Service anomaly detection method, apparatus, device, and medium

By superimposing a preset analog signal and the original signal and using a target amplification bypass to process the signal difference deviation, the problem of high detection complexity in existing technologies is solved, and highly sensitive service anomaly detection is achieved.

CN116866023BActive Publication Date: 2026-05-19CETC CYBERSPACE SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CETC CYBERSPACE SECURITY TECH CO LTD
Filing Date
2023-06-30
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing service anomaly detection solutions struggle to balance detection complexity and sensitivity, necessitating improved detection accuracy while reducing detection difficulty.

Method used

By superimposing a preset analog signal with the original service signal, and utilizing the target amplification bypass and signal difference deviation, it is possible to determine whether there is an anomaly in the service thread and avoid interference signal amplification.

Benefits of technology

It improves the sensitivity of service anomaly detection, reduces the complexity of detection, and enables early identification of subtle anomalies without affecting normal processing flow.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116866023B_ABST
    Figure CN116866023B_ABST
Patent Text Reader

Abstract

The application discloses a service exception detection method and device, equipment and medium, and relates to the technical field of safe operation supervision. The method comprises the following steps: superimposing a preset simulation signal and an original service signal to obtain a superimposed signal; inputting the original service signal and the superimposed signal into a target service thread to obtain a first output signal of the original service signal and a second output signal of the superimposed signal, and determining an actual signal difference value between the first output signal and the second output signal; obtaining a first deviation between the actual signal difference value and an expected signal difference value, obtaining an actual processed signal by using a target amplification bypass, the first deviation, the original service signal and the target service thread, obtaining a second deviation between the actual processed signal and an expected processed signal; and determining whether the target service thread is abnormal according to the relationship between the second deviation and a preset abnormal condition. The sensitivity of the service exception detection process can be improved, and the complexity of the service exception detection process can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of safe operation monitoring technology, and in particular to methods, devices, equipment and media for detecting service anomalies. Background Technology

[0002] Service anomaly detection and response orchestration technology, also known as Security Orchestration Automation and Response (SOAR), is a cutting-edge approach to service security governance and is now widely used in real-world systems. Existing service anomaly detection solutions rely on specific signal detection or log keyword extraction as alarm triggers, or manual checks to initiate tasks for specific events, followed by analysis and processing through a series of calculations or auxiliary methods. However, current technologies are passive and can only be assessed when an anomaly is very obvious. They also require the design of specific data collection and calculation models, and the detection accuracy depends entirely on the model design, resulting in high detection complexity.

[0003] In summary, how to improve the sensitivity while reducing the complexity of service anomaly detection is a problem that needs to be solved in this field. Summary of the Invention

[0004] In view of this, the purpose of this invention is to provide a service anomaly detection method, apparatus, device, and medium that can improve the sensitivity and reduce the complexity of service anomaly detection. The specific solution is as follows:

[0005] Firstly, this application discloses a service anomaly detection method, including:

[0006] The original service signal and the preset analog signal are acquired, and the preset analog signal is superimposed on the original service signal to obtain the superimposed signal;

[0007] The original service signal and the superimposed signal are respectively input to the target service thread to obtain the first output signal of the original service signal and the second output signal of the superimposed signal, and the actual signal difference between the first output signal and the second output signal is determined.

[0008] The first deviation between the actual signal difference and the expected signal difference is obtained, and the actual processed signal is obtained by using the target amplification bypass, the first deviation, the original service signal and the target service thread. Then, the second deviation between the actual processed signal and the expected processed signal is obtained.

[0009] Based on the relationship between the second deviation and the preset abnormal conditions, it is determined whether the target service thread is abnormal.

[0010] Optionally, the step of inputting the original service signal and the superimposed signal to the target service thread respectively to obtain a first output signal of the original service signal and a second output signal of the superimposed signal includes:

[0011] The original service signal and the superimposed signal are respectively input to the upstream node in the target service thread, so that the target service thread can process the service signal and the superimposed signal accordingly to obtain the first output signal of the original service signal and the second output signal of the superimposed signal output by the downstream node in the target service thread.

