Data uploading method, device, equipment, storage medium and program product
By setting up a multi-backup message queue cluster in the cluster center, the problems of data upload interruption and inaccuracy caused by message queue failure are solved, the real-time and accuracy of data upload is achieved, and the safe operation of business organizations is ensured.
Patent Information
- Application Number
- CN202411717562.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-26
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2044-11-26
AI Technical Summary
In the prior art, when using a message queue to upload data, a failure of the message queue may cause interruption or inaccurate data upload, thus affecting the operational security of the business organization.
Deploy two cluster centers, each with two message queue clusters. Through multiple backup strategies, when an exception occurs in the message queue cluster of one cluster center, the message queue cluster of the other cluster center is used to upload data to ensure the real-time and accuracy of the data.
It improves the real-time and accuracy of data transmission, ensures that data can still be transmitted normally when the message queue cluster fails, and guarantees the safe operation of business organizations.
Smart Images

Figure CN119383145B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of big data, and in particular to a data uploading method, apparatus, device, storage medium and program product. Background Art
[0002] In the modern information environment, it is necessary to collect the operational security situation data of business organizations and upload it to the security situation awareness platform to determine the operational security of the business organizations.
[0003] In the existing technology, message queues are used as a data flow tool to process the real-time consumption data collected from various business organizations, obtain operational security situation data, and send it to the security situation awareness platform.
[0004] However, in the above method, a message queue is used. When a message queue fails, data upload is interrupted or inaccurate, thereby affecting the operational security of the business organization. Summary of the Invention
[0005] The embodiments of the present application provide a data uploading method, apparatus, device, storage medium and program product to achieve the effect of improving the real-time, continuity and accuracy of data uploading.
[0006] In a first aspect, an embodiment of the present application provides a data uploading method, the method being applied to a computing device, the computing device deploying a first cluster center and a second cluster center; the first cluster center including two first message queue clusters; the second cluster center including a second message queue cluster; the method comprising:
[0007] Based on the first message queue cluster, the currently pending consumption data is processed to obtain the uploaded data of the first message queue cluster; at the same time, based on the second message queue cluster, the consumption data is processed to obtain the uploaded data of the second message queue cluster; wherein the uploaded data represents the operational security status of the business organization to which the consumption data belongs;
[0008] Processing the data sent by each of the first message queue clusters to obtain corresponding processing results of the data sent by each of the first message queue clusters;
[0009] If it is determined that the processing result indicates that the data sent by each first message queue cluster does not meet the preset conditions, the data sent by the second message queue cluster is sent to the security situation awareness platform.
[0010] In one possible implementation, the first cluster center includes a running node and a cold standby node; processing the data sent by each of the first message queue clusters to obtain corresponding processing results of the data sent by each of the first message queue clusters includes:
[0011] If it is determined that the running node is abnormal, the data sent by each first message queue cluster is processed based on the cold standby node to obtain corresponding processing results of the data sent by each first message queue cluster.
[0012] In a possible implementation, based on the cold standby node, processing the data sent by each of the first message queue clusters to obtain corresponding processing results of the data sent by each of the first message queue clusters includes:
[0013] Obtain historical uploaded data based on a processing time slice of uploaded data of each of the first message queue clusters; wherein the processing time slice of uploaded data of each of the first message queue clusters is the same; and the historical uploaded data is uploaded data that has been uploaded to the security situation awareness platform within a historical time period;
[0014] The processing result is determined according to the uploaded data of each of the first message queue clusters and the historical uploaded data.
[0015] In a possible implementation, determining the processing result according to the uploaded data of each first message queue cluster and the historical uploaded data includes:
[0016] Compare the uploaded data of the first message queue cluster with the first data and the second data in the historical uploaded data to determine a first comparison result of the first message queue cluster; wherein the first data is the uploaded data corresponding to the processing time slice within the previous day; the second data is the uploaded data corresponding to the processing time slice one week ago; the first comparison result represents a sudden change in the uploaded data of the first message queue cluster;
[0017] Comparing the uploaded data of the first message queue cluster with at least one third data in the historical uploaded data to determine a second comparison result of the first message queue cluster; wherein the third data is the uploaded data corresponding to each processing time slice in a time period before the time period of the processing time slice on the same day; the second comparison result indicates the continuity of the uploaded data of the first message queue cluster;
[0018] The processing result is determined according to each of the first comparison results and each of the second comparison results.
