A method for intelligent log data fusion and modeling analysis
By analyzing the work logs of the enterprise server and identifying abnormal network areas, combining data feature information and operation log data, establishing a data interaction process model, predicting abnormal applications and performing network link adjustments, the problems of operation status prediction and network link adjustment in enterprise-level local area networks are solved, and equipment reliability is improved and costs are reduced.
Patent Information
- Application Number
- CN202411054086.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-02
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2044-08-02
AI Technical Summary
The prior art is difficult to achieve stable and reliable operational status prediction and network link adjustment in enterprise-level local area networks, resulting in increased equipment hardware costs and operation load and reduced work reliability of user terminal equipment.
By analyzing the enterprise side work log of the enterprise server, identifying abnormal network areas and abnormal data flows, obtaining data characteristic information, finding the target user end of abnormal data processing behavior, and performing associated network link calibration and cluster processing based on location information. Then, the running log data of the target user side is fused, a data interaction process model is established, abnormal applications are predicted, and network link adjustments are performed.
It realizes stable and reliable operation status prediction of enterprise-level LANs, improves the working reliability of user terminal equipment, and reduces equipment hardware costs and operation load.
Smart Images

Figure CN118842690B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data modeling processing, and in particular to a method for intelligent log data fusion and modeling analysis. Background Art
[0002] The enterprise-level LAN contains a large number of user terminal devices. When processing work tasks, the user terminal devices will exchange data with other user terminal devices, thereby forming a data stream between different user terminal devices. The data stream will carry the data components generated by the corresponding user terminal devices in the process of processing work tasks. When an abnormality occurs in the user terminal device through which the data stream passes, the content of the data stream will be disordered, affecting the accuracy of task processing of subsequent user terminal devices. In order to ensure the normal processing and transmission of data streams within the enterprise-level LAN, each user terminal device is usually tracked and monitored separately, which can ensure the normal operation of the enterprise-level LAN as a whole, but at the same time it also increases the overall equipment hardware cost and operating load of the enterprise-level LAN, resulting in the inability to predict the stable and reliable operating status of the enterprise-level LAN, reducing the working reliability of user terminal devices within the enterprise-level LAN. Summary of the invention
[0003] In view of the defects of the prior art, the present invention provides a method for intelligent log data fusion and modeling analysis, which analyzes the enterprise-side work log of the enterprise server, identifies the abnormal network area connected to the enterprise server, and monitors all abnormal data flows from the abnormal network area, thereby identifying the data feature information of each abnormal data flow and calibrating the data transmission status inside the abnormal network area; based on the data feature information, all target user terminals with abnormal data processing behaviors are found, and based on the location information of the target user terminals, the associated network links of all target user terminals are calibrated, and all target user terminals are paired and processed into a number of target user terminal clusters to achieve differentiated centralized adjustment and control of the target user terminals; the operation log data of all target user terminals under the target user terminal cluster are fused into an operation log data set, and the modeling is performed to process the data interaction process model between all target user terminals under the target user terminal cluster, and the abnormal application programs inside all target user terminals under the target user terminal cluster are predicted, so as to accurately adjust the network links of the target user terminals, predict the stable and reliable operation status of the enterprise-level local area network, and improve the working reliability of the terminals inside the enterprise-level local area network.
[0004] The present invention provides a method for intelligent log data fusion and modeling analysis, comprising the following steps:
[0005] Step S1, obtaining the enterprise-side work log of the enterprise server, analyzing the enterprise-side work log, identifying the abnormal network area to which the enterprise server is connected; monitoring the abnormal network area, determining all abnormal data flows in the abnormal network area, and identifying each abnormal data flow to obtain data feature information corresponding to each abnormal data flow;
[0006] Step S2, based on the data feature information, searching for all target user terminals that have abnormal data processing behavior in the abnormal network area; based on the location information of all target user terminals in the abnormal network area, calibrating the associated network links of all target user terminals, and pairing all target user terminals based on the calibrated associated network links to obtain a number of target user terminal clusters;
[0007] Step S3, obtaining the operation log data of all target user terminals under the target user terminal cluster, performing fusion preprocessing on all the operation log data to obtain an operation log data set; performing modeling processing on the operation log data set to obtain a data interaction process model between all target user terminals under the target user terminal cluster;
[0008] Step S4, based on the data interaction process model, determining abnormal applications within all target user terminals under the target user terminal cluster; and performing network link adjustment processing on the corresponding target user terminals based on the program port information of all abnormal applications.