[0012] Optionally, obtaining the actual processed signal using the target amplification bypass, the first deviation, the original service signal, and the target service thread includes:

[0013] Determine whether the first deviation meets the preset abnormal conditions;

[0014] If not satisfied, the actual processed signal is obtained by using the target amplification bypass, the first deviation, the original service signal, and the target service thread.

[0015] If the conditions are met, the target service thread is determined to be abnormal.

[0016] Optionally, determining whether the target service thread is abnormal based on the relationship between the second deviation and preset abnormal conditions includes:

[0017] If the second deviation satisfies the preset abnormal condition, then the target service thread is determined to be abnormal.

[0018] If the second deviation does not meet the preset abnormal condition, then it is determined that the target service thread is not abnormal.

[0019] Optionally, after determining that the target service thread is abnormal, the method further includes:

[0020] A preset handling procedure is triggered to eliminate the abnormal situation of the target service thread.

[0021] Secondly, this application discloses a service anomaly detection device, comprising:

[0022] A signal overlay module is used to acquire the original service signal and a preset analog signal, and to overlay the preset analog signal with the original service signal to obtain the overlaid signal;

[0023] The signal difference determination module is used to input the original service signal and the superimposed signal to the target service thread respectively, so as to obtain the first output signal of the original service signal and the second output signal of the superimposed signal, and determine the actual signal difference between the first output signal and the second output signal;

[0024] The deviation acquisition module is used to acquire a first deviation between the actual signal difference and the expected signal difference, and to obtain the actual processed signal using the target amplification bypass, the first deviation, the original service signal and the target service thread, and then acquire a second deviation between the actual processed signal and the expected processed signal.

[0025] The anomaly determination module is used to determine whether the target service thread has an anomaly based on the relationship between the second deviation and the preset anomaly conditions.

[0026] Optionally, the anomaly determination module includes:

[0027] The first determination unit is used to determine that the target service thread is abnormal if the second deviation satisfies the relationship of the preset abnormal condition.

[0028] The second determination unit is used to determine that the target service thread is not abnormal if the second deviation does not meet the preset abnormal condition.

[0029] Optionally, the deviation acquisition module includes:

[0030] The judgment unit is used to determine whether the first deviation amount meets the preset abnormal conditions;

[0031] The first processing unit is configured to, if the conditions are not met, obtain the actual processed signal by utilizing the target amplification bypass, the first deviation, the original service signal, and the target service thread.

[0032] The second processing unit is used to determine that the target service thread is abnormal if the conditions are met.

[0033] Thirdly, this application discloses an electronic device, including:

[0034] Memory, used to store computer programs;

[0035] A processor is configured to execute the computer program to implement the steps of the aforementioned disclosed service anomaly detection method.

[0036] Fourthly, this application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the steps of the aforementioned disclosed service anomaly detection method.

[0037] As can be seen, this application acquires the original service signal and a preset analog signal, and superimposes the preset analog signal with the original service signal to obtain a superimposed signal; the original service signal and the superimposed signal are respectively input to the target service thread to obtain a first output signal of the original service signal and a second output signal of the superimposed signal, and the actual signal difference between the first output signal and the second output signal is determined; a first deviation between the actual signal difference and the expected signal difference is acquired, and the actual processed signal is obtained using the target amplification bypass, the first deviation, the original service signal, and the target service thread; then a second deviation between the actual processed signal and the expected processed signal is acquired; based on the relationship between the second deviation and preset abnormal conditions, it is determined whether the target service thread has an abnormality. Therefore, after obtaining the first deviation, this application cannot determine whether the first deviation is caused by a minor anomaly or by interference signals. Therefore, it uses the target amplification bypass, the first deviation, the original service signal, and the target service thread to obtain the actual processed signal and determine the second deviation between the actual processed signal and the expected processed signal. If there is an anomaly in the target service thread, the target amplification bypass will amplify the anomaly, but will not amplify the interference signal of the target service thread. Therefore, the existence of an anomaly in the target service thread can be determined based on the relationship between the second deviation and the preset anomaly conditions. In other words, this application amplifies service anomalies through the target amplification bypass, which can improve the sensitivity of service anomaly detection. Thus, simple logic can detect whether there is an anomaly without designing a complex data model for detection, thereby reducing the difficulty of service anomaly detection. Attached Figure Description