[0019] In a possible implementation, comparing the uploaded data of the first message queue cluster with the first data and the second data in the historical uploaded data to determine a first comparison result of the first message queue cluster includes:
[0020] Determine an absolute value of a difference between the data sent by the first message queue cluster and the first data as a first increase difference;
[0021] Determine an absolute value of a difference between the data sent by the first message queue cluster and the second data as a second increase difference;
[0022] The first comparison result is determined according to the first amplification difference and the second amplification difference.
[0023] In a possible implementation, comparing the uploaded data of the first message queue cluster with at least one third data in the historical uploaded data to determine a second comparison result of the first message queue cluster includes:
[0024] Determine the difference between the uploaded data of the first message queue cluster and the adjacent uploaded data as the third increase difference; and determine the absolute value of the difference between the third data with the latest processing time slice in each of the third data and the adjacent uploaded data as the fourth increase difference; wherein the processing time slice of the adjacent uploaded data is the previous processing time slice of the processing time slice of the uploaded data of the first message queue cluster;
[0025] Determine the absolute value of the difference between every two adjacent third data in each processing time slice in each of the third data as at least one fifth amplification difference; and determine the average value between each of the fifth amplification difference and the fourth amplification difference as the amplification average value;
[0026] The second comparison result is determined according to the third increase difference and the increase average value.
[0027] In a possible implementation, determining the processing result according to each of the first comparison results and each of the second comparison results includes:
[0028] If it is determined that each of the first comparison results indicates that there is a sudden change in the data uploaded by the first message queue cluster, and it is determined that each of the second comparison results indicates that the continuity of the data uploaded by the first message queue cluster is abnormal, then it is determined that the processing result indicates that the data uploaded by each of the first message queue clusters does not meet the preset conditions.
[0029] In one possible implementation, the method further includes:
[0030] If it is determined that an abnormality exists in the running node and an abnormality exists in the cold standby node, the uploaded data of the second message queue cluster is uploaded to the security situation awareness platform.
[0031] In one possible implementation, the method further includes:
[0032] If it is determined that the processing result indicates that the data sent by each of the first message queue clusters meets a preset condition, determining target data from the data sent by each of the first message queue clusters;
[0033] Based on the first cluster center, the target uploaded data is uploaded to the security situation awareness platform.
[0034] In a possible implementation, determining target uploaded data from uploaded data of each of the first message queue clusters includes:
[0035] If it is determined that the running node of the first cluster center is normal, then comparing and processing the uploaded data of each first message queue cluster based on the running node;
[0036] If it is determined that the corresponding values of the uploaded data of each of the first message queue clusters are consistent, determining the uploaded data of any one of the first message queue clusters as the target uploaded data;
[0037] If it is determined that the corresponding values of the uploaded data of each first message queue cluster are inconsistent, the uploaded data with a larger corresponding value among the uploaded data of each first message queue cluster is determined as the target uploaded data.
[0038] In a possible implementation, the uploaded data includes but is not limited to: transaction volume, transaction success rate, and latency.
[0039] In a second aspect, an embodiment of the present application provides a data uploading device, the device being applied to a computing device, the computing device deploying a first cluster center and a second cluster center; the first cluster center including two first message queue clusters; the second cluster center including a second message queue cluster; the device comprising:
[0040] A first processing module is configured to process the currently pending consumption data based on the first message queue cluster to obtain the uploaded data of the first message queue cluster; and simultaneously process the consumption data based on the second message queue cluster to obtain the uploaded data of the second message queue cluster; wherein the uploaded data represents the operational security status of the business organization to which the consumption data belongs;
[0041] A second processing module is used to process the data sent by each of the first message queue clusters to obtain corresponding processing results of the data sent by each of the first message queue clusters;
[0042] The sending module is used to send the sent data of the second message queue cluster to the security situation awareness platform if it is determined that the processing result indicates that the sent data of each first message queue cluster does not meet the preset conditions.
