A blockchain system anomaly detection method and device, a terminal and a storage medium
By aggregating data based on identifiers in the blockchain system, the accuracy and efficiency issues of anomaly detection in the blockchain system are solved, and more efficient anomaly detection is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HANGZHOU QULIAN TECHNOLOGY CO LTD
- Filing Date
- 2023-04-27
- Publication Date
- 2026-04-10
AI Technical Summary
Existing technologies for anomaly detection in blockchain systems suffer from low accuracy, high false alarm rate, and low computational efficiency.
By obtaining the association information of blocks from various nodes in the blockchain system and using identifiers to aggregate data, abnormal node behavior can be identified.
It improves the accuracy of anomaly detection, increases computational efficiency, and reduces the false alarm rate.
Smart Images

Figure CN116582310B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of blockchains, and particularly relates to a blockchain system anomaly detection method and device, a terminal and a storage medium. BACKGROUND
[0002] As a distributed ledger technology, the security and decentralization features of blockchains have been widely recognized. However, blockchain networks still face various threats and challenges, such as 51% attacks, transaction double spending, smart contract vulnerabilities, etc. For consortium chains, there are possible attack points such as malicious attacks by Byzantine fault-tolerant nodes and vulnerabilities in node implementation, which result in the inability to guarantee the security of the blockchain network and the abnormality of the nodes on the blockchain.
[0003] At present, many blockchain system anomaly detection methods and technologies based on data analysis and mining have been proposed. These methods mainly find abnormal patterns and rules in the blockchain system to detect abnormal transactions and behaviors. However, due to the complexity and diversity of data in the blockchain system, this method often has problems such as low accuracy, high false positive rate, and low computational efficiency. SUMMARY
[0004] The embodiments of the application provide a blockchain system anomaly detection method, device, terminal and storage medium to solve the problems of low detection accuracy, high false positive rate and low computational efficiency of the blockchain system anomaly in the prior art.
[0005] The first aspect of the embodiments of the application provides a blockchain system anomaly detection method, comprising:
[0006] Obtaining association information of blocks from each node in a first blockchain system, each association information containing an identifier, and the identifiers in the association information of the same block being the same or corresponding;
[0007] Based on the identifier, the association information is aggregated according to the blocks to obtain aggregated data corresponding to different blocks respectively;
[0008] Based on the aggregated data, determining the abnormal behavior of the nodes in the first blockchain system.
[0009] The second aspect of the embodiments of the application provides a blockchain system anomaly detection device, comprising:
[0010] An obtaining module is configured to obtain association information of blocks from each node in a first blockchain system, each association information containing an identifier, and the identifiers in the association information of the same block being the same or corresponding;
[0011] aggregating the association information according to blocks based on the identifier, to obtain aggregated data corresponding to different blocks respectively;
[0012] determining module, configured to determine the abnormal behavior of the node in the first block chain system based on the aggregated data.
[0013] A third aspect of the embodiment of the present application provides a terminal, including a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the steps of the method according to the first aspect when executing the computer program.
[0014] A fourth aspect of the embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the computer program is executable by a processor to implement the steps of the method according to the first aspect.
[0015] A fifth aspect of the present application provides a computer program product, which, when executed on a terminal, causes the terminal to perform the steps of the method according to the first aspect.
[0016] As can be seen from the above, based on the association information of the blocks obtained from each node in the block chain system, the association information is aggregated according to the blocks by means of the identifier, and then the abnormal behavior of the node in the block chain system is determined based on the aggregated data, so that when facing complex and diverse data in the block chain system, the data can be integrated in the granularity of blocks, and effective anomaly detection can be carried out based on the integrated data, the accuracy of anomaly detection is improved, the computing efficiency is improved, and the false positive rate is reduced. BRIEF DESCRIPTION OF DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0018] Figure 1 is a flow of a block chain system anomaly detection method provided by the embodiment of the present application Figure 1 ;
[0019] Figure 2 is a flow of a block chain system anomaly detection method provided by the embodiment of the present application Figure 2 ;
[0020] Figure 3 is a structural diagram of a block chain system anomaly detection device provided by the embodiment of the present application
[0021] Figure 4 Figure 1 is a block diagram of a terminal according to an embodiment of the present application. DETAILED DESCRIPTION
[0022] In the following description, for purposes of explanation and not limitation, specific details are set forth, such as particular architectures, techniques, etc., in order to provide a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application can be practiced in other embodiments that depart from these specific details. In other instances, detailed descriptions of well-known methods, devices, circuits, and
[0023] It is to be understood that the terminology "includes", "has", "holds", "contains" and / or "comprising", when used in this specification and in the following claims, indicates the presence of the described features, integers, steps, operations, elements, and / or components but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0024] It is also to be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting. As used in this specification and the appended claims, the singular forms "a", "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0025] It will be further understood that the terms "and", "or", as used herein, and in the following claims are used to mean one and / or the other and / or both in exclusive disjunction or in inclusive disjunction, as context permits.
