation monitoring data may include monitoring data for system login address monitoring, system login website monitoring, and system operation information monitoring.

[0061] In this embodiment, the abnormal state indicates that an abnormal situation exists in the current target system.

[0062] In this embodiment, the abnormality type may be a specific manifestation of the abnormal state, including: abnormal system login address, illegal system login website, and illegal system information.

[0063] In this embodiment, the target decision may be a solution strategy that helps the target system handle the abnormal state based on the matching of the abnormality type.

[0064] The beneficial effects of the above technical solution are: by monitoring the operation of the target system, the operation monitoring data of the system login address, system login website and system operation information in the target system are determined, and through real-time analysis of the operation monitoring data, it is effectively judged whether the target system has an abnormal state during operation, and thus by determining the abnormality type and then matching the target decision to achieve operation and maintenance of the target system, the timeliness and accuracy of the operation and maintenance of the target system are improved, and the smooth operation of the system is ensured.

[0065] Example 2:

[0066] Based on Example 1, this embodiment provides an operation method of an intelligent auxiliary decision-making and maintenance system, such as Figure 2 As shown, in step 1, the target system is monitored for operation and the operation monitoring data of the target system is determined, including:

[0067] Step 101: Obtain N monitoring indicators for abnormal monitoring of the target system, and set N sub-data recording terminals according to the N monitoring indicators;

[0068] Step 102: Based on the sub-data recording end, the monitoring data corresponding to the monitoring indicator is recorded in sequence according to the time frame order, and the sub-operation monitoring data corresponding to each sub-data recording end is determined;

[0069] Step 103: Obtain a data summary database, upload the sub-operation monitoring data corresponding to the N sub-data recording terminals into the data summary database, and determine the operation monitoring data of the target system in the data summary database.

[0070] In this embodiment, the monitoring indicator may be the intensity and type of monitoring performed on the target system.

[0071] In this embodiment, the sub-data recording terminal may be a terminal set according to a monitoring indicator to record the operation monitoring data corresponding to the monitoring indicator, and one monitoring indicator corresponds to one sub-data recording terminal.

[0072] In this embodiment, the time frame may be time information representing the acquisition of different monitoring data, and specifically may be information representing the order of acquisition.

[0073] In this embodiment, the sub-operation monitoring data may be monitoring data of the target system under various monitoring indicators recorded by each sub-data recording terminal.

[0074] In this embodiment, the data summary library may summarize and organize the sub-operation monitoring data obtained from different sub-data recording terminals.

[0075] The beneficial effect of the above technical solution is: by determining the monitoring indicators for abnormal monitoring of the target system, the sub-data recording end can be accurately and effectively determined through the monitoring indicators, thereby facilitating the accurate and effective acquisition of the sub-operation monitoring data corresponding to each monitoring indicator from the sub-data recording end, and summarizing the obtained sub-operation monitoring data in the data summary library, thereby achieving accurate and effective acquisition of the operation monitoring data of the target system, and providing data support for accurately judging whether there is an abnormality in the system.

[0076] Example 3:

[0077] Based on Example 2, this embodiment provides an operation method of an intelligent decision support and maintenance system, which uploads sub-operation monitoring data corresponding to N sub-data recording terminals to a data summary database, including:

[0078] Acquire multiple first addresses corresponding to each sub-data recording end, and determine the second address corresponding to the data aggregation library. At the same time, establish data upload links between the multiple first addresses and the second addresses, wherein there are multiple data upload links, and the data upload links correspond one-to-one to the sub-data recording ends;

[0079] A corresponding data storage package is set for each data upload link in the data summary library, and the sub-operation monitoring data is uploaded to the corresponding data storage package in the data summary library.

[0080] In this embodiment, the first address may be a communication address corresponding to different sub-data recording terminals.

[0081] In this embodiment, the second address may be a network address corresponding to the characterization data aggregation library.

[0082] In this embodiment, the data storage package may be a data aggregation library that sets a corresponding storage file for each sub-data recording end, thereby storing the sub-operation monitoring data of different sub-data recording ends.