[0043] In one possible implementation, the first cluster center includes a running node and a cold standby node; the second processing module is specifically used to: if it is determined that there is an abnormality in the running node, then based on the cold standby node, process the uploaded data of each first message queue cluster to obtain the corresponding processing results of the uploaded data of each first message queue cluster.
[0044] In one possible implementation, the second processing module is specifically used to: obtain historical uploaded data based on the processing time slice of the uploaded data of each first message queue cluster; wherein, the processing time slice of the uploaded data of each first message queue cluster is the same; the historical uploaded data is the uploaded data that has been uploaded to the security situation awareness platform within a historical time period; determine the processing result based on the uploaded data of each first message queue cluster and the historical uploaded data.
[0045] In one possible embodiment, the second processing module is specifically used to: compare the uploaded data of the first message queue cluster with the first data and the second data in the historical uploaded data to determine the first comparison result of the first message queue cluster; wherein the first data is the uploaded data corresponding to the processing time slice within the previous day; the second data is the uploaded data corresponding to the processing time slice one week ago; the first comparison result represents the sudden change of the uploaded data of the first message queue cluster; compare the uploaded data of the first message queue cluster with at least one third data in the historical uploaded data to determine the second comparison result of the first message queue cluster; wherein the third data is the uploaded data corresponding to each processing time slice in the previous time period within the time period of the processing time slice on the same day; the second comparison result represents the continuity of the uploaded data of the first message queue cluster; and determine the processing result based on each first comparison result and each second comparison result.
[0046] In one possible embodiment, the second processing module is specifically used to: determine the absolute value of the difference between the uploaded data of the first message queue cluster and the first data, which is the first amplification difference; determine the absolute value of the difference between the uploaded data of the first message queue cluster and the second data, which is the second amplification difference; and determine the first comparison result based on the first amplification difference and the second amplification difference.
[0047] In one possible embodiment, the second processing module is further specifically used to: determine the difference between the uploaded data of the first message queue cluster and the adjacent uploaded data, which is the third amplification difference; and determine the absolute value of the difference between the third data with the latest processing time slice in each of the third data and the adjacent uploaded data, which is the fourth amplification difference; wherein the processing time slice of the adjacent uploaded data is the previous processing time slice of the processing time slice of the uploaded data of the first message queue cluster; determine the absolute value of the difference between every two adjacent third data in each of the third data in the processing time slices, which is at least one fifth amplification difference; and determine the average value between each of the fifth amplification differences and the fourth amplification difference, which is the amplification average value; determine the second comparison result based on the third amplification difference and the amplification average value.
[0048] In a possible embodiment, the second processing module is further specifically used to: if it is determined that each of the first comparison results indicates that there is a sudden change in the uploaded data of the first message queue cluster, and it is determined that each of the second comparison results indicates that the continuity of the uploaded data of the first message queue cluster is abnormal, then it is determined that the processing result indicates that the uploaded data of each of the first message queue clusters does not meet the preset conditions.
[0049] In a possible implementation, the second processing module is further specifically configured to: if it is determined that an abnormality exists in the running node and an abnormality exists in the cold standby node, upload the uploaded data of the second message queue cluster to the security situation awareness platform.
[0050] In a possible embodiment, the device is also used to: if it is determined that the processing result indicates that the uploaded data of each first message queue cluster meets the preset conditions, then determine the target uploaded data from the uploaded data of each first message queue cluster; based on the first cluster center, upload the target uploaded data to the security situation awareness platform.
[0051] In one possible embodiment, the device is further specifically used to: if it is determined that the operating node of the first cluster center is normal, then based on the operating node, compare and process the uploaded data of each first message queue cluster; if it is determined that the corresponding values of the uploaded data of each first message queue cluster are consistent, then determine that the uploaded data of any first message queue cluster is the target uploaded data; if it is determined that the corresponding values of the uploaded data of each first message queue cluster are inconsistent, then determine that the uploaded data with a larger corresponding value among the uploaded data of each first message queue cluster is the target uploaded data.
[0052] In a possible implementation, the uploaded data includes but is not limited to: transaction volume, transaction success rate, and latency.
[0053] In a third aspect, an embodiment of the present application provides a computing device, including: a memory, a processor;
[0054] The memory stores computer-executable instructions;
[0055] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementations of the first aspect.
