A hotspot traffic identification and early warning system, method, device and storage medium

By identifying and issuing early warnings of traffic spikes in the e-commerce system in real time, and by employing traffic recording, log collection, and statistical judgment modules to trigger defensive measures, the system instability caused by sudden traffic spikes has been resolved, improving the stability of the transaction chain and the user experience.

CN116708133BActive Publication Date: 2026-03-27SHANGHAI WEIMOB ENTERPRISE DEV CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-11
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

In the distributed architecture of e-commerce, when upstream business systems suffer from sudden traffic surges, downstream systems are unable to proactively defend against them, resulting in slow system recovery times in the transaction chain, affecting stability and user experience.

Method used

Through traffic recording, log collection, log statistics and judgment, and hotspot traffic early warning modules, hotspot traffic can be identified and warned in real time, triggering defensive measures to improve the stability of the transaction chain.

Benefits of technology

Effectively identify and provide early warnings of traffic spikes, reduce downtime caused by sudden traffic surges, and improve the stability of the transaction chain and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116708133B_ABST
    Figure CN116708133B_ABST
Patent Text Reader

Abstract

The application discloses a hotspot traffic identification early warning system and method, equipment and a storage medium, and relates to the field of e-commerce, and comprises: a traffic recording module, which is used for recording service requests of each preset traffic reported to a service system through a preset channel in the form of a log to obtain traffic access logs; a log collection module, which is used for performing a log collection operation on each generated traffic access log through a preset asynchronous collector to obtain a traffic access log set; a log statistical judgment module, which is used for performing a statistical operation on the traffic access log set based on a preset real-time calculation engine and a preset statistical rule, and judging whether there is hotspot traffic based on a log statistical result and a corresponding preset threshold; and a hotspot traffic early warning module, which is used for performing an early warning information sending operation based on a preset early warning rule when there is hotspot traffic, so that the traffic subscription service system receives the early warning information and implements defense measures. The application can effectively improve the stability of the transaction link.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of e-commerce, and particularly relates to a hot traffic identification and early warning system, method, device and storage medium. BACKGROUND

[0002] Under the distributed architecture of e-commerce Internet, the entire e-commerce consumer shopping transaction process has formed a standardized process in the industry. Behind the standard process, according to the different responsibilities of the business domain, the commodity domain, the promotion domain, the merchant domain, the transaction domain, the order domain, the payment domain, the user domain and other systems are divided. According to the time sequence of user shopping access, a sequential data flow is formed.

[0003] At present, when the upstream business system is subjected to traffic impact, the downstream business system does not actively defend in advance, but can only passively wait for the arrival of traffic, especially some unexpected non-advance predictable traffic, which will cause a large area of various problems on the entire transaction link system due to the huge traffic, and cause the recovery time of the entire link system to be very slow. SUMMARY

[0004] Therefore, the purpose of the present application is to provide a hot traffic identification and early warning system, method, device and storage medium, which can effectively improve the stability of the transaction link. The specific scheme is as follows:

[0005] In a first aspect, the present application provides a hot traffic identification and early warning system applied to a preset hot traffic platform, comprising:

[0006] A traffic record module is configured to record the business requests reported by each preset traffic reporting business system through a preset channel in the form of a log, so as to obtain a plurality of traffic access logs;

[0007] A log collection module is configured to perform a corresponding log collection operation on each of the traffic access logs generated at present through a preset asynchronous collector, so as to obtain a corresponding traffic access log set;

[0008] A log statistical judgment module is configured to perform a corresponding statistical operation on the traffic access log set based on a preset real-time calculation engine and a preset statistical rule, and to judge whether there is hot traffic at present based on the obtained log statistical result and the corresponding preset threshold value;

[0009] A hot traffic early warning module is configured to perform a corresponding early warning information sending operation based on a preset early warning rule when it is determined that there is hot traffic at present, so that the corresponding traffic subscription business system receives the corresponding early warning information and implements a corresponding defense measure.

