Abnormal computing resource information alarm method, electronic device and computer readable medium

By standardizing and aggregating computing resource information and combining it with an instance relationship prediction model, the problem of monitoring tools being unable to fully integrate different types of data is solved, timely and accurate alerts for abnormal computing resources are achieved, and monitoring efficiency and accuracy are improved.

CN119179628BActive Publication Date: 2025-10-17HUAQING RONGTIAN (BEIJING) SOFTWARE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411265065.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-10
Publication Date
2025-10-17
Estimated Expiration
2044-09-10

AI Technical Summary

Technical Problem

Existing monitoring tools are unable to fully integrate different types of computing resource data, making it difficult to issue abnormal alerts in a timely and accurate manner. In particular, when processing complex computing resource information, there is a lack of effective aggregation and standardization mechanisms.

Method used

By obtaining the computing resource information set and the call chain information set, data standardization and aggregation processing are performed, and combined with the pre-trained instance relationship prediction model, abnormal computing resource identification results are generated, and alarm processing is performed when the preset conditions are met.

Benefits of technology

It achieves timely and accurate alarms for abnormal computing resources, ensures comprehensive monitoring and anomaly detection of different types of computing resource information, can dynamically update and identify potential relationships, and improves the efficiency and accuracy of alarm processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119179628B_ABST
    Figure CN119179628B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure disclose an abnormal computing resource information alarm method, an electronic device and a computer readable medium. A specific implementation of the method comprises: performing data aggregation processing on a computing resource call chain information set to generate a computing resource call chain aggregation information set; performing incremental update processing on a computing resource standardization information set; performing incremental update processing on the computing resource call chain aggregation information set; inputting a computing resource instance information set and a computing resource call chain instance information set into a pre-trained instance relationship prediction model; performing data standardization processing on a computing resource instance relationship prediction information set to generate a computing resource instance relationship prediction standardization information set; and performing abnormality identification processing on the computing resource instance relationship prediction standardization information set to generate an abnormal computing resource information identification result. The implementation can issue an alarm in a timely manner by verifying multiple types of detection data, dynamic updating, standardization processing and application of a prediction model.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present disclosure relate to the field of computer, in particular to an abnormal computing resource information alarm method, an electronic device and a computer readable medium. BACKGROUND

[0002] In modern computing environment, the management and monitoring of computing resources is a key link to guarantee system performance. At present, when performing abnormal computing resource information alarm, the commonly used way is to obtain computing resource information and perform alarm by integrating various monitoring tools (network monitoring tools).

[0003] However, in practice, it is found that when the above-mentioned way of abnormal computing resource information alarm is adopted, the following technical problems often exist:

[0004] First, the monitoring tool can usually only process specific types of information, and cannot comprehensively integrate different types of computing resource data, so that when processing complex computing resource information, it is difficult to timely and accurately issue abnormal alarm;

[0005] Second, when processing complex computing resource instance relationship prediction information, the monitoring tool lacks effective aggregation and standardization mechanism, which makes it difficult to accurately identify abnormal computing resource results. This makes it impossible to effectively issue alarm for abnormal computing resource identification results.

[0006] The above information disclosed in the background section is only for the purpose of enhancing the understanding of the background of the present inventive concept, and therefore, it can include information that does not form the prior art known to those of ordinary skill in the art in the country. SUMMARY

[0007] The summary section of the present disclosure is used to introduce the concepts in a brief manner, which will be described in detail in the specific embodiments section. The summary section of the present disclosure is not intended to identify key or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0008] Some embodiments of the present disclosure propose an abnormal computing resource information alarm method, device, electronic device and computer readable medium to solve one or more of the technical problems mentioned in the background section.

[0009] In a first aspect, some embodiments of the present disclosure provide an abnormal computing resource information alarm method, which comprises: obtaining a set of computing resource information and a set of computing resource call chain information; obtaining an initial set of computing resource call chain information; performing data standardization processing on the set of computing resource information to generate a set of computing resource standardized information; performing data aggregation processing on the set of computing resource call chain information to generate a set of computing resource call chain aggregated information; performing incremental update processing on the set of computing resource standardized information to generate a set of computing resource instance information; performing incremental update processing on the set of computing resource call chain aggregated information to generate a set of computing resource call chain instance information; inputting the set of computing resource instance information and the set of computing resource call chain instance information into a pre-trained instance relationship prediction model to obtain a set of computing resource instance relationship prediction information; performing data standardization processing on the set of computing resource instance relationship prediction information to generate a set of computing resource instance relationship prediction standardized information, and storing the set of computing resource instance relationship prediction standardized information into a resource management database; performing abnormal identification processing on the set of computing resource instance relationship prediction standardized information to generate an abnormal computing resource information identification result; and in response to determining that the abnormal computing resource information identification result satisfies a preset abnormal alarm condition, sending the set of computing resource instance relationship prediction standardized information to an associated alarm terminal for abnormal alarm processing.

[0010] In a second aspect, some embodiments of the present disclosure provide an abnormal computing resource information alarm device, which comprises: a first acquisition unit configured to acquire a computing resource information set and a computing resource call chain information set; a second acquisition unit configured to acquire an initial computing resource call chain information set; a standardization unit configured to perform data standardization processing on the computing resource information set to generate a computing resource standardized information set; an aggregation unit configured to perform data aggregation processing on the computing resource call chain information set to generate a computing resource call chain aggregated information set; a first update unit configured to perform incremental update processing on the computing resource standardized information set to generate a computing resource instance information set; a second update unit configured to perform incremental update processing on the computing resource call chain aggregated information set to generate a computing resource call chain instance information set; an input unit configured to input the computing resource instance information set and the computing resource call chain instance information set into a pre-trained instance relationship prediction model to obtain a computing resource instance relationship prediction information set; a storage unit configured to perform data standardization processing on the computing resource instance relationship prediction information set to generate a computing resource instance relationship prediction standardized information set, and store the computing resource instance relationship prediction standardized information set into a resource management database; an identification unit configured to perform abnormal identification processing on the computing resource instance relationship prediction standardized information set to generate an abnormal computing resource information identification result; and a sending unit configured to, in response to determining that the abnormal computing resource information identification result meets a preset abnormal alarm condition, send the computing resource instance relationship prediction standardized information set to an associated alarm terminal for abnormal alarm processing.