[0056] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the first aspect above and / or various possible implementation methods of the first aspect.
[0057] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the above first aspect and / or various possible implementation methods of the first aspect.
[0058] The data uploading method, apparatus, equipment, storage medium and program product provided in the embodiments of the present application are implemented by deploying two cluster centers, wherein two message queue clusters are set in one cluster center and one message queue cluster is set in the other cluster center. After obtaining the consumption data to be processed, each message queue cluster needs to process the consumption data to obtain the corresponding uploaded data. Based on the uploaded data obtained by the two message queue clusters in the same cluster center, it can be determined whether both message queue clusters in the cluster center have failed. If so, the uploaded data obtained by the message queue cluster of the other cluster center can be uploaded to the security situation awareness platform, thereby ensuring that when a message queue cluster fails, data upload processing can be performed through the message queue cluster of the other cluster center to improve the real-time, continuity and accuracy of data upload. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0060] Figure 1 A schematic diagram of an application scenario provided for this application;
[0061] Figure 2 A flowchart of a data uploading method provided in an embodiment of the present application;
[0062] Figure 3 A schematic diagram of a dual-active dual-center security deployment structure provided in an embodiment of the present application;
[0063] Figure 4 A schematic diagram of a stream processing process based on a message queue cluster provided in an embodiment of the present application;
[0064] Figure 5 A schematic diagram of the structure of an active-active high-availability mechanism provided in an embodiment of the present application;
[0065] Figure 6 A schematic diagram of a cluster-based data time window provided in an embodiment of the present application;
[0066] Figure 7 A flowchart of another data uploading method provided in an embodiment of the present application;
[0067] Figure 8 A schematic diagram of the structure of another active-active high-availability mechanism provided in an embodiment of the present application;
[0068] Figure 9 A schematic diagram of the structure of another active-active high-availability mechanism provided in an embodiment of the present application;
[0069] Figure 10 A schematic diagram of the deployment structure of a data uploading module provided in an embodiment of the present application;
[0070] Figure 11 A schematic diagram of an example of historical data comparison provided in an embodiment of the present application;
[0071] Figure 12 A schematic diagram of a dual-active dual-center data uploading deployment structure provided in an embodiment of the present application;
[0072] Figure 13 A schematic diagram of the structure of a data uploading device provided in an embodiment of the present application;
[0073] Figure 14 A schematic diagram of the structure of a computing device provided in an embodiment of the present application.
[0074] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0075] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0076] First, let’s explain the terms involved in this application:
[0077] Message queue: A mechanism for implementing asynchronous communication in distributed systems. It is often used for data flow, decoupling system components, and improving system scalability and reliability.
[0078] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, processing, transmission, provision, disclosure and application of relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0079] Figure 1 This is a schematic diagram of an application scenario provided by this application. Figure 1 As shown, the specific application scenario of this application includes a computing device 101, a security situation awareness platform 102, and a business organization 103. The computing device 101 collects the operational security situation data of the business organization 103 and sends it to the security situation awareness platform 102 to determine the operational security of the business organization 103.
[0080] In one example, by collecting monitoring data from distributed clusters, the system can detect clusters with faults, determine the corresponding fault types, and then formulate effective repair strategies; or, based on the message offset of the distributed cluster partitions and their monitoring strategy information and the corresponding preset thresholds, make anomaly judgments. Once an anomaly in data transmission or reception is detected, the system can obtain the partition corresponding to the corresponding topic name information and the message offset of the partition; based on the offset and the preset threshold, the fault anomaly can be automatically and promptly discovered, and the anomaly information can be proactively conveyed to the business organization through various notification methods.
[0081] However, these approaches may be insufficient in scenarios with strict real-time requirements. Even if data can be recovered, it may have exceeded business time constraints. Therefore, these technologies are limited in supporting scenarios with strict real-time requirements.
[0082] In another example, by using the ant colony algorithm and its efficient heuristic strategy, an effective partition rebalancing plan can be quickly developed.
[0083] However, the above method may increase the message batch size, which means that more data is written to the distributed cluster waiting for consumers to read, which may slow down the overall processing speed and affect real-time performance.