[0038] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0039] Figure 1 This is a flowchart of a service anomaly detection method disclosed in this application;

[0040] Figure 2 This is a flowchart of a specific service anomaly detection method disclosed in this application;

[0041] Figure 3 This is a schematic diagram of a specific testing process disclosed in this application;

[0042] Figure 4This is a schematic diagram of a specific target service thread disclosed in this application;

[0043] Figure 5 This is a schematic diagram of a specific service anomaly detection disclosed in this application;

[0044] Figure 6 This is a schematic diagram of the structure of a service anomaly detection device disclosed in this application;

[0045] Figure 7 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation

[0046] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.

[0047] Service anomaly detection and response orchestration technology, also known as "security orchestration and automatic response," is a cutting-edge approach to service security governance and is now widely used in practical systems. Existing service anomaly detection solutions use methods such as specific signal detection or log keyword extraction as alarm triggers, or rely on manual checks to initiate a task for a specific event, followed by analysis and processing through a series of calculations or auxiliary methods. However, existing technologies are passive and can only be assessed when an anomaly is very obvious. They also require the design of specific data collection and calculation models, and the accuracy of detection depends entirely on the model design, resulting in high detection complexity.

[0048] Therefore, this application provides a service anomaly detection scheme that can improve the sensitivity and reduce the complexity of the service anomaly detection process.

[0049] See Figure 1 As shown in the figure, this application discloses a service anomaly detection method, including:

[0050] Step S11: Obtain the original service signal and the preset analog signal, and superimpose the preset analog signal with the original service signal to obtain the superimposed signal.

[0051] In this embodiment, when the target service thread processes the task, after the pre-collected original service signal is input to the target service thread, the target service thread will start a series of pre-set processes, that is, to process the original service signal accordingly, and finally obtain the first output signal of the original service signal. Since the target service thread is like a black box and cannot predict the collected original service signal, it is impossible to determine whether there is an anomaly in the service based solely on the original service signal and the first output signal. Therefore, the known preset analog signal and the original service signal are superimposed to obtain the superimposed signal, so that subsequent detection can be performed based on the difference between the first output signal of the original service signal and the second output signal of the superimposed signal.

[0052] Step S12: Input the original service signal and the superimposed signal to the target service thread respectively to obtain the first output signal of the original service signal and the second output signal of the superimposed signal, and determine the actual signal difference between the first output signal and the second output signal.

[0053] Understandably, since the preset analog signal is artificially generated, i.e. known and controllable, after obtaining the actual signal difference between the first output signal and the second output signal, the service anomaly detection can be performed using the first deviation between the actual signal difference and the expected signal difference.

[0054] Step S13: Obtain the first deviation between the actual signal difference and the expected signal difference, and use the target amplification bypass, the first deviation, the original service signal and the target service thread to obtain the actual processed signal, and then obtain the second deviation between the actual processed signal and the expected processed signal.

[0055] To determine whether a service is abnormal, the first deviation between the actual signal difference and the expected signal difference is used. That is, if the service is abnormal, there will be a deviation between the actual signal difference and the expected signal difference. However, there are usually interference signals in the target service thread, which will also cause a deviation between the actual signal difference and the expected signal difference. Since the deviation caused by the minor abnormality and the deviation caused by the interference signal may be small at present, it is not possible to determine whether the target service thread is abnormal based on the small first deviation. In this embodiment, the target amplification bypass is used to process the first deviation. Therefore, if the service is abnormal, the target amplification bypass will amplify the minor abnormality, but it will not affect the normal processing flow of the target service thread, nor will it amplify the interference signal.