[0009] In one embodiment disclosed in the present application, in the step S1, obtaining the enterprise-side work log of the enterprise server, analyzing the enterprise-side work log, and identifying the abnormal network area to which the enterprise server is connected, includes:
[0010] Monitor the data receiving port of the enterprise server to obtain the change information of the reception flow of the enterprise server to the external data; determine the distribution information of the time period when the enterprise server is in an active data reception state based on the change information of the reception flow; filter and process the log records of the enterprise server based on the time period distribution information to obtain the enterprise-side work log generated by the enterprise server in the corresponding time period;
[0011] Analyze the enterprise-side work log to obtain all gateway devices that are connected to the enterprise server during operation; determine the network area associated with the enterprise server based on the address information of all gateway devices within the network where the enterprise server is located;
[0012] Data flow detection is performed on the network area, and a network sub-area whose average data transmission flow within the network area exceeds a preset flow threshold is determined as an abnormal network area to which the enterprise server is subordinately connected.
[0013] In one embodiment disclosed in the present application, in step S1, the abnormal network area is monitored to determine all abnormal data flows in the abnormal network area, and each abnormal data flow is identified to obtain data feature information corresponding to each abnormal data flow, including:
[0014] All network links under the abnormal network area are monitored to obtain data sample sequences transmitted by all network links under the abnormal network area; data content recognition is performed on the data sample sequence to obtain a data content repetition ratio within the data sample sequence; if the data content repetition ratio is greater than a preset ratio threshold, the data flow transmitted by the corresponding network link is determined to be an abnormal data flow;
[0015] The source of the abnormal data flow is tracked and identified to obtain the identity information of the terminal device through which the abnormal data flow passes during the entire transmission process, which is used as the data feature information.
[0016] In one embodiment disclosed in the present application, in the step S2, based on the data feature information, searching for all target user terminals that have abnormal data processing behaviors in the abnormal network area includes:
[0017] The terminal device identity information is compared with the identity information of all user terminals accessing the abnormal network area. If the identity information of the user terminal accessing the abnormal network area exists in the terminal device identity information, and there is a data flow processing task process inside the user terminal, the user terminal is determined as the target user terminal where the abnormal data processing behavior occurs; otherwise, the user terminal is not determined as the target user terminal where the abnormal data processing behavior occurs.
[0018] In one embodiment disclosed in the present application, in step S2, based on the location information of all target user terminals in the abnormal network area, the associated network links of all target user terminals are calibrated, and based on the calibrated associated network links, all target user terminals are paired to obtain a plurality of target user terminal clusters, including:
[0019] Acquire access gateway address information of all target user terminals in the abnormal network area, and identify network links accessed by all target user terminals within the abnormal network area based on the access gateway address information, so as to calibrate and obtain associated network links of all target user terminals within the abnormal network area;
[0020] Based on the calibrated data flow transmission direction information within the associated network link, all target user terminals with direct data interaction are paired and divided into the same target user terminal cluster.
[0021] In one embodiment disclosed in the present application, in the step S3, the operation log data of all target user terminals under the target user terminal cluster are obtained, and all the operation log data are fused and pre-processed to obtain an operation log data set, including:
[0022] Based on the application installation directories of all target user terminals under the target user terminal cluster, the operation log data of all application programs installed by all target user terminals are obtained, and based on the application program type information corresponding to the operation log data, the operation log data is identified and distinguished;
[0023] The operation log data of all target user terminals corresponding to the same type of application are processed to remove garbled data content and deduplicate data content, so as to obtain a set of operation log data of all target user terminals corresponding to the same type of application by merging.
