Data classification processing method, apparatus, device, and storage medium

By using protocol addresses, deployment unit names, and system names in the banking system for multi-level data classification, the problem of low efficiency in large-scale data analysis in existing technologies is solved, and efficient data information processing is achieved.

CN116701548BActive Publication Date: 2025-12-30CHINA CONSTRUCTION BANK +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310731798.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-19
Publication Date
2025-12-30
Estimated Expiration
2043-06-19

AI Technical Summary

Technical Problem

Existing technologies in banking systems lack multi-dimensional data statistical analysis methods. Script tools cannot effectively handle large amounts of data, are complex to operate, inefficient, and cannot perform complex business logic analysis.

Method used

By obtaining raw data information from the database, multi-level data classification is performed using protocol address, deployment unit name, and system name as filtering conditions to obtain multiple data classification results, which are then added to the database to support data querying.

Benefits of technology

It enables efficient analysis of large volumes of data, avoids the use of script tools, simplifies the operation process, and improves data processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116701548B_ABST
    Figure CN116701548B_ABST
Patent Text Reader

Abstract

The application provides a data classification processing method, and relates to the technical field of data processing. The method comprises the following steps: obtaining original data information from a database; taking a detection type of a preset batch under a protocol address as an initial screening condition, performing data classification processing on a detection result in the original data information, and obtaining a first data classification result; taking a deployment unit name as a second screening condition, performing data classification processing on the first data classification result, and obtaining a second data classification result; taking a system name as a third screening condition, performing data classification processing on the second data classification result, and obtaining a third data classification result; and adding the third data classification result to the database. By using the technical solution, a script tool is not needed, and a large amount of data information can be analyzed, so that the efficiency of data information processing is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing technology, and in particular to data classification and processing methods, apparatus, equipment and storage media. Background Technology

[0002] Currently, banks have numerous internal systems handling a vast amount of data. However, there is a lack of comprehensive multi-dimensional data statistical analysis methods in the industry. When multi-dimensional data statistics are needed, they are often achieved through scripts or manual Excel manipulation. However, this approach only focuses on data at a specific point in time and cannot retrospectively analyze past data. Furthermore, existing scripting tools have several shortcomings: they can only perform simple data statistical analysis and cannot handle more complex business logic. In practical use cases, the data extraction scope, detection rules, and data dimensions are relatively complex, and these variables are often significantly adjusted according to specific work requirements. Scripting tools perform poorly on large datasets, often taking a very long time to analyze data exceeding tens of millions of records. The operation of scripting tools is highly complex; users need certain system knowledge and an understanding of data analysis tools, and extensive summarization work is required after script execution.

[0003] Therefore, there is an urgent need for a data classification and processing method that can analyze large amounts of data without using script tools, thereby improving the efficiency of data processing. Summary of the Invention

[0004] This application provides a data classification and processing method, apparatus, device, and storage medium that can analyze large amounts of data without using scripting tools, thereby improving data processing efficiency.

[0005] Firstly, this application provides a data classification and processing method, the method comprising:

[0006] Raw data information is obtained from the database; wherein, the raw data information represents the running result information generated during the system operation in the same detection environment; wherein, the raw data information includes: detection type, batch, protocol address, deployment unit name, system name, and detection result; the detection type, the batch, the protocol address, the deployment unit, and the system have a hierarchical relationship; the system includes multiple deployment units; each deployment unit includes multiple protocol addresses; each protocol address includes multiple batches; each batch includes multiple detection types;

[0007] Using the detection type of a preset batch under the protocol address as the initial filtering condition, the detection results in the original data information are classified to obtain a first data classification result;

[0008] Using the name of the deployment unit as the second filtering condition, the first data classification result is processed to obtain the second data classification result;

[0009] Using the system name as the third filtering condition, the second data classification result is processed to obtain the third data classification result;

[0010] The third data classification result is added to the database; wherein, the third data classification result in the database is used to complete data query processing according to preset fields.

[0011] In one example, the detection results in the original data information are classified using the detection type of a preset batch under the protocol address as the initial filtering condition to obtain a first data classification result, including:

[0012] Using the detection type of a preset batch under the protocol address as the initial filtering condition, the detection results of the detection type of the preset batch under the protocol address are obtained from the original data information;

[0013] Based on the detection results of the preset batch under the protocol address, the detection results in the original data information are classified to obtain a first data classification result.

[0014] In one example, the step of classifying the detection results in the original data information according to the detection results of a preset batch under the protocol address to obtain a first data classification result includes:

[0015] If the detection results of the preset batch of detection types under the protocol address are all normal, then the detection results are classified under the first field to obtain the data classification result of the first field;

[0016] If the detection result of the last batch in the preset batch detection type under the protocol address is abnormal, then the detection result is classified under the second field to obtain the data classification result of the second field;

[0017] If the detection result of the last batch in the preset batch detection type under the protocol address is normal, but the detection result of at least one batch is abnormal, then the detection result is classified under the third field to obtain the third field data classification result;

[0018] The set of the first field data classification result, the second field data classification result, and the third field data classification result is determined as the first data classification result.

[0019] In one example, if the detection result of the last batch in the preset batch detection type under the protocol address is abnormal, it includes:

[0020] If any detection type in the last batch under the protocol address results in an abnormal result, then the detection result of the last batch under the protocol address is abnormal.