[0056] In this embodiment, obtaining the actual processed signal using the target amplification bypass, the first deviation, the original service signal, and the target service thread includes: determining whether the first deviation meets a preset anomaly condition; if not, obtaining the actual processed signal using the target amplification bypass, the first deviation, the original service signal, and the target service thread; if it does, determining that the target service thread has an anomaly. It can be understood that if there is a minor anomaly in the service, the first deviation does not meet the preset anomaly condition; if there is a significant anomaly, the first deviation meets the preset anomaly condition. The preset anomaly condition can be greater than a preset threshold. For example, if the first deviation is 0.08 and the preset threshold is 0.1, the first deviation does not meet the preset anomaly condition. Alternatively, if the first deviation is 0.2 and the preset threshold is 0.1, the first deviation meets the preset threshold, and the service is determined to have an anomaly. Furthermore, the preset threshold can have multiple levels, in which case the preset anomaly condition can be greater than a first preset threshold and less than a second preset threshold. If the deviation is greater than or equal to the second preset threshold, it is directly determined that the service is abnormal. For example, if the first preset threshold is 0.1 and the second preset threshold is 0.3, when the first deviation is 0.12, the first deviation is greater than the first preset threshold of 0.1 and less than the second preset threshold of 0.3. That is to say, the first deviation may be caused by interference signals or by minor abnormalities. In order to further determine, the subsequent step of using target amplification bypass to obtain the actual processed signal can be performed. When the first deviation is 0.4, the first deviation is greater than the second preset threshold, and it can be directly determined that the service is abnormal.

[0057] In this embodiment, signals that deviate slightly from the normal range (average value), i.e., the first deviation, are converted and input to the target service thread. In other words, a specific input is artificially created. If there is no problem with the system, the target service thread will automatically adjust and digest the input as negative feedback. However, if there is indeed a problem with the system, the result will be that the subtle changes are treated as positive feedback and amplified by the target amplification bypass, so that the second deviation obtained satisfies the preset abnormal conditions.

[0058] Step S14: Determine whether the target service thread is abnormal based on the relationship between the second deviation and the preset abnormal conditions.

[0059] Alternatively, in this embodiment, determining whether the target service thread is abnormal based on the relationship between the second deviation and a preset abnormality condition includes: if the second deviation satisfies the relationship of the preset abnormality condition, then the target service thread is determined to be abnormal; if the second deviation does not satisfy the relationship of the preset abnormality condition, then the target service thread is determined not to be abnormal. For example, the preset abnormality condition is that the second deviation is greater than 0.5. When the second deviation is 0.7, the preset abnormality condition is satisfied, and the target service thread is determined to be abnormal; when the second deviation is 0.1, the preset abnormality condition is not satisfied, and the target service thread is determined not to be abnormal.

[0060] In this embodiment, after determining that the target service thread is abnormal, the process further includes: triggering a preset handling procedure to eliminate the abnormal situation of the target service thread. It is understood that when the target service thread is abnormal, it is necessary to eliminate the abnormal situation. The specific elimination procedure can be preset according to the specific circumstances to restore service balance.

[0061] As can be seen, this application acquires the original service signal and a preset analog signal, and superimposes the preset analog signal with the original service signal to obtain a superimposed signal; the original service signal and the superimposed signal are respectively input to the target service thread to obtain a first output signal of the original service signal and a second output signal of the superimposed signal, and the actual signal difference between the first output signal and the second output signal is determined; a first deviation between the actual signal difference and the expected signal difference is acquired, and the actual processed signal is obtained using the target amplification bypass, the first deviation, the original service signal, and the target service thread; then a second deviation between the actual processed signal and the expected processed signal is acquired; based on the relationship between the second deviation and preset abnormal conditions, it is determined whether the target service thread has an abnormality. Therefore, after obtaining the first deviation, this application cannot determine whether the first deviation is caused by a minor anomaly or by interference signals. Therefore, it uses the target amplification bypass, the first deviation, the original service signal, and the target service thread to obtain the actual processed signal and determine the second deviation between the actual processed signal and the expected processed signal. If there is an anomaly in the target service thread, the target amplification bypass will amplify the anomaly, but will not amplify the interference signal of the target service thread. Therefore, the existence of an anomaly in the target service thread can be determined based on the relationship between the second deviation and the preset anomaly conditions. In other words, this application amplifies service anomalies through the target amplification bypass, which can improve the sensitivity of service anomaly detection. Thus, simple logic can detect whether there is an anomaly without designing a complex data model for detection, thereby reducing the difficulty of service anomaly detection.