[0010] Optionally, the log statistical judgment module comprises:

[0011] The first log statistics unit is configured to perform a corresponding first statistical operation based on the preset real-time computing engine and a commodity number field corresponding to each of the traffic access logs in the traffic access log set, to obtain a corresponding first log statistics result; each of the traffic access logs includes a corresponding preset traffic reporting business system identifier field and the commodity number field;

[0012] The second log statistics unit is configured to perform a corresponding second statistical operation based on the preset real-time computing engine and a preset time window on each of the traffic access logs in the traffic access log set, to obtain a corresponding second log statistics result.

[0013] Optionally, the log statistics judgment module comprises:

[0014] The first hot spot traffic judgment unit is configured to judge whether there is hot spot traffic currently based on a first preset threshold and the first log statistics result.

[0015] The second hot spot traffic judgment unit is configured to judge whether there is hot spot traffic currently based on a second preset threshold and the second log statistics result.

[0016] Optionally, the hot spot traffic identification and early warning system further comprises:

[0017] The cleaning storage module is configured to perform a corresponding cleaning operation on the obtained log statistics result based on a preset traffic cleaning rule, and store the cleaned log statistics result into a preset relational database management system.

[0018] Optionally, the hot spot traffic identification and early warning system further comprises:

[0019] The traffic pushing module is configured to perform a corresponding traffic pushing operation based on a traffic subscription system list and the cleaned log statistics result obtained from a preset traffic subscription center and the preset relational database management system respectively.

[0020] Optionally, the hot spot traffic early warning module comprises:

[0021] The first traffic early warning unit is configured to perform a corresponding first early warning information sending operation to a preset traffic alarm communication group based on a preset early warning rule when it is judged that there is hot spot traffic currently, so that a corresponding traffic subscription business system receives corresponding first early warning information and implements corresponding defense measures.

[0022] And / or, a second traffic early warning unit, configured to, when it is determined that there is currently hotspot traffic, directly perform a second early warning information sending operation based on the preset early warning rule to the corresponding traffic subscription service system, so that the traffic subscription service system implements the corresponding defense measures after receiving the corresponding second early warning information.

[0023] Optionally, the log collection module comprises:

[0024] A log collection unit is configured to perform corresponding log collection operations on each of the currently generated traffic access logs based on the preset timing collection time point and the preset asynchronous collector.

[0025] In a second aspect, the present application provides a hotspot traffic identification and early warning method, applied to a preset hotspot traffic platform, comprising:

[0026] The business requests reported by each preset traffic reporting service system through a preset channel are recorded in the form of logs to obtain a plurality of traffic access logs.

[0027] The preset asynchronous collector performs corresponding log collection operations on each of the currently generated traffic access logs to obtain a corresponding traffic access log set.

[0028] Based on a preset real-time computing engine and a preset statistical rule, the traffic access log set is subjected to corresponding statistical operations, and based on the obtained log statistical result and the corresponding preset threshold, it is determined whether there is currently hotspot traffic.

[0029] When it is determined that there is currently hotspot traffic, a corresponding early warning information sending operation is performed based on a preset early warning rule, so that the corresponding traffic subscription service system implements corresponding defense measures after receiving the corresponding early warning information.

[0030] In a third aspect, the present application provides an electronic device, comprising:

[0031] A memory is configured to save a computer program.

[0032] A processor is configured to execute the computer program to implement the steps of the aforementioned hotspot traffic identification and early warning method.

[0033] In a fourth aspect, the present application provides a computer readable storage medium for saving a computer program, which is executed by a processor to implement the steps of the aforementioned hotspot traffic identification and early warning method.