[0021] In one example, the step of performing data classification processing on the first data classification result to obtain a second data classification result includes:

[0022] If all the data classification results in the first data classification result are data classification results of the first field, then the data classification results of the first field will be classified under the fourth field and used as the data classification results of the fourth field.

[0023] If not all of the first data classification results are the first field data classification results, then the first data classification results are classified under the fifth field and used as the fifth field data classification results;

[0024] The set of the data classification results of the fourth field and the data classification results of the fifth field is determined as the second data classification result.

[0025] In one example, the process of classifying the second data classification result to obtain a third data classification result includes:

[0026] If all the data classification results in the second data classification result are the fourth field data classification results, then the fourth field data classification results will be classified under the sixth field and used as the sixth field data classification results;

[0027] If not all of the second data classification results are the fourth field data classification results, then the second data classification results will be classified under the seventh field and used as the seventh field data classification results;

[0028] The set of the data classification results of the fourth field and the data classification results of the fifth field is determined as the second data classification result.

[0029] In one example, the preset fields include: a first field, a second field, a third field, a fourth field, a fifth field, a sixth field, and a seventh field;

[0030] The first field is used to query the data classification result of the first field, and the data classification result of the first field indicates that the detection results of the detection type of the preset batch under the protocol address are all normal.

[0031] The second field is used to query the data classification result of the second field. The data classification result of the second field indicates that the detection result of the last batch in the preset batch detection type under the protocol address is abnormal.

[0032] The third field is used to query the data classification result of the third field. The data classification result of the third field indicates that the detection result of the last batch in the preset batch detection type under the protocol address is normal, but there is at least one batch whose detection result is abnormal.

[0033] The fourth field is used to query the data classification results of the fourth field, and the data classification results of the fourth field represent that all the data classification results of the first field are data classification results of the first field;

[0034] The fifth field is used to query the data classification result of the fifth field, and the data classification result of the fifth field indicates that not all of the data classification results of the first field are data classification results of the first field.

[0035] The sixth field is used to query the data classification result of the sixth field, and the data classification result of the seventh field indicates that all the data classification results in the second data classification result are the data classification results of the fourth field.

[0036] The seventh field is used to query the data classification results of the seventh field, and the data classification results of the seventh field represent that not all of the data classification results of the second data are the data classification results of the fourth field.

[0037] Secondly, this application provides a data classification and processing apparatus, comprising:

[0038] An acquisition unit is used to acquire raw data information from a database; wherein the raw data information represents the running result information generated during system operation in the same detection environment; wherein the raw data information includes: detection type, batch, protocol address, deployment unit name, system name, and detection result; the detection type, batch, protocol address, deployment unit, and system have a hierarchical relationship; the system includes multiple deployment units; each deployment unit includes multiple protocol addresses; each protocol address includes multiple batches; each batch includes multiple detection types;

[0039] The first classification processing unit is used to classify the detection results in the original data information using the detection type of a preset batch under the protocol address as the initial screening condition, and to obtain the first data classification result.

[0040] The second classification processing unit is used to perform data classification processing on the first data classification result using the name of the deployment unit as the second filtering condition, so as to obtain the second data classification result.

[0041] The third classification processing unit is used to perform data classification processing on the second data classification result using the system name as the third filtering condition, and to obtain the third data classification result.

[0042] An adding unit is used to add the third data classification result to the database; wherein the third data classification result in the database is used to complete data query processing according to preset fields.

[0043] In one example, the first classification processing unit includes:

[0044] The acquisition module is used to obtain the detection results of the preset batch under the protocol address from the original data information, using the detection type of the preset batch under the protocol address as the initial filtering condition;

[0045] The first classification processing module is used to perform data classification processing on the detection results in the original data information according to the detection results of the detection type of the preset batch under the protocol address, so as to obtain the first data classification result.

[0046] In one example, the first classification processing module includes:

[0047] The first classification submodule is used to classify the detection results into the first field if the detection results of the preset batch of detection types under the protocol address are all normal, so as to obtain the data classification result of the first field.

[0048] The second classification submodule is used to classify the detection result into the second field if the detection result of the last batch in the preset batch detection type under the protocol address is abnormal, so as to obtain the data classification result of the second field.

[0049] The third classification submodule is used to classify the detection results into the third field if the detection result of the last batch in the preset batch detection type under the protocol address is normal, but the detection result of at least one batch is abnormal, so as to obtain the third field data classification result.

[0050] The determination submodule is used to determine the set of the first field data classification result, the second field data classification result, and the third field data classification result as the first data classification result.

[0051] In one example, if the detection result of the last batch in the preset batch detection type under the protocol address is abnormal, it includes:

[0052] If any detection type in the last batch under the protocol address results in an abnormal result, then the detection result of the last batch under the protocol address is abnormal.

[0053] In one example, the second classification processing unit includes:

[0054] The second classification processing module is used to classify the first field data classification result into the fourth field if all the first data classification results are the first field data classification results, and use them as the fourth field data classification results.

[0055] The third classification processing module is used to classify the first data classification result into the fifth field if not all of the first data classification results are the first field data classification results.

