Alarm processing method, device, apparatus and storage medium

By using machine learning models to process alarms in multi-cloud security management, identifying entities and generating analysis results, the problem of inconsistent alarm logs in multi-cloud environments is solved, and alarm processing efficiency and accuracy are improved.

CN119356994BActive Publication Date: 2025-11-07BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411598049.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-08
Publication Date
2025-11-07
Estimated Expiration
2044-11-08

AI Technical Summary

Technical Problem

In multi-cloud security management scenarios, the large number of assets from different providers and the inconsistent alarm log formats pose significant challenges for operations and maintenance personnel, making it difficult to effectively manage a large number of alarms and easily leading to alarm storms.

Method used

By using machine learning-based methods, the entity involved is identified based on the description information of the target alarm, log information and auxiliary information related to the entity are obtained, analysis results are generated, and alarm processing is performed using machine learning models.

Benefits of technology

It reduces the management cost of alarms, improves processing efficiency, reduces the need for manual viewing of the log system, and enhances the ability to judge and trace alarm events.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119356994B_ABST
    Figure CN119356994B_ABST
Patent Text Reader

Abstract

According to an embodiment of the present disclosure, a method, device, equipment and storage medium for alarm processing are provided. The method comprises: determining a first entity involved in a target alarm occurring in a target system based on description information of the target alarm; obtaining first log information related to the first entity in the target system and first auxiliary information corresponding to the first log information, the auxiliary information being used to describe an exception in a log of the target system; and generating an analysis result for the target alarm based on the first log information and the first auxiliary information. In this way, manual checking of the log system by an operation and maintenance personnel can be reduced, the management cost for the alarm can be reduced, and the efficiency of processing the alarm can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Example embodiments of the present disclosure generally relate to the field of computers, and in particular, to a method, apparatus, device and computer readable storage medium for alarm processing. BACKGROUND

[0002] In the operation and maintenance management of information systems such as business networks, business platforms, etc., alarms are the most important part to determine whether the information system has a security risk or intrusion behavior. In particular, in some scenarios, various assets (e.g., physical devices, software systems, applications) in the information system may come from different providers. One such example scenario is a multi-cloud security management scenario. In these scenarios, the operation and maintenance personnel need to discover and solve problems in time through alarms to ensure the availability and stability of services. However, due to the large number of assets in the information system, the number of alarms also increases dramatically. On the other hand, assets from different providers are not uniform in terms of the format, content, etc. of the alarm logs. These factors pose a huge challenge to the operation and maintenance personnel. For example, scattered alarms for indicators, links, logs, without good monitoring management, can easily cause an alarm storm. Therefore, for a large number of alarms, an effective management method is expected. SUMMARY

[0003] In a first aspect of the present disclosure, a method for alarm processing is provided. The method comprises: determining a first entity involved in a target alarm occurring in a target system based on description information of the target alarm; obtaining first log information related to the first entity in the target system and first auxiliary information corresponding to the first log information, the auxiliary information being used to describe an anomaly in a log of the target system; and generating an analysis result for the target alarm based on the first log information and the first auxiliary information.

[0004] In a second aspect of the present disclosure, an apparatus for alarm processing is provided. The apparatus comprises: an entity determination module configured to determine a first entity involved in a target alarm occurring in a target system based on description information of the target alarm; an information obtaining module configured to obtain first log information related to the first entity in the target system and first auxiliary information corresponding to the first log information, the auxiliary information being used to describe an anomaly in a log of the target system; and an analysis result generation module configured to generate an analysis result for the target alarm based on the first log information and the first auxiliary information.

[0005] In a third aspect of the present disclosure, an electronic device is provided. The device comprises at least one processing unit; and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit. The instructions, when executed by the at least one processing unit, cause the device to perform the method of the first aspect.

[0006] In a fourth aspect of the present disclosure, a computer readable storage medium is provided. The computer readable storage medium has stored thereon a computer program, which is executable by a processor to implement the method of the first aspect.

[0007] It should be understood that the content described in this section is not intended to limit the key features or important features of the embodiments of the present disclosure, nor to limit the scope of the present disclosure. Other features of the present disclosure will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0008] The above and other features, advantages and aspects of embodiments of the present disclosure will become more apparent by describing in detail some embodiments thereof with reference to the attached drawings in which:

[0009] Figure 1 A schematic diagram showing an example environment in which embodiments of the present disclosure can be implemented is shown;

[0010] Figure 2 A schematic diagram showing an example architecture for alarm processing according to some embodiments of the present disclosure is shown;

[0011] Figure 3 A schematic diagram showing an example architecture of mapping relationship of entities and data sources according to some embodiments of the present disclosure is shown;

[0012] Figure 4 A schematic diagram showing an example interface for parameter configuration according to some embodiments of the present disclosure is shown;

[0013] Figure 5 A schematic diagram showing an example architecture for tracing an alarm according to some embodiments of the present disclosure is shown;

[0014] Figure 6 A flow chart showing a process of alarm processing according to some embodiments of the present disclosure is shown;

[0015] Figure 7 A block diagram of an apparatus for alarm processing according to some embodiments of the present disclosure is shown; and

[0016] Figure 8 A block diagram of an apparatus capable of implementing embodiments of the present disclosure is shown. DETAILED DESCRIPTION

[0017] It can be understood that, before using the technical solutions disclosed by the embodiments of the present disclosure, the type of personal information involved in the present disclosure, the scope of use, the scenario of use, etc. should be informed to the user and the authorization of the user should be obtained in accordance with relevant laws and regulations.

[0018] For example, in response to receiving an active request of a user, a prompt information is sent to the user to explicitly prompt the user that the operation requested to be performed by the user will require obtaining and using personal information of the user. Thus, the user can autonomously select whether to provide the personal information to the software or hardware such as an electronic device, an application program, a server or a storage medium performing the operation of the technical solution of the present disclosure according to the prompt information.

[0019] As an optional but non-limiting implementation, in response to receiving an active request of a user, the manner of sending a prompt information to the user may, for example, be a pop-up window manner, and the prompt information may, for example, be presented in the pop-up window in the form of text. In addition, the pop-up window may, for example, also carry a selection control for the user to select “agree” or “disagree” to provide personal information to the electronic device.

[0020] It can be understood that the above notification and obtaining of user authorization process is only illustrative, and does not limit the implementation of the present disclosure, and other manners meeting the relevant laws and regulations can also be applied to the implementation of the present disclosure.

[0021] It can be understood that the data involved in the technical solution (including but not limited to the data itself, the obtaining or use of the data) should comply with the requirements of the relevant laws and regulations and the relevant provisions.

[0022] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms, and should not be interpreted as being limited to the embodiments set forth herein, rather, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes, and are not intended to limit the scope of protection of the present disclosure.