[0011] In a third aspect, some embodiments of the present disclosure provide an electronic device, comprising: one or more processors; a storage device having one or more programs stored thereon, when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any of the implementations of the first aspect.

[0012] In a fourth aspect, some embodiments of the present disclosure provide a computer readable medium having a computer program stored thereon, wherein the program is executed by a processor to implement the method described in any of the implementations of the first aspect.

[0013] The above various embodiments of the present disclosure have the following beneficial effects: through the abnormal computing resource information alarm method of some embodiments of the present disclosure, an alarm can be sent in time. Specifically, the reason why it is difficult to send an abnormal alarm in time and accurately is that monitoring tools can usually only process specific types of information and cannot comprehensively integrate different types of computing resource data, so it is difficult to send an abnormal alarm in time and accurately when processing complex computing resource information. Based on this, the abnormal computing resource information alarm method of some embodiments of the present disclosure. First, a set of computing resource information and a set of computing resource call chain information are obtained; an initial set of computing resource call chain information is obtained. In this way, comprehensive monitoring and abnormal detection of the computing resource state can be realized, the root cause of the computing resource abnormality can be analyzed in depth in combination with the computing resource call chain data, and a foundation can be laid for subsequent analysis of the computing resource call chain, ensuring that the latest call chain data can be obtained in the abnormal detection process. Secondly, the above set of computing resource information is subjected to data standardization processing to generate a set of computing resource standardized information. In this way, data of different sources can be converted into a consistent format. Thirdly, the above set of computing resource call chain information is subjected to data aggregation processing to generate a set of computing resource call chain aggregated information. In this way, the call chain information can be summarized according to certain rules to identify important patterns and abnormal behaviors in the call chain. Next, the above set of computing resource standardized information is subjected to incremental update processing to generate a set of computing resource instance information; the above set of computing resource call chain aggregated information is subjected to incremental update processing to generate a set of computing resource call chain instance information. In this way, the state information of the computing resource and the call chain can be dynamically updated. Next, the above set of computing resource instance information and the above set of computing resource call chain instance information are input into a pre-trained instance relationship prediction model to obtain a set of computing resource instance relationship prediction information. In this way, based on the prediction result of the model, the potential relationship between the computing resources and its abnormal pattern can be analyzed. Then, the above set of computing resource instance relationship prediction information is subjected to data standardization processing to generate a set of computing resource instance relationship prediction standardized information, and the above set of computing resource instance relationship prediction standardized information is stored in a resource management database. In this way, the consistency of the information can be maintained, and the prediction result can be stored in the database. Next, the above set of computing resource instance relationship prediction standardized information is subjected to abnormal identification processing to generate an abnormal computing resource information identification result. In this way, the abnormal computing resource state or relationship can be identified from the set of computing resource instance relationship prediction standardized information, providing a reliable basis for abnormal detection. Finally, in response to determining that the above abnormal computing resource information identification result meets a preset abnormal alarm condition, the above set of computing resource instance relationship prediction standardized information is sent to an associated alarm terminal for abnormal alarm processing. In this way, the discovered abnormal computing resource can be alarmed in time. Therefore, through the inspection of multiple types of detection data, dynamic updating, standardization processing, and the application of a prediction model, an alarm can be sent in time. BRIEF DESCRIPTION OF DRAWINGS

[0014] The above and other features, aspects and advantages of the present disclosure will become more apparent after a reading of the following detailed description together with the accompanying drawings. Throughout the drawings, similar or same reference numerals are used to denote similar or same elements. It is to be noted that the drawings are schematic and elements and features do not necessarily appear to scale.

[0015] Figure 1 is a flowchart of some embodiments of an abnormal computing resource information alarming method according to the present disclosure;

[0016] Figure 2 is a structural schematic diagram of some embodiments of an abnormal computing resource information alarming apparatus according to the present disclosure;

[0017] Figure 3 is a structural schematic diagram of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION

[0018] Embodiments of the present disclosure will be described in detail with reference to the drawings, wherein the same or similar components are denoted by the same reference numerals, and therefore repeated description is omitted as appropriate. Although certain embodiments of the present disclosure are shown and described in the drawings, it is to be understood that the present disclosure can be embodied in various forms and should not be construed as being limited to the embodiments set forth herein. Rather, these embodiments are provided so that the present disclosure will be thorough and complete, and fully convey the scope of the present disclosure to those skilled in the art. It should be understood that the drawings and embodiments are only for illustrative purposes and are not intended to limit the scope of the present disclosure.

[0019] It should also be noted that, for the sake of brevity, only the portions of the drawings that are necessary for the understanding of the present disclosure are shown. The embodiments and features of the present disclosure can be combined with each other, without conflict.

[0020] It should be noted that the terms "first", "second", and the like in the present disclosure are used only to distinguish different devices, modules or units, and do not imply the order or the interdependence of the functions performed by these devices, modules or units.

[0021] It should be noted that the terms "one", "multiple" in the present disclosure are illustrative and not restrictive, and those skilled in the art should understand that, unless otherwise explicitly stated in the context, "one" should be understood as "one or more".

[0022] The names of the messages or information exchanged between the devices in the embodiments of the present disclosure are only for illustrative purposes, and are not intended to limit the scope of the messages or information.