[0062] See Figure 2 As shown in the figure, this application discloses a specific service anomaly detection method, including:

[0063] Step S21: Input the original service signal and the superimposed signal to the upstream node in the target service thread, so that the target service thread can process the service signal and the superimposed signal accordingly to obtain the first output signal of the original service signal and the second output signal of the superimposed signal output by the downstream node in the target service thread.

[0064] In this embodiment, upstream and downstream nodes are relative. For example, in a total of 5 nodes, the second node is the upstream node of the third node and also the downstream node of the first node. To determine the location of an anomaly, several nodes can be identified as target service threads in a large system. That is, the upstream node of the thread is the input node for the original service signal and the superimposed signal, and the downstream node of the thread outputs the processed signal.

[0065] Understandably, before performing service anomaly detection, it's necessary to program the target service thread based on the specific circumstances. The automatically orchestrated script is called a script. A script consists of a start node, an end node, and a series of intermediate actions. A well-programmed script can be assigned to a service thread for execution. According to the rules defined in the script, starting from the start node, each designed node can obtain input data from the output of the preceding node or from a specified external system, process this data according to regulations, form output, and pass it to subsequent nodes, until the end node completes and the thread terminates. A system is also composed of a series of processes, and these nodes also have dependencies based on their sequence; for example... Figure 3 The diagram illustrates a specific detection process. By combining automated script arrangement with the system flow and setting up detection points, the entire system's operation can be monitored to identify and troubleshoot system malfunctions. By combining the relationship between the system flow and the BPMN (Business Process Modeling Notation) flow, and utilizing the existing system logic, the abnormal positive feedback can be amplified through a bypass without affecting the system's operation. This allows for easy identification of the abnormality, and during the handling phase, corrective information can be transmitted to the system to restore it to a normal state, thus achieving the purpose of detection and automatic handling.

[0066] Step S22: Input the original service signal and the superimposed signal to the target service thread respectively to obtain the first output signal of the original service signal and the second output signal of the superimposed signal, and determine the actual signal difference between the first output signal and the second output signal.

[0067] Step S23: Obtain the first deviation between the actual signal difference and the expected signal difference, and use the target amplification bypass, the first deviation, the original service signal and the target service thread to obtain the actual processed signal, and then obtain the second deviation between the actual processed signal and the expected processed signal.

[0068] Step S24: Determine whether the target service thread is abnormal based on the relationship between the second deviation and the preset abnormal conditions.

[0069] For example Figure 4 The diagram illustrates a specific target service thread. A target service thread calculates sales profit. In normal operation, it automatically calculates the sales profit based on the input data, ensuring accuracy and validity. However, if the service thread is maliciously tampered with, the calculated data will be invalid. By intercepting the output data at the result point and comparing it with the intended correct data, it's possible to determine if the service thread is compromised. Furthermore, some attacks subtly modify data, making it difficult to detect. For example, rounding down to three decimal places may seem undetectable. However, by using positive feedback to amplify the difference between the input and output data, the tampering can be detected. Figure 5 The diagram illustrates a specific service anomaly detection method. The simulated data injection can be several times the actual business funds. As long as it is proportionally deducted during profit calculation, it will not affect the real data. If the budgeted results do not match the actual forecast results, an alarm can be issued according to the preset handling logic.

[0070] Therefore, this application utilizes the characteristic that the target amplification bypass only amplifies the anomaly but not the interference signal, which can improve the sensitivity of service anomaly detection. As a result, simple logic can detect whether an anomaly exists, reducing the complexity of service anomaly detection.

[0071] See Figure 6 As shown in the figure, this application discloses a service anomaly detection device, including:

[0072] The signal superposition module 11 is used to acquire the original service signal and the preset analog signal, and superimpose the preset analog signal with the original service signal to obtain the superimposed signal;

[0073] The signal difference determination module 12 is used to input the original service signal and the superimposed signal to the target service thread respectively to obtain the first output signal of the original service signal and the second output signal of the superimposed signal, and to determine the actual signal difference between the first output signal and the second output signal.