[0034] It can be seen that in the present application, the traffic record module is used to record the service requests reported by each preset traffic to the service system through the preset channel in the form of a log to obtain a plurality of traffic access logs; the log collection module is used to perform corresponding log collection operations on each of the currently generated traffic access logs through a preset asynchronous collector to obtain a corresponding traffic access log set; the log statistical judgment module is used to perform corresponding statistical operations on the traffic access log set based on a preset real-time calculation engine and a preset statistical rule, and to judge whether there is hot traffic currently based on the obtained log statistical result and the corresponding preset threshold; the hot traffic early warning module is used to perform corresponding early warning information sending operations based on a preset early warning rule when it is determined that there is hot traffic currently, so that the corresponding traffic subscription service system implements corresponding defense measures after receiving the corresponding early warning information. The present application records the service requests reported by each preset traffic to the service system through the preset channel in the form of a log, and judges whether there is hot traffic currently based on the obtained log statistical result and the corresponding preset threshold, so as to perform corresponding early warning information sending operations when there is hot traffic, so that the corresponding traffic subscription service system implements corresponding defense measures after receiving the corresponding early warning information. In this way, the stability of the transaction link can be effectively improved, and the user experience can be improved. BRIEF DESCRIPTION OF DRAWINGS

[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description are only embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of the provided drawings.

[0036] Figure 1 A hot traffic identification and early warning system structure schematic diagram is provided for the present application.

[0037] Figure 2 A role function schematic diagram of a hot traffic identification and early warning system is provided for the present application.

[0038] Figure 3 A traffic record module schematic diagram is provided for the present application.

[0039] Figure 4 A log collection module schematic diagram is provided for the present application.

[0040] Figure 5 A log statistical judgment module schematic diagram is provided for the present application.

[0041] Figure 6 A whole architecture schematic diagram of a hot traffic identification and early warning system is provided for the present application.

[0042] Figure 7 A hotspot traffic identification and early warning method flow chart is provided for the present application;

[0043] Figure 8 An electronic device structure diagram is provided for the present application. DETAILED DESCRIPTION

[0044] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of protection of the present application.

[0045] Currently, when the upstream system is subjected to traffic impact, the downstream system does not actively defend in advance, but can only passively wait for the arrival of traffic, especially some unexpected traffic that cannot be predicted in advance. This will cause a large area of problems on the entire transaction link system due to the huge traffic, and cause the recovery time of the entire link system to be very slow. Therefore, the present application provides a hotspot traffic identification and early warning system, which can effectively improve the stability of the transaction link.

[0046] Referring to Figure 1 The embodiments of the present application disclose a hotspot traffic identification and early warning system applied to a preset hotspot traffic platform, which comprises a traffic record module 11, a log collection module 12, a log statistical judgment module 13, and a hotspot traffic early warning module 14.

[0047] The traffic record module 11 is used for recording the service requests reported by each preset traffic reporting business system through a preset channel in the form of logs to obtain a plurality of traffic access logs.

[0048] Specifically, in combination with Figure 2As shown, in the embodiment, the hotspot traffic identification and early warning system is a system constructed based on a distributed architecture. It is considered that when any business system reports traffic, it will pass through any one of the channels in the web (World Wide Web, global local area network) layer nginx (engine x, a high-performance HTTP and reverse proxy web server), the distributed PRC (Remote Procedure Call, remote procedure call protocol) calling dubbo (an open source distributed service framework) layer, and the distributed cache redis (Remote Dictionary Server, remote dictionary service) layer. Therefore, by pre-configuring corresponding traffic recording modules in the above three channels, the business requests reported by the preset traffic reporting business system through the corresponding preset channels are recorded in the form of logs to obtain a plurality of traffic access logs. It can be understood that the preset channels include the nginx in the web layer, the distributed PRC calling dubbo layer, and the distributed cache redis layer.

[0049] It should be understood that in combination with Figure 3 As shown, in the embodiment of the application, there are a plurality of transaction links. For the business system on each transaction link, there is a corresponding upstream traffic reporting system and a downstream subscription system. The upstream traffic reporting system serves as a traffic reporter, that is, a preset traffic reporting business system. The downstream subscription system serves as a traffic subscriber, that is, a traffic subscription business system. The preset traffic reporting business system can register a reporting source and report traffic. The traffic subscription business system can receive early warning information. The management platform is the hub platform of the hotspot traffic identification and early warning system and is mainly responsible for traffic management, rule management, traffic reporting business system management, subscription management, etc.

[0050] The log collection module 12 is configured to perform corresponding log collection operations on the currently generated traffic access logs based on the preset asynchronous collector to obtain a corresponding traffic access log set.