[0023] The present disclosure will be described in detail with reference to the accompanying drawings and embodiments.

[0024] Figure 1is a flowchart of some embodiments of the abnormal computing resource information alarming method according to the present disclosure. The flowchart 100 of some embodiments of the abnormal computing resource information alarming method according to the present disclosure is shown. The abnormal computing resource information alarming method comprises the following steps:

[0025] Step 101, obtaining a computing resource information set and a computing resource call chain information set.

[0026] In some embodiments, the execution subject (for example, a computing device) of the abnormal computing resource information alarming method can obtain the computing resource information set and the computing resource call chain information set through wired connection or wireless connection. The computing resource information in the computing resource information set can represent, but is not limited to, computing resource information usage, computing resource information performance indicators. The computing resource call chain information can represent, but is not limited to, performance data of the computing resource call chain information, node information of the computing resource call chain information. For example, the computing resource information usage can be CPU utilization, memory usage. The computing resource information performance indicators can be response time, throughput. The performance data of the computing resource call chain information can be latency, error rate. The node information of the computing resource call chain information can be database, cache.

[0027] It should be noted that the above wireless connection mode can include, but is not limited to, 3G / 4G connection, WiFi connection, Bluetooth connection, WiMAX connection, Zigbee connection, UWB (ultra wideband) connection, and other now known or future developed wireless connection modes.

[0028] Step 102, obtaining an initial computing resource call chain information set.

[0029] In some embodiments, the above execution subject can obtain the initial computing resource call chain information set through wired connection or wireless connection. The initial computing resource call chain information in the initial computing resource call chain information set can be the performance data of the current computing resource call chain information measured by Opentelemetry, the node information of the computing resource call chain information. For example, the performance data of the computing resource call chain information can include response time, throughput. The node information of the computing resource call chain information can include node type, node state.

[0030] It should be noted that the computing resource information set, the computing resource call chain information set, and the initial computing resource call chain information set correspond to the same application system.

[0031] Step 103, performing data standardization processing on the computing resource information set to generate a computing resource standardized information set.

[0032] In some embodiments, the execution subject can perform data standardization processing on the set of computing resource information to generate a set of computing resource standardized information.

[0033] In practice, the execution subject can perform data standardization processing on the set of computing resource information to generate a set of computing resource standardized information by the following steps:

[0034] Firstly, perform normalization processing on the set of computing resource information to generate a set of computing resource normalized information. In practice, the execution subject can perform normalization processing on the meteorological index information in each computing resource information in the set of computing resource information by a preset normalization algorithm to generate computing resource normalized information, thereby obtaining the set of computing resource normalized information. For example, the preset normalization algorithm can be decimal scaling method.

[0035] Secondly, perform data cleaning processing on the set of computing resource normalized information to generate a set of computing resource standardized information. In practice, the execution subject can perform missing value processing on the computing resource normalized information in each computing resource normalized information in the set of computing resource normalized information by a preset missing value algorithm to generate computing resource standardized information in response to determining that the computing resource normalized information satisfies a preset missing condition, thereby obtaining the set of computing resource standardized information. The preset missing condition can be that the computing resource normalized information is empty. For example, the preset missing value algorithm can be interpolation method.

[0036] Step 104, perform data aggregation processing on the set of computing resource call chain information to generate a set of computing resource call chain aggregated information.

[0037] In some embodiments, the execution subject can perform data aggregation processing on the set of computing resource call chain information to generate a set of computing resource call chain aggregated information.

[0038] In practice, the execution subject can perform data aggregation processing on the set of computing resource call chain information to generate a set of computing resource call chain aggregated information by the following steps:

[0039] Firstly, perform node instantiation processing on each computing resource call chain information in the set of computing resource call chain information to generate node instance information, thereby obtaining a set of node instance information. In practice, the execution subject can perform node instantiation processing on the computing resource call chain information in each computing resource call chain information in the set of computing resource call chain information by a preset node instantiation algorithm to generate node instance information, thereby obtaining the set of node instance information. For example, the preset node instantiation algorithm can be depth-first search method.

[0040] Secondly, the computing resource calling chain information set is processed by chain instantiation to generate a chain instance information set. In practice, the execution subject can process each computing resource calling chain information in the computing resource calling chain information set by a preset chain instantiation algorithm to generate a computing resource calling chain instance information, thereby obtaining a computing resource calling chain instance information set. For example, the preset chain instantiation algorithm can be a hierarchical instantiation method.

[0041] Thirdly, the node instance information set and the chain instance information set are processed by data aggregation to generate a computing resource calling chain aggregation information set. In practice, the execution subject can process each node instance information in the node instance information set and the chain instance information corresponding to the node instance information in the chain instance information set to generate a computing resource calling chain aggregation information, thereby obtaining a computing resource calling chain aggregation information set.

[0042] Step 105, the computing resource standardized information set is processed by incremental update to generate a computing resource instance information set.

[0043] In some embodiments, the execution subject can process the computing resource standardized information set by incremental update to generate a computing resource instance information set.

[0044] In practice, the execution subject can process the computing resource standardized information set by incremental update to generate a computing resource instance information set by the following steps:

[0045] Firstly, an initial computing resource information set of each time granularity in a preset time period is obtained. In practice, the execution subject can obtain an initial computing resource information set of each time granularity in a preset time period by wired connection or wireless connection. The initial computing resource information in the initial computing resource information set can be the current computing resource information usage and performance indicators monitored by the resource management platform. For example, the preset time period can be from one hour before the current time to the current time. The time granularity can be 60 seconds.