[0026] As used in this specification and claims, the terms "if' and "when" can be interpreted to mean "upon determination" or "in response to a determination" or "upon detection" or "in response to a detection" depending on the context. Similarly, the phrase "if determined" or "if detected" can be interpreted to mean "upon determination" or "in response to a determination" or "upon detection" or "in response to a detection" depending on the context.
[0027] In particular implementations, the terminal described in the embodiments of the present application includes, but is not limited to, other portable devices such as mobile telephones, laptop computers, or tablet computers with touch-sensitive surfaces (e.g., touch screen displays and / or touch pads). It will be appreciated that, in certain embodiments, the device is not a portable communication device, but rather a desktop computer with a touch-sensitive surface (e.g., a touch screen display and / or a touch pad).
[0028] In the following discussion, a terminal including a display and a touch-sensitive surface is described. It should be appreciated, however, that a terminal can include one or more other physical user-interface devices, such as a physical keyboard, a mouse, and / or a joystick.
[0029] The terminal supports a variety of applications, such as one or more of the following: a drawing application, a presentation application, a word processing application, a website creation application, a disk authoring application, a spreadsheet application, a game application, a telephone application, a video conferencing application, an e-mail application, an instant messaging application, a workout support application, a photo management application, a digital camera application, a digital camcorder application, a web browsing application, a digital music player application, and / or a digital video player application.
[0030] The various applications that can be executed on the terminal can use at least one common physical user-interface device, such as a touch-sensitive surface. One or more functions of the touch-sensitive surface, as well as the corresponding information displayed on the terminal, can be adjusted and / or changed between applications and / or within respective applications. By way of example, the
[0031] It should be understood that the sequence of the steps in the embodiments does not mean the order of execution, the execution order of the processes should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0032] Before the embodiments of the present application are explained and supplemented, the following description of the related content of the blockchain is required.
[0033] The blockchain system is a system for sharing data between nodes, and the blockchain system includes a plurality of nodes and servers. The nodes store data generated by transactions with the blockchain system or other nodes, and the data on the nodes is consensus data after the consensus algorithm. The blockchain system is a computer technology that has distributed data storage, peer-to-peer transmission, consensus mechanism, encryption algorithm and other mechanisms. In general, it is a distributed shared ledger and database. The server can analyze and store the consensus data output by the node.
[0034] In the embodiments of the present application, due to network attacks or network threats suffered by some nodes on the blockchain system, the blockchain system or other nodes cannot receive the data sent by these nodes, which causes the blockchain system to be abnormal, and even causes the negative result of the blockchain system to be paralyzed. In order to avoid this phenomenon, the embodiments of the present application provide a blockchain anomaly detection method.
[0035] To more specifically illustrate the technical solutions described in the present application, the following will be described by specific examples.
[0036] Referring to Figure 1 , Figure 1 is a flow of a blockchain system anomaly detection method provided by an embodiment of the present application Figure 1 . As shown in Figure 2 , a blockchain system anomaly detection method includes the following steps:
[0037] Step 101, obtaining association information of a block from each node in a first blockchain system.
[0038] Each association information contains an identifier, and the identifiers in the association information of the same block are the same or corresponding.
[0039] The corresponding relationship between the association information of the block and the block is that multiple consensus data are generated when the nodes in the blockchain system perform block consensus, and the corresponding information corresponding to each consensus data is the association information, for example, index data, log data, tracking data, etc.
[0040] Specifically, the nodes in the first blockchain system trigger a consensus mechanism for one or more transactions, and generate data blocks corresponding to the one or more transactions, and the generated blocks have different association information in the consensus process.
[0041] The identifiers contained in the multiple association information of the block can be the same, or the identifiers contained in the multiple association information of the block have a corresponding relationship. Otherwise, if the identifiers in the two association information do not have the same or corresponding relationship, it indicates that the two association information do not correspond to the same block.
[0042] For example, when the nodes in the first blockchain system generate a block, an identifier data corresponding to the block is set, which can be TraceID, and in the same block, the identifiers in the association information are set as TraceID or corresponding identifier data of TraceID, and the different association information corresponding to the same block can be determined according to the identifier.