[0051] In the embodiment, in combination with Figure 4 As shown, the log collection module can specifically include a log collection unit configured to perform corresponding log collection operations on the currently generated traffic access logs based on the preset timing collection time point and the preset asynchronous collector. The preset timing collection time point can be set based on actual needs.

[0052] The log statistical judgment module 13 is configured to perform corresponding statistical operations on the traffic access log set based on a preset real-time calculation engine and a preset statistical rule, and to judge whether there is hotspot traffic based on the obtained log statistical result and the corresponding preset threshold.

[0053] In this embodiment, in combination with Figure 5 As shown in the figure, the log statistics judgment module can specifically include: a first log statistics unit, configured to perform a corresponding first statistical operation based on a preset real-time computing engine and a product number field corresponding to each of the traffic access logs in the traffic access log set, to obtain a corresponding first log statistics result; each of the traffic access logs includes a corresponding preset traffic reporting business system identifier field and the product number field; a second log statistics unit, configured to perform a corresponding second statistical operation on each of the traffic access logs in the traffic access log set based on the preset real-time computing engine and a preset time window, to obtain a corresponding second log statistics result. The preset real-time computing engine can be jstorm (an Alibaba open-source distributed real-time computing engine). It should be understood that each of the traffic access logs also includes a corresponding source field and a timestamp field. The preset time window can be preconfigured based on actual needs.

[0054] It should be understood that the log statistics judgment module can specifically include: a first hot spot traffic judgment unit, configured to judge whether there is hot spot traffic currently based on a first preset threshold and the first log statistics result; a second hot spot traffic judgment unit, configured to judge whether there is hot spot traffic currently based on a second preset threshold and the second log statistics result. That is, when greater than the first preset threshold or the second preset threshold, it is determined that there is hot spot traffic currently.

[0055] Further, in combination with Figure 6 As shown in the figure, it can specifically further include: a cleaning storage module, configured to perform a corresponding cleaning operation on the obtained log statistics result based on a preset traffic cleaning rule, and store the cleaned log statistics result in a preset relational database management system. A traffic pushing module, configured to perform a corresponding traffic pushing operation based on a traffic subscription system list and the cleaned log statistics result obtained from a preset traffic subscription center and the preset relational database management system respectively. The preset relational database management system can be mysql (a relational database management system developed by the Swedish MySQL AB company).

[0056] The hot spot traffic early warning module 14 is configured to perform a corresponding early warning information sending operation based on a preset early warning rule when it is determined that there is hot spot traffic currently, so that the corresponding traffic subscription business system receives the corresponding early warning information and implements corresponding defense measures.

[0057] In the embodiment, the hotspot traffic early warning module can specifically include: a first traffic early warning unit, configured to, when it is determined that there is hotspot traffic currently, perform a corresponding first early warning information sending operation on a preset traffic warning communication group based on a preset early warning rule, so that the corresponding traffic subscription business system implements corresponding defense measures after receiving the corresponding first early warning information; and / or a second traffic early warning unit, configured to, when it is determined that there is hotspot traffic currently, perform a corresponding second early warning information sending operation on the corresponding traffic subscription business system based on the preset early warning rule, so that the traffic subscription business system implements corresponding defense measures after receiving the corresponding second early warning information. In this way, the corresponding traffic subscription business system downstream can be predicted in advance, so that the traffic subscription business system can perform corresponding defense based on its actual situation. In addition, partial degradation measures can also be taken, or corresponding hotspot commodity local caching operations can be performed, or hotspot commodity traffic isolation and flow limiting protection measures can be taken in advance to prevent downtime caused by sudden traffic.