[0083] The beneficial effect of the above technical solution is: by determining the first address and the second address corresponding to the sub-data recording end and the data aggregation library, and based on the first address and the second address, the data upload link between the sub-data recording end and the data aggregation library is accurately and effectively constructed. At the same time, a corresponding data storage package is set for each sub-data recording end in the data aggregation library, so that each sub-operation monitoring data is accurately and reliably stored in the data aggregation library, thereby facilitating timely determination of whether there is an abnormality in the target system, and ensuring the timeliness and accuracy of the operation and maintenance of the target system.

[0084] Example 4:

[0085] Based on Example 1, this embodiment provides an operation method of an intelligent auxiliary decision-making and maintenance system, such as Figure 3 As shown, in step 2, the operation monitoring data is analyzed in real time to determine whether the target system has any abnormal state during operation, including:

[0086] Step 201: Acquire monitoring types for monitoring the operation of the target system, learn the monitoring types and their corresponding features, and construct a data classification model based on the learning results, using each monitoring type as a classification node;

[0087] Step 202: Input the operation monitoring data into the data classification model for category analysis, and output the target operation category corresponding to the operation monitoring data in the data classification model based on the analysis result;

[0088] Step 203: Based on the target operation type corresponding to the operation monitoring data, a corresponding abnormality analysis condition is matched in the abnormality management library, and an abnormality determination is performed on the operation monitoring data corresponding to the target operation type based on the abnormality analysis condition.

[0089] In this embodiment, the types of monitoring for the target system operation monitoring include: system login address monitoring, system login website monitoring, and system operation information monitoring;

[0090] Abnormal analysis conditions correspond to monitoring types one by one, and abnormal analysis conditions include: system login address abnormal analysis conditions, system login website violation analysis conditions, and system illegal information analysis conditions;

[0091] Based on the abnormality analysis conditions, the operation monitoring data corresponding to the target operation type is judged to be abnormal.

[0092] In this embodiment, the monitoring type may be a dimension of monitoring the target system, specifically, monitoring the system login address, the system login website, and the system operation information.

[0093] In this embodiment, the feature may be a type characteristic that characterizes the monitoring category.

[0094] In this embodiment, the classification node may be a basis or standard for classifying the operation monitoring data, and accurate and reliable classification of the operation monitoring data may be achieved based on the classification node.

[0095] In this embodiment, the target operation category may be the monitoring category to which the operation monitoring data belongs, determined after analyzing the operation monitoring data.

[0096] In this embodiment, the anomaly management library is used to store different analysis conditions, including system login anomaly analysis conditions, system login website violation analysis conditions, and system illegal information analysis conditions.

[0097] The beneficial effects of the above technical solution are: by determining the monitoring type of the target system to be monitored, and building a data classification model based on the monitoring type, and inputting the acquired operation monitoring data into the data classification model for analysis and processing, the monitoring type of the operation monitoring data is determined; secondly, through the abnormal analysis conditions in the abnormal management library, it is possible to accurately and effectively determine whether the current operation monitoring data stores abnormalities, thereby facilitating timely matching of corresponding decision-making strategies when abnormalities exist, realizing timely and reliable maintenance of the system, and ensuring the stable operation of the system.

[0098] Example 5:

[0099] Based on Example 4, this embodiment provides an operation method of an intelligent decision support and maintenance system, which performs abnormality determination on operation monitoring data corresponding to a target operation type based on abnormality analysis conditions, including:

[0100] When the target operation type is system login address monitoring, the system login abnormality analysis condition is retrieved from the abnormality management library, and a first abnormality determination is performed on the first operation monitoring data corresponding to the system login address monitoring based on the abnormality analysis condition;

[0101] When the target operation type is system login website monitoring, the system login website violation analysis condition is retrieved from the exception management library, and a second exception determination is performed on the second operation monitoring data corresponding to the system login website monitoring based on the system login website violation analysis condition;

[0102] When the target operation type is system operation information monitoring, the system illegal information analysis condition is retrieved from the abnormality management library, and a third abnormality determination is performed on the second monitoring data corresponding to the system operation information monitoring based on the system illegal information analysis condition.