[0056] The first determining module is used to determine the set of the fourth field data classification result and the fifth field data classification result as the second data classification result.

[0057] In one example, the third classification processing unit includes:

[0058] The fourth classification processing module is used to classify the fourth field data classification results into the sixth field if all the second data classification results are fourth field data classification results, and use them as the sixth field data classification results.

[0059] The fifth classification processing module is used to classify the second data classification result into the seventh field if not all of the second data classification results are the fourth field data classification results.

[0060] The second determining module is used to determine the set of the fourth field data classification result and the fifth field data classification result as the second data classification result.

[0061] In one example, the preset fields include: a first field, a second field, a third field, a fourth field, a fifth field, a sixth field, and a seventh field;

[0062] The first field is used to query the data classification result of the first field, and the data classification result of the first field indicates that the detection results of the detection type of the preset batch under the protocol address are all normal.

[0063] The second field is used to query the data classification result of the second field. The data classification result of the second field indicates that the detection result of the last batch in the preset batch detection type under the protocol address is abnormal.

[0064] The third field is used to query the data classification result of the third field. The data classification result of the third field indicates that the detection result of the last batch in the preset batch detection type under the protocol address is normal, but there is at least one batch whose detection result is abnormal.

[0065] The fourth field is used to query the data classification results of the fourth field, and the data classification results of the fourth field represent that all the data classification results of the first field are data classification results of the first field;

[0066] The fifth field is used to query the data classification result of the fifth field, and the data classification result of the fifth field indicates that not all of the data classification results of the first field are data classification results of the first field.

[0067] The sixth field is used to query the data classification result of the sixth field, and the data classification result of the seventh field indicates that all the data classification results in the second data classification result are the data classification results of the fourth field.

[0068] The seventh field is used to query the data classification results of the seventh field, and the data classification results of the seventh field represent that not all of the data classification results of the second data are the data classification results of the fourth field.

[0069] Thirdly, this application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;

[0070] The memory stores computer-executed instructions;

[0071] The processor executes computer execution instructions stored in the memory to implement the method as described in the first aspect.

[0072] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method described in the first aspect.

[0073] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the method described in the first aspect.

[0074] This application provides a data classification and processing method, which involves: obtaining raw data information from a database; classifying the detection results in the raw data information using the detection type of a preset batch under the protocol address as an initial filtering condition to obtain a first data classification result; classifying the first data classification result using the deployment unit name as a second filtering condition to obtain a second data classification result; classifying the second data classification result using the system name as a third filtering condition to obtain a third data classification result; and adding the third data classification result to the database. This technical solution enables the analysis of large volumes of data without the use of scripting tools, thus improving the efficiency of data processing. Attached Figure Description

[0075] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0076] Figure 1 This is a flowchart illustrating a data classification and processing method according to Embodiment 1 of this application;

[0077] Figure 2a This is a flowchart illustrating a data classification and processing method according to Embodiment 2 of this application;

[0078] Figure 2b This is a schematic diagram of a first data classification result provided in Embodiment 2 of this application;

[0079] Figure 2c This is a schematic diagram of a second data classification result provided in Embodiment 2 of this application;

[0080] Figure 2d This is a schematic diagram of a third data classification result provided in Embodiment 2 of this application;

[0081] Figure 3 This is a schematic diagram of a data classification and processing device according to Embodiment 3 of this application;

[0082] Figure 4 This is a schematic diagram of the structure of a data classification and processing device according to Embodiment 4 of this application;

[0083] Figure 5 This is a block diagram illustrating an electronic device according to an exemplary embodiment.

[0084] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0085] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0086] This application provides a data classification and processing method, apparatus, device, and storage medium, which aims to solve the above-mentioned technical problems in the prior art.

[0087] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0088] Figure 1 This is a flowchart illustrating a data classification and processing method according to Embodiment 1 of this application. Embodiment 1 includes the following steps:

[0089] S101. Obtain raw data information from the database; wherein, the raw data information represents the running result information generated during the system operation in the same detection environment; wherein, the raw data information includes: detection type, batch, protocol address, deployment unit name, system name and detection result; the detection type, batch, protocol address, deployment unit and system have a hierarchical relationship; the system includes multiple deployment units; each deployment unit includes multiple protocol addresses; each protocol address includes multiple batches; each batch includes multiple detection types.

[0090] In one example, the database could be the Elastic Search database. The Elastic Search database is a distributed search and analytics engine located at the core of the Elastic Stack. It provides near real-time search and analysis for all types of data. The raw data information represents the operational results generated during system operation within the same detection environment. These results can present various data types, including: detection type, batch, protocol address, deployment unit name, system name, and detection result. The detection type, batch, protocol address, deployment unit, and system have a hierarchical relationship; the system includes multiple deployment units; each deployment unit includes multiple protocol addresses; each protocol address includes multiple batches; and each batch includes multiple detection types.

[0091] In this embodiment, the detection type can be basic environment detection.

[0092] S102. Using the detection type of the preset batch under the protocol address as the initial screening condition, perform data classification processing on the detection results in the original data information to obtain the first data classification result.