[0058] As can be seen, in the embodiment of the application, the traffic record module is configured to record the service requests reported by each preset traffic reporting business system through a preset channel in the form of a log to obtain a plurality of traffic access logs; the log collection module is configured to perform a corresponding log collection operation on each of the traffic access logs generated currently through a preset asynchronous collector to obtain a corresponding traffic access log set; the log statistical judgment module is configured to perform a corresponding statistical operation on the traffic access log set based on a preset real-time calculation engine and a preset statistical rule, and determine whether there is hotspot traffic currently based on the obtained log statistical result and a corresponding preset threshold; and the hotspot traffic early warning module is configured to, when it is determined that there is hotspot traffic currently, perform a corresponding early warning information sending operation based on a preset early warning rule, so that the corresponding traffic subscription business system implements corresponding defense measures after receiving the corresponding early warning information. The application records the service requests reported by each preset traffic reporting business system through a preset channel in the form of a log, determines whether there is hotspot traffic currently based on the obtained log statistical result and a corresponding preset threshold, and performs a corresponding early warning information sending operation when there is, so that the corresponding traffic subscription business system implements corresponding defense measures after receiving the corresponding early warning information. In this way, the downtime caused by sudden traffic can be effectively prevented, the stability of the transaction link is improved, and the user experience is improved.

[0059] Referring to Figure 7 The embodiment of the application also discloses a hotspot traffic identification and early warning method applied to a preset hotspot traffic platform, including:

[0060] In step S11, the service requests reported by each preset traffic reporting service system through a preset channel are recorded in a log manner to obtain a plurality of traffic access logs.

[0061] In step S12, a corresponding log collection operation is performed on the currently generated traffic access logs by a preset asynchronous collector to obtain a corresponding traffic access log set.

[0062] In step S13, a corresponding statistical operation is performed on the traffic access log set based on a preset real-time computing engine and a preset statistical rule, and whether there is a hot traffic currently is judged based on the obtained log statistical result and a corresponding preset threshold.

[0063] In step S14, when it is determined that there is a hot traffic currently, a corresponding early warning information sending operation is performed based on a preset early warning rule, so that the corresponding traffic subscription service system receives the corresponding early warning information and implements a corresponding defense measure.

[0064] The more specific working processes of the above steps can refer to the corresponding contents disclosed in the foregoing embodiments, and will not be described here.

[0065] As can be seen, in the present application, the service requests reported by each preset traffic reporting service system through a preset channel are recorded in a log manner to obtain a plurality of traffic access logs; a corresponding log collection operation is performed on the currently generated traffic access logs by a preset asynchronous collector to obtain a corresponding traffic access log set; a corresponding statistical operation is performed on the traffic access log set based on a preset real-time computing engine and a preset statistical rule, and whether there is a hot traffic currently is judged based on the obtained log statistical result and a corresponding preset threshold; when it is determined that there is a hot traffic currently, a corresponding early warning information sending operation is performed based on a preset early warning rule, so that the corresponding traffic subscription service system receives the corresponding early warning information and implements a corresponding defense measure. The present application records the service requests reported by each preset traffic reporting service system through a preset channel in a log manner by statistics, and judges whether there is a hot traffic currently based on the obtained log statistical result and a corresponding preset threshold, so that when there is, a corresponding early warning information sending operation is performed, so that the corresponding traffic subscription service system receives the corresponding early warning information and implements a corresponding defense measure. In this way, the downtime caused by sudden traffic can be effectively avoided, the stability of the transaction link is improved, and the user experience is improved.

[0066] Further, the present application also discloses an electronic device, Figure 8 The electronic device 20 is shown in the structure diagram according to an exemplary embodiment, and the contents in the diagram cannot be considered as any limitation on the use range of the present application.

[0067] Figure 8 A structural schematic diagram of an electronic device 20 is provided in the embodiments of the present application. The electronic device 20 can specifically include at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25 and a communication bus 26. The memory 22 is configured to store a computer program, and the processor 21 is configured to load and execute the computer program to implement the related steps in the hotspot traffic identification and early warning method disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in the embodiments of the present application can be specifically an electronic computer.

[0068] In the embodiments of the present application, the power supply 23 is configured to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 is capable of creating a data transmission channel between the electronic device 20 and external devices, and the communication protocol followed by the communication interface 24 can be any communication protocol applicable to the technical solution of the present application, which is not specifically limited herein; the input / output interface 25 is configured to obtain external input data or output data to the outside, and the specific interface type can be selected according to the specific application needs, which is not specifically limited herein.