[0103] In this embodiment, the first operation monitoring data may be a monitoring address for monitoring a system login address;

[0104] The abnormality analysis condition is retrieved from the abnormality management library, and a first abnormality determination is performed on the first operation monitoring data corresponding to the system login address monitoring based on the abnormality analysis condition, including:

[0105] Obtaining a first target monitoring operation data set corresponding to the system login address (referring to a data set for monitoring the system login address), identifying the data address in the first target monitoring operation data set, and determining the target address (including multiple IP addresses) contained in the first target monitoring operation data set;

[0106] Based on big data, crawl abnormal address samples and normal address samples, determine the first sample feature of the abnormal address samples (the first sample feature refers to the address code component feature of the abnormal address) and the second sample feature of the normal address samples (the second sample feature refers to the address code component feature of the normal address);

[0107] Determine a correlation hub between the abnormal address sample and the normal address sample based on the first sample feature and the second sample feature (the correlation hub refers to the common feature portion between the abnormal address sample and the normal address sample);

[0108] Constructing a first evaluation block (features of abnormal addresses), a second evaluation block (features of normal addresses), and a third evaluation block (including both features of abnormal addresses and features of normal addresses) for evaluating address anomalies, wherein the first evaluation block includes first sample features, the second evaluation block includes second sample features, and the third evaluation block includes both first and second sample features;

[0109] Obtaining address features of the target address, and matching the target address with the first evaluation block, the second evaluation block, and the third evaluation block respectively according to the address features of the target address;

[0110] When the address feature of the target address is in the first evaluation block, the target address is determined to be an abnormal address;

[0111] When the address feature of the target address is in the second evaluation block, the target address is determined to be a normal address;

[0112] When the address feature of the target address is in the third assessment block, a risk assessment is performed on the target address based on the associated hub to determine a risk assessment score for the target address (for example, a first similarity between the address feature of the target address and the first sample feature, and a second similarity between the address feature of the target address and the second sample feature may be determined; when the first similarity is greater than the second similarity, the risk assessment score is 1; when the first similarity is equal to the second similarity, the risk assessment score is 2; and when the first similarity is less than the second similarity, the risk assessment score is 3);

[0113] Compare the risk assessment score of the target address with the set assessment threshold (the risk assessment score can be set to 2) to determine whether the target address is an abnormal address;

[0114] Among them, when the risk assessment score of the target address is less than or equal to the set assessment threshold, the target address is determined to be an abnormal address;

[0115] Otherwise, the target address is determined to be a normal address.

[0116] The first evaluation block, the second evaluation block and the third evaluation block are the system login address abnormality analysis conditions.

[0117] The above beneficial effect is that by determining the first evaluation block and the second evaluation block, it is possible to accurately determine whether the login address is an abnormal address. By using the third evaluation block, it is possible to avoid the disadvantage of being unable to judge when encountering an uncertain login address (that is, when it has both the characteristics of an abnormal address and the characteristics of a normal address), thereby achieving accurate identification of the target address.

[0118] In this embodiment, the system login website violation analysis conditions may be: first, determining the website characteristics of the illegal website (the website characteristics may be, for example, the website operation data of the illegal website, or the website page layout of the illegal website, etc.); second, determining that the second operation monitoring data corresponding to the monitored system login website matches the website characteristics of the illegal website; when the website characteristics of the illegal website exist in the second operation monitoring data, the system login website is determined to be in violation; otherwise, the system login website is determined not to be in violation.

[0119] In this embodiment, the system illegal information analysis conditions can be: first, determine the information content of the illegal information; second, determine whether the third operation monitoring data has the same part as the information content of the illegal information; when there is the same part, it is determined that there is illegal information in the system operation information; otherwise, it is determined that there is no illegal information in the system operation information.