[0093] In one example, the detection type of a preset batch under a protocol address refers to the detection type of a preset batch under the same IP. For example, the same batch of detections may contain multiple pieces of raw data. If the detection type is basic environment detection, and in batch A, the basic environment memory detection data is successful, the basic environment CPU detection data is unsuccessful, and the basic environment disk storage detection data is successful, then after analyzing the data according to the detection type under the IP, it will be concluded that the basic environment detection failed. That is, if there is unsuccessful data in a certain batch of the detection type of that IP, then the batch is considered to have failed.

[0094] In this embodiment, the preset batch can be 3 times. Further, using the detection type of the preset batch under the protocol address as the initial screening condition, the detection results in the original data information are processed for data classification to obtain the first data classification result.

[0095] S103. Using the deployment unit name as the second filtering condition, perform data classification processing on the first data classification result to obtain the second data classification result.

[0096] In one example, the deployment unit includes multiple protocol addresses. After filtering data information at the next higher level, a first data classification result is obtained. In this embodiment, the first data classification result is further classified by the deployment unit name to obtain a second data classification result. Further, the second data classification result includes: normal detection result, abnormal detection result, or abnormal detection result that has been recovered.

[0097] S104. Using the system name as the third filtering condition, perform data classification processing on the second data classification results to obtain the third data classification results.

[0098] In one example, the system is the level above the deployment unit. After filtering the second data classification results by system name, the third data classification results are obtained. Furthermore, the third data classification results include normal detection results, abnormal detection results, or abnormal detection results that have been recovered. However, the data information under these three types differs.

[0099] S105. Add the third data classification results to the database; wherein, the third data classification results in the database are used to complete data query processing based on preset fields.

[0100] In one example, the third-party data classification results are added to the database, and data query processing is completed based on these results. When a user sends a query request through the front end, data query processing can be performed based on preset fields.

[0101] This application provides a data classification and processing method. The method involves: obtaining raw data from a database; classifying the detection results in the raw data using the detection type of a preset batch under a protocol address as the initial filtering condition to obtain a first data classification result; classifying the first data classification result using the deployment unit name as a second filtering condition to obtain a second data classification result; classifying the second data classification result using the system name as a third filtering condition to obtain a third data classification result; and adding the third data classification result to the database. This technical solution enables the analysis of large volumes of data without the use of scripting tools, thus improving the efficiency of data processing.

[0102] Figure 2a This is a flowchart illustrating a data classification and processing method according to Embodiment 2 of this application. Embodiment 2 includes the following steps:

[0103] S201. Obtain raw data information from the database; wherein, the raw data information represents the running result information generated during the system operation in the same detection environment; wherein, the raw data information includes: detection type, batch, protocol address, deployment unit name, system name and detection result; the detection type, batch, protocol address, deployment unit and system have a hierarchical relationship; the system includes multiple deployment units; each deployment unit includes multiple protocol addresses; each protocol address includes multiple batches; each batch includes multiple detection types.

[0104] For example, this step can refer to step S101 above, and will not be repeated here.

[0105] S202. Using the detection type of the preset batch under the protocol address as the initial filtering condition, obtain the detection results of the detection type of the preset batch under the protocol address from the original data information.

[0106] In this embodiment, data information under the protocol address is first filtered out from the original data information, then data information under the protocol address in a preset batch is filtered out, and then detection results of a preset detection type are filtered out under the preset batch under the protocol address.

[0107] S203. Based on the detection results of the preset batch detection type under the protocol address, perform data classification processing on the detection results in the original data information to obtain the first data classification result.

[0108] In one example, based on the detection results of a preset batch under the protocol address, the detection results in the original data information are classified to obtain the first data classification result, including:

[0109] If the test results of the preset batch of test types under the protocol address are all normal, the test results will be classified under the first field to obtain the data classification result of the first field;

[0110] If the detection result of the last batch in the preset batch detection type under the protocol address is abnormal, the detection result will be classified under the second field to obtain the data classification result of the second field;

[0111] If the last batch of the preset batch detection type under the protocol address has a normal detection result, but at least one batch has an abnormal detection result, then the detection result will be classified under the third field to obtain the third field data classification result.

[0112] The set of the data classification results of the first field, the second field, and the third field is determined as the first data classification result.

[0113] In this embodiment, the first field can be an IP index of 2, the second field can be an IP index of 0, and the third field can be an IP index of 1. Further, the logic for the detection results can be as follows: among the three most recent batches of detections, if the most recent detection result is abnormal, then the detection result is abnormal; if all three detection results are normal, then the detection result is normal; if the most recent detection result is normal, and one of the three detection results is abnormal, then the current detection result is abnormal and has been recovered. If the detection result is normal, then the detection result is classified under 2; if the detection result is abnormal, then the detection result is classified under 0; if the detection result is abnormal and has been recovered, then the detection result is classified under 1. Further, the first data classification result includes the case where the detection result is classified as 0, which is further divided into the case where the detection result is classified as 1, and the case where the detection result is classified as 2. For a better explanation, please refer to... Figure 2b This diagram illustrates the process of a first data classification result.

[0114] In one example, if the detection result of the last batch in the preset batch detection types under the protocol address is abnormal, it includes:

[0115] If any detection type in the last batch under the protocol address has an abnormal result, then the detection result of the last batch under the protocol address is abnormal.