[0043] The block described above can be a generated block or a to-be-generated block. The block is used as the information aggregation granularity to achieve the aggregation processing of the multiple and complex information in the blockchain system.
[0044] The identifier can be obtained by setting an identification bit in the association information and assigning a value to the identification bit. The identifier is, for example, ID information such as block number or block name.
[0045] Specifically, when the first blockchain system generates a block corresponding to one or more transactions, a consensus algorithm is called, and each node on the first blockchain system generates associated information corresponding to the consensus algorithm.
[0046] The associated information is specifically information data generated in the process of each node in the blockchain system executing the consensus algorithm to generate a data block corresponding to one or more transactions.
[0047] In one example, the associated information includes indicator data, log data, and tracking data.
[0048] Each node in the blockchain system locally stores indicator data, log data, and tracking data corresponding to the block. Based on the associated information stored in each node, data aggregation is performed according to different information data dimensions included in the associated information. In subsequent node anomaly analysis, multi-dimensional data content in the associated data can be comprehensively analyzed, and therefore it is necessary to ensure that other data associated with each dimension can be found through the data on each dimension.
[0049] The indicator data is, for example, performance indicator data (such as memory usage, CPU resource usage, etc.), efficiency indicator data (time consumption, data processing rate, etc.), and the like.
[0050] The log data records data processing logs recorded by each node in the data consensus process.
[0051] The tracking data records the transmission path of the node interaction information in the consensus process. The tracking data is used to track the consensus processing process of a block.
[0052] That is, the associated information of the block is obtained from each node in the first blockchain system, including:
[0053] The indicator data, log data, and tracking data associated with different blocks in each node in the first blockchain system are collected.
[0054] The indicator data, log data, and tracking data include identifiers, and the identifiers in the indicator data, log data, and tracking data of the same block are the same or corresponding.
[0055] Specifically, in one implementation process, the execution subject of the anomaly detection method in this embodiment can be a server node set independently of the first blockchain system. That is, the server node is independent of each node in the blockchain system. Each node in the blockchain system reports the associated information recorded by itself to the server node, and the server node implements data aggregation processing and anomaly detection of the blockchain node.
[0056] Among them, different software needs to be installed in each node in the blockchain system to support the implementation of consensus mechanism observability.
[0057] For example, each node in the blockchain system is based on the Golang SDK software, namely metrics SDK, and the consensus data is pulled by the monitoring software Prometheus to obtain the index data; the nodes in the first blockchain system adjust the logs to standard output to obtain the log data, and install and configure the proxy software Promtail on each node, so that each node pushes the log data to the corresponding main server Loki of the server node independent of the first blockchain system, and the main server Loki is responsible for storing logs and processing queries and other work; through the open source project OpenTelemetry SDK on each node of the first blockchain system, the tracing data generated by the nodes of the first blockchain system in the process of generating blocks based on one or more transaction execution consensus algorithms is sent to the distributed tracking backend Grafana Tempo of the server node, that is, the associated data corresponding to the consensus data of the block includes three aspects of indexes, logs and traces, so that the indexes, logs and traces are formed in each node of the first blockchain system, and the indexes, logs and traces correspond to each other, specifically, the traces correspond to the logs and indexes, and the identifiers in these data contain the same identifiers of the logs, indexes and traces corresponding to the same block, based on the identifiers, the complex and numerous associated information of the consensus data can be sorted out to realize data aggregation at the block granularity.
[0058] Among them, for example, the index data is used to represent the status of the nodes on the blockchain system, indicating the health status and performance of the nodes, specifically the collected indexes and statistical data of each aspect of the first blockchain system, such as CPU usage, memory occupancy, network traffic, query rate per second QPS, for example, CPU usage is 80%, memory occupancy is 60%, so as to evaluate the system health status and performance; the index data has multiple sources, including infrastructure equipment, application programs, hosts, servers, cloud platforms and other external sources, etc.
[0059] Differently, the log data is used to record the events and log information generated by the nodes on the blockchain system at runtime, specifically the structured or unstructured text record data of discrete events occurring at a specific time, including errors, warnings, exceptions, operations and states, etc., so as to find problems and trace back history, for example, when the application program in the blockchain system records the user login event, it will generate a log data: [2023-03-10T15:04:48.157][INFO]User“johndoe”has logged in.
[0060] Optionally, the log data can be structured or unstructured; the structured data has corresponding first identification information, and the unstructured data has second identification information, wherein the first identification information and the second identification information are different.