[0024] In one embodiment disclosed in the present application, in step S3, the operation log data set is modeled to obtain a data interaction process model between all target user terminals under the target user terminal cluster, including:
[0025] The running process information of the application of the corresponding type of the running log data set in all target user terminals is obtained, and based on the running process information, the running log data set is modeled and processed to obtain a data interaction process model between all target user terminals under the target user terminal cluster; wherein, the data interaction process model is used to characterize the processing process running status information of all target user terminals for the same data stream.
[0026] In one embodiment disclosed in the present application, in the step S4, based on the data interaction process model, determining abnormal applications in all target user terminals under the target user terminal cluster includes:
[0027] Based on the data interaction process model, obtaining the processing process running status information of all target user terminals under the target user terminal cluster on the same data stream; wherein the processing process running status information includes the operation speed and operation error rate of each target user terminal under the target user terminal cluster processing the same data stream;
[0028] The processing operation speed and the operation error rate are compared with the preset operation speed threshold and the preset operation error rate threshold respectively. If the processing operation speed is greater than the preset operation speed threshold or the operation error rate is greater than the preset operation error threshold, the application executing the corresponding processing process on the corresponding target user end is determined as an abnormal application.
[0029] In one embodiment disclosed in the present application, in step S4, based on the program port information of all abnormal application programs, a network link adjustment process is performed on the corresponding target user terminal, including:
[0030] Based on the program port information of all abnormal application programs, the network link paths to which all abnormal application programs are connected are determined; and based on the network link paths, network link isolation processing is performed on the corresponding target user terminal.
[0031] In one embodiment disclosed in the present application, in step S4, the network link isolation process is performed on the corresponding target user terminal, further comprising:
[0032] Redundant process clearing is performed on abnormal applications within the target user terminal that is undergoing network link isolation processing until the data computing volume of the abnormal applications is reduced to below a preset computing volume threshold.
[0033] Compared with the prior art, the intelligent log data fusion and modeling analysis method analyzes the enterprise-side work log of the enterprise server, identifies the abnormal network area connected to the enterprise server, and monitors all abnormal data flows from the abnormal network area, thereby identifying the data feature information of each abnormal data flow and calibrating the data transmission status inside the abnormal network area; based on the data feature information, all target user terminals with abnormal data processing behavior are found, and based on the location information of the target user terminals, the associated network links of all target user terminals are calibrated, and all target user terminals are paired and processed into several target user terminal clusters to achieve differentiated centralized adjustment and control of the target user terminals; the operation log data of all target user terminals under the target user terminal cluster are fused into an operation log data set, and the modeling is used to process the data interaction process model between all target user terminals under the target user terminal cluster, and the abnormal application programs inside all target user terminals under the target user terminal cluster are predicted, so as to accurately adjust the network links of the target user terminals, predict the stable and reliable operation status of the enterprise-level LAN, and improve the working reliability of the terminals inside the enterprise-level LAN.
[0034] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings.
[0035] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0037] Figure 1 A schematic diagram of the flow chart of the method for intelligent log data fusion and modeling analysis provided by the present invention. DETAILED DESCRIPTION
[0038] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0039] See also Figure 1 , is a flow chart of a method for intelligent log data fusion and modeling analysis provided by an embodiment of the present invention. The method for intelligent log data fusion and modeling analysis includes:
[0040] Step S1, obtaining the enterprise-side work log of the enterprise server, analyzing the enterprise-side work log, identifying the abnormal network area to which the enterprise server is connected; monitoring the abnormal network area, determining all abnormal data flows in the abnormal network area, and identifying each abnormal data flow to obtain data feature information corresponding to each abnormal data flow;
[0041] Step S2, based on the data feature information, searching for all target user terminals that have abnormal data processing behaviors in the abnormal network area; based on the location information of all target user terminals in the abnormal network area, calibrating the associated network links of all target user terminals, and pairing all target user terminals based on the calibrated associated network links to obtain a number of target user terminal clusters;
[0042] Step S3, obtaining the operation log data of all target user terminals under the target user terminal cluster, performing fusion preprocessing on all the operation log data to obtain an operation log data set; performing modeling processing on the operation log data set to obtain a data interaction process model between all target user terminals under the target user terminal cluster;
[0043] Step S4, based on the data interaction process model, determining abnormal applications within all target user terminals under the target user terminal cluster; and performing network link adjustment processing on the corresponding target user terminals based on the program port information of all abnormal applications.