[0084] In response to the above technical problems, this application proposes the following technical concept: by deploying two cluster centers, one of which is equipped with two message queue clusters, and the other is equipped with one message queue cluster. Each message queue cluster needs to process the consumption data to be processed and obtain the corresponding uploaded data. When it is determined that both message queue clusters in the same cluster center have failed, the uploaded data obtained by the message queue cluster in the other cluster center can be used for data upload processing. In this way, the problem of interrupted or inaccurate data upload caused by message queue failure in the existing technology can be solved.
[0085] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0086] Figure 2 A flow chart of a data uploading method provided in an embodiment of the present application is shown as follows: Figure 2 As shown, the method includes:
[0087] 201. Based on the first message queue cluster, the consumption data to be processed is processed to obtain the uploaded data of the first message queue cluster; at the same time, based on the second message queue cluster, the consumption data is processed to obtain the uploaded data of the second message queue cluster; wherein the uploaded data represents the operational security status of the business organization to which the consumption data belongs.
[0088] The execution subject of this embodiment may be a computing device, which deploys a first cluster center and a second cluster center; the first cluster center includes two first message queue clusters; the second cluster center includes a second message queue cluster.
[0089] For example, the execution subject of this embodiment may be a computing device, which is referred to as a device for ease of description. Figure 3 A schematic diagram of a dual-active dual-center security deployment structure provided in an embodiment of the present application is shown as follows: Figure 3As shown, a dual-active dual-center mechanism can be deployed in the device, that is, two cluster centers are deployed, including a first cluster center and a second cluster center, wherein two message queue clusters are deployed in the first cluster center, namely, two first message queue clusters, cluster A and cluster B, and one message queue cluster is deployed in the second cluster center, namely, the second message queue cluster. For the sake of convenience of description, the message queue cluster may be referred to as a cluster below. The device obtains the current consumption data to be processed, including detailed data such as transaction business and financial consumption data of some business institutions. Each message queue cluster deployed in the device processes the current consumption data to be processed at the same time, that is, based on each first message queue cluster, the current consumption data to be processed is processed to obtain the uploaded data of each first message queue cluster, such as the operation security situation data, to characterize the operation security situation of the business institution to which the consumption data belongs; at the same time, the obtained consumption data is processed based on the second message queue cluster to obtain the uploaded data of the second message queue cluster.
[0090] For example, Figure 4 A schematic diagram of a stream processing process based on a message queue cluster is provided in an embodiment of the present application, such as Figure 4 As shown, the device sends the detailed consumption data obtained from the specified business platform to each message queue cluster. Each message queue cluster includes a conversion module, a pre-statistics module, and an aggregation module. The conversion module is responsible for processing this consumption data and identifying the objects to be monitored. The pre-statistics module then processes the results provided by the transfer module and generates statistics for the indicators of each monitored object. Next, the aggregation module receives the calculated output results of the pre-statistics module and, based on distributed data processing, aggregates the statistical results to generate the final summary statistics, which are the uploaded data.
[0091] For example, Figure 5 A schematic diagram of the structure of a dual-active high availability mechanism provided in an embodiment of the present application is shown as follows: Figure 5 As shown in the figure, in this mechanism, cluster B serves as a cold standby for cluster A. When cluster A's data upload module A fails, cluster A is stopped and cluster B is started. Cluster B deploys the same conversion module, pre-statistics module, and summary module as cluster A, performing the same streaming processing on the same detailed data and ultimately sending the summary results to cluster B's data upload module B. In other words, the General Data Distribution System (GDDS) sends the same detailed data to both clusters A and B, where the data undergoes the same processing in both clusters. Figure 6 A schematic diagram of a cluster-based data time window provided in an embodiment of the present application is shown in FIG. Figure 6As shown in the figure, a stream processing flow based on a message queue cluster can use 10-second processing time slices (hereinafter referred to as time slices). Six consecutive 10-second data slices are combined into 1-minute granularity data. For example, a 2-minute window includes time slices 1 to 12. The resulting uploaded data includes key metrics such as transaction volume, success rate, and latency. Transaction volume is calculated as: transaction volume = sum(time slices 1 to 6); success rate is calculated as: success rate = sum(time slices 1 to 6) successful transactions / transaction volume; latency is calculated as: latency = sum(time slices 1 to 6) processing time / transaction volume. This improves the high availability of data upload. Even if one cluster fails, the other can continue real-time data transmission.