[0061] Unlike other methods, trace data is used to track the process of a request or event being invoked by nodes in a blockchain system, including the services, components, and network requests it passes through. The data generated during this process is trace data, used to diagnose and optimize system performance. For example, in a blockchain system using the PBFT (Practical Byzantine Fault Tolerance) algorithm, the master node initiates the consensus process for a block using the sendPreprepare method. Internally, this method calls the recvPreprepare method of other nodes via RPC, and these other nodes then call the sendPrepare method, proceeding to the next step of the consensus process. By tracing the call process of this block request between different nodes, trace data is generated. Users can view this trace data on a display device to identify performance issues and errors.
[0062] When performing data aggregation, the aggregation process is carried out on the three different data content dimensions mentioned above, based on the identifiers contained in different data content in the related information and at the block level.
[0063] Step 102: Based on the identifier, the associated information is aggregated according to the blocks to obtain aggregated data corresponding to different blocks.
[0064] The server aggregates the associated information based on whether the identifiers contained in multiple pieces of related information have the same or corresponding relationship, thus obtaining aggregated data.
[0065] During aggregation, based on identifiers, association information corresponding to the same block is grouped together from a large amount of complex association information. Optionally, the association information corresponding to the same block can be divided into the same dataset, forming a dataset obtained after data aggregation processing at the block level. Subsequent anomaly detection analysis can then be carried out based on the data within this dataset, ensuring the effectiveness and accuracy of anomaly detection.
[0066] For example, when it is detected that the identifiers contained in the multiple pieces of associated information are the same, such as TraceID, or correspond to each other, such as TraceID and &TraceID corresponding to TraceID, it is determined that the multiple pieces of associated information correspond to the same block, and the server node divides the multiple pieces of consensus data into the same data set to realize data aggregation.
[0067] Further, in one example, after the associated information is aggregated according to the blocks based on the identifiers to obtain aggregated data corresponding to different blocks respectively, the method further includes:
[0068] The aggregated data is visually displayed through a display panel.
[0069] Specifically, a Grafana display panel can be arranged in the server node to visually display the aggregated data.
[0070] At step 103, based on the aggregated data, the abnormal behavior of the node in the first blockchain system is determined.
[0071] In the blockchain system, different blockchain nodes generate log data, index data, trace data, etc. associated with the consensus process of a block during the consensus process of the block. The associated data generated by different blockchain nodes during the consensus process of the same block is different. That is, the aggregated data contains associated information of blocks sent by different blockchain nodes, and there are some data differences between the contents of the associated information corresponding to the same block. Therefore, in this step, the aggregated data is used to determine the abnormal behavior of the node in the blockchain system.
[0072] Specifically, when the aggregated data is used to determine the abnormal behavior of the node in the first blockchain system, the determination of the abnormal behavior of the node can be performed by the server node itself, that is, the server node directly analyzes the aggregated data to determine the abnormal behavior of the node.
[0073] Alternatively, the determination of the abnormal behavior of the node can be performed by outputting the aggregated data obtained by aggregation to other service nodes for data analysis to determine the abnormal behavior of the node. In one example, the other service nodes are nodes in other blockchain systems outside the first blockchain system, or a service node independent of the server node executing the method.
[0074] In one aspect, when the server node directly analyzes the aggregated data to determine the node abnormal behavior, the server node can determine, based on the aggregated data, what associated information each of the different blockchain nodes generates in the consensus process for the same block, and perform data analysis based on the associated information from the different blockchain nodes and corresponding to the same block to determine the possible node abnormal behavior in the blockchain system.
[0075] After determining the node abnormal behavior, a repair scheme corresponding thereto can be determined, and indication information can be sent to indicate that the node abnormal repair processing is performed according to the repair scheme.
[0076] In actual application, the corresponding determination process and repair scheme of the node abnormal behavior exist in the following cases:
[0077] First, the aggregated data lacks the associated information of a certain blockchain node, and no data interaction record of the node is found after data searching and analysis based on the associated information such as log data sent by other blockchain nodes, so it can be considered that the node is down or disconnected.
[0078] After determining the node abnormal behavior, corresponding abnormal handling operation needs to be performed. In the above case, indication information can be output to instruct the maintenance personnel to make the down or disconnected node resume operation as soon as possible to perform consensus processing, or delete the node to avoid too many failed nodes in the node cluster of the blockchain system to cause the consensus progress to be unable to proceed.