[0044] In the above technical scheme, the method of intelligent log data fusion and modeling analysis analyzes the enterprise-side work log of the enterprise server, identifies the abnormal network area connected to the enterprise server, and monitors all abnormal data flows from the abnormal network area, thereby identifying the data feature information of each abnormal data flow and calibrating the data transmission status inside the abnormal network area; based on the data feature information, all target user terminals with abnormal data processing behavior are found, and based on the location information of the target user terminals, the associated network links of all target user terminals are calibrated, and all target user terminals are paired into several target user terminal clusters to achieve differentiated centralized adjustment and control of the target user terminals; the operation log data of all target user terminals under the target user terminal cluster are fused into an operation log data set, and the modeling is used to process the data interaction process model between all target user terminals under the target user terminal cluster, and the abnormal application programs inside all target user terminals under the target user terminal cluster are predicted, so as to accurately adjust the network links of the target user terminals, predict the stable and reliable operation status of the enterprise-level LAN, and improve the working reliability of the terminals inside the enterprise-level LAN.
[0045] Preferably, in step S1, obtaining the enterprise-side work log of the enterprise server, analyzing the enterprise-side work log, and identifying the abnormal network area to which the enterprise server is connected, includes:
[0046] Monitor the data receiving port of the enterprise server to obtain the change information of the flow rate of the enterprise server receiving external data; based on the change information of the flow rate, determine the distribution information of the time period when the enterprise server is in an active data receiving state; based on the time period distribution information, filter and process the log records of the enterprise server to obtain the enterprise-side work log generated by the enterprise server in the corresponding time period;
[0047] Analyze the enterprise-side work log to obtain all gateway devices that are connected to the enterprise server during operation; determine the network area associated with the enterprise server based on the address information of all gateway devices within the network where the enterprise server is located;
[0048] Data traffic detection is performed on the network area, and the network sub-area in which the average data transmission traffic within the network area exceeds a preset traffic threshold is determined as an abnormal network area connected to the enterprise server.
[0049] In the above technical scheme, an enterprise server and multiple user terminals are arranged inside the enterprise-level local area network. The enterprise server is connected to multiple user terminals through corresponding network links to realize data interaction and control with each user terminal, and a corresponding enterprise terminal work log is formed during the operation of the enterprise server to realize the status record of the entire operation process of the enterprise server. The data receiving port of the enterprise server is monitored to obtain the change information of the receiving flow rate of the enterprise server to the external data, and the receiving flow rate value of the enterprise server to the external data in each working time interval is determined according to the change information of the receiving flow rate. If the receiving flow rate value is greater than or equal to the preset flow rate threshold, it is determined that the enterprise server is in an active data receiving state in the corresponding working time interval, thereby determining the time period distribution information of the enterprise server in the active data receiving state, and then filtering the log records of the enterprise server based on the time period distribution information to obtain the enterprise terminal work log generated by the enterprise server in the corresponding time period, which provides a reliable basis for the subsequent determination of abnormal network areas. The enterprise-side work log is also analyzed to obtain all gateway devices that are connected to the enterprise server during operation; based on the address information of all gateway devices within the network where the enterprise server is located, the network area associated with the enterprise server is determined, so that the network connection range of the enterprise server can be accurately delineated. Then the network area is tested for data traffic, and the network sub-area with an average data transmission traffic in the network area exceeding the preset traffic threshold is determined as the abnormal network area of the enterprise server's subordinate connection, so that the target user end with abnormal data processing behavior can be accurately identified without the need to search the entire enterprise-level LAN.