[0092] 202. Process the data sent by each first message queue cluster to obtain corresponding processing results of the data sent by each first message queue cluster.
[0093] For example, in combination Figure 3 Based on any data uploading module in the first cluster center, data uploading module A or data uploading module B, the uploaded data of the two first message queue clusters are first processed through a configurable intelligent integration calculation method. The processing result can be obtained based on a preset threshold judgment rule or a preset condition, such as whether the numerical value corresponding to the data is within the threshold range, etc., to determine whether the uploaded data of the two first message queue clusters meet the preset conditions.
[0094] 203. If it is determined that the processing result indicates that the data sent by each first message queue cluster does not meet the preset conditions, the data sent by the second message queue cluster is sent to the security situation awareness platform.
[0095] For example, based on any data uploading module in the first cluster center, after obtaining the processing result, if it is determined that the uploading data of the two first message queue clusters do not meet the preset conditions, it may indicate that the two first message queue clusters have failed, that is, the first cluster center has completely failed. In order to ensure the accuracy of the uploading data, Figure 3 Based on the data uploading module of the second cluster center, the uploaded data obtained by the second message queue cluster can be uploaded to the security situation awareness platform to complete the complete process of uploading the security situation data of multiple institutions to the security situation awareness platform.
[0096] This embodiment provides a data upload method. By deploying two cluster centers, one with two message queue clusters and the other with one, and employing a multiple backup strategy, this method ensures that even if a message queue cluster experiences an anomaly, the backup solution can still ensure real-time and accurate data upload. Furthermore, multiple message queue clusters simultaneously send data to a data upload module, which integrates, processes, and analyzes data from these sources. This improves the operational flexibility and processing efficiency of the data upload module.
[0097] Figure 7 A flow chart of another data uploading method provided in an embodiment of the present application is shown as follows: Figure 7 As shown, the method includes:
[0098] 301. Based on the first message queue cluster, the consumption data to be processed is processed to obtain the uploaded data of the first message queue cluster; at the same time, based on the second message queue cluster, the consumption data is processed to obtain the uploaded data of the second message queue cluster; wherein the uploaded data represents the operational security status of the business organization to which the consumption data belongs.
[0099] For example, this step can refer to step 201 and will not be described in detail here.
[0100] After step 301 , step 302 or step 306 may be executed.
[0101] 302. If it is determined that an abnormality exists in the running node, the data sent by each first message queue cluster is processed based on the cold standby node to obtain corresponding processing results of the data sent by each first message queue cluster.
[0102] The first cluster center includes running nodes and cold standby nodes.
[0103] The uploaded data includes but is not limited to: transaction volume, transaction success rate, and latency.
[0104] Exemplarily, after step 301, Figure 8 This is a schematic diagram of another active-active high-availability mechanism provided in an embodiment of the present application. Figure 9 A structural diagram of another active-active high availability mechanism provided in the embodiment of the present application is shown as follows: Figure 8 、 9As shown, the first cluster center includes cluster A and cluster B, as well as an operating node and a cold standby node, corresponding to data upload module A and data upload module B, respectively. Data upload module B serves as the cold standby node for data upload module A. The device performs self-check monitoring on the two data upload modules. If an abnormality is determined in the operating node, the two data upload modules are promptly switched. Based on the cold standby node, the uploaded data of the two first message queue clusters is obtained. Each uploaded data includes, but is not limited to, transaction volume, transaction success rate, and latency. The uploaded data of the two first message queue clusters is processed to determine whether the uploaded data of the two first message queue clusters meets the preset conditions. It is worth noting that, based on the self-check monitoring, if the current operating node is determined to be normal, the uploaded data of the two first message queue clusters is determined to meet the preset conditions based on the current operating node using the same processing method as the cold standby node, so that the appropriate uploaded data can be uploaded to the security situation awareness platform. In this way, the switching between the two sets AB does not need to rely on the comprehensive judgment of all module and cluster anomalies in the two sets, which simplifies the anomaly judgment logic and improves the stability and efficiency of the upload process.