[0116] In one example, if any one of the detection results in the same batch under an IP detection type is abnormal, then the IP is considered to be abnormal in that batch of detection types.

[0117] S204. Using the deployment unit name as the second filtering condition, perform data classification processing on the first data classification result to obtain the second data classification result.

[0118] In one example, the first data classification result is processed to obtain the second data classification result, which includes:

[0119] If all the data classification results in the first data category are classified under the first field, then the data classification results in the first field will be classified under the fourth field and used as the data classification results in the fourth field.

[0120] If not all data in the first data classification result are classified under the first field, then the first data classification result will be classified under the fifth field and used as the fifth field data classification result.

[0121] The set of the data classification results from the fourth field and the data classification results from the fifth field is determined as the second data classification result.

[0122] In one example, if any deployment unit in a system is abnormal, the entire system is considered abnormal; if any IP detection type in a deployment unit is abnormal, the deployment unit is considered abnormal; if any detection result in the same batch of an IP detection type is abnormal, the IP and the batch of detection types are considered abnormal.

[0123] In one example, the fourth field has a deployment unit index of 2, and the fifth field can have a deployment unit index of 0. For a better illustration, please refer to [link to relevant documentation]. Figure 2c This diagram illustrates a process for a second data classification result.

[0124] S205. Using the system name as the third filtering condition, perform data classification processing on the second data classification results to obtain the third data classification results.

[0125] In one example, the second data classification result is processed to obtain the third data classification result, which includes:

[0126] If all the data classification results in the second data classification result are the data classification results of the fourth field, then the data classification results of the fourth field will be classified under the sixth field and used as the data classification results of the sixth field.

[0127] If the second data classification result is not all of the fourth field data classification result, then the second data classification result will be classified under the seventh field and used as the seventh field data classification result;

[0128] The set of the data classification results from the fourth field and the data classification results from the fifth field is determined as the second data classification result.

[0129] In this embodiment, the sixth field has a system index of 2, and the seventh field can have a system index of 0. For a better explanation, please refer to [link to relevant documentation]. Figure 2d This diagram illustrates a process for classifying third-party data results.

[0130] S206. Add the third data classification results to the database; wherein, the third data classification results in the database are used to complete data query processing based on preset fields.

[0131] In one example, the preset fields include: field 1, field 2, field 3, field 4, field 5, field 6, and field 7;

[0132] The first field is used to query the data classification results of the first field. The data classification results of the first field indicate that the detection results of the preset batch of detection types under the protocol address are all normal.

[0133] The second field is used to query the data classification results of the second field. The data classification results of the second field indicate that the detection results of the last batch in the preset batch under the protocol address are abnormal.

[0134] The third field is used to query the data classification results of the third field. The data classification results of the third field indicate that the detection result of the last batch in the preset batch under the protocol address is normal, but there is at least one batch whose detection result is abnormal.

[0135] The fourth field is used to query the data classification results of the fourth field. The data classification results of the fourth field indicate that all the data classification results of the first field are the data classification results of the first field.

[0136] The fifth field is used to query the classification results of the data in the fifth field. The classification results of the data in the fifth field indicate that not all of the data in the first field are classified as data in the first field.

[0137] The sixth field is used to query the data classification results of the sixth field, and the seventh field data classification results indicate that all the data classification results in the second field are the data classification results of the fourth field.

[0138] The seventh field is used to query the classification results of the data in the seventh field. The classification results of the data in the seventh field represent that the data in the second field are not all classified as the data in the fourth field.

[0139] In this embodiment, the preset fields are stored in the Elastic Search database. Specifically, the first data classification result yields a sum index, the second data classification result yields a unit index, and the third data classification result yields a system index. The other field data for the sum index is obtained from the original data information, the other field data for the unit index is obtained from the sum data, and the other field data for the system index is obtained from the sum data.

[0140] This application provides a data classification and processing method that completes data query processing through preset fields, including: a first field, a second field, a third field, a fourth field, a fifth field, a sixth field, and a seventh field. This technical solution can meet the needs of aggregation and statistical analysis of massive amounts of data on large servers.

[0141] Figure 3 This is a schematic diagram of a data classification and processing apparatus according to Embodiment 3 of this application. Specifically, the apparatus 30 in Embodiment 3 includes:

[0142] The acquisition unit 301 is used to acquire raw data information from the database. The raw data information represents the running result information generated during the system operation in the same detection environment. The raw data information includes: detection type, batch, protocol address, deployment unit name, system name, and detection result. The detection type, batch, protocol address, deployment unit, and system have a hierarchical relationship. The system includes multiple deployment units. Each deployment unit includes multiple protocol addresses. Each protocol address includes multiple batches. Each batch includes multiple detection types.

[0143] The first classification processing unit 302 is used to classify the detection results in the original data information based on the detection type of the preset batch under the protocol address as the initial screening condition, and obtain the first data classification result.

[0144] The second classification processing unit 303 is used to perform data classification processing on the first data classification result with the deployment unit name as the second filtering condition, so as to obtain the second data classification result.

[0145] The third classification processing unit 304 is used to perform data classification processing on the second data classification result with the system name as the third filtering condition to obtain the third data classification result.

[0146] Add unit 305 to add the third data classification results to the database; the third data classification results in the database are used to complete data query processing based on preset fields.