[0079] Second, the aggregated data lacks the associated information of a certain blockchain node, but the track determined based on the log data and trace data in the associated information of other blockchain nodes can find that the node sends network messages to other nodes, so it can be considered that the node only fails to upload the data for performing abnormal detection. At this time, the node should be urged to upload the associated data to avoid the possible hidden malicious operation behavior of the node.
[0080] Third, the associated data from different nodes in the aggregated data is compared, and it is found that there is conflict data (for example, the log data of a certain node does not match or is opposite to the log data of other nodes) between the associated data of some nodes and the associated data of other nodes, or some nodes omit information to other nodes, delete internal variable information and other behaviors, so it is determined that the nodes have node abnormal behavior. It is indicated that these nodes can be Byzantine nodes. When the Byzantine nodes are enough, the consensus state of the blockchain system will be damaged, and corresponding punishment measures need to be determined for abnormal repair processing, for example, sending indication information to instruct the maintenance personnel to make punishment measures based on the found Byzantine behavior of the nodes, such as removing the node from the blockchain system.
[0081] Fourth, based on the aggregated data, it is detected that a node in the blockchain system has not successfully communicated with other nodes for a long time, and it is determined that the node has abnormal behavior.
[0082] Specifically, based on the associated information from different nodes in the aggregated data, the trace data and log data can be compared. If it is found that a node in the blockchain system has not successfully communicated with other nodes for a long time, it is determined that the network of the node has failed. At this time, an indication information can be sent to indicate the maintenance personnel to repair the network, so as to avoid the speed of node consensus in the blockchain system being affected.
[0083] On the other hand, when the aggregated data is analyzed by a service node other than the server node to determine the abnormal behavior of the node, in one embodiment, based on the aggregated data, the abnormal behavior of the node in the first blockchain system is determined, including:
[0084] The server node outputs an abnormal analysis instruction based on the aggregated data to the target node.
[0085] Among them, the target node is one or more nodes in the second blockchain system.
[0086] The abnormal analysis instruction carries the aggregated data, and the abnormal analysis instruction is used to instruct the target node to store the aggregated data in the second blockchain system and instruct the target node to analyze the abnormal behavior of the node in the first blockchain system based on the aggregated data.
[0087] Specifically, the second blockchain system is a blockchain system with data storage function and supporting Turing complete smart contract, and the second blockchain system is a server node cluster independent of the first blockchain system. The two blockchain systems can interact with each other. Based on the associated data corresponding to the blocks sent by each node in the first blockchain system, the aggregated data is aggregated and sent to the target node in the second blockchain system with the abnormal analysis instruction, so that the target node in the second blockchain system executes the abnormal analysis instruction based on the smart contract, and stores the aggregated data in the chain, retains the evidence, and analyzes the abnormal behavior of the node in the blockchain system based on the aggregated data, improves the non-tamperability of data processing, and improves the reliability of abnormal analysis.
[0088] Further, in the process of determining the abnormal behavior of the node in the first blockchain system based on the aggregated data, whether it is implemented by the server node or by the target node in the second blockchain system, the analysis of the aggregated data can be implemented by means of the abnormal analysis program to determine the abnormal behavior of the node.
[0089] In one example, the anomaly analyzer is composed of a rule engine and a set of rule scripts. Each rule script follows a fixed syntax and contains multiple fields, such as name, event source, rule body, etc.
[0090] The rule scripts can be triggered by various event sources, such as a timer trigger, a remote procedure call made by a blockchain node, a block in the blockchain reaching a certain block height, etc.
[0091] The rule engine analyzes the aggregated data, extracts the events that have occurred, and calls the rule script corresponding to the execution of the event to analyze the corresponding node abnormal behavior.
[0092] Correspondingly, in combination with Figure 3 As shown in FIG. 1, based on the aggregated data, the node abnormal behavior in the first blockchain system is determined, including:
[0093] In step 201, based on the identifier, the target association information corresponding to the target block is extracted from the aggregated data.
[0094] The aggregated data contains association information corresponding to each block. Here, a set of association information corresponding to the target block needs to be extracted in units of blocks for node anomaly analysis and processing.
[0095] In step 202, based on the target association information, the node processing event in the first blockchain system is determined.
[0096] The node processing event is specifically a processing event that occurs in each node during the process of generating a block in the blockchain system based on one or more transactions after the node consensus based on one or more transactions reaches a consensus among nodes.
[0097] Since the target association information is related to the target block, the node processing event corresponding to the target block in the first blockchain system can be determined based on the association information.
[0098] The node processing event is, for example, a node interaction event of consensus data during the node consensus process, a data addition, deletion, or modification event corresponding to a transaction, etc.