[0023] It should be noted that the titles of any section / subsection provided herein are not limiting. Various embodiments are described throughout this document, and any type of embodiment can be included under any section / subsection. Furthermore, embodiments described in any section / subsection can be combined with any other embodiment described in the same section / subsection and / or a different section / subsection in any manner.

[0024] In this document, unless explicitly stated, performing a step “in response to A” does not mean that the step is performed immediately after “A”, but can include one or more intermediate steps.

[0025] In the description of embodiments of the disclosure, the term "comprising" and its conjugations should be understood as open-ended inclusion, i.e., "including but not limited to". The term "based on" should be understood as "based at least in part on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The term "some embodiments" should be understood as "at least some embodiments". The following may also include other explicit and implicit definitions. The terms "first", "second", etc. can refer to different or the same objects. The following may also include other explicit and implicit definitions.

[0026] As used herein, the term "model" can learn the association between the corresponding input and output from the training data, so that the corresponding output can be generated for a given input after the training is completed. The generation of the model can be based on machine learning techniques. Deep learning is a machine learning algorithm that processes input and provides a corresponding output by using multiple layers of processing units. In this document, "model" can also be referred to as "machine learning model", "machine learning network" or "network", which are used interchangeably in this document. A model can also include different types of processing units or networks.

[0027] As used herein, the judgment of the alarm refers to determining whether the alarm is truly risky or has the possibility of being risky. The traceability of the alarm refers to determining the source of the event corresponding to the alarm and / or the attack link, etc.

[0028] As briefly mentioned above, as the business continues to expand and the system continues to upgrade, the number of alarms also increases dramatically. Conventionally, the management of alarms is mainly performed by providing raw log search. However, this approach has weak capabilities for alarm event judgment and traceability, and the raw log needs to be understood manually, which increases the cost.

[0029] Further, through the addition of a large amount of expert experience and a large amount of context data mining, the ability to judge and trace events can be improved. However, the construction investment for improving the ability to judge and trace events is large. Accordingly, a variety of technologies and a large amount of expert experience need to be invested, such as extracting entity relationships, a large number of recommended experiences of experts (e.g., log search), investigating graphs, etc.

[0030] In view of this, embodiments of the disclosure propose a scheme for alarm processing. According to various embodiments of the disclosure, based on description information of a target alarm occurring in a target system, a first entity involved in the target alarm is determined. Subsequently, first log information related to the first entity in the target system and first auxiliary information corresponding to the first log information are obtained. The first auxiliary information is used to describe an anomaly in the log of the target system. Then, based on the first log information and the first auxiliary information, an analysis result for the target alarm is generated.

[0031] In the embodiments of this disclosure, for each alarm, the entity involved in the alarm is first extracted, that is, the focus is initially on the entity with potential problems. Then, the focus is further on log information and auxiliary information related to that entity. In this way, information related to the current alarm event can be extracted from a large amount of data in the target system, and this information can be used to analyze the alarm. This approach reduces the need for manual review of the log system by operations and maintenance personnel, lowers the management cost of alarms, and improves the efficiency of alarm processing.

[0032] Example Environment

[0033] Figure 1 A schematic diagram of an example environment 100 in which embodiments of the present disclosure can be implemented is shown. For example... Figure 1 As shown, environment 100 may include system management platform 110. In this example environment 100, system management platform 110 can be used to manage a large number of alarms generated by hosts, networks, security devices, etc., within an organization (enterprise, government agency, other group, etc.). System management platform 110 can present a large number of alarms in a list format on its corresponding interface 142. User 140 can manage the large number of alarms in the organization based on system management platform 110.

[0034] Based on the descriptive information of alarms occurring within the organization, the system management platform 110 determines the log information of the entity corresponding to the alarm and auxiliary information used to describe the anomalies in the logs. Then, the system management platform 110 generates an analysis result for the alarm based on the log information and auxiliary information. In some embodiments, at least some functions of the system management platform 110 can be implemented based on the target model 155.

[0035] In the process of generating analysis results for alarms occurring within the organization, the system management platform 110 can invoke one or more target models 155, such as the capabilities of target model 155. As used herein, the term "model" refers to a model that learns the correlation between inputs and outputs from training data, thereby generating corresponding outputs for a given input after training is complete. Model generation can be based on machine learning techniques. Deep learning is a machine learning algorithm that processes inputs and provides corresponding outputs using multiple layers of processing units. A neural network model is an example of a model based on deep learning. In this document, "model" may also be referred to as a "machine learning model," "learning model," "machine learning network," or "learning network," and these terms are used interchangeably herein.

[0036] The system management platform 110 can be deployed locally at the terminal device of the user 140, and / or can be supported by a server device. For example, the terminal device of the user 140 can run a client of the system management platform, which can support the user’s interaction with the system management platform provided by the server. In the case that the system management platform is run locally at the terminal device of the user, the user 140 can directly utilize the terminal device to interact with the local system management platform. In the case that the system management platform is run at the server device, the server device can implement service provision to the client run at the terminal device based on the communication connection between the server device and the terminal device. The system management platform 110 can present a corresponding interface 142 to the user 140 based on the operation of the user 140, to output and / or receive information related to system management to / from the user 140.

[0037] The system management platform 110 can be run at an appropriate electronic device. The electronic device here can be any type of device with computing capability, including a terminal device or a server device. The terminal device can be any type of mobile terminal, stationary terminal, or portable terminal, including a mobile phone, a desktop computer, a laptop computer, a notebook computer, a netbook computer, a tablet computer, a media computer, a multimedia tablet, a personal communication system (PCS) device, a personal navigation device, a personal digital assistant (PDA), an audio / video player, a digital camera / camcorder, a positioning device, a television receiver, a radio broadcast receiver, an electronic book device, a game device, or any combination of the foregoing, including accessories and peripherals of these devices or any combination thereof. The server device may, for example, include a computing system / server, such as a mainframe, an edge computing node, a computing device in a cloud environment, etc. In some embodiments, the data management platform 110 can be implemented based on a cloud service.

[0038] It should be understood that the structure and function of the environment 100 are described for illustrative purposes only, without implying any limitation on the scope of the present disclosure.

[0039] Some example embodiments of the present disclosure will be described hereinafter with continuous reference to the drawings. In the following, the example embodiments will be mainly described with respect to the system management platform 110. It should be understood that the actions described with respect to the system management platform 110 can be performed by a plugin included in the system management platform 110, or can be performed by the plugin in cooperation with its server (e.g., server) and / or machine learning model.

[0040] The process of the present disclosure for alarm processing will be described first with reference to Figure 2 Figure 2 A schematic diagram of an example architecture 200 for alarm processing according to some embodiments of the present disclosure is shown.

[0041] ​In some embodiments, the system management platform 110 determines the first entity involved in the target alarm according to the description information of the target alarm sent in the target system. In some examples, the description information of the target alarm (e.g., the detail information of the target alarm) can include one or more of the following: the name of the target alarm, the occurrence time of the target alarm, the context field related to the target alarm, the original log corresponding to the target alarm, the device corresponding to the target alarm, login information, and the like. The specific content of the description information of the target alarm is related to the type of the target alarm.