[0147] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the above-described device can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0148] Figure 4 This is a schematic diagram of a data classification and processing apparatus according to Embodiment 4 of this application. Specifically, the apparatus 40 in Embodiment 4 includes:

[0149] The acquisition unit 401 is used to acquire raw data information from the database. The raw data information represents the running result information generated during the system operation in the same detection environment. The raw data information includes: detection type, batch, protocol address, deployment unit name, system name, and detection result. The detection type, batch, protocol address, deployment unit, and system have a hierarchical relationship. The system includes multiple deployment units. Each deployment unit includes multiple protocol addresses. Each protocol address includes multiple batches. Each batch includes multiple detection types.

[0150] The first classification processing unit 402 is used to classify the detection results in the original data information based on the detection type of the preset batch under the protocol address as the initial screening condition, and obtain the first data classification result.

[0151] The second classification processing unit 403 is used to perform data classification processing on the first data classification result with the deployment unit name as the second filtering condition, so as to obtain the second data classification result.

[0152] The third classification processing unit 404 is used to perform data classification processing on the second data classification result with the system name as the third filtering condition, so as to obtain the third data classification result.

[0153] Add unit 405 to add the third data classification results to the database; the third data classification results in the database are used to complete data query processing based on preset fields.

[0154] In one example, the first classification processing unit 402 includes:

[0155] The acquisition module 4021 is used to obtain the detection results of the preset batch under the protocol address from the original data information, using the detection type of the preset batch under the protocol address as the initial filtering condition.

[0156] The first classification processing module 4022 is used to perform data classification processing on the detection results in the original data information according to the detection results of the detection type of the preset batch under the protocol address, so as to obtain the first data classification result.

[0157] In one example, the first classification processing module 4022 includes:

[0158] The first classification submodule 40221 is used to classify the detection results into the first field if the detection results of the preset batch of detection types under the protocol address are all normal, so as to obtain the data classification result of the first field.

[0159] The second classification submodule 40222 is used to classify the detection result into the second field if the detection result of the last batch in the preset batch detection type under the protocol address is abnormal, so as to obtain the data classification result of the second field.

[0160] The third classification submodule 40223 is used to classify the detection results into the third field if the detection result of the last batch in the preset batch detection type under the protocol address is normal, but the detection result of at least one batch is abnormal, and thus obtain the data classification result of the third field.

[0161] The determination submodule 40224 is used to determine the set of the first field data classification results, the second field data classification results, and the third field data classification results as the first data classification result.

[0162] In one example, if the detection result of the last batch in the preset batch detection types under the protocol address is abnormal, it includes:

[0163] If any detection type in the last batch under the protocol address has an abnormal result, then the detection result of the last batch under the protocol address is abnormal.

[0164] In one example, the second classification processing unit 403 includes:

[0165] The second classification processing module 4031 is used to classify the first field data classification results into the fourth field if all the first data classification results are the first field data classification results, and use them as the fourth field data classification results.

[0166] The third classification processing module 4032 is used to classify the first data classification result into the fifth field if the first data classification result is not all of the first field data classification result.

[0167] The first determining module 4033 is used to determine the set of the data classification results of the fourth field and the data classification results of the fifth field as the second data classification result.

[0168] In one example, the third classification processing unit 404 includes:

[0169] The fourth classification processing module 4041 is used to classify the fourth field data classification results into the sixth field if the second data classification results are all fourth field data classification results, and use them as the sixth field data classification results.

[0170] The fifth classification processing module 4042 is used to classify the second data classification result into the seventh field if the second data classification result is not all of the fourth field data classification result.

[0171] The second determining module 4043 is used to determine the set of the data classification results of the fourth field and the data classification results of the fifth field as the second data classification result.

[0172] In one example, the preset fields include: field 1, field 2, field 3, field 4, field 5, field 6, and field 7;

[0173] The first field is used to query the data classification results of the first field. The data classification results of the first field indicate that the detection results of the preset batch of detection types under the protocol address are all normal.

[0174] The second field is used to query the data classification results of the second field. The data classification results of the second field indicate that the detection results of the last batch in the preset batch under the protocol address are abnormal.

[0175] The third field is used to query the data classification results of the third field. The data classification results of the third field indicate that the detection result of the last batch in the preset batch under the protocol address is normal, but there is at least one batch whose detection result is abnormal.

[0176] The fourth field is used to query the data classification results of the fourth field. The data classification results of the fourth field indicate that all the data classification results of the first field are the data classification results of the first field.

[0177] The fifth field is used to query the classification results of the data in the fifth field. The classification results of the data in the fifth field indicate that not all of the data in the first field are classified as data in the first field.

[0178] The sixth field is used to query the data classification results of the sixth field, and the seventh field data classification results indicate that all the data classification results in the second field are the data classification results of the fourth field.

[0179] The seventh field is used to query the classification results of the data in the seventh field. The classification results of the data in the seventh field represent that the data in the second field are not all classified as the data in the fourth field.

[0180] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the above-described device can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0181] Figure 5 This is a block diagram illustrating an electronic device according to an exemplary embodiment. The device may be a mobile phone, computer, digital broadcasting terminal, messaging device, game console, tablet device, medical device, fitness device, personal digital assistant, etc.