[0099] In step 203, a target rule script matching the node processing event is selected from a plurality of pre-written rule scripts.
[0100] Each of the pre-written rule scripts corresponds to an abnormality detection rule of a node processing event.
[0101] In the implementation process, a plurality of rule scripts are pre-written, and the plurality of rule scripts are all written according to a fixed abnormality detection rule.
[0102] In step 204, the target rule script is executed to obtain a node anomaly detection result of the node processing event.
[0103] The target rule script corresponding to the node processing event is executed to find out the corresponding node abnormal behavior, thereby improving the processing efficiency of the abnormal behavior detection and the flexibility of the abnormal behavior detection in the face of complex and diverse data.
[0104] Further, as an example, in the process of determining the node abnormal behavior in the first blockchain system based on the aggregated data, whether implemented by the server node or the target node in the second blockchain system, whether with the help of the abnormal analysis program to analyze the aggregated data, in the case where the association information contains the block-associated indicator data, log data and tracking data, the implementation principle of the abnormal analysis based on the aggregated data can be the following processing process.
[0105] Specifically, determining the node abnormal behavior in the first blockchain system based on the aggregated data comprises:
[0106] Based on the first tracking data in the aggregated data, a plurality of target nodes corresponding to the same block are determined.
[0107] Based on the identifier, the target log data and the target indicator data corresponding to the first tracking data in the plurality of target nodes are determined.
[0108] Based on the target log data and the target indicator data, the node abnormal behavior is determined from the plurality of target nodes.
[0109] Since the aggregated data contains association information from different nodes, the transfer path of the node interaction information in the consensus mechanism processing process corresponding to each blockchain node can be determined based on the tracking data in the aggregated data, i.e., the plurality of target nodes corresponding to the same block.
[0110] Further, since the indicator data, log data and tracking data associated with a block have the same or corresponding identifier, the target log data and the target indicator data corresponding to the first tracking data in the plurality of target nodes can be determined based on the identifier. Further, the log data and the indicator data from different target nodes are compared and analyzed to determine the node abnormal behavior.
[0111] In one example, based on the target log data and the target indicator data, the node abnormal behavior is determined from the plurality of target nodes, comprising:
[0112] The target log data and the target indicator data in different target nodes are compared to obtain a comparison result.
[0113] In a case where it is determined based on the comparison result that there is conflict data in the plurality of target nodes, based on the conflict data, the node abnormal behavior is determined.
[0114] Wherein, the conflict data can be confirmed to come from which nodes and from which data items, the conflict data can be verified based on the data content of the same data item recorded in other nodes before the source node, to find out the problem node of the conflict data verified as problem data from the source node, and confirm the abnormal behavior of the problem node in the problem data in the problem node.
[0115] The above implementation process is based on the association information of the blocks obtained from each node in the blockchain system, and the association information is aggregated according to the blocks by means of the identifiers, and then based on the aggregated data, the node abnormal behavior in the blockchain system is determined, so that when facing complex and diverse data in the blockchain system, the data can be integrated in the granularity of blocks, and effective anomaly detection can be carried out based on the integrated data, the accuracy of anomaly detection is improved, the computing efficiency is improved, and the false positive rate is reduced.
[0116] Referring to Figure 3 , Figure 4 is a structural diagram of a blockchain system anomaly detection device provided by an embodiment of the application, only parts related to the embodiments of the application are shown for ease of description.
[0117] The blockchain system anomaly detection device 300 comprises an acquisition module 301, an aggregation module 302 and a determination module 303.
[0118] The acquisition module 301 is configured to acquire association information of blocks from each node in the first blockchain system, each association information comprising an identifier, and the identifiers in the association information of the same block being the same or corresponding.
[0119] The aggregation module 302 is configured to aggregate the association information according to blocks based on the identifiers, to obtain aggregated data corresponding to different blocks respectively.
[0120] The determination module 303 is configured to determine a node abnormal behavior in the first blockchain system based on the aggregated data.
[0121] The acquisition module 301 is specifically configured to:
[0122] Collect index data, log data and tracking data associated with different blocks from each node in the first blockchain system;
[0123] The identifier is contained in the index data, the log data and the tracking data, and the identifier in the index data, the log data and the tracking data of the same block is the same or corresponding.
[0124] The determination module 303 is specifically configured to:
[0125] Determine, based on the first tracking data in the aggregated data, a plurality of target nodes corresponding to the same block;
[0126] Determine, based on the identifier, target log data and target index data corresponding to the first tracking data in the plurality of target nodes;
[0127] Determine, based on the target log data and the target index data, a node abnormal behavior from the plurality of target nodes.