[0050] Preferably, in step S1, the abnormal network area is monitored to determine all abnormal data flows in the abnormal network area, and each abnormal data flow is identified to obtain data feature information corresponding to each abnormal data flow, including:
[0051] All network links under the abnormal network area are monitored to obtain data sample sequences transmitted by all network links under the abnormal network area; data content is identified on the data sample sequence to obtain the data content repetition ratio within the data sample sequence; if the data content repetition ratio is greater than a preset ratio threshold, the data flow transmitted by the corresponding network link is determined to be an abnormal data flow;
[0052] The source of the abnormal data flow is tracked and identified to obtain the identity information of the terminal device through which the abnormal data flow passes during the entire transmission process, which is used as the data feature information.
[0053] In the above technical scheme, all network links under the abnormal network area are monitored and data sampling is performed to obtain a data sample sequence transmitted by each of the network links under the abnormal network area, and the data sample sequence includes data samples arranged in chronological order according to the sampling time. Then, the data content of the data sample sequence is identified to obtain the data content repetition ratio within the data sample sequence. When the data content repetition ratio is greater than the preset ratio threshold, it indicates that the data sample sequence corresponds to a large amount of repetitive invalid content. At this time, the data stream transmitted by the corresponding network link is determined to be an abnormal data stream, thereby improving the accuracy of identifying the abnormal data stream. In addition, the source of the abnormal data stream is tracked and identified to obtain the identity information of the terminal device through which the abnormal data stream passes during the entire transmission process, which is used as the data feature information to facilitate the subsequent accurate identification of the target user end where abnormal data processing behavior occurs.
[0054] Preferably, in step S2, based on the data feature information, searching for all target user terminals having abnormal data processing behaviors in the abnormal network area includes:
[0055] The identity information of the terminal device is compared with the identity information of all user terminals accessing the abnormal network area. If the identity information of the user terminal accessing the abnormal network area exists in the identity information of the terminal device, and there is a data flow processing task process inside the user terminal, the user terminal is determined as the target user terminal where the abnormal data processing behavior occurs; otherwise, the user terminal is not determined as the target user terminal where the abnormal data processing behavior occurs.
[0056] In the above technical solution, the identity information of the terminal device is compared with the identity information of all user terminals accessing the abnormal network area. If the identity information of the user terminal accessing the abnormal network area exists in the identity information of the terminal device, and there is a data flow processing task process inside the user terminal, then the user terminal is determined as the target user terminal where abnormal data processing behavior occurs. In this way, the target user terminal that generates abnormal data processing behavior can be screened and processed from all user terminals, providing an accurate scope for the subsequent centralized classification and demarcation of all target user terminals.
[0057] Preferably, in step S2, based on the location information of all target user terminals in the abnormal network area, the associated network links of all target user terminals are calibrated, and based on the calibrated associated network links, all target user terminals are paired to obtain a plurality of target user terminal clusters, including:
[0058] Obtaining access gateway address information of all target user terminals in the abnormal network area, and based on the access gateway address information, identifying network links accessed by all target user terminals within the abnormal network area, thereby calibrating associated network links of all target user terminals within the abnormal network area;
[0059] Based on the calibrated data flow transmission direction information within the associated network link, all target user terminals with direct data interaction are paired and divided into the same target user terminal cluster.
[0060] In the above technical solution, based on the access gateway address information of all target user terminals in the abnormal network area, the network links accessed by all target user terminals in the abnormal network area are identified, and the associated network links of all target user terminals in the abnormal network area are calibrated, so that the access network links of all target user terminals in the abnormal network area can be accurately calibrated. Based on the data flow transmission direction information inside the calibrated associated network link, all target user terminals with direct data interaction are paired and divided into the same target user terminal cluster, so that all target user terminals under the same target user terminal cluster are involved in the processing of the same data flow.