[0042] In some examples, the system management platform 110 can generate the first entity related to the target alarm according to the description information of the target alarm. In the description herein, an entity can refer to various types of components in an information system that can be distinguished and identified, such as physical components, abstract components. In some embodiments, the first entity includes at least one of a host, a file, an object, an account, an address, a process. In some examples, the first entity can be an entity determined from a plurality of predetermined types of entities. For example, the IP address, host, process, account, object, file, and the like entities involved in the target alarm. As Figure 2 As shown in the example process 200, at block 210, the system management platform 110 obtains the description information of the target alarm. At block 211, the system management platform 110 can input the description information of the target alarm into the machine learning model 211. At block 212, the system management platform 110 determines whether there is an alarm in the alarm information library that matches the target alarm via the machine learning model 211 based on the description information of the target alarm. In some embodiments, the alarm information library is obtained based on the determination of historical alarms, which includes the description information and analysis results corresponding to each historical alarm.

[0043] In the case where there is no alarm in the alarm information library that matches the alarm, the system management platform 110 determines the first entity involved in the target alarm based on the description information of the target alarm. The following will continue to refer to Figure 2 The following describes how the system management platform 110 determines the first entity involved in the target alarm in the case where there is an alarm in the alarm information library that matches the alarm. At block 213, in the case where there is no alarm in the alarm information library that matches the alarm, the system management platform 110 can input the description information of the target alarm into the machine learning model. At block 214, the system management platform 110 obtains a plurality of entities (e.g., address, domain name, file, resource, account, user, alarm, and the like) related to the target alarm output via the machine learning model, and the plurality of entities include the first entity.

[0044] In some examples, the system management platform 110 extracts an entity related to the target alarm according to the description information of the target alarm. For example, in the case of asset external connection external IP or external IP accessing assets in the log details, the system management platform 110 extracts the IP entity. If the alarm entity is extracted, the name of the alarm, the earliest sending time of the alarm, and the latest update time of the alarm are all represented by timestamps. If the asset in the log details belongs to a cloud account, the user entity is extracted. If the user entity is extracted, the cloud account to which the current asset belongs, the cloud account name to which the current asset belongs, and the like are extracted. If the asset in the alarm details is a host, the host entity is extracted, including the ID of the host asset, the name of the host asset, the private IP of the host asset, and the public IP of the host asset.

[0045] If the domain name asset of the Web Application Firewall (WAF) alarm or the domain name matched from the command line resolution library (cmdline) is extracted, the domain name entity is extracted. If there is a file (for example, a malicious file or a downloaded file) in the alarm details, the file entity is extracted, including the file path, the hash value or the message digest algorithm (md5) value of the file. If there is process related information in the alarm details, the process entity is extracted, including the process ID, the process name, the file that starts the process, the process start time, the host ID that starts the process, the user ID that executes the process, the command that starts the process, the process call chain, the ID of the parent process, the name of the parent process, and the command of the parent process. If a cloud resource interface is accessed, the interface is abstracted into a service entity, including the service name, the service ID, and the method or operation of the service.

[0046] In some embodiments, the system management platform 110 obtains first log information related to a first entity in a target system and first auxiliary information corresponding to the first log information. In some embodiments, the first auxiliary information is used to describe an anomaly in the log of the target system. The auxiliary information corresponding to the log information may, for example, be a predetermined rule, an expert description, and the like.

[0047] In some examples, the system management platform 110 obtains a plurality of data sets associated with the first entity after determining the first entity involved in the target alert. Each data set in the plurality of data sets includes first log information (e.g., login logs, network logs, etc.) related to the first entity and first auxiliary information (also can be referred to as judgment rules, or hints provided for machine learning models) corresponding to the first log information. For example, for an IP entity, the system management platform 110 can obtain login logs corresponding to the IP address and first auxiliary information corresponding to the login logs indicating abnormal behaviors (e.g., brute force cracking, accessing sensitive interfaces, etc.). For a host entity, the system management platform 110 can obtain network logs of the host and first auxiliary information corresponding to the network logs indicating abnormal behaviors, etc. The system management platform 110 obtaining the first log information related to the first entity and the first auxiliary information corresponding to the first log information will be described in detail below.

[0048] In some embodiments, the system management platform 110 generates an analysis result for the target alert according to the first log information and the first auxiliary information. In some examples, the system management platform 110 generates contexts of the target alert according to the first log information and the first auxiliary information, and summarizes a plurality of contexts as an analysis report for the target alert. In some examples, the system management platform 110 can obtain the analysis result output in a predetermined format (e.g., JSON format) via a machine learning model.

[0049] For example, the analysis result for the target alert generated by the system management platform 110 can include an attack rate corresponding to the target alert, an attack rate corresponding to the first entity, a logic of analyzing the target alert, detailed information of abnormalities in each entity involved in the target alert, etc. In some examples, the system management platform 110 can generate contexts of the target alert according to the first log information and the first auxiliary information by using a machine learning model.

[0050] Continuing the process 200, since the original logs 217 include fragments of logs in various storage systems, the system management platform 110 can obtain the log fragments based on the plug-ins. In some examples, the system management platform 110 can obtain, for each log fragment, hints 218 (also can be referred to as expert experience, or rules) configured by a user based on the scenario query requirements 219.

[0051] At block 230, the system management platform 110 obtains an analysis result for the first entity by invoking a machine learning model based on the log snippet of the first entity (e.g., a domain name entity) and the prompt word 218 corresponding to the log snippet. For example, the first entity can correspond to multiple data sets, and each data set can correspond to multiple rules. In some examples, the system management platform 110 can invoke the machine learning model to obtain an attack probability of each data set. Accordingly, the attack probability of the first entity can be calculated in the following expression: 1-(1-a data set attack rate)*(1-b data set attack rate)*…*(1-n data set attack rate). In some examples, if the attack probability of an entity is greater than a predetermined probability threshold (e.g., XX%), the entity has a risk of attack.

[0052] At block 231, the system management platform 110 determines an analysis result of the target alert (i.e., a report formed by the context information of the target alert) based on the analysis results of the multiple entities respectively corresponding to the analysis results obtained by invoking the machine learning model. Subsequently, the system management platform 110 can store the description information and the analysis result of the target alert in the alert information library 234.

[0053] Thus, processing the alert based on the log information and the auxiliary information can reduce the threshold of judgment and tracing of the alert, thereby improving the efficiency of processing the alert. The system management platform 110 obtains the first log information related to the first entity and the first auxiliary information corresponding to the first log information is described as follows.