[0128] The determination module 303 is more specifically configured to:
[0129] Compare the target log data and the target index data in different target nodes to obtain a comparison result;
[0130] In a case where it is determined based on the comparison result that there is conflicting data in the plurality of target nodes, determine, based on the conflicting data, the node abnormal behavior.
[0131] The determination module 303 is specifically configured to:
[0132] Output an abnormal analysis instruction to a target node based on the aggregated data; the target node is a node in a second blockchain system, the abnormal analysis instruction carries the aggregated data, and the abnormal analysis instruction is used to instruct the target node to store the aggregated data in the second blockchain system and instruct the target node to analyze the node abnormal behavior in the first blockchain system based on the aggregated data.
[0133] The determination module 303 is specifically configured to:
[0134] Extract, based on the identifier, target associated information corresponding to a target block from the aggregated data;
[0135] Determine, based on the target associated information, a node processing event in the first blockchain system;
[0136] Select, from a plurality of pre-written rule scripts, a target rule script matching the node processing event; each pre-written rule script corresponds to an abnormal detection rule of a node processing event;
[0137] Execute the target rule script to obtain the node anomaly detection results for the node processing events.
[0138] The device also includes:
[0139] The display module is used to visualize the aggregated data through a display panel.
[0140] The blockchain anomaly detection device provided in this application embodiment can implement all the processes of the above-described blockchain anomaly detection method embodiment and achieve the same technical effect. To avoid repetition, it will not be described again here.
[0141] Figure 4 This is a structural diagram of a terminal provided in an embodiment of this application. As shown in the figure, the terminal 4 of this embodiment includes: at least one processor 40 ( Figure 4 (Only one is shown in the diagram), memory 41, and computer program 42 stored in said memory 41 and executable on said at least one processor 40, which, when executed, implements the steps in any of the above method embodiments.
[0142] The terminal 4 can be a computing device such as a desktop computer, laptop, handheld computer, or cloud server. The terminal 4 may include, but is not limited to, a processor 40 and a memory 41. Those skilled in the art will understand that... This is merely an example of terminal 4 and does not constitute a limitation on terminal 4. It may include more or fewer components than shown, or combine certain components, or different components. For example, the terminal may also include input / output devices, network access devices, buses, etc.
[0143] The processor 40 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.
[0144] The memory 41 can be an internal storage unit of the terminal 4, such as a hard disk or a memory of the terminal 4. The memory 41 can also be an external storage device of the terminal 4, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, and the like equipped on the terminal 4. Further, the memory 41 can also include both the internal storage unit and the external storage device of the terminal 4. The memory 41 is used to store the computer program and other programs and data required by the terminal. The memory 41 can also be used to temporarily store data that has been output or is to be output.
[0145] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional units and modules is exemplified, and in actual application, the above functions can be completed by different functional units and modules according to needs, that is, the internal structure of the apparatus is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit, and the integrated unit can be realized in the form of hardware or in the form of software functional unit. In addition, the specific names of each functional unit and module are only for convenient distinction, and do not limit the protection scope of the present application. The specific working process of the units and modules in the system can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0146] In the above embodiments, the description of each embodiment has its own emphasis, and the parts not described or recorded in detail in a certain embodiment can be referred to the relevant description of other embodiments.
[0147] Those of ordinary skill in the art can appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0148] In the embodiments of the present application, it should be understood that the disclosed apparatus / terminal and method can be implemented in other manners. For example, the embodiments of the apparatus / terminal described above are merely schematic, and the division of the modules or units is merely logical function division, and there can be another division manner in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between the units can be indirect couplings or communication connections through some interfaces, devices or units, and can be electrical, mechanical or in other forms.
[0149] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.
[0150] In addition, each functional unit in the various embodiments of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0151] The integrated module / unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, all or part of the flow of the above-mentioned embodiment methods can also be completed by a computer program instructing related hardware, and the computer program can be stored in a computer readable storage medium. The computer program can implement the steps of each method embodiment when executed by a processor. The computer program includes computer program code, which can be in the form of source code, object code, executable file or some intermediate form. The computer readable medium can include any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that the computer readable medium can include or exclude contents according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to legislation and patent practice, the computer readable medium does not include electrical carrier signals and telecommunication signals.
[0152] The application can realize all or part of the processes in the above-mentioned embodiment methods, and can also be realized by a computer program product. When the computer program product runs on a terminal, the terminal is caused to realize the steps in the above-mentioned various method embodiments.