[0120] The beneficial effect of the above technical solution is: by determining the monitoring type of operation monitoring, the corresponding abnormality analysis conditions are matched, and an accurate and effective judgment is made on whether the current operation monitoring data stores abnormalities, thereby ensuring the stable operation of the system.

[0121] Example 6:

[0122] Based on Example 5, this embodiment provides an operation method of an intelligent decision support and maintenance system, including:

[0123] When the first abnormality is determined to be abnormal, a first alarm operation is performed;

[0124] When the second abnormality is determined to be abnormal, a second alarm operation is performed;

[0125] When the third abnormality is determined to be abnormal, a third alarm operation is performed.

[0126] In this embodiment, the first alarm operation may be an alarm operation performed on the first abnormality determination, and may specifically be a sound alarm or the like.

[0127] In this embodiment, the second alarm operation can be an alarm operation for the second abnormality determination, specifically a light alarm, etc.

[0128] In this embodiment, the third alarm operation may be an alarm operation performed on the third abnormality determination, and specifically may be a combination of a sound alarm and a light alarm.

[0129] The beneficial effect of the above technical solution is: by performing corresponding alarm operations on the first abnormality judgment, the second abnormality judgment and the third abnormality judgment, it is convenient to make a quick and accurate judgment on the abnormality type according to the alarm type in a timely manner. At the same time, it is convenient to match the target decision according to the alarm operation to realize the operation and maintenance of the target system, thereby improving the timeliness and accuracy of the operation and maintenance of the target system and ensuring the smooth operation of the system.

[0130] Example 7:

[0131] Based on Example 1, this embodiment provides an operation method of an intelligent decision support and maintenance system. In step 3, when an abnormal state occurs in the target system during operation, the abnormal type of the abnormal state is obtained, and the corresponding target decision is matched according to the abnormal type, including:

[0132] Read the abnormal state, determine the abnormal type corresponding to the abnormal state and the target abnormal operation data corresponding to the abnormal state;

[0133] Read the target abnormal operation data to determine the abnormality level of the target system when an abnormal state occurs during operation;

[0134] Match the target-related node in the preset decision network according to the anomaly type, and match the corresponding target-related sub-node in the target-related node according to the degree of anomaly;

[0135] Read the decision data corresponding to the target associated sub-node and generate the target decision based on the decision data.

[0136] In this embodiment, the abnormal operation data may be a data segment of an abnormal portion in the operation monitoring data.

[0137] In this embodiment, the degree of abnormality can be the severity of the abnormality when the target system occurs. For example, when the system login address is monitored, when the number of abnormal IP addresses in the monitored IP addresses is greater than the set number, the degree of abnormality is determined to be high; when the number of abnormal IP addresses in the monitored IP addresses is equal to the set number, the degree of abnormality is determined to be medium; when the number of abnormal IP addresses in the monitored IP addresses is less than the set number, the degree of abnormality is determined to be low, where the set number can be half of the number of monitored IP addresses.

[0138] In this embodiment, the preset decision network can be a decision network that uses the exception type (system login address exception, system login website violation, system illegal information) as a node and the different abnormality levels corresponding to each exception type as sub-nodes. It is set in advance and is used to match the target decision corresponding to the exception type and the abnormality level corresponding to the exception type. The preset decision network includes auxiliary decisions for handling each exception type, and different sub-auxiliary decisions corresponding to the auxiliary decision are determined according to the abnormality level. The sub-auxiliary decisions corresponding to the auxiliary decision can be obtained through the Internet and empirical data on the handling of the system's abnormal state.

[0139] In this embodiment, the target associated node may be a node associated with the abnormality type in a preset decision network.

[0140] In this embodiment, the target-associated sub-node may be a node in a preset decision network that is attached to the target-associated node and matches the abnormality level, wherein the target-associated sub-node contains decision data corresponding to the abnormality type and related to the abnormality level.