[0054] In some embodiments, the system management platform 110 determines at least one scene according to the entity type of the first entity. In some embodiments, a scene in the at least one scene is configured with a corresponding log range and an abnormal state description in the log range. In some embodiments, the system management platform 110 first determines a plurality of candidate scenes corresponding to the first entity type. Then, the system management platform 110 selects at least one scene from the plurality of candidate scenes according to the description information of the target alert by using a machine learning model.

[0055] Continuing the process 200, at block 215, the system management platform 110 inputs a first entity of the plurality of entities 214 into a machine learning model. At block 216, the system management platform 110 invokes a plugin (e.g., a search plugin) 221, a plugin (e.g., a log service language plugin) 222, a plugin (e.g., a visualization plugin) 223, a plugin (e.g., a transport layer plugin) 224, a plugin (e.g., other log query plugins) 225, and so on to obtain a plurality of candidate scenarios (may also be referred to as entity built-in scenarios) 220 for the first entity. It can be appreciated that the system management platform 110 utilizes the plugins to convert the data set corresponding to the first entity into natural language understandable by the machine learning model. Then, the system management platform 110 utilizes the machine learning model to determine at least one scenario from the plurality of candidate scenarios for investigating whether the target alert is abnormal.

[0056] In some embodiments, the at least one scenario is configured with a corresponding log range and an abnormal state description within the log range. It can be appreciated that the at least one scenario indicates a plurality of rules (e.g., prompt words for providing to the machine learning model) corresponding to the data set related to the first entity associated with the target alert. The data set and the scenario are in a one-to-many relationship, i.e., one data set can be configured with a plurality of rules (e.g., prompt words for providing to the machine learning model). As shown in Table 1, a user can customize and extend the prompt words according to the data set, and Table 1 is an example of the at least one scenario.

[0057] Table 1

[0058]

[0059]

[0060]

[0061] In some embodiments, the system management platform 110 determines the first log information based on the log range respectively configured by the at least one scenario. As shown in Table 1, each row is a scenario. The log range configured by the scenario is shown for the second row in Table 1, e.g., login logs N days before the alert. Subsequently, the system management platform 110 is able to determine the first log information to be extracted according to the login logs N days before the alert and the occurrence time of the alert.

[0062] In some embodiments, the system management platform 110 extracts, as at least part of the first log information, a target log segment from the target system for a first scenario of the at least one scenario based on a log range configured for the first scenario. In some examples, the system management platform 110 can extract the target log segment from the target system based on a log query statement of a data set corresponding to the first entity based on the log range configured for the first scenario. In some examples, each data set corresponds to a query statement (e.g., a structured query language (SQL)). Due to the difference in user log formats, the SQL statements have differences, and thus the mapping of the SQL template field and the original log field can be automatically completed by the prompt words used to generate the SQL statements. As shown in Table 2, the data sets are extensible, and Table 2 shows a plurality of examples of the data sets.

[0063] Table 2

[0064]

[0065]

[0066]

[0067] In some embodiments, the log range configured for the first scenario indicates a log name and a time range. In some embodiments, the system management platform 110 determines a target log in the target system based on the log name. Accordingly, the system management platform 110 determines an extraction range of the target log based on the occurrence time of the alarm and the time range. Then, the system management platform 110 extracts a part within the extraction range from the target log as the target log segment.

[0068] As shown in Table 1, the log range configured for the scenario is shown for the second row in Table 1. For example, the log name is a login log, and the time range is the previous N days. The system management platform 110 can determine the extraction range of the target log to be extracted according to the log name of the login log and the occurrence time of the alarm. Then, the system management platform 110 extracts the part at risk from the target log as the target log segment. It can be understood that for the entity type of the first entity, the data set related to the first entity is determined, and the data set indicates the segment of the log of the core field of the first entity.

[0069] In some embodiments, the system management platform 110 determines the first auxiliary information based on the configured abnormal state description of the first scenario respectively. In some embodiments, the system management platform 110 determines the first auxiliary information item corresponding to the target log segment according to the configured abnormal state description of the first scenario, to describe the abnormality in the target log segment. In some examples, one entity can correspond to multiple scenarios, each scenario has a corresponding prompt word for providing to the machine learning model, that is, an auxiliary information item. Therefore, the auxiliary information is a collection of multiple auxiliary information items. That is, the system management platform 110 determines the first auxiliary information item corresponding to the target log segment according to the configured prompt word of the first scenario.

[0070] Continuing the process 200, the system management platform 110 determines the first log information from the original log 217 based on the mapping relationship of the plug-in, the entity and the data source, the data source configuration, and the mapping relationship of the SQL and the scenario.

[0071] The following is a reference Figure 3 to describe the mapping relationship 226 of the data source and the entity. Figure 3 An example architecture of the mapping relationship of the entity and the data source is shown according to some embodiments of the present disclosure.

[0072] As Figure 3 shown, for the mapping relationship of the host entity 320 and the data source related to the target alarm, for example, it can include alarm, risk, the alarm includes intrusion backtracking and horizontal analysis, and the risk includes high exploitable risk. For the mapping relationship of the file entity 320 and the data source related to the target alarm, for example, it can include file download, file change, host fingerprint, and alarm. For the mapping relationship of the object entity 340 and the data source related to the target alarm, for example, it can include audit log and level certificate. For the mapping relationship of the account entity 350 and the data source related to the target alarm, for example, it can include login log, file change log, host network log, host process log, and alarm. For the mapping relationship of the address entity 360 and the data source related to the target alarm, for example, it can include alarm, host network, network address translation, process external connection, download analysis, login log, audit log, and domain name system. For the mapping relationship of the process entity 370 and the data source related to the target alarm, for example, it can include host process startup, host network connection, and alarm.

[0073] In some embodiments, the system management platform 110 performs associated entity detection on a first entity based on first log information and first auxiliary information. If the system management platform 110 detects a second entity associated with the first entity, it obtains second log information related to the second entity in the target system and second auxiliary information corresponding to the second log information. The second auxiliary information describes the anomalies in the logs of the target system. Accordingly, the system management platform 110 performs associated entity detection on the second entity based on the second log information and the second auxiliary information. Then, the system management platform 110 determines the occurrence path of the target alarm based on the results of the first entity and the associated entity detection on the second entity.

[0074] Figure 5 A schematic diagram of an example process 500 for alarm tracing according to some embodiments of the present disclosure is shown. Figure 5 As shown, the system management platform 110 can trace the first entity 510 based on the first log information and the first auxiliary information. Specifically, in box 512, if the system management platform 110 detects an address entity 511 related to the first entity 510, it can determine at least one scenario based on the entity type of the address entity 511. In box 513, based on the at least one scenario corresponding to the address entity 511, the system management platform 110 can extract the relationship between the host entity 541 and the address entity 511 based on the log information corresponding to the address entity 511 (e.g., host network connection logs). In box 514, the system management platform 110 can trace back to the host entity 541 based on the relationship between the host entity 541 and the address entity 511.