[0153] The above-mentioned embodiments are only used to illustrate the technical solutions of the present application, rather than limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that the technical solutions recorded in the foregoing embodiments can be modified, or some technical features can be replaced by equivalents. The modifications or replacements do not change the essence of the corresponding technical solutions, and should be included in the protection scope of the present application.
Claims
1. A blockchain system anomaly detection method, characterized in that, The method comprises: obtaining association information of blocks from each node in a first blockchain system, each of the association information comprising an identifier, the identifiers in the association information of the same block being the same or corresponding; wherein the association information comprises index data, log data and tracking data; based on the identifier, the association information is aggregated according to the block to obtain aggregated data corresponding to different blocks respectively; based on the aggregated data, determining the abnormal behavior of the nodes in the first blockchain system, comprising: based on the first tracking data in the aggregated data, determining a plurality of target nodes corresponding to the same block; based on the identifier, determining the target log data and the target index data corresponding to the first tracking data in the plurality of target nodes; based on the target log data and the target index data, determining the abnormal behavior of the nodes from the plurality of target nodes.
2. The method of claim 1, wherein, The method comprises: collecting index data, log data and tracking data associated with different blocks from each node in the first blockchain system; the identifier is contained in the index data, the log data and the tracking data, and the identifiers in the index data, the log data and the tracking data of the same block are the same or corresponding.
3. The method of claim 1, wherein, The method comprises: comparing the target log data and the target index data in different target nodes to obtain a comparison result; in the case where it is determined based on the comparison result that there is conflicting data in the plurality of target nodes, determining the abnormal behavior of the nodes based on the conflicting data.
4. The method of claim 1, wherein, The method further comprises: based on the aggregated data, outputting an abnormal analysis instruction to a target node; wherein the target node is a node in a second blockchain system, the aggregated data is carried in the abnormal analysis instruction, and the abnormal analysis instruction is used to instruct the target node to store the aggregated data in the second blockchain system and instruct the target node to analyze the aggregated data to obtain the abnormal behavior of the nodes in the first blockchain system.
5. The method of claim 1, wherein, The method further comprises: visualizing the aggregated data through a display panel. 6.A method for detecting anomalies in a blockchain system, the method comprising: The method comprises: obtaining association information of blocks from each node in a first blockchain system, each of the association information comprising an identifier, the identifiers in the association information of the same block being the same or corresponding; wherein the association information comprises index data, log data and tracking data; based on the identifier, the association information is aggregated according to the block to obtain aggregated data corresponding to different blocks respectively; based on the aggregated data, determining the abnormal behavior of the nodes in the first blockchain system, comprising: based on the identifier, extracting target association information corresponding to a target block from the aggregated data; determine a node processing event in the first blockchain system based on the target association information; select a target rule script matching the node processing event from a plurality of pre-written rule scripts, each of the pre-written rule scripts corresponding to an abnormality detection rule of a node processing event; execute the target rule script to obtain a node abnormality detection result of the node processing event. 7.A blockchain anomaly detection apparatus, characterized by, comprise: an acquisition module configured to acquire association information of blocks from each node in a first blockchain system, each of the association information containing an identifier, the identifiers in the association information of a same block being the same or corresponding; wherein the association information comprises index data, log data and trace data; an aggregation module configured to aggregate the association information according to blocks based on the identifiers to obtain aggregated data corresponding to different blocks respectively; a determination module configured to determine a node abnormal behavior in the first blockchain system based on the aggregated data; the determination module is specifically configured to determine a plurality of target nodes corresponding to a same block based on first trace data in the aggregated data, determine target log data and target index data corresponding to the first trace data in the plurality of target nodes based on the identifiers, and determine a node abnormal behavior from the plurality of target nodes based on the target log data and the target index data; alternatively, the determination module is specifically configured to extract target association information corresponding to a target block from the aggregated data based on the identifiers, determine a node processing event in the first blockchain system based on the target association information, select a target rule script matching the node processing event from a plurality of pre-written rule scripts, each of the pre-written rule scripts corresponding to an abnormality detection rule of a node processing event, and execute the target rule script to obtain a node abnormality detection result of the node processing event. the processor executes the computer program to implement the steps of the method of any one of claims 1 to 6. the computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 6. 8. A terminal comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, 9. A computer-readable storage medium storing a computer program, the computer program comprising instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1 to 8.
Citation Information
Patent Citations
Health data verification method, device and server based on block chain
CN109472598A