[0105] In one example, step 302 includes the following steps:
[0106] The first step of step 302 is to obtain historical uploaded data based on the processing time slice of the uploaded data of each first message queue cluster; wherein, the processing time slice of the uploaded data of each first message queue cluster is the same; the historical uploaded data is the uploaded data that has been uploaded to the security situation awareness platform within the historical time period.
[0107] The second step of step 302 is to determine the processing result according to the uploaded data and the historical uploaded data of each first message queue cluster.
[0108] For example, when processing uploaded data, when the message queue cluster processes data with a preset processing time slice, each uploaded data corresponds to a processing time slice, and the corresponding processing time slice can be determined based on the timestamp field carried in each uploaded data, for example, 11:05:10-11:05:20. Figure 10 A schematic diagram of the deployment structure of a data uploading module provided in an embodiment of the present application is shown as follows: Figure 10As shown, based on the data collection layer of the data uploading module, data collection is performed on the uploaded data obtained from the two message queue cluster data of cluster A and cluster B, that is, the uploaded data of the two clusters with the same processing time slice is obtained. Based on the processing time slice of the uploaded data, the preset historical time period before the processing time slice is determined, and the uploaded data that has been uploaded to the security situation awareness platform is obtained, that is, the historical uploaded data, such as the historical uploaded data from 11:05:10 to 11:05:20 every day in the previous week. Based on the historical data comparison layer of the data uploading module, based on the preset trend setting threshold and judgment rules, the uploaded data of the two first message queue clusters and the historical uploaded data are compared and processed, and then the processing results of whether the uploaded data of the two first message queue clusters meet the preset conditions are obtained.
[0109] In one example, the second step of step 302 includes:
[0110] Step 1: Compare the uploaded data of the first message queue cluster with the first data and the second data in the historical uploaded data to determine the first comparison result of the first message queue cluster; wherein the first data is the uploaded data corresponding to the processing time slice within the previous day; the second data is the uploaded data corresponding to the processing time slice one week ago; the first comparison result represents the sudden change of the uploaded data of the first message queue cluster.
[0111] Step 2: Compare the uploaded data of the first message queue cluster with at least one third data in the historical uploaded data to determine the second comparison result of the first message queue cluster; wherein the third data is the uploaded data corresponding to each processing time slice in the previous time period within the time period of the processing time slice within the day; the second comparison result represents the continuity of the uploaded data of the first message queue cluster.
[0112] Step 3: Determine a processing result based on each first comparison result and each second comparison result.
[0113] Specifically, combined Figure 10, based on the historical data comparison layer of the data uploading module, according to the processing time slice of the uploaded data, the historical uploaded data obtained includes the uploaded data corresponding to the processing time slice in the previous day, that is, the first data; it also includes the uploaded data corresponding to the processing time slice a week ago, that is, the second data; it also includes the uploaded data corresponding to each processing time slice in the previous time period within the time period of the processing time slice on the same day, that is, multiple third data. The historical data comparison layer compares the uploaded data of each first message queue cluster with the first data and the second data in the historical uploaded data based on the preset comparison rules, and determines the comparison result of each first message queue cluster, that is, the first comparison result, so as to identify whether there is a sudden change in the summary result of the current time slice. At the same time, the historical data comparison layer compares the uploaded data of each first message queue cluster with all the third data based on the preset comparison rules, and obtains the comparison result of each first message queue cluster, that is, the second comparison result, so as to judge whether there is an abnormality in the continuity of the data in the current time slice. The historical data comparison layer analyzes the first comparison results and the second comparison results of the two first message queue clusters based on the preset comparison rules and in combination with the preset rules, and then judges whether the uploaded data of the two first message queue clusters meet the preset conditions, such as whether they are abnormal, based on whether there are sudden changes in the uploaded data of the two first message queue clusters and whether there are abnormalities in the continuity.
[0114] In one example, step one includes:
[0115] The first step is to determine the absolute value of the difference between the data sent by the first message queue cluster and the first data, which is the first increase difference.
[0116] The second step is to determine the absolute value of the difference between the data sent by the first message queue cluster and the second data, which is the second increase difference.
[0117] The third step is to determine a first comparison result according to the first amplification difference and the second amplification difference.