[0046] Secondly, based on the initial computing resource information set, the computing resource standardized information set is processed in data format updating to generate a computing resource instance information set, and the computing resource instance information set is stored in the resource management database. In practice, the execution subject can process the computing resource standardized information set in data format updating by a preset data format updating algorithm to generate the computing resource instance information set, and store the computing resource instance information set in the resource management database. The resource management database can be a database for storing the computing resource instance information set. For example, the preset data format updating algorithm can be an incremental updating method. The resource management database can be a relational database (Mysql).

[0047] Step 106, the computing resource call chain aggregation information set is processed in incremental updating to generate a computing resource call chain instance information set.

[0048] In some embodiments, the execution subject can process the computing resource call chain aggregation information set in incremental updating to generate the computing resource call chain instance information set.

[0049] In practice, the execution subject can process the computing resource call chain aggregation information set in incremental updating to generate the computing resource call chain instance information set by the following steps:

[0050] Firstly, the initial computing resource call chain information set is processed in data aggregation to generate a computing resource link information set. In practice, the specific implementation manner of processing the initial computing resource call chain information set in data aggregation to generate the computing resource link information set and the technical effects brought by the specific implementation manner can be referred to the step 104 in the above embodiments and will not be described here.

[0051] Secondly, based on the computing resource link information set, the computing resource call chain aggregation information set is processed in data aggregation updating to generate a computing resource call chain instance information set, and the computing resource call chain instance information set is stored in the resource management database. In practice, the execution subject can process the computing resource call chain aggregation information set in data aggregation updating by a preset data aggregation updating algorithm to generate the computing resource call chain instance information set, and store the computing resource call chain instance information set in the resource management database. For example, the preset data aggregation updating algorithm can be an incremental updating method.

[0052] In practice, the execution subject can process the computing resource call chain aggregation information set in incremental updating to generate the computing resource call chain instance information set by the following steps:

[0053] In a first step, the initial computing resource call chain information set is graphically processed to generate a computing resource call chain relationship graph. In practice, the execution subject can graphically process the initial computing resource call chain information set by using a preset graphing algorithm to generate a computing resource call chain relationship graph. The computing resource call chain relationship graph can be a graph with computing resource call chain information as nodes and computing resource call chain relationships as edges. For example, the preset graphing algorithm can be a shortest path method.

[0054] In a second step, the computing resource call chain aggregation information set is subjected to data aggregation update processing based on the computing resource call chain relationship graph to generate a computing resource call chain instance information set, and the computing resource call chain instance information set is stored in the resource management database. In practice, the execution subject can perform data aggregation update processing on the computing resource call chain aggregation information set by using a preset graph analysis algorithm to generate a computing resource call chain instance information set, and store the computing resource call chain instance information set in the resource management database. For example, the preset graph analysis algorithm can be a minimum spanning tree method.

[0055] In step 107, the computing resource instance information set and the computing resource call chain instance information set are input into a pre-trained instance relationship prediction model to obtain a computing resource instance relationship prediction information set.

[0056] In some embodiments, the execution subject can input the computing resource instance information set and the computing resource call chain instance information set into a pre-trained instance relationship prediction model to obtain a computing resource instance relationship prediction information set. The instance relationship prediction model can be a pre-trained neural network model that takes the computing resource instance information set and the computing resource call chain instance information set as input and outputs a computing resource instance relationship prediction information set. The computing resource instance relationship prediction information in the computing resource instance relationship prediction information set can represent, but is not limited to, a computing resource information usage mode and a dependency relationship between the computing resource information and the computing resource call chain. For example, the computing resource information usage mode can include access frequency and load conditions. The dependency relationship between the computing resource information and the computing resource call chain can include a shared resource relationship and a hierarchical relationship. The instance relationship prediction model can be a graph neural network (GNN) model or a long short-term memory (LSTM) model.

[0057] Optionally, before the computing resource instance information set and the computing resource call chain instance information set are input into the pre-trained instance relationship prediction model to obtain the computing resource instance relationship prediction information set, the following steps are performed to train the instance relationship prediction model:

[0058] In a first step, an initial training sample set is obtained.

[0059] In some embodiments, the execution subject can obtain the initial training sample set through wired connection or wireless connection. The initial training sample in the initial training sample set can include: an initial sample computing resource instance information set, an initial sample computing resource call chain instance information set, and an initial sample computing resource instance relationship prediction information set.

[0060] Secondly, for each initial training sample in the initial training sample set, the following feature extraction steps are performed:

[0061] Firstly, the initial training sample is preprocessed to generate a sample preprocessing information set.

[0062] In some embodiments, the execution subject can perform feature extraction processing on the initial training sample through a preset preprocessing algorithm to generate the sample preprocessing information set. For example, the preset preprocessing algorithm can be a maximum and minimum normalization method.

[0063] Secondly, the sample preprocessing information set is subjected to feature selection processing to generate a sample feature information set.

[0064] In some embodiments, the execution subject can perform feature selection processing on each sample preprocessing information in the sample preprocessing information set through a preset feature selection algorithm to generate a sample feature information, thereby obtaining the sample feature information set. For example, the preset feature selection algorithm can be an embedding method.

[0065] Thirdly, the sample feature information set and the initial training sample are subjected to sample fusion processing to generate a training sample.

[0066] In some embodiments, the execution subject performs sample fusion processing on the sample feature information and the initial training sample to generate a training sample. The training sample in the training sample set includes: a sample computing resource instance information set, a sample computing resource call chain instance information set, and a sample computing resource instance relationship prediction information set.

[0067] Thirdly, each generated training sample is determined as a training sample set.

[0068] In some embodiments, the execution subject determines each generated training sample as a training sample set.

[0069] Fourthly, an initial instance relationship prediction model is determined, wherein the initial instance relationship prediction model includes: an initial instance relationship information model and an initial instance relationship inference model.