[0141] The beneficial effect of the above technical solution is: by determining the abnormality type and degree of the target system, the target associated node and the target associated sub-node corresponding to the target key node can be accurately determined, thereby achieving accurate confirmation of the decision data, thereby improving the accuracy of the target decision acquisition, and is conducive to ensuring the maintenance efficiency of the system.

[0142] Example 8:

[0143] Based on Example 1, this embodiment provides an operation method of an intelligent decision-making support and maintenance system. In step 3, abnormal conditions in the target system are handled based on the target decision to implement operation and maintenance of the target system, including:

[0144] Determine a disposal strategy for abnormal states in the target system based on the target decision, and convert the disposal strategy into a policy text;

[0145] Read the policy text, determine the logical keywords, and determine the target execution process of the disposal policy according to the logical keywords. At the same time, generate the target execution instruction according to the target execution process, wherein the target execution instruction includes: a first execution instruction and a second execution instruction;

[0146] Dealing with abnormal conditions in the target system in real time based on the first execution instruction, and monitoring the execution process based on the second instruction and obtaining monitoring results;

[0147] Among them, when the monitoring results reach the target standard, the operation and maintenance of the target system are completed.

[0148] In this embodiment, the handling strategy may be a specific execution process of the target decision to handle the abnormal state in the target system.

[0149] In this embodiment, the policy text may be a text that can be recognized by a machine corresponding to the handling policy.

[0150] In this embodiment, the logic keyword may be an execution relationship of the processing strategy, including: or, and, not, and-or, exclusive-or, etc.

[0151] In this embodiment, the target execution process may be a standard execution process composed of each execution step in the processing strategy.

[0152] In this embodiment, the first execution instruction may be an instruction for handling an abnormal state in the target system.

[0153] In this embodiment, the second execution instruction may be used to monitor the execution process of handling the abnormal state.

[0154] In this embodiment, the monitoring result includes: the execution steps of handling the abnormal state in the target system and the execution progress of handling the abnormal state in the target system;

[0155] The target standards include: the first target standard and the second target standard;

[0156] The first target criterion is that when the execution steps for handling the abnormal state in the target system are consistent with the target execution steps, it is determined that the first target criterion is met (the execution steps can be the execution process obtained by real-time monitoring when handling the abnormal state, and the target execution process is the standard execution process composed of each execution step, and the two are not the same);

[0157] The second target standard is that when the execution progress of handling the abnormal state in the target system reaches the target progress (the execution progress is the progress of real-time handling, and the target progress can be the total progress of completing the handling of the abnormal state based on the target decision), it is determined that the second target standard is reached.

[0158] The beneficial effects of the above technical solution are: by determining the target execution instructions, the abnormal state in the target system can be accurately handled, and accurate monitoring during the execution process can be achieved, thereby improving the accuracy of execution, and facilitating the precise control of the execution process, thereby improving the controllability of system maintenance.

[0159] Example 9:

[0160] On the basis of Example 1, step 2 further includes:

[0161] Obtaining historical operation monitoring data for operation monitoring of the target system, and respectively determining, in the historical operation monitoring data, a first data volume of analyzing normal data into normal data, a second data volume of analyzing the normal data into abnormal data, a third data volume of analyzing the abnormal data into abnormal data, and a fourth data volume of analyzing the abnormal data into normal data after analyzing the historical operation monitoring data;

[0162] Establishing an accurate evaluation model for analyzing the operation monitoring data based on the first data amount, the second data amount, the third data amount, and the fourth data amount;

[0163]

[0164] Wherein, M represents the accurate evaluation model when analyzing the operation monitoring data; S1 represents the first data volume; S2 represents the second data volume; S3 represents the third data volume; S4 represents the fourth data volume; ω represents the analysis error rate of the historical operation monitoring data; μ represents the omission rate of the historical operation monitoring data; δ1 represents the first influencing factor of the analysis error rate on the accurate evaluation model, and the value range is (0.02, 0.03); δ2 represents the second influencing factor of the omission rate on the accurate evaluation model;