[0061] Preferably, in step S3, the operation log data of all target user terminals under the target user terminal cluster are obtained, and all the operation log data are fused and pre-processed to obtain an operation log data set, including:
[0062] Based on the application installation directories of all target user terminals under the target user terminal cluster, the operation log data of all application programs installed by all target user terminals are obtained, and based on the application program type information corresponding to the operation log data, the operation log data is identified and distinguished;
[0063] The operation log data of all target user terminals corresponding to the same type of application are processed to remove garbled data content and deduplicate data content, so as to obtain a set of operation log data of all target user terminals corresponding to the same type of application by merging.
[0064] In the above technical solution, based on the application installation directories of all target user terminals under the target user terminal cluster, the operation log data of all applications installed by all target user terminals are obtained, and based on the application type information corresponding to the operation log data, the operation log data is identified and distinguished, so that all operation log data can be distinguished according to their corresponding application types. Then, the operation log data corresponding to the same type of application of all target user terminals are subjected to data garbled content elimination and data content deduplication processing, so as to merge and obtain the operation log data set corresponding to the same type of application of all target user terminals, so as to ensure the accuracy of all operation log data under the operation log data set.
[0065] Preferably, in step S3, the operation log data set is modeled to obtain a data interaction process model between all target user terminals under the target user terminal cluster, including:
[0066] The running process information of the application of the corresponding type of the running log data set in all target user terminals is obtained, and based on the running process information, the running log data set is modeled and processed to obtain a data interaction process model between all target user terminals under the target user terminal cluster; wherein, the data interaction process model is used to characterize the processing process running status information of all target user terminals for the same data stream.
[0067] In the above technical scheme, the running process information of the application of the corresponding type of the running log data set in all target user terminals is obtained, and the running log data set is modeled and processed to obtain the data interaction process model between all target user terminals under the target user terminal cluster. The data interaction process model can be used to effectively and accurately predict the processing process running status information of all target user terminals for the same data stream.
[0068] Preferably, in step S4, based on the data interaction process model, determining abnormal applications within all target user terminals under the target user terminal cluster includes:
[0069] Based on the data interaction process model, the processing process running status information of all target user terminals under the target user terminal cluster on the same data stream is obtained; wherein the processing process running status information includes the operation speed and operation error rate of each target user terminal under the target user terminal cluster processing the same data stream;
[0070] The processing operation speed and the operation error rate are compared with the preset operation speed threshold and the preset operation error rate threshold respectively. If the processing operation speed is greater than the preset operation speed threshold or the operation error rate is greater than the preset operation error threshold, the application executing the corresponding processing process on the corresponding target user end is determined as an abnormal application.
[0071] In the above technical scheme, based on the data interaction process model, the processing process running status information of all target user terminals under the target user terminal cluster for the same data stream is obtained, and then the computing speed and computing error rate of each target user terminal under the target user terminal cluster for the same data stream contained in the processing process running status information are subjected to threshold comparison, so that abnormal applications in the target user terminal can be accurately identified.
[0072] Preferably, in step S4, based on the program port information of all abnormal application programs, a network link adjustment process is performed on the corresponding target user terminal, including:
[0073] Based on the program port information of all abnormal applications, the network link paths to which all abnormal applications are connected are determined; and based on the network link path, network link isolation processing is performed on the corresponding target user end.
[0074] In the above technical solution, based on the program port information of all abnormal applications, the network link paths to which all abnormal applications are connected are determined, so that the network link isolation processing is performed on the corresponding target user terminal to prevent the target user terminal from affecting the operation of other user terminals.
[0075] Preferably, in step S4, performing network link isolation processing on the corresponding target user terminal also includes:
[0076] Redundant process clearing is performed on abnormal applications within the target user terminal that is undergoing network link isolation processing until the data computing volume of the abnormal application is reduced to below a preset computing volume threshold.