[0069] In addition, the memory 22 as a carrier for resource storage can be a read-only memory, a random access memory, a magnetic disk or an optical disk, etc., and the resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage mode can be temporary storage or permanent storage.

[0070] The operating system 221 is configured to manage and control each hardware device on the electronic device 20 and the computer program 222, and can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program capable of completing the hotspot traffic identification and early warning method executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 can further include a computer program capable of completing other specific work.

[0071] Further, the present application further discloses a computer readable storage medium for storing a computer program; wherein the computer program is executed by a processor to implement the foregoing disclosed hotspot traffic identification and early warning method. The specific steps of the method can refer to the corresponding contents disclosed in the foregoing embodiments, which will not be described here.

[0072] The embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts of each embodiment can be referred to each other. For the device disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and the related parts can refer to the method part.

[0073] Those skilled in the art will further appreciate that the units and algorithm steps of the various examples described in connection with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or combinations of both. To clearly illustrate this interchangeability of hardware and software, various examples have been described herein in terms of their functionality, which has been described generally and symbolically in flow charts. Having thus described the functionality of the examples, a person of ordinary skill in the art will be able to implement such functionality in hardware and / or software, and will recognize that the bounds of the examples are not limited by one approach or the other. The various examples can be realized in a centralized fashion in one computer system or network, or in a distributed fashion where different elements are spread across several computer systems or sub-networks. Any kind of computer system or other apparatus adapted for carrying out the methods described herein is suited. A typical combination of hardware and software could be a general purpose computer system with a computer program that, when being loaded and executed, carries out the methods described herein.

[0074] The steps of a method or algorithm described in connection with the embodiments disclosed herein can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module can reside in random access memory (RAM), flash memory, read-only memory (ROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), registers, hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. In the alternative, hard disk can be used as a storage medium.

[0075] Finally, it should be noted that the terms "first", "second", and the like, herein do not denote any order, quantity, combination, or importance, but rather are used to distinguish one element from another, and do not imply singular or plural. Moreover, the terms "include", "have", or any other variant thereof are intended to encompass non-exclusive inclusions, such that processes, methods, articles, or apparatuses that comprise a set of elements not expressly listed are also within the scope of the present application. In addition, the articles "a" and "an" are used herein to refer to one or to more than one (i.e., to one or at least one) of the grammatical object of the article. By way of example, "an element" means one element or one or more elements.

[0076] The above detailed description of the technical solutions provided by the present application has been described in detail, and the principles and implementation modes of the present application have been described in the text. The above description of the examples is only used to help understand the method and core idea of the present application; at the same time, for those skilled in the art, according to the idea of the present application, the specific implementation mode and application range will be changed; in view of the above, the content of the description should not be understood as limiting the present application.

Claims

1. A hotspot traffic identification and early warning system, characterized in that, Applied to pre-defined hotspot traffic platforms, including: The traffic recording module is used to record the business requests reported by each preset traffic reporting business system through preset channels in the form of logs to obtain several traffic access logs; the preset channels include nginx at the global local area network layer, the distributed remote procedure call protocol calling the dubbo layer, and the distributed cache remote dictionary service layer; The log collection module is used to perform corresponding log collection operations on each of the currently generated traffic access logs through a preset asynchronous collector, so as to obtain the corresponding traffic access log set; The log statistics and judgment module is used to perform corresponding statistical operations on the traffic access log set based on the preset real-time computing engine and preset statistical rules, and to determine whether there is hot traffic based on the obtained log statistics results and the corresponding preset threshold. The hotspot traffic warning module is used to send corresponding warning information based on preset warning rules when it is determined that there is hotspot traffic, so that the corresponding traffic subscription business system can implement corresponding defensive measures after receiving the warning information. The log statistics and judgment module includes: The first log statistics unit is used to perform a corresponding first statistical operation based on a preset real-time computing engine and the product number field corresponding to each of the traffic access logs in the traffic access log set, to obtain a corresponding first log statistics result; wherein, each of the traffic access logs includes a corresponding preset traffic reporting business system identifier field and the product number field; The second log statistics unit is used to perform corresponding second statistical operations on each of the traffic access logs in the traffic access log set based on the preset real-time computing engine and the preset time window, and obtain corresponding second log statistics results. The log statistics and judgment module includes: The first hotspot traffic determination unit is used to determine whether there is hotspot traffic based on a first preset threshold and the first log statistics result. The second hotspot traffic determination unit is used to determine whether there is hotspot traffic based on the second preset threshold and the second log statistics result.