[0070] In some embodiments, the execution subject determines an initial instance relationship prediction model. The initial instance relationship prediction model includes an initial instance relationship information model and an initial instance relationship inference model.

[0071] The initial instance relationship information model can be a model that takes a sample computing resource instance information set and a sample computing resource invocation chain instance information set as input, and outputs an initial computing resource feature information set. For example, the initial instance relationship information model can be a relational model.

[0072] The initial instance relationship inference model can be a custom model that takes an initial sample computing resource feature information set as input, and outputs a computing resource instance relationship prediction information set. For example, the instance relationship inference model can be a probabilistic graphical model. The custom model can include three layers.

[0073] The first layer is an input layer, configured to input the initial sample computing resource feature information set to the second layer.

[0074] The second layer is a processing layer, including a first sub-model and a second sub-model. The first sub-model can be a model that takes the initial sample computing resource feature information set as input, and outputs a first prediction information sequence. The second sub-model can be a model that takes the first prediction information sequence as input, and outputs the initial computing resource instance relationship prediction information set. For example, the first sub-model can be a support vector machine model. The second sub-model can be a regression tree model. The first prediction information sequence can be a feature embedding vector.

[0075] The third layer is an output layer, configured to output the computing resource instance relationship prediction information set as the output of the entire initial instance relationship inference model.

[0076] In the fifth step, the execution subject selects a target training sample from the training sample set.

[0077] In some embodiments, the execution subject can select a target training sample from the training sample set. In practice, the execution subject can randomly select a training sample from the training sample set as the target training sample.

[0078] In the sixth step, the execution subject inputs the sample computing resource instance information set and the sample computing resource invocation chain instance information set included in the selected target training sample into the initial instance relationship model, to obtain an initial computing resource feature information set.

[0079] In some embodiments, the execution subject can input the sample computing resource instance information set and the sample computing resource invocation chain instance information set included in the selected target training sample into the initial instance relationship model, to obtain an initial computing resource feature information set.

[0080] In the seventh step, the initial sample computing resource feature information set is input into the initial instance relationship inference model to obtain an initial computing resource instance relationship prediction information set.

[0081] In some embodiments, the execution subject described above can input the initial sample computing resource feature information set into the initial instance relationship inference model to obtain an initial computing resource instance relationship prediction information set.

[0082] In the eighth step, based on a preset loss function, a difference value between the initial computing resource instance relationship prediction information set and a sample computing resource instance relationship prediction information set included in the selected target training sample is determined.

[0083] In some embodiments, the execution subject described above can determine, based on a preset loss function, a difference value between the initial computing resource instance relationship prediction information set and a sample computing resource instance relationship prediction information set included in the selected target training sample. The preset loss function can be, but is not limited to, a mean square error loss function (MSE), a hinge loss function (SVM), a cross-entropy loss function (CrossEntropy), a 0-1 loss function, an absolute value loss function, a log loss function, a square loss function, an exponential loss function, etc.

[0084] In the ninth step, in response to determining that the difference value is greater than or equal to a preset difference value, the network parameters of the initial instance relationship prediction model are adjusted.

[0085] In some embodiments, in response to determining that the difference value is greater than or equal to a preset difference value, the execution subject described above can adjust the network parameters of the initial instance relationship prediction model. For example, the difference between the difference value and the preset difference value can be calculated. On this basis, the network parameters of the initial instance relationship prediction model are adjusted by using methods such as back propagation and gradient descent. The preset difference value is not limited, for example, the preset difference value can be 0.4.

[0086] Optionally, in response to determining that the difference value is less than the preset difference value, the initial instance relationship prediction model is determined as a trained instance relationship prediction model.

[0087] In some embodiments, in response to determining that the difference value is less than the preset difference value, the initial instance relationship prediction model is determined as a trained instance relationship prediction model.

[0088] The related content of step 107 is one of the invention points of the embodiments of the present disclosure, which solves the second technical problem mentioned in the background that "it is difficult to effectively issue an alarm for abnormal computing resource identification results". Wherein, it is often difficult to effectively issue an alarm for abnormal computing resource identification results when processing complex computing resource instance relationship prediction information, because the monitoring tool lacks effective aggregation and standardization mechanism, resulting in difficulty in accurately identifying abnormal computing resource results. If the above factors are solved, the effect of reducing the efficiency of alarm processing can be achieved. In order to achieve this effect, based on this, the present disclosure generates an initial instance relationship prediction model. First, an initial training sample set is obtained; thereby the identification ability of the model for different types of alarm information can be improved. Second, the initial training sample set is preprocessed to generate a sample preprocessing information set; the sample preprocessing information set is processed by feature selection to generate a sample feature information set; the sample feature information set and the initial training sample are processed by sample fusion to generate a training sample. Wherein, the training sample in the training sample set includes: a sample computing resource instance information set, a sample computing resource call chain instance information set, and a sample computing resource instance relationship prediction information set; thereby the accurate identification and processing ability of the model for alarm information can be improved. Thirdly, an initial instance relationship prediction model is determined. Wherein, the initial instance relationship prediction model includes: an initial instance relationship information model and an initial instance relationship inference model; thereby the prediction accuracy of the model for computing resource relationship can be improved. Next, a target training sample is selected from the training sample set; thereby the representativeness and effectiveness of the model training can be ensured. Then, the sample computing resource instance information set and the sample computing resource call chain instance information set included in the selected target training sample are input into the initial instance relationship model to obtain an initial computing resource feature information set; the initial sample computing resource feature information set is input into the initial instance relationship inference model to obtain an initial computing resource instance relationship prediction information set; thereby high-quality computing resource relationship prediction information can be generated. Then, based on a preset loss function, a difference value between the initial computing resource instance relationship prediction information set and the sample computing resource instance relationship prediction information set included in the selected target training sample is determined; thereby the performance of the prediction model can be evaluated and the model optimization can be guided. Finally, in response to determining that the difference value is greater than or equal to a preset difference value, the network parameters of the initial instance relationship prediction model are adjusted. Thereby, the prediction accuracy of the model can be improved, thereby improving the efficiency of alarm processing.