[0077] In the above technical solution, redundant process clearing is performed on the abnormal application inside the target user terminal that is undergoing network link isolation processing until the data computing volume of the abnormal application is reduced to below the preset computing volume threshold. This can effectively eliminate the abnormal condition of the abnormal application and facilitate the abnormal application to quickly return to normal.
[0078] It can be seen from the contents of the above embodiments that the method of intelligent log data fusion and modeling analysis analyzes the enterprise-side work log of the enterprise server, identifies the abnormal network area connected to the enterprise server, and monitors all abnormal data flows from the abnormal network area, thereby identifying the data feature information of each abnormal data flow, and calibrating the data transmission status inside the abnormal network area; based on the data feature information, all target user terminals that have abnormal data processing behaviors are found, and based on the location information of the target user terminals, the associated network links of all target user terminals are calibrated, and all target user terminals are paired and processed into several target user terminal clusters to achieve differentiated centralized adjustment and control of the target user terminals; the operation log data of all target user terminals under the target user terminal cluster are also fused into an operation log data set, and the modeling is used to process the data interaction process model between all target user terminals under the target user terminal cluster, and the abnormal application programs inside all target user terminals under the target user terminal cluster are predicted, so as to accurately adjust the network links of the target user terminals, predict the stable and reliable operation status of the enterprise-level LAN, and improve the working reliability of the terminals inside the enterprise-level LAN.
[0079] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.
Claims
1. A method for intelligent log data fusion and modeling analysis, characterized in that: It includes the following steps: Step S1, obtaining an enterprise-side work log of an enterprise server, analyzing the enterprise-side work log, and identifying an abnormal network area to which the enterprise server is connected; Monitoring the abnormal network area, determining all abnormal data flows in the abnormal network area, and identifying each abnormal data flow to obtain data feature information corresponding to each abnormal data flow; Step S2, based on the data feature information, searching for all target user terminals that have abnormal data processing behaviors in the abnormal network area; based on the location information of all target user terminals in the abnormal network area, calibrating the associated network links of all target user terminals, and based on the calibrated associated network links, pairing all target user terminals to obtain a number of target user terminal clusters, including obtaining access gateway address information of all target user terminals in the abnormal network area, identifying the network links accessed by all target user terminals within the abnormal network area based on the access gateway address information, thereby calibrating the associated network links of all target user terminals within the abnormal network area, and pairing all target user terminals that have direct data interaction based on the data flow transmission direction information within the calibrated associated network links, and dividing them into the same target user terminal cluster; Step S3, obtaining the operation log data of all target user terminals under the target user terminal cluster, performing fusion preprocessing on all the operation log data, and obtaining an operation log data set; Modeling the operation log data set to obtain a data interaction process model between all target user terminals under the target user terminal cluster; Step S4, determining abnormal applications within all target user terminals under the target user terminal cluster based on the data interaction process model; Based on the program port information of all abnormal application programs, network link adjustment processing is performed on the corresponding target user terminal.
2. The method for intelligent log data fusion and modeling analysis according to claim 1, characterized in that: In the step S1, the enterprise-side work log of the enterprise server is obtained, the enterprise-side work log is analyzed, and the abnormal network area to which the enterprise server is connected is identified, including: Monitor the data receiving port of the enterprise server to obtain the change information of the reception flow of the enterprise server to the external data; determine the distribution information of the time period when the enterprise server is in an active data reception state based on the change information of the reception flow; filter and process the log records of the enterprise server based on the time period distribution information to obtain the enterprise-side work log generated by the enterprise server in the corresponding time period; Analyze the enterprise-side work log to obtain all gateway devices that are connected to the enterprise server during operation; determine the network area associated with the enterprise server based on the address information of all gateway devices within the network where the enterprise server is located; Data flow detection is performed on the network area, and a network sub-area whose average data transmission flow within the network area exceeds a preset flow threshold is determined as an abnormal network area to which the enterprise server is subordinately connected.