[0075] In box 542, the system management platform 110 can determine at least one scenario based on the entity type of host entity 541. In box 543, based on at least one scenario corresponding to host entity 541, the system management platform 110 can extract the relationship between account entity 521 and host entity 541 according to the log information (e.g., host login logs) corresponding to host entity 541. In some examples, the system management platform 110 can trace back to account entity 521 based on the relationship between host entity 541 and account entity 521.

[0076] Accordingly, in box 532, if the system management platform 110 detects a process entity 531 related to the first entity 510, it can determine at least one scenario based on the entity type of the process entity 531. In box 533, based on the at least one scenario corresponding to the process entity 531, the system management platform 110 can extract the relationship between the account entity 521 and the process entity 533 according to the log information (e.g., host process log) corresponding to the process entity 531. In box 534, the system management platform 110 can trace back to the account entity 521 based on the relationship between the account entity 521 and the process entity 533.

[0077] At block 522, the system management platform 110 can determine at least one scenario based on the entity type of the account entity 521. At block 523, the system management platform 110 can extract the relationship between the account entity 521 and the address entity 511 according to the log information (e.g., host login log) corresponding to the account entity 521 based on the at least one scenario corresponding to the account entity 521. At block 524, the system management platform 110 can trace to the address entity 511 based on the relationship between the account entity 521 and the address entity 511. At block 525, the system management platform 110 determines whether the account entity 521 and the address entity 511 are the same. At block 526, the system management platform 110 ends the tracing of the address entity 511 if it is determined that the account entity 521 and the address entity 511 are the same.

[0078] Thus, by tracing the entity with risks, the source of the risks of the entity can be determined. The following continues to refer to Figure 2 The following describes how the system management platform 110 determines the first entity involved in the target alarm in the case that there is an alarm in the alarm information library that matches the alarm.

[0079] In some embodiments, the system management platform 110 acquires an alarm information library including corresponding description information and corresponding analysis results of a plurality of historical alarms occurred in the target system. In some examples, the system management platform 110 can acquire an alarm information library including analysis results of historical alarms generated by the system management platform 110 based on log information and auxiliary information corresponding to the historical alarms.

[0080] In some embodiments, the system management platform 110 updates the alarm information library according to the description information of the target alarm and the analysis result for the target alarm. Recall Figure 2 As shown in the example process 200, the system management platform 110 can store the description information of the current alarm and the corresponding analysis result generated for the current alarm in the alarm information library 234.

[0081] Further, the system management platform 110 can retrieve a historical alarm that matches the target alarm from the alarm information library based on the description information of the target alarm if the target alarm is received. Then, the system management platform 110 can determine the first entity by using the machine learning model based on the description information if no historical alarm that matches the target alarm is retrieved.

[0082] Recall Figure 2In the illustrated example process 200, at block 212, the system management platform 110 invokes the machine learning model to determine whether to judge the target alert based on the target alert. At block 232, the system management platform 110 determines the historical alert matching the target alert from the alert information library 234 based on the description information of the target alert. The system management platform 110 returns the analysis result for the target alert if it is determined that there is a historical alert matching the target alert from the alert information library 234. Accordingly, the system management platform 110 utilizes the machine learning model to judge the target alert if it is determined that there is no historical alert matching the target alert from the alert information library 234.

[0083] Thus, storing the analysis result and the description information of the alert in the alert information library can provide a basis for judging subsequent similar alerts. The following continues to describe the system management platform 110 deploying the machine learning model before obtaining the first log information.

[0084] In some embodiments, the system management platform 110 determines the target log field corresponding to the variable in the log query instruction in the target log of the target system before obtaining the first log information. In some embodiments, the system management platform 110 extracts a plurality of log records from the target log. Accordingly, the system management platform 110 provides prompt word information to the machine learning model based on the variable description for the variable and the plurality of log records to obtain the output of the machine learning model. Then, the system management platform 110 determines the target log field based on one or more target fields indicated by the output of the machine learning model.

[0085] It can be understood that the system management platform 110 needs to deploy the machine learning model before obtaining the first log information. In some examples, the system management platform 110 provides an application program interface (API) to invoke the machine learning model. The system management platform 110 can also provide a global web service to provide plug-in capabilities for the machine learning model. The machine learning model is pre-configured with built-in metadata, for example, the machine learning model is pre-configured with prompt words, data sets, plug-in usage, judgment expert experience, and traceable expert experience.

[0086] In some examples, the machine learning model is pre-configured with a plurality of different function prompt words, such as entity extraction prompt words, and general prompt words for performing data sets and expert experience. The machine learning model can be pre-configured with commonly used data sets, which can be saved in a csv file or saved in a db file. In some examples, the machine learning model pre-configured data sets can be extended on demand, as shown in Table 2, and the user can extend the data sets. The table name and field corresponding to the data set are independent of the user's log, and all available data sets can be built into the machine learning model in advance. For the log table configured in the machine learning model, the system management platform 110 can filter out the log table on the user's corresponding client side. Table 3 shows an example of configuration information required for the built-in data sets in the machine learning model.

[0087] Table 3

[0088] Entity Log Table Dataset Name Description Information Start Time IP ssh login-from-ip XXXXX XX IP ti_for_ip ti_for_ip XXXXXX XX Host alert alert-context XXXXXXXX XXX Account process process-context XXXXXXXX XXX User audit audit-context XXXXXXXXXX XX Host risk risk-context XXXXXXXX XXXX

[0089] In some examples, the system management platform 110 can configure the parameters corresponding to the plug-ins required to be called by the machine learning model in the machine learning model. Figure 4 An example interface 400 for parameter configuration is shown in accordance with some embodiments of the present disclosure. As shown, a user (may also be referred to as an administrator) can configure the configuration interface 400 for parameter configuration based on the system management platform 110 presented in the interface 142. The user can configure the parameter name 411, parameter description information 412, parameter type 413, parameter corresponding incoming method 414, etc. corresponding to the plug-in in the interface 400. Figure 4

[0090] In some examples, the system management platform 110 can integrate different expert experience based on data sets, which can be stored in a csv file or a db file. Accordingly, the expert experience pre-configured in the machine learning model can also be extended on demand. Table 4 shows an example of configuration information required for expert experience.

[0091] Table 4

[0092]

[0093] For traceability expert experience, the system management platform 110 can integrate different expert experience according to the data set. These expert experience, for example, can be stored in a csv file or a db file. Accordingly, the expert experience pre-configured in the machine learning model can also be extended on demand. Table 5 shows an example of configuration information required for traceability expert experience.

[0094] Table 5

[0095]

[0096] In some embodiments, based on the alarm, a plurality of entities corresponding thereto can be determined, each of the plurality of entities corresponding to a plurality of data sets. Each of the plurality of data sets can be pre-configured. In some examples, the data set corresponding log category can be pre-configured, and the large model needs to learn the necessary field mapping. In some examples, if the log category is in the form of a table, the name of the table corresponding to the log can be different from the table name of the user, but needs to be consistent with the configuration of the data set. In some examples, the log can be stored in the format of file and tls. If the log category is in the form of a logical table, a query condition needs to be added in the configuration information. If the log category is in the form of a file, the file needs to be placed in a predetermined directory.