[0089] In step 108, the computing resource instance relationship prediction information set is processed by data standardization to generate a computing resource instance relationship prediction standardized information set, and the computing resource instance relationship prediction standardized information set is stored in the resource management database.

[0090] In some embodiments, the execution subject can perform data standardization processing on the set of computing resource instance relationship prediction information to generate a set of computing resource instance relationship prediction standardized information, and store the set of computing resource instance relationship prediction standardized information into the resource management database.

[0091] In practice, the execution subject can perform data standardization processing on each piece of computing resource instance relationship prediction information in the set of computing resource instance relationship prediction information by using a preset standardization algorithm to generate computing resource instance relationship prediction standardized information, obtain the set of computing resource instance relationship prediction standardized information, and store the set of computing resource instance relationship prediction standardized information into the resource management database. For example, the preset standardization algorithm can be a min-max standardization method.

[0092] Step 109, performing abnormality identification processing on the set of computing resource instance relationship prediction standardized information to generate an abnormal computing resource information identification result.

[0093] In some embodiments, the execution subject can perform abnormality identification processing on the set of computing resource instance relationship prediction standardized information to generate an abnormal computing resource information identification result.

[0094] In practice, the execution subject can perform abnormality identification processing on the set of computing resource instance relationship prediction standardized information by using a preset abnormality identification algorithm to generate an abnormal computing resource information identification result. The abnormal computing resource information identification result can represent a computing resource information performance indicator abnormality or a computing resource information performance indicator abnormality. For example, the preset abnormality identification algorithm can be an outlier detection method. For example, the computing resource information performance indicator abnormality can be that the CPU utilization rate exceeds 80%.

[0095] Step 110, in response to determining that the abnormal computing resource information identification result meets a preset abnormality alarm condition, sending the set of computing resource instance relationship prediction standardized information to an associated alarm terminal for abnormality alarm processing.

[0096] In some embodiments, in response to determining that the abnormal computing resource information identification result meets a preset abnormality alarm condition, the execution subject can send the set of computing resource instance relationship prediction standardized information to an associated alarm terminal for abnormality alarm processing. The preset abnormality alarm condition can be that the abnormal computing resource information identification result represents an abnormality. The associated alarm terminal can be an alarm terminal that is communicatively connected to the execution subject. The abnormality alarm processing can be displaying a warning text or controlling a loudspeaker to emit a prompt sound.

[0097] Further reference is made to Figure 2As an implementation of the method shown in the above figures, the present disclosure provides some embodiments of an abnormal computing resource information alarm device, which corresponds to the method embodiments shown in Figure 1 The abnormal computing resource information alarm device can be applied in various electronic devices.

[0098] As shown in Figure 2 The abnormal computing resource information alarm device 200 of some embodiments includes a first acquisition unit 201, a second acquisition unit 202, a standardization unit 203, an aggregation unit 204, a first update unit 205, a second update unit 206, an input unit 207, a storage unit 208, an identification unit 209, and a sending unit 210. The first acquisition unit 201 is configured to acquire a set of computing resource information and a set of computing resource call chain information. The second acquisition unit 202 is configured to acquire an initial set of computing resource call chain information. The standardization unit 203 is configured to perform data standardization processing on the set of computing resource information to generate a set of computing resource standardized information. The aggregation unit 204 is configured to perform data aggregation processing on the set of computing resource call chain information to generate a set of computing resource call chain aggregated information. The first update unit 205 is configured to perform incremental update processing on the set of computing resource standardized information to generate a set of computing resource instance information. The second update unit 206 is configured to perform incremental update processing on the set of computing resource call chain aggregated information to generate a set of computing resource call chain instance information. The input unit 207 is configured to input the set of computing resource instance information and the set of computing resource call chain instance information into a pre-trained instance relationship prediction model to obtain a set of computing resource instance relationship prediction information. The storage unit 208 is configured to perform data standardization processing on the set of computing resource instance relationship prediction information to generate a set of computing resource instance relationship prediction standardized information, and store the set of computing resource instance relationship prediction standardized information into a resource management database. The identification unit 209 is configured to perform abnormality identification processing on the set of computing resource instance relationship prediction standardized information to generate an abnormal computing resource information identification result. The sending unit 210 is configured to, in response to determining that the abnormal computing resource information identification result satisfies a preset abnormal alarm condition, send the set of computing resource instance relationship prediction standardized information to an associated alarm terminal for abnormal alarm processing.

[0099] It can be understood that the units described in the abnormal computing resource information alarm device 200 correspond to the steps in the method described with reference to Figure 1 The operations, features, and beneficial effects described above for the method also apply to the abnormal computing resource information alarm device 200 and the units included therein, which will not be described here.

[0100] Reference will now be made to Figure 3 which shows a structural diagram of an electronic device 300 (e.g., a computing device) suitable for use in implementing some embodiments of the present disclosure. The electronic device in some embodiments of the present disclosure can include, but is not limited to, a mobile terminal such as a mobile phone, a notebook computer, a digital broadcasting receiver, a PDA (Personal Digital Assistant), a PAD (Tablet PC), a PMP (Portable Multimedia Player), and the like, and a stationary terminal such as a digital TV, a desktop computer, and the like. Figure 3 The illustrated electronic device is merely an example and should not bring any limitation to the function and range of use of embodiments of the present disclosure.