[0074] The deviation acquisition module 13 is used to acquire a first deviation between the actual signal difference and the expected signal difference, and to obtain the actual processed signal using the target amplification bypass, the first deviation, the original service signal and the target service thread, and then acquire a second deviation between the actual processed signal and the expected processed signal.

[0075] The anomaly determination module 14 is used to determine whether the target service thread has an anomaly based on the relationship between the second deviation amount and the preset anomaly conditions.

[0076] As can be seen, this application acquires the original service signal and a preset analog signal, and superimposes the preset analog signal with the original service signal to obtain a superimposed signal; the original service signal and the superimposed signal are respectively input to the target service thread to obtain a first output signal of the original service signal and a second output signal of the superimposed signal, and the actual signal difference between the first output signal and the second output signal is determined; a first deviation between the actual signal difference and the expected signal difference is acquired, and the actual processed signal is obtained using the target amplification bypass, the first deviation, the original service signal, and the target service thread; then a second deviation between the actual processed signal and the expected processed signal is acquired; based on the relationship between the second deviation and preset abnormal conditions, it is determined whether the target service thread has an abnormality. Therefore, after obtaining the first deviation, this application cannot determine whether the first deviation is caused by a minor anomaly or by interference signals. Therefore, it uses the target amplification bypass, the first deviation, the original service signal, and the target service thread to obtain the actual processed signal and determine the second deviation between the actual processed signal and the expected processed signal. If there is an anomaly in the target service thread, the target amplification bypass will amplify the anomaly, but will not amplify the interference signal of the target service thread. Therefore, the existence of an anomaly in the target service thread can be determined based on the relationship between the second deviation and the preset anomaly conditions. In other words, this application amplifies service anomalies through the target amplification bypass, which can improve the sensitivity of service anomaly detection. Thus, simple logic can detect whether there is an anomaly without designing a complex data model for detection, thereby reducing the difficulty of service anomaly detection.

[0077] In some specific embodiments, the anomaly determination module 13 includes:

[0078] The first determination unit is used to determine that the target service thread is abnormal if the second deviation satisfies the relationship of the preset abnormal condition.

[0079] The second determination unit is used to determine that the target service thread is not abnormal if the second deviation does not meet the preset abnormal condition.

[0080] In some specific embodiments, the deviation acquisition module 12 includes:

[0081] The judgment unit is used to determine whether the first deviation amount meets the preset abnormal conditions;

[0082] The first processing unit is configured to, if the conditions are not met, obtain the actual processed signal by utilizing the target amplification bypass, the first deviation, the original service signal, and the target service thread.

[0083] The second processing unit is used to determine that the target service thread is abnormal if the conditions are met.

[0084] Furthermore, embodiments of this application also provide an electronic device. Figure 7 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.

[0085] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Specifically, it may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the service anomaly detection method performed by the electronic device disclosed in any of the foregoing embodiments.

[0086] In this embodiment, the power supply 23 is used to provide operating voltage for various hardware devices on the electronic device; the communication interface 24 can create a data transmission channel between the electronic device and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0087] The processor 21 may include one or more processing cores, such as a quad-core processor or an octa-core processor. The processor 21 may be implemented using at least one hardware form selected from DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 21 may also include a main processor and a coprocessor. The main processor, also known as a CPU (Central Processing Unit), is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor 21 may integrate a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the screen. In some embodiments, the processor 21 may also include an AI (Artificial Intelligence) processor, which is used to handle computational operations related to machine learning.

[0088] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored on it include operating system 221, computer program 222 and data 223, etc., and the storage method can be temporary storage or permanent storage.

[0089] The operating system 221 manages and controls the various hardware devices and computer programs 222 on the electronic device to enable the processor 21 to perform calculations and processing on the massive amounts of data 223 in the memory 22. The operating system can be Windows, Unix, Linux, etc. The computer program 222, in addition to including a computer program capable of performing the service anomaly detection method disclosed in any of the foregoing embodiments, may further include computer programs capable of performing other specific tasks. The data 223 may include data received by the electronic device from external devices, as well as data collected by its own input / output interface 25.