[0097] In some examples, the machine learning model needs to learn the necessary field mapping, for example, the machine learning model learns the field mapping configured in the data set. Based on the necessary field mapping, the machine learning model can convert the standard field into the corresponding original field in the scenario of calling the plug-in capability. Table 6 shows an example of a field mapping table.

[0098] Table 6

[0099]

[0100]

[0101] In some embodiments, the system management platform 110 can enable the machine learning model to learn the field mapping in the following manner. The system management platform 110 extracts the configuration in the data set configuration and generates a prompt word for each table. Further, the system management platform 110 loops through all the data source configurations and extracts a predetermined number of logs and prompt words from each log source. Subsequently, the system management platform 110 inputs the predetermined number of logs and prompt words into the machine learning model to obtain a preliminary learning result output by the machine learning model. Then, the system management platform 110 can also provide the preliminary learning result to the user for confirmation of whether there is a deviation. Further, the system management platform 110 stores the mapping document output by the machine learning model in a predetermined folder. For example, the mapping document is named field_mapping.

[0102] In summary, the embodiments of the present disclosure can reduce the threshold for determining and tracing the alarm, thereby improving the efficiency of processing the alarm. The following is a description of the method for managing the alarm of the present disclosure with reference to some case analysis for ease of understanding. In some embodiments, the system management platform 110 can adopt the following steps to determine the abnormal IP login.

[0103] As an example, the system management platform 110 first receives an alert of an abnormal IP login. By calling the webshell to do the intrusion link analysis, the alert time is obtained as "xxxx-xx-xx". Then, the system management platform 110 analyzes the alert and obtains an analysis report about the alert. In some examples, the analysis report can include an overall summary for the alert. The overall summary can include a judgment result, a risk score, and a judgment basis.

[0104] In some embodiments, the analysis report can also include a step-by-step summary. For example, the step-by-step summary can include a step name corresponding to each step, an analysis result, a judgment result, a risk score, a judgment basis, an analysis detail, and a calling time axis.

[0105] In some embodiments, the analysis report can list the data sets used. For example, the name and description of the data set can be shown.

[0106] In some embodiments, the analysis report can also include a next step processing strategy for investigating the alert. For example, the analysis report can include an ID, a reason, a next step suggestion, and an entity corresponding to each step recommended.

[0107] In some embodiments, the analysis report can also include further investigation for the alert. For example, the further investigation includes a judgment result, a risk score, a score calculation logic, a judgment basis, an attack time axis (e.g., including a start time, an end time, an alert name, an alert level, and an alert number), a horizontal movement analysis, an intrusion process analysis, a summary for the alert, and a listed data set.

[0108] In some embodiments, the analysis report can also include a query condition for the data set.

[0109] In some embodiments, the system management platform 110 obtains a final trace analysis report based on the automatic judgment for the alert and the trace of the result after the judgment. The trace analysis report includes a judgment result, a risk score, and a judgment basis.

[0110] In some embodiments, the trace analysis report includes a step-by-step summary. The step-by-step summary can include a judgment step for each entity related to the alert, such as a judgment result, an alert importance (or attack probability), and a judgment basis.

[0111] In some embodiments, the trace analysis report can also include evidence for the trace of the target alert. For example, it can include a log name, a judgment result, an attack probability, and a judgment basis for each log information.

[0112] In some embodiments, the traceability analysis report can further include a summary of the traceability alerts.

[0113] By providing information of various dimensions in the analysis report, a user such as an operation and maintenance personnel can understand the process and logic of analyzing alerts by utilizing a machine learning model. In this way, the user can be facilitated to judge the accuracy of the analysis result.

[0114] To sum up, the embodiments of the present disclosure can enable a user to quickly obtain an analysis result of an alert by invoking a machine learning model, and assist the user to make a quick decision. Further, the analysis result and description information of the alert can be stored in an alert information library, so as to provide a basis for judging a similar alert in the future, thereby improving the efficiency of processing alerts.

[0115] Example Process

[0116] Figure 6 A flowchart of a process 600 for alert processing is shown according to some embodiments of the present disclosure. The process 600 can be implemented at the system management platform 110. The process 600 is described below with reference to Figure 1 the system management platform 110.

[0117] At block 610, the system management platform 110 determines a first entity involved in a target alert based on description information of the target alert occurring in a target system.

[0118] At block 620, the system management platform 110 obtains first log information related to the first entity in the target system and first auxiliary information corresponding to the first log information, the first auxiliary information being used to describe an abnormality in a log of the target system.

[0119] At block 630, the system management platform 110 generates an analysis result for the target alert based on the first log information and the first auxiliary information.

[0120] In some embodiments, obtaining the first log information and the first auxiliary information includes: determining at least one scene based on an entity type of the first entity, a scene in the at least one scene being configured with a corresponding log range and an abnormal state description within the log range; determining the first log information based on the log range respectively configured for the at least one scene; and determining the first auxiliary information based on the abnormal state description respectively configured for the at least one scene.

[0121] In some embodiments, determining the at least one scene based on the entity type of the first entity includes: determining a plurality of candidate scenes corresponding to the entity type of the first entity; and selecting at least one scene from the plurality of candidate scenes based on the description information of the target alert by utilizing a machine learning model.

[0122] In some embodiments, determining the first log information comprises: for a first scene in the at least one scene, extracting a target log segment from the target system as at least a part of the first log information based on a log range configured for the first scene.

[0123] In some embodiments, the log range configured for the first scene indicates a log name and a time range, and extracting the target log segment comprises: determining a target log in the target system based on the log name; determining an extraction range of the target log based on the occurrence time of the target alarm and the time range; and extracting a part within the extraction range from the target log as the target log segment.

[0124] In some embodiments, determining the first auxiliary information comprises: determining an auxiliary information item corresponding to the target log segment based on an abnormal state description configured for the first scene, for describing the abnormality in the target log segment.

[0125] In some embodiments, the process 600 further comprises: performing associated entity detection for the first entity based on the first log information and the first auxiliary information; in response to detecting a second entity associated with the first entity, obtaining second log information related to the second entity in the target system and second auxiliary information corresponding to the second log information, the second auxiliary information being used to describe an abnormality in the log of the target system; performing associated entity detection for the second entity based on the second log information and the second auxiliary information; and determining an occurrence path of the target alarm based on the first entity and a result of the associated entity detection of the second entity.

[0126] In some embodiments, determining the first entity involved in the target alarm comprises: obtaining an alarm information library, the alarm information library comprising corresponding description information and corresponding analysis results of a plurality of historical alarms occurred in the target system; in response to receiving the target alarm, retrieving a historical alarm matching the target alarm from the alarm information library based on description information of the target alarm; and in response to not retrieving the historical alarm matching the target alarm, determining the first entity based on the description information by using a machine learning model.