[0101] As Figure 3 shown, the electronic device 300 can include a processing means (e.g., a central processor, a graphic processor, etc.) 301 that can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 302 or loaded into a random access memory (RAM) 303 from a storage means 308. In the RAM 303, various programs and data required for the operation of the electronic device 300 are also stored. The processing means 301, the ROM 302, and the RAM 303 are connected to each other through a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.

[0102] In general, the following means can be connected to the I / O interface 305: an input means 306 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, and the like; an output means 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, and the like; a storage means 308 including, for example, a magnetic tape, a hard disk, and the like; and a communication means 309. The communication means 309 can allow the electronic device 300 to communicate wirelessly or by wire with other devices to exchange data. Although Figure 3 The electronic device 300 is shown with various means, but it is understood that all of the illustrated means are not required to be implemented or present. More or fewer means can alternatively be implemented or present. Figure 3 Each block shown in the middle can represent one means or, as desired, multiple means.

[0103] In particular, the processes described above with reference to the flowcharts can be implemented as a computer software program according to some embodiments of the present disclosure. For example, some embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer readable medium, the computer program comprising program code for performing the methods illustrated by the flowcharts. In some such embodiments, the computer program can be downloaded and installed from a network via the communication device 309, or installed from the storage device 308, or installed from the ROM 302. When the computer program is executed by the processing device 301, the above-described functions defined in the methods of some embodiments of the present disclosure are performed.

[0104] It should be noted that the computer readable medium recorded with the program code according to some embodiments of the present disclosure can be a computer readable signal medium or a computer readable storage medium, or any combination of the two. The computer readable storage medium may, for example, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination of the above. More specific examples of the computer readable storage medium can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus or device. In some embodiments of the present disclosure, the computer readable signal medium can include a data signal carried in a baseband or as a part of a carrier wave, which carries computer readable program code. Such a propagated data signal can take on many forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. The computer readable signal medium can also be any computer readable medium that is not a computer readable storage medium and that can communicate, propagate or transport program for use by or in connection with an instruction execution system, apparatus or device. The program code contained on the computer readable medium can be transmitted by any suitable medium, including but not limited to a wire, cable, optical fiber, RF (radio frequency), or any suitable combination of the above.

[0105] In some embodiments, the client, server, or other machines communicating can utilize any current or future developed network protocols, such as HTTP (HyperText Transfer Protocol), to communicate, and can be interconnected with any form or medium of digital data communication (e.g., communication networks). Examples of communication networks include local area networks ("LANs"), wide area networks ("WANs"), the Internet, and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any current or future developed network.

[0106] The computer readable medium described above can be included in the electronic device described above; or can exist separately from the electronic device and be not assembled into the electronic device. The computer readable medium described above carries one or more programs, when the one or more programs are executed by the electronic device, cause the electronic device to: acquire a set of computing resource information and a set of computing resource invocation chain information; acquire an initial set of computing resource invocation chain information; perform data standardization processing on the set of computing resource information to generate a set of computing resource standardized information; perform data aggregation processing on the set of computing resource invocation chain information to generate a set of computing resource invocation chain aggregated information; perform incremental update processing on the set of computing resource standardized information to generate a set of computing resource instance information; perform incremental update processing on the set of computing resource invocation chain aggregated information to generate a set of computing resource invocation chain instance information; input the set of computing resource instance information and the set of computing resource invocation chain instance information into a pre-trained instance relationship prediction model to obtain a set of computing resource instance relationship prediction information; perform data standardization processing on the set of computing resource instance relationship prediction information to generate a set of computing resource instance relationship prediction standardized information, and store the set of computing resource instance relationship prediction standardized information into a resource management database; perform abnormality identification processing on the set of computing resource instance relationship prediction standardized information to generate an abnormal computing resource information identification result; in response to determining that the abnormal computing resource information identification result satisfies a preset abnormality alarm condition, send the set of computing resource instance relationship prediction standardized information to an associated alarm terminal to perform abnormality alarm processing.

[0107] Computer program code for carrying out operations of some embodiments of the present disclosure can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0108] The flow diagrams and the block diagrams in the drawings are illustrations of architectures, functionalities, and operations of possible implementations of systems, methods, and computer program products according to various embodiments of present disclosure. In this regard, each block in the flow diagrams or block diagrams can represent a module, a segment, or a portion of code, which comprises one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks may

[0109] The units described in some embodiments of the present disclosure can be implemented by software, or can be implemented by hardware. The described units can also be arranged in a processor, for example, can be described as: a processor comprising a first acquisition unit, a second acquisition unit, a standardization unit, an aggregation unit, a first update unit, a second update unit, an input unit, a storage unit, an identification unit, and a sending unit. Among them, the names of these units do not constitute a limitation on the units themselves in some cases, for example, the sending unit can also be described as: "a unit that, in response to determining that the abnormal computing resource information identification result meets the preset abnormal alarm condition, sends the computing resource instance relationship prediction standardization information set to the associated alarm terminal for abnormal alarm processing".

[0110] The functionality described herein above can be performed, at least in part, by one or more hardware logic components. For example, and without limitation, illustrative types of hardware logic components that can be used include Field-programmable Gate Arrays (FPGAs), Program- specific Integrated Circuits (ASICs), Program- specific Standard Products (ASSPs), System-on-a-chip systems (SOCs), Complex Programmable Logic Devices (CPLDs), etc.

[0111] The above description is merely exemplary of the disclosure and the application made use of the principles of the technology. It is to be understood that the application scope of the embodiments of the disclosure is not limited to the specific combinations of technical features described above, and should also cover other technical solutions formed by any combination of the above technical features or equivalent features thereof without departing from the inventive concept. For example, the technical solutions formed by replacing the above features with technical features having similar functions disclosed in the embodiments of the disclosure (but not limited to) with each other.