[0182] The device 500 may include one or more of the following components: a processing component 502, a memory 504, a power supply component 506, a multimedia component 508, an audio component 510, an input / output (I / O) interface 512, a sensor component 514, and a communication component 516.

[0183] Processing component 502 typically controls the overall operation of device 500, such as operations associated with display, telephone calls, data communication, camera operation, and recording. Processing component 502 may include one or more processors 520 to execute instructions to complete all or part of the steps of the methods described above. Furthermore, processing component 502 may include one or more modules to facilitate interaction between processing component 502 and other components. For example, processing component 502 may include a multimedia module to facilitate interaction between multimedia component 508 and processing component 502.

[0184] Memory 504 is configured to store various types of data to support the operation of device 500. Examples of such data include instructions for any application or method operating on device 500, contact data, phonebook data, messages, pictures, videos, etc. Memory 504 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0185] Power supply component 506 provides power to various components of device 500. Power supply component 506 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to device 500.

[0186] Multimedia component 508 includes a screen that provides an output interface between device 500 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors may sense not only the boundaries of the touch or swipe action but also the duration and pressure associated with the touch or swipe operation. In some embodiments, multimedia component 508 includes a front-facing camera and / or a rear-facing camera. When device 500 is in an operating mode, such as a shooting mode or a video mode, the front-facing camera and / or the rear-facing camera may receive external multimedia data. Each front-facing camera and rear-facing camera may be a fixed optical lens system or have focal length and optical zoom capabilities.

[0187] Audio component 510 is configured to output and / or input audio signals. For example, audio component 510 includes a microphone (MIC) configured to receive external audio signals when device 500 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 504 or transmitted via communication component 516. In some embodiments, audio component 510 also includes a speaker for outputting audio signals.

[0188] I / O interface 512 provides an interface between processing component 502 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include, but are not limited to, home buttons, volume buttons, power buttons, and lock buttons.

[0189] Sensor assembly 514 includes one or more sensors for providing status assessments of various aspects of device 500. For example, sensor assembly 514 may detect the on / off state of device 500, the relative positioning of components such as the display and keypad of device 500, changes in the position of device 500 or a component of device 500, the presence or absence of user contact with device 500, the orientation or acceleration / deceleration of device 500, and temperature changes of device 500. Sensor assembly 514 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 514 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, sensor assembly 514 may also include an accelerometer, a gyroscope, a magnetometer, a pressure sensor, or a temperature sensor.

[0190] Communication component 516 is configured to facilitate wired or wireless communication between device 500 and other devices. Device 500 can access wireless networks based on communication standards, such as WiFi, 2G, or 3G, or combinations thereof. In one exemplary embodiment, communication component 516 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 516 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0191] In an exemplary embodiment, the apparatus 500 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods described above.

[0192] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 504 including instructions, which can be executed by a processor 520 of the device 500 to perform the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.

[0193] A non-transitory computer-readable storage medium, wherein instructions in the storage medium, when executed by a processor of an electronic device, enable the electronic device to perform a data classification processing method of the electronic device.

[0194] This application also discloses a computer program product, including a computer program that, when executed by a processor, implements a data classification processing method as described in this embodiment.

[0195] Various embodiments of the systems and technologies described above in this application can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include: implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0196] The program code used to implement the methods of this application may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or electronic device.

[0197] In the context of this application, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0198] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0199] The systems and technologies described herein can be implemented in computing systems that include back-end components (e.g., as data electronic devices), or computing systems that include middleware components (e.g., application electronic devices), or computing systems that include front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and technologies described herein), or any combination of such back-end, middleware, or front-end components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.

[0200] Computer systems can include client and electronic devices. Clients and electronic devices are generally geographically separated and typically interact via communication networks. The client-electronic device relationship is created by computer programs running on the respective computers and having a client-electronic device relationship with each other. The electronic device can be a cloud electronic device, also known as a cloud computing electronic device or cloud host, a host product within the cloud computing service system, addressing the shortcomings of traditional physical hosts and VPS services ("Virtual Private Server," or simply "VPS") in terms of management difficulty and weak business scalability. The electronic device can also be an electronic device in a distributed system or an electronic device incorporating blockchain technology. It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this application can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this application is achieved, and this is not limited herein.

[0201] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.