[0127] In some embodiments, the process 600 further comprises: updating the alarm information library based on the description information of the target alarm and the analysis result for the target alarm.

[0128] In some embodiments, the first log information is obtained by using a predetermined log query statement, and the method further comprises: before obtaining the first log information, determining a target log field in a target log of the target system corresponding to a variable in the log query instruction.

[0129] In some embodiments, determining the target log field comprises: extracting a plurality of log records from the target log; providing prompt word information to the machine learning model based on the variable description for the variable and the plurality of log records to obtain an output of the machine learning model; and determining the target log field based on one or more target fields indicated by the output of the machine learning model.

[0130] In some embodiments, the first entity comprises at least one of a subject, a file, an object, an account, an address, and a process.

[0131] Example Apparatus and Device

[0132] Figure 7 A schematic structural block diagram of an apparatus 700 for alarm processing according to certain embodiments of the present disclosure is shown. The apparatus 700 can be implemented as or included in the system management platform 110. Various modules / components in the apparatus 700 can be implemented by hardware, software, firmware, or any combination thereof.

[0133] As shown, the apparatus 700 includes an entity determination module 710 configured to determine a first entity involved in a target alarm occurring in a target system based on description information for the target alarm. The apparatus 700 further includes an information acquisition module 720 configured to acquire first log information related to the first entity in the target system and first auxiliary information corresponding to the first log information, the first auxiliary information being used to describe an abnormality in a log of the target system. The apparatus 700 further includes an analysis result generation module 730 configured to generate an analysis result for the target alarm based on the first log information and the first auxiliary information.

[0134] In some embodiments, the information acquisition module 720 is further configured to determine at least one scenario based on an entity type of the first entity, a scenario in the at least one scenario being configured with a corresponding log range and an abnormal state description within the log range; determine the first log information based on the log range respectively configured for the at least one scenario; and determine the first auxiliary information based on the abnormal state description respectively configured for the at least one scenario.

[0135] In some embodiments, the apparatus 700 further includes a scenario determination module configured to determine a plurality of candidate scenarios corresponding to the entity type of the first entity; and select, based on the description information of the target alarm, at least one scenario from the plurality of candidate scenarios by using a machine learning model.

[0136] In some embodiments, the information acquisition module 720 is further configured to, for a first scenario in the at least one scenario, extract a target log segment from the target system as at least a part of the first log information based on a log range configured for the first scenario.

[0137] In some embodiments, the log range configured by the first scenario indicates a log name and a time range, and the information obtaining module 720 is further configured to determine, based on the log name, a target log in the target system; determine, based on the occurrence time of the target alarm and the time range, an extraction range of the target log; and extract, from the target log, a part within the extraction range as the target log segment.

[0138] In some embodiments, the information obtaining module 720 is further configured to determine, based on the abnormal state description configured by the first scenario, an auxiliary information item corresponding to the target log segment, to describe the abnormality in the target log segment.

[0139] In some embodiments, the apparatus 700 further includes an occurrence path determining module configured to perform, based on the first log information and the first auxiliary information, associated entity detection for the first entity; in response to detecting a second entity associated with the first entity, obtain second log information related to the second entity in the target system and second auxiliary information corresponding to the second log information, the second auxiliary information being used to describe an abnormality in a log of the target system; perform, based on the second log information and the second auxiliary information, associated entity detection for the second entity; and determine, based on the first entity and a result of the associated entity detection for the second entity, an occurrence path of the target alarm.

[0140] In some embodiments, the entity determining module 710 is further configured to obtain an alarm information library including respective description information and respective analysis results of a plurality of historical alarms occurred in the target system; in response to receiving the target alarm, retrieve, based on the description information of the target alarm, a historical alarm matching the target alarm from the alarm information library; and in response to not retrieving the historical alarm matching the target alarm, determine, based on the description information, the first entity by using a machine learning model.

[0141] In some embodiments, the apparatus 700 further includes an alarm information library determining module configured to update the alarm information library based on the description information of the target alarm and the analysis result for the target alarm.

[0142] In some embodiments, the first log information is obtained by using a predetermined log query statement, and the apparatus 700 further includes a log field determining module configured to determine, before obtaining the first log information, a target log field in a target log of the target system corresponding to a variable in the log query instruction.

[0143] In some embodiments, the log field determination module is further configured to extract a plurality of log records from the target log; provide the hint word information to the machine learning model based on the variable description for the variable and the plurality of log records to obtain an output of the machine learning model; and determine the target log field based on one or more target fields indicated by the output of the machine learning model.

[0144] In some embodiments, the first entity includes at least one of a subject, a file, an object, an account, an address, a process.

[0145] Figure 8 A block diagram illustrating an electronic device 800 in which one or more embodiments of the disclosure can be implemented is shown. It should be understood that Figure 8 The electronic device 800 shown is merely exemplary and should not be construed as limiting the scope of the embodiments described herein. Figure 8 The electronic device 800 shown can be used to implement Figure 1 the electronic device 110.

[0146] As Figure 8 shown, the electronic device 800 is in the form of a general electronic device. Components of the electronic device 800 can include, but are not limited to, one or more processors or processing units 810, a memory 820, a storage device 830, one or more communication units 840, one or more input devices 850, and one or more output devices 860. The processing unit 810 can be a real or virtual processor and is capable of executing various processing in accordance with programs stored in the memory 820. In a multi-processor system, multiple processing units execute computer-executable instructions in parallel to improve the parallel processing capability of the electronic device 800.

[0147] The electronic device 800 typically includes a plurality of computer storage media. Such media can be any available media that is accessible by the electronic device 800 and includes both volatile and non-volatile media, removable and non-removable media. The memory 820 can be a volatile memory (e.g., registers, cache, random access memory (RAM)), a non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. The storage device 830 can be a removable or non-removable media and can include machine-readable media such as a flash drive, a magnetic disk drive, or any other media that can be used to store information and / or data and that can be accessed by the electronic device 800.

[0148] The electronic device 800 can further include additional removable / non-removable, volatile / non-volatile storage media. For example, computer storage media can include, but is not limited to, Blu-ray discs, DVDs, CD-ROMs, memory sticks, removable hard drives, and other fixed or removable media. Figure 8As shown in FIG. 12, a disk drive 821 or CD drive 822 can be provided that enable reading from or writing to a removable, non- volatile, magnetic media (e.g., a "floppy drive") or optical media (e.g., a "CD ROM drive"). In these instances, each drive can be connected to the system bus 820 by one or more data media interfaces. The memory 820 can include a computer program product 825 having one or more program modules configured to carry out the various methods or actions of the various embodiments of the present disclosure.