2. The hotspot traffic identification and early warning system according to claim 1, characterized in that, Also includes: The cleaning and storage module is used to perform corresponding cleaning operations on the obtained log statistics results based on preset traffic cleaning rules, and store the cleaned log statistics results in a preset relational database management system.

3. The hotspot traffic identification and early warning system according to claim 2, characterized in that, Also includes: The traffic push module is used to perform corresponding traffic push operations based on the list of traffic subscription systems obtained from the preset traffic subscription center and the preset relational database management system, respectively, and the cleaned log statistics results.

4. The hotspot traffic identification and early warning system according to claim 1, characterized in that, The hotspot traffic early warning module includes: The first traffic warning unit is used to send the corresponding first warning information to the preset traffic alarm communication group based on the preset warning rules when it is determined that there is currently hot traffic, so that the corresponding traffic subscription business system can implement corresponding defense measures after receiving the corresponding first warning information. And / or, the second traffic warning unit is used to, when it is determined that there is currently hot traffic, directly send the corresponding second warning information to the corresponding traffic subscription service system based on the preset warning rules, so that the traffic subscription service system can implement the corresponding defense measures after receiving the corresponding second warning information.

5. The hotspot traffic identification and early warning system according to claim 1, characterized in that, The log collection module includes: The log collection unit is used to perform corresponding log collection operations on each of the currently generated traffic access logs based on a preset timed collection point and a preset asynchronous collector.

6. A method for identifying and issuing early warnings of hotspot traffic, characterized in that, Applied to pre-defined hotspot traffic platforms, including: The business requests reported by each preset traffic reporting business system through preset channels are recorded in the form of logs to obtain several traffic access logs; the preset channels include nginx at the global local area network layer, the distributed remote procedure call protocol calling the dubbo layer, and the distributed cache remote dictionary service layer; By using a preset asynchronous collector, corresponding log collection operations are performed on each of the currently generated traffic access logs to obtain the corresponding traffic access log set; Based on a preset real-time computing engine and preset statistical rules, corresponding statistical operations are performed on the traffic access log set, and based on the obtained log statistical results and the corresponding preset threshold, it is determined whether there is hot traffic. When a hot spot of traffic is identified, the corresponding warning information is sent based on the preset warning rules so that the corresponding traffic subscription business system can receive the warning information and implement the corresponding defense measures. The step of performing corresponding statistical operations on the traffic access log set based on a preset real-time computing engine and preset statistical rules includes: Based on the preset real-time computing engine and the product number field corresponding to each of the traffic access logs in the traffic access log set, the corresponding first statistical operation is performed to obtain the corresponding first log statistical result; wherein, each of the traffic access logs includes the corresponding preset traffic reporting business system identifier field and the product number field; Based on the preset real-time computing engine and the preset time window, perform corresponding second statistical operations on each of the traffic access logs in the traffic access log set to obtain corresponding second log statistical results; The method of determining whether there is current hotspot traffic based on the obtained log statistics results and the corresponding preset thresholds includes: Based on the first preset threshold and the first log statistics result, it is determined whether there is currently hotspot traffic; Based on the second preset threshold and the second log statistics results, it is determined whether there is currently hotspot traffic.

7. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor is used to execute the computer program to implement the hotspot traffic identification and early warning method as described in claim 6.

8. A computer-readable storage medium, characterized in that, Used to store a computer program, which, when executed by a processor, implements the hotspot traffic identification and early warning method as described in claim 6.

Citation Information

Patent Citations

  • Hotspot access request processing method, server, terminal and program product

    CN113225338A

  • Hotspot request detection system, method and device, server and medium

    CN113765978A