[0090] Furthermore, embodiments of this application also disclose a computer-readable storage medium storing a computer program. When the computer program is loaded and executed by a processor, it implements the method steps performed during the service anomaly detection process disclosed in any of the foregoing embodiments.

[0091] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0092] The above provides a detailed description of the service anomaly detection method, apparatus, device, and medium provided by the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A service anomaly detection method, characterized in that, include: The original service signal and the preset analog signal are acquired, and the preset analog signal is superimposed on the original service signal to obtain the superimposed signal; The original service signal and the superimposed signal are respectively input to the target service thread to obtain the first output signal of the original service signal and the second output signal of the superimposed signal, and the actual signal difference between the first output signal and the second output signal is determined. The first deviation between the actual signal difference and the expected signal difference is obtained, and the actual processed signal is obtained by using the target amplification bypass, the first deviation, the original service signal and the target service thread. Then, the second deviation between the actual processed signal and the expected processed signal is obtained. Based on the relationship between the second deviation and the preset abnormal conditions, it is determined whether the target service thread is abnormal; The process of obtaining the actual processed signal by utilizing the target amplification bypass, the first deviation, the original service signal, and the target service thread includes: Determine whether the first deviation meets the preset abnormal conditions; If the conditions are not met, the actual processed signal is obtained by using the target amplification bypass, the first deviation, the original service signal, and the target service thread; if the conditions are met, it is determined that the target service thread is abnormal.

2. The service anomaly detection method according to claim 1, characterized in that, The step of inputting the original service signal and the superimposed signal to the target service thread respectively to obtain a first output signal of the original service signal and a second output signal of the superimposed signal includes: The original service signal and the superimposed signal are respectively input to the upstream node in the target service thread, so that the target service thread can process the original service signal and the superimposed signal accordingly to obtain the first output signal of the original service signal and the second output signal of the superimposed signal output by the downstream node in the target service thread.

3. The service anomaly detection method according to claim 1, characterized in that, The step of determining whether the target service thread is abnormal based on the relationship between the second deviation and the preset abnormal conditions includes: If the second deviation satisfies the preset abnormal condition, then the target service thread is determined to be abnormal. If the second deviation does not meet the preset abnormal condition, then it is determined that the target service thread is not abnormal.

4. The service anomaly detection method according to claim 3, characterized in that, After determining that the target service thread is abnormal, the process further includes: A preset handling procedure is triggered to eliminate the abnormal situation of the target service thread.

5. A service anomaly detection device, characterized in that, include: A signal overlay module is used to acquire the original service signal and a preset analog signal, and to overlay the preset analog signal with the original service signal to obtain the overlaid signal; The signal difference determination module is used to input the original service signal and the superimposed signal to the target service thread respectively, so as to obtain the first output signal of the original service signal and the second output signal of the superimposed signal, and determine the actual signal difference between the first output signal and the second output signal; The deviation acquisition module is used to acquire a first deviation between the actual signal difference and the expected signal difference, and to obtain the actual processed signal using the target amplification bypass, the first deviation, the original service signal and the target service thread, and then acquire a second deviation between the actual processed signal and the expected processed signal. The anomaly determination module is used to determine whether the target service thread is abnormal based on the relationship between the second deviation and the preset anomaly conditions. The deviation acquisition module includes: The judgment unit is used to determine whether the first deviation amount meets the preset abnormal conditions; The first processing unit is configured to, if the conditions are not met, obtain the actual processed signal by utilizing the target amplification bypass, the first deviation, the original service signal, and the target service thread. The second processing unit is used to determine that the target service thread is abnormal if the conditions are met.

6. The service anomaly detection device according to claim 5, characterized in that, The anomaly determination module includes: The first determination unit is used to determine that the target service thread is abnormal if the second deviation satisfies the relationship of the preset abnormal condition. The second determination unit is used to determine that the target service thread is not abnormal if the second deviation does not meet the preset abnormal condition.

7. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the steps of the service anomaly detection method as described in any one of claims 1 to 4.

8. A computer-readable storage medium, characterized in that, Used to store a computer program; wherein, when the computer program is executed by a processor, it implements the steps of the service anomaly detection method as described in any one of claims 1 to 4.