[0165] Based on the accuracy evaluation model, determine the amount of data for accurate analysis of the target system's operation monitoring data, and determine the accuracy of the analysis of the operation monitoring data based on the amount of data for accurate analysis of the operation monitoring data

[0166] Where ρ represents the analysis accuracy; a represents the amount of accurate analysis of the target system's operation monitoring data; A represents the total amount of operation monitoring data of the target system;

[0167] Compare the analysis accuracy with the accuracy threshold to determine whether the analysis of the operation monitoring data is qualified;

[0168] When the analysis accuracy is equal to or greater than the accuracy threshold, the analysis of the operation monitoring data is determined to be qualified;

[0169] Otherwise, the analysis of the operation monitoring data is determined to be unqualified, and when the analysis of the operation monitoring data is unqualified, the analysis of the operation monitoring data is optimized, and the operation monitoring data of the target system is re-analyzed after the optimization.

[0170] In this embodiment, general operation monitoring data is stored in the operation data management database, so the historical operation monitoring data may be a section of operation monitoring data randomly extracted from the operation management database and analyzed.

[0171] In this embodiment, the accuracy threshold may be set in advance and used as a standard to measure whether the analysis of the operation monitoring data is qualified.

[0172] The beneficial effects of the above technical solution are: by establishing an accurate evaluation model, the amount of data for accurate analysis of the operation monitoring data of the target system can be effectively determined, and then the analysis accuracy of the operation monitoring data can be determined, and by comparing the analysis accuracy with the accuracy threshold, the qualification of the analysis of the operation monitoring data can be objectively measured, thereby improving the accuracy and objectivity of the analysis and evaluation, effectively evaluating the rationality of the analysis of the operation monitoring data, and indirectly improving the accuracy of auxiliary decision-making.

[0173] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A method for operating an intelligent decision-making support and maintenance system, characterized in that: include: Step 1: Monitor the operation of the target system and determine the operation monitoring data of the target system; Step 2: Analyze the operation monitoring data in real time to determine whether the target system has any abnormal status during operation; Step 3: When an abnormal state occurs in the target system during operation, the abnormal state type is obtained, and the corresponding target decision is matched according to the abnormal type. The abnormal state in the target system is handled based on the target decision to achieve operation maintenance of the target system; In step 2, the operation monitoring data is analyzed in real time to determine whether the target system has any abnormal state during operation, including: Obtain the monitoring types for the target system's operation monitoring, learn the monitoring types and their corresponding features, and construct a data classification model based on the learning results, using each monitoring type as a classification node; Input the operation monitoring data into the data classification model for category analysis, and output the target operation category corresponding to the operation monitoring data in the data classification model based on the analysis results; Based on the target operation type corresponding to the operation monitoring data, the corresponding abnormality analysis conditions are matched in the abnormality management library, and the operation monitoring data corresponding to the target operation type is judged to be abnormal based on the abnormality analysis conditions.

2. The method for operating an intelligent decision-making support and maintenance system according to claim 1, characterized in that: In step 1, the target system is monitored for operation and the target system's operation monitoring data is determined, including: Obtain N monitoring indicators for abnormal monitoring of the target system, and set N sub-data recording terminals according to the N monitoring indicators; Based on the sub-data recording end, the monitoring data corresponding to the monitoring indicator is recorded in sequence according to the time frame, and the sub-operation monitoring data corresponding to each sub-data recording end is determined; A data summary database is obtained, and the sub-operation monitoring data corresponding to the N sub-data recording terminals are uploaded to the data summary database, and the operation monitoring data of the target system is determined in the data summary database.

3. The method for operating an intelligent decision-making support and maintenance system according to claim 2, characterized in that: Upload the sub-operation monitoring data corresponding to N sub-data recording terminals to the data summary library, including: Acquire multiple first addresses corresponding to each sub-data recording end, and determine the second address corresponding to the data aggregation library. At the same time, establish data upload links between the multiple first addresses and the second addresses, wherein there are multiple data upload links, and the data upload links correspond one-to-one to the sub-data recording ends; A corresponding data storage package is set for each data upload link in the data summary library, and the sub-operation monitoring data is uploaded to the corresponding data storage package in the data summary library.