[0149] The communication unit 840 enables communication with other electronic devices over a communication medium. Additionally, the functionality of the components of the electronic device 800 can be implemented in a single computing cluster or a plurality of computer machines that are capable of communicating over a communication connection. As such, the electronic device 800 can operate in a networked environment using logical connections to one or more other servers, network personal computers (PCs), or another network nodes in the networking environment.

[0150] The input device 850 can be one or more input devices, such as a mouse, a keyboard, a trackball, etc. The output device 860 can be one or more output devices, such as a display, a speaker, a printer, etc. The electronic device 800 can also communicate with one or more external devices (not shown) such as a storage device, a display device, etc., one or more devices that enable a user to interact with the electronic device 800, or any devices (e.g., a network card, a modem, etc.) that enable the electronic device 800 to communicate with one or more other electronic devices, as needed, through the communication unit 840. Such communication can be carried out via an input / output (I / O) interface (not shown).

[0151] According to an example implementation of the present disclosure, a computer readable storage medium is provided having computer executable instructions stored thereon, where the computer executable instructions are executed by a processor to implement the method described above. According to an example implementation of the present disclosure, a computer program product is also provided that is tangibly stored on a non-transitory computer readable medium and includes computer executable instructions, where the computer executable instructions are executed by a processor to implement the method described above.

[0152] Various aspects of the disclosure are now described with reference to the drawings. In general, the drawings described below are diagrammatic and schematic representations of actual or conceptual structures and processes, and as such, they are not drawn to scale. Certain aspects of the disclosure are described below with reference to flowchart illustrations and / or block diagrams of methods, apparatuses, systems, and computer program products according to this disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer readable program instructions.

[0153] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0154] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0155] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0156] implementations of the present disclosure have been described above, the description is illustrative only and not restrictive ones, and is not limited to the disclosed implementations. Numerous modifications and variations will become apparent to those skilled in the art in light of the above teachings. The terminology used is for the purpose of describing the various implementations, and is not intended to limit the scope of the present disclosure. The scope of the present disclosure is limited only by the claims.

Claims

1. An alarm processing method comprising: determining, based on description information of a target alarm occurring in a target system, a first entity involved in the target alarm; obtaining first log information related to the first entity in the target system and first auxiliary information corresponding to the first log information, the first auxiliary information being used to describe abnormal related information in a log of the target system, the abnormal related information including a judgment rule for the abnormality, wherein the judgment rule includes a plurality of first prompt word information used to provide to a first machine learning model; and generating, based on the first log information and the first auxiliary information, an analysis result for the target alarm by the first machine learning model, wherein obtaining the first log information and the first auxiliary information comprises: determining at least one scene based on an entity type of the first entity, a scene in the at least one scene being configured with a corresponding log range and an abnormal state description within the log range; determining the first log information based on the log range respectively configured for the at least one scene; and determining the first auxiliary information based on the abnormal state description respectively configured for the at least one scene.

2. The method of claim 1, wherein determining at least one scene based on an entity type of the first entity comprises: determining a plurality of candidate scenes corresponding to the entity type of the first entity; and selecting, based on the description information of the target alarm, the at least one scene from the plurality of candidate scenes using a second machine learning model.

3. The method of claim 1, wherein determining the first log information comprises: for a first scene in the at least one scene, extracting, based on the log range configured for the first scene, a target log segment from the target system as at least a part of the first log information.

4. The method of claim 3, wherein the log range configured for the first scene indicates a log name and a time range, and extracting a target log segment comprises: determining a target log in the target system based on the log name; determining an extraction range of the target log based on an occurrence time of the target alarm and the time range; and extracting, from the target log, a portion within the extraction range as the target log segment.

5. The method of claim 3, wherein determining the first auxiliary information comprises: determining, based on the abnormal state description configured for the first scene, an auxiliary information item corresponding to the target log segment for describing an abnormality in the target log segment.

6. The method of claim 1, further comprising: performing, based on the first log information and the first auxiliary information, associated entity detection for the first entity; in response to detecting a second entity associated with the first entity, obtaining second log information related to the second entity in the target system and second auxiliary information corresponding to the second log information, the second auxiliary information being used to describe an abnormality in a log of the target system; ​ ​ perform associated entity detection for the second entity based on the second log information and the second auxiliary information; and determine an occurrence path of the target alarm based on the first entity and a result of the associated entity detection for the second entity.

7. The method of claim 1, wherein determining the first entity involved in the target alarm comprises: obtaining an alarm information library including respective description information and respective analysis results of a plurality of historical alarms occurred in the target system; in response to receiving the target alarm, retrieving a historical alarm matching the target alarm from the alarm information library based on description information of the target alarm; and in response to not retrieving the historical alarm matching the target alarm, determining the first entity based on the description information using a third machine learning model.

8. The method of claim 7, further comprising: updating the alarm information library based on the description information of the target alarm and the analysis result for the target alarm.

9. The method of claim 1, wherein the first log information is obtained using a predetermined log query statement, and the method further comprises: before obtaining the first log information, determining a target log field in a target log of the target system corresponding to a variable in the log query statement.

10. The method of claim 9, wherein determining the target log field comprises: extracting a plurality of log records from the target log; based on a variable description for the variable and the plurality of log records, providing second prompt word information to a fourth machine learning model to obtain an output of the fourth machine learning model; and based on one or more target fields indicated by the output of the fourth machine learning model, determining the target log field.

11. The method of claim 1, wherein the first entity includes at least one of a subject, a file, an object, an account, an address, and a process.

12. An apparatus for alarm processing, comprising: an entity determination module configured to determine a first entity involved in a target alarm occurred in a target system based on description information of the target alarm; an information obtaining module configured to obtain first log information related to the first entity in the target system and first auxiliary information corresponding to the first log information, the first auxiliary information being used to describe abnormal related information in a log of the target system, the abnormal related information including a judgment rule for the abnormality; wherein the judgment rule includes a plurality of first prompt word information provided to a first machine learning model; and an analysis result generation module configured to generate an analysis result for the target alarm by the first machine learning model based on the first log information and the first auxiliary information. ​ ​ The information acquisition module is further configured to determine at least one scene based on an entity type of the first entity, a scene in the at least one scene is configured with a corresponding log range and an abnormal state description within the log range; determine the first log information based on the log range configured for each of the at least one scene; and determine the first auxiliary information based on the abnormal state description configured for each of the at least one scene.

13. An electronic device, comprising: at least one processing unit; and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, the instructions, when executed by the at least one processing unit, cause the electronic device to perform the method according to any one of claims 1-11.

14. A computer-readable storage medium having stored thereon a computer program, the computer program being executable by a processor to implement the method according to any one of claims 1-11.

Citation Information

Patent Citations

  • Alarm analysis method and device, electronic equipment and storage medium

    CN115150261A

  • Root cause positioning method and device of micro-service system, readable medium and electronic equipment

    CN118012657A