Claims

1. A method for alarming abnormal computing resource information, comprising: Obtaining a computing resource information set and a computing resource call chain information set, wherein the computing resource information in the computing resource information set represents: computing resource information usage and computing resource information performance indicators; the computing resource call chain information represents: performance data of computing resource call chain information and node information of computing resource call chain information; Obtain the initial computing resource call chain information set; Performing data standardization processing on the computing resource information set to generate a computing resource standardized information set, wherein performing data standardization processing on the computing resource information set to generate a computing resource standardized information set includes: Normalizing the computing resource information set to generate a computing resource normalized information set; Performing data cleaning on the computing resource normalization information set to generate a computing resource standardization information set; Performing data aggregation processing on the computing resource call chain information set to generate a computing resource call chain aggregate information set; Performing incremental update processing on the computing resource standardized information set to generate a computing resource instance information set; Performing incremental update processing on the computing resource call chain aggregate information set to generate a computing resource call chain instance information set; Inputting the computing resource instance information set and the computing resource call chain instance information set into a pre-trained instance relationship prediction model to obtain a computing resource instance relationship prediction information set, wherein the computing resource instance relationship prediction information in the computing resource instance relationship prediction information set represents: a computing resource information usage pattern, and a dependency relationship between the computing resource information and the computing resource call chain; performing data standardization processing on the computing resource instance relationship prediction information set to generate a computing resource instance relationship prediction standardized information set, and storing the computing resource instance relationship prediction standardized information set in a resource management database; Performing anomaly identification processing on the computing resource instance relationship prediction standardized information set to generate an abnormal computing resource information identification result, wherein the abnormal computing resource information identification result indicates that: a computing resource information performance indicator is abnormal; In response to determining that the abnormal computing resource information identification result meets the preset abnormal alarm condition, the computing resource instance relationship prediction standardized information set is sent to the associated alarm terminal for abnormal alarm processing.

2. The method according to claim 1, wherein The performing data aggregation processing on the computing resource call chain information set to generate a computing resource call chain aggregate information set includes: Performing node instantiation processing on each computing resource call chain information in the computing resource call chain information set to generate node instance information and obtain a node instance information set; Performing chain instantiation processing on the computing resource call chain information set to generate a chain instance information set; Data aggregation processing is performed on the node instance information set and the chain instance information set to generate a computing resource call chain aggregation information set.

3. The method according to claim 1, wherein The incremental updating process of the computing resource standardized information set to generate a computing resource instance information set includes: Obtaining an initial computing resource information set for each time granularity within a preset time period; Based on the initial computing resource information set, data format updating processing is performed on the computing resource standardization information set to generate a computing resource instance information set, and the computing resource instance information set is stored in a resource management database.

4. The method according to claim 1, wherein The incremental updating process of the computing resource call chain aggregate information set to generate a computing resource call chain instance information set includes: Performing data aggregation processing on the initial computing resource call chain information set to generate a computing resource link information set; Based on the computing resource link information set, data aggregation and update processing is performed on the computing resource call chain aggregation information set to generate a computing resource call chain instance information set, and the computing resource call chain instance information set is stored in a resource management database.

5. The method according to claim 1, wherein The incremental updating process of the computing resource call chain aggregate information set to generate a computing resource call chain instance information set includes: Graphically processing the initial computing resource call chain information set to generate a computing resource call chain relationship graph; Based on the computing resource call chain relationship diagram, data aggregation and update processing is performed on the computing resource call chain aggregation information set to generate a computing resource call chain instance information set, and the computing resource call chain instance information set is stored in a resource management database.

6. An abnormal computing resource information alarm device, comprising: A first acquisition unit is configured to acquire a computing resource information set and a computing resource call chain information set, wherein the computing resource information in the computing resource information set represents: computing resource information usage and computing resource information performance indicators, and the computing resource call chain information represents: performance data of computing resource call chain information and node information of computing resource call chain information; A second acquiring unit is configured to acquire an initial computing resource call chain information set; A standardization unit is configured to perform data standardization processing on the computing resource information set to generate a computing resource standardized information set, wherein the performing data standardization processing on the computing resource information set to generate the computing resource standardized information set includes: Normalizing the computing resource information set to generate a computing resource normalized information set; Performing data cleaning on the computing resource normalization information set to generate a computing resource standardization information set; an aggregation unit configured to perform data aggregation processing on the computing resource call chain information set to generate a computing resource call chain aggregation information set; a first updating unit configured to perform incremental update processing on the computing resource standardized information set to generate a computing resource instance information set; a second updating unit configured to perform incremental update processing on the computing resource call chain aggregate information set to generate a computing resource call chain instance information set; An input unit is configured to input the computing resource instance information set and the computing resource call chain instance information set into a pre-trained instance relationship prediction model to obtain a computing resource instance relationship prediction information set, wherein the computing resource instance relationship prediction information in the computing resource instance relationship prediction information set represents: a computing resource information usage pattern, and a dependency relationship between computing resource information and a computing resource call chain; a storage unit configured to perform data standardization processing on the computing resource instance relationship prediction information set to generate a computing resource instance relationship prediction standardized information set, and store the computing resource instance relationship prediction standardized information set in a resource management database; an identification unit configured to perform an abnormality identification process on the computing resource instance relationship prediction standardized information set to generate an abnormal computing resource information identification result, wherein the abnormal computing resource information identification result indicates that: a computing resource information performance indicator is abnormal; The sending unit is configured to send the computing resource instance relationship prediction standardized information set to the associated alarm terminal for abnormal alarm processing in response to determining that the abnormal computing resource information identification result meets the preset abnormal alarm condition.

7. An electronic device comprising: one or more processors; a storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 5.

8. A computer-readable medium having a computer program stored thereon, wherein: When the program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Abnormity prediction method and device in full-link monitoring system

    CN110428018A

  • Alarm aggregation method and related equipment

    CN113486192A