3. The method for intelligent log data fusion and modeling analysis according to claim 2, characterized in that: In the step S1, the abnormal network area is monitored to determine all abnormal data flows in the abnormal network area, and each abnormal data flow is identified to obtain data feature information corresponding to each abnormal data flow, including: All network links under the abnormal network area are monitored to obtain data sample sequences transmitted by all network links under the abnormal network area; data content recognition is performed on the data sample sequence to obtain a data content repetition ratio within the data sample sequence; if the data content repetition ratio is greater than a preset ratio threshold, the data flow transmitted by the corresponding network link is determined to be an abnormal data flow; The source of the abnormal data flow is tracked and identified to obtain the identity information of the terminal device through which the abnormal data flow passes during the entire transmission process, which is used as the data feature information.
4. The method for intelligent log data fusion and modeling analysis as claimed in claim 3, characterized in that: In the step S2, based on the data feature information, searching for all target user terminals having abnormal data processing behaviors in the abnormal network area includes: The terminal device identity information is compared with the identity information of all user terminals accessing the abnormal network area. If the identity information of the user terminal accessing the abnormal network area exists in the terminal device identity information, and there is a data flow processing task process inside the user terminal, the user terminal is determined as the target user terminal where the abnormal data processing behavior occurs; otherwise, the user terminal is not determined as the target user terminal where the abnormal data processing behavior occurs.
5. The method for intelligent log data fusion and modeling analysis according to claim 1, characterized in that: In the step S3, the operation log data of all target user terminals under the target user terminal cluster are obtained, and all the operation log data are fused and pre-processed to obtain an operation log data set, including: Based on the application installation directories of all target user terminals under the target user terminal cluster, the operation log data of all application programs installed by all target user terminals are obtained, and based on the application program type information corresponding to the operation log data, the operation log data is identified and distinguished; The operation log data of all target user terminals corresponding to the same type of application are processed to remove garbled data content and deduplicate data content, so as to obtain a set of operation log data of all target user terminals corresponding to the same type of application by merging.
6. The method for intelligent log data fusion and modeling analysis according to claim 5, characterized in that: In the step S3, the operation log data set is modeled to obtain a data interaction process model between all target user terminals under the target user terminal cluster, including: The running process information of the application of the corresponding type of the running log data set in all target user terminals is obtained, and based on the running process information, the running log data set is modeled and processed to obtain a data interaction process model between all target user terminals under the target user terminal cluster; wherein, the data interaction process model is used to characterize the processing process running status information of all target user terminals for the same data stream.
7. The method for intelligent log data fusion and modeling analysis according to claim 1, characterized in that: In the step S4, based on the data interaction process model, determining abnormal applications in all target user terminals under the target user terminal cluster includes: Based on the data interaction process model, obtaining the processing process running status information of all target user terminals under the target user terminal cluster on the same data stream; wherein the processing process running status information includes the operation speed and operation error rate of each target user terminal under the target user terminal cluster processing the same data stream; The processing operation speed and the operation error rate are compared with the preset operation speed threshold and the preset operation error rate threshold respectively. If the processing operation speed is greater than the preset operation speed threshold or the operation error rate is greater than the preset operation error threshold, the application executing the corresponding processing process on the corresponding target user end is determined as an abnormal application.
8. The method for intelligent log data fusion and modeling analysis according to claim 7, characterized in that: In step S4, based on the program port information of all abnormal application programs, a network link adjustment process is performed on the corresponding target user terminal, including: Based on the program port information of all abnormal application programs, the network link paths to which all abnormal application programs are connected are determined; and based on the network link paths, network link isolation processing is performed on the corresponding target user terminal.
9. The method for intelligent log data fusion and modeling analysis according to claim 8, characterized in that: In the step S4, the network link isolation process is performed on the corresponding target user terminal, and further includes: Redundant process clearing is performed on abnormal applications within the target user terminal that is undergoing network link isolation processing until the data computing volume of the abnormal applications is reduced to below a preset computing volume threshold.
Citation Information
Patent Citations
Real-time attack tracing method and system based on machine learning
CN118158002A