4. The method for operating an intelligent decision-making support and maintenance system according to claim 1, characterized in that: include: The types of monitoring for target system operation monitoring include: system login address monitoring, system login website monitoring, and system operation information monitoring; Abnormal analysis conditions correspond to monitoring types one by one, and abnormal analysis conditions include: system login address abnormal analysis conditions, system login website violation analysis conditions, and system illegal information analysis conditions; Based on the abnormality analysis conditions, the operation monitoring data corresponding to the target operation type is judged to be abnormal.

5. The method for operating an intelligent decision-making support and maintenance system according to claim 4, characterized in that: Based on the abnormal analysis conditions, the operation monitoring data corresponding to the target operation type is judged as abnormal, including: When the target operation type is system login address monitoring, the system login abnormality analysis condition is retrieved from the abnormality management library, and a first abnormality determination is performed on the first operation monitoring data corresponding to the system login address monitoring based on the abnormality analysis condition; When the target operation type is system login website monitoring, the system login website violation analysis condition is retrieved from the exception management library, and a second exception determination is performed on the second operation monitoring data corresponding to the system login website monitoring based on the system login website violation analysis condition; When the target operation type is system operation information monitoring, the system illegal information analysis condition is retrieved from the abnormality management library, and a third abnormality determination is performed on the second monitoring data corresponding to the system operation information monitoring based on the system illegal information analysis condition.

6. The method for operating an intelligent decision-making support and maintenance system according to claim 5, characterized in that: include: When the first abnormality is determined to be abnormal, a first alarm operation is performed; When the second abnormality is determined to be abnormal, a second alarm operation is performed; When the third abnormality is determined to be abnormal, a third alarm operation is performed.

7. The method for operating an intelligent decision-making support and maintenance system according to claim 1, characterized in that: In step 3, when an abnormal state occurs in the target system during operation, the abnormal type of the abnormal state is obtained, and the corresponding target decision is matched according to the abnormal type, including: Read the abnormal state, determine the abnormal type corresponding to the abnormal state and the target abnormal operation data corresponding to the abnormal state; Read the target abnormal operation data to determine the abnormality level of the target system when an abnormal state occurs during operation; Match the target-related node in the preset decision network according to the anomaly type, and match the corresponding target-related sub-node in the target-related node according to the degree of anomaly; Read the decision data corresponding to the target associated sub-node and generate the target decision based on the decision data.

8. The method for operating an intelligent decision-making support and maintenance system according to claim 1, characterized in that: In step 3, the abnormal state in the target system is handled based on the target decision to achieve the operation and maintenance of the target system, including: Determine a disposal strategy for abnormal states in the target system based on the target decision, and convert the disposal strategy into a policy text; Read the policy text, determine the logical keywords, and determine the target execution process of the disposal policy according to the logical keywords. At the same time, generate the target execution instruction according to the target execution process, wherein the target execution instruction includes: a first execution instruction and a second execution instruction; Dealing with abnormal conditions in the target system in real time based on the first execution instruction, and monitoring the execution process based on the second instruction and obtaining monitoring results; Among them, when the monitoring results reach the target standard, the operation and maintenance of the target system are completed.

9. The method for operating an intelligent decision-making support and maintenance system according to claim 8, characterized in that: include: The monitoring results include: the execution steps for handling the abnormal state in the target system and the execution progress of handling the abnormal state in the target system; The target standards include: the first target standard and the second target standard; The first target standard is that when the execution steps for handling the abnormal state in the target system are consistent with the target execution steps, it is determined that the first target standard is met; The second target standard is that when the execution progress of handling the abnormal state in the target system reaches the target progress, it is determined that the second target standard is met.

Citation Information

Patent Citations

  • Power grid abnormal information intelligent alarming and assistant decision-making method

    CN105139158A