[0202] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A data classification processing method characterized by, The method comprises: obtaining original data information from a database; wherein the original data information represents running result information generated in a system running process under a same detection environment; wherein the original data information comprises detection types, batches, protocol addresses, deployment unit names, system names and detection results; the detection types, the batches, the protocol addresses, the deployment units and the system have a hierarchical relationship; the system comprises a plurality of deployment units; each deployment unit comprises a plurality of protocol addresses; each protocol address comprises a plurality of batches; and each batch comprises a plurality of detection types; taking the detection types of a preset batch under a protocol address as an initial screening condition, and obtaining detection results of the detection types of the preset batch under the protocol address from the original data information; if the detection results of the detection types of the preset batch under the protocol address are all normal, then classifying the detection results into a first field to obtain a first field data classification result; if the detection result of a last batch of the detection types of the preset batch under the protocol address is abnormal, then classifying the detection result into a second field to obtain a second field data classification result; if the detection result of the last batch of the detection types of the preset batch under the protocol address is normal, but the detection results of at least one batch are abnormal, then classifying the detection results into a third field to obtain a third field data classification result; determining a set of the first field data classification result, the second field data classification result and the third field data classification result as a first data classification result; taking the deployment unit name as a second screening condition, and performing data classification processing on the first data classification result to obtain a second data classification result; taking the system name as a third screening condition, and performing data classification processing on the second data classification result to obtain a third data classification result; adding the third data classification result to the database; wherein the third data classification result in the database is used for completing data query processing according to a preset field; wherein the data classification processing on the first data classification result to obtain the second data classification result comprises: if all the first data classification results are first field data classification results, then classifying the first field data classification results into a fourth field as fourth field data classification results; if not all the first data classification results are first field data classification results, then classifying the first data classification results into a fifth field as fifth field data classification results; determining a set of the fourth field data classification results and the fifth field data classification results as the second data classification result.

2. The method of claim 1, wherein, the if the detection result of the last batch of the detection types of the preset batch under the protocol address is abnormal comprises: if the detection result of a detection type in the last batch under the protocol address is abnormal, then the detection result of the last batch under the protocol address is abnormal.

3. The method of claim 1, wherein, the data classification processing on the second data classification result to obtain the third data classification result comprises: If the second data classification result is not the fourth field data classification result, the second data classification result is classified under the seventh field as a seventh field data classification result. If the second data classification result is not the fourth field data classification result, the second data classification result is classified under the seventh field as a seventh field data classification result. The fourth field data classification result and the fifth field data classification result are determined as the second data classification result.

4. The method according to any one of claims 1 to 3, characterized in that, The preset fields include a first field, a second field, a third field, a fourth field, a fifth field, a sixth field, and a seventh field. The first field is used to query a first field data classification result, and the first field data classification result indicates that the detection results of the detection types of the preset batches under the protocol address are all normal. The second field is used to query a second field data classification result, and the second field data classification result indicates that the detection result of the last batch of the detection types of the preset batches under the protocol address is abnormal. The third field is used to query a third field data classification result, and the third field data classification result indicates that the detection result of the last batch of the detection types of the preset batches under the protocol address is normal, but the detection result of at least one batch is abnormal. The fourth field is used to query a fourth field data classification result, and the fourth field data classification result indicates that the first data classification result is all the first field data classification result. The fifth field is used to query a fifth field data classification result, and the fifth field data classification result indicates that the first data classification result is not all the first field data classification result. The sixth field is used to query a sixth field data classification result, and the seventh field data classification result indicates that the second data classification result is all the fourth field data classification result. The seventh field is used to query a seventh field data classification result, and the seventh field data classification result indicates that the second data classification result is not all the fourth field data classification result.

5. A data sorting processing device, characterized by comprising: The device includes: An acquisition unit is configured to acquire original data information from a database, wherein the original data information indicates running result information generated in a system running process under a same detection environment, and the original data information includes detection types, batches, protocol addresses, deployment unit names, system names, and detection results; the detection types, the batches, the protocol addresses, the deployment units, and the systems have a hierarchical relationship; the system includes a plurality of deployment units; each deployment unit includes a plurality of protocol addresses; each protocol address includes a plurality of batches; and each batch includes a plurality of detection types. The first classification processing unit is configured to take the detection types of the preset batches under the protocol address as initial screening conditions, and obtain detection results of the detection types of the preset batches under the protocol address from the original data information; if the detection results of the detection types of the preset batches under the protocol address are all normal, the detection results are classified into a first field to obtain a first field data classification result; if the detection result of the last batch of the detection types of the preset batches under the protocol address is abnormal, the detection results are classified into a second field to obtain a second field data classification result; if the detection result of the last batch of the detection types of the preset batches under the protocol address is normal, but the detection results of at least one batch are abnormal, the detection results are classified into a third field to obtain a third field data classification result; and a set of the first field data classification result, the second field data classification result and the third field data classification result is determined as a first data classification result. The second classification processing unit is configured to take the deployment unit name as a second screening condition, and perform data classification processing on the first data classification result to obtain a second data classification result. The third classification processing unit is configured to take the system name as a third screening condition, and perform data classification processing on the second data classification result to obtain a third data classification result. The adding unit is configured to add the third data classification result to a database; wherein the third data classification result in the database is used for completing data query processing according to a preset field. The second classification processing unit is specifically configured to classify the first field data classification result into a fourth field as a fourth field data classification result if the first data classification result is all the first field data classification result; or classify the first data classification result into a fifth field as a fifth field data classification result if the first data classification result is not all the first field data classification result; and a set of the fourth field data classification result and the fifth field data classification result is determined as the second data classification result.

6. An electronic device, comprising: It comprises: a processor and a memory connected with the processor in communication; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory to realize the method in any one of claims 1-4.

7. A computer readable storage medium characterized by The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to realize the method in any one of claims 1-4.

8. A computer program product, characterised in that, It comprises a computer program, which is executed by the processor to realize the method in any one of claims 1-4.

Citation Information

Patent Citations

  • Data stream processing

    US20210390119A1

  • Method, apparatus, device and storage medium for training model

    US20210390428A1