[0118] For example, in combination Figure 10For each first message queue cluster, the historical data comparison layer calculates the absolute value of the difference between the uploaded data of the first message queue cluster and the first data to obtain the first increase difference, and calculates the absolute value of the difference between the uploaded data of the first message queue cluster and the second data to obtain the second increase difference. According to the preset threshold rule, the first increase difference and the second increase difference are judged to determine whether there is a sudden change in the uploaded data of the first message queue cluster; for example, if the first increase difference and the second increase difference are both within or any one of the values is within the corresponding preset threshold range, then there is no sudden change in the uploaded data of the first message queue cluster; otherwise, there is a sudden change in the uploaded data of the first message queue cluster.
[0119] In one example, step 2 includes the following steps:
[0120] The first step is to determine the difference between the uploaded data of the first message queue cluster and the adjacent uploaded data, which is the third increase difference; and determine the absolute value of the difference between the third data with the latest processing time slice in each third data and the adjacent uploaded data, which is the fourth increase difference; wherein, the processing time slice of the adjacent uploaded data is the previous processing time slice of the processing time slice of the uploaded data of the first message queue cluster.
[0121] The second step is to determine the absolute value of the difference between each two adjacent third data in each processing time slice, which is at least one fifth amplification difference; and determine the average value between each fifth amplification difference and the fourth amplification difference, which is the amplification average value.
[0122] The third step is to determine a second comparison result based on the third increase difference and the increase average value.
[0123] For example, in combination Figure 10For each first message queue cluster, the historical data comparison layer first determines the adjacent uploaded data of the uploaded data of the first message queue cluster, that is, the processing time slice of the adjacent uploaded data is the previous processing time slice of the processing time slice of the uploaded data of the first message queue cluster. Then, the historical data comparison layer calculates the absolute value of the difference between the uploaded data of the first message queue cluster and the adjacent uploaded data to obtain the third increase difference; at the same time, the third data with the latest processing time slice is determined from all the third data, and the absolute value of the difference between the third data and the adjacent uploaded data is calculated to obtain the fourth increase difference. For all the third data, the historical data comparison layer calculates the absolute value of the difference between every two adjacent third data in the processing time slices to obtain at least one corresponding fifth increase difference. Based on the historical data comparison layer, all the calculated fifth increase differences and fourth increase differences are averaged to obtain a corresponding average value, that is, the increase average value. The historical data comparison layer judges the average increase value and the third increase difference value according to the preset threshold rules, and then obtains whether there is any abnormality in the continuity of the uploaded data of the first message queue cluster; for example, if the third increase difference value and the average increase value are both within or any one of them is within the corresponding preset threshold range, then there is no abnormality in the continuity of the uploaded data of the first message queue cluster; otherwise, there is an abnormality in the continuity of the uploaded data of the first message queue cluster; or, if the absolute value of the difference between the third increase difference value and the average increase value is within the corresponding preset threshold range, then there is no abnormality in the continuity of the uploaded data of the first message queue cluster; otherwise, there is an abnormality in the continuity of the uploaded data of the first message queue cluster.
[0124] For example, Figure 11 A schematic diagram of an example of historical data comparison provided in an embodiment of the present application is shown as follows: Figure 11 As shown, the processing time slice is referred to as the time slice for short. By calculating the absolute value of the difference in the increase between time slice 2 and time slice 1, time slice 3 and time slice 2, time slice 4 and time slice 3, time slice 5 and time slice 4, time slice 6 and time slice 5, and time slice 7 and time slice 6, and taking the average value of the absolute values of these differences, the average value is combined with the absolute value of the difference in the increase between time slice 7 and time slice 8 to determine whether time slice 8 is abnormal.
[0125] In one example, step three includes the following steps: if it is determined that each first comparison result indicates that there is a sudden change in the uploaded data of the first message queue cluster, and it is determined that each second comparison result indicates that the continuity of the uploaded data of the first message queue cluster is abnormal, then it is determined that the processing result indicates that the uploaded data of each first message queue cluster does not meet the preset conditions.
[0126] For example, in combination Figure 10After the historical data comparison layer determines whether there is a sudden change in the data uploaded by the two first message queue clusters and whether the continuity is abnormal, it analyzes based on the preset rules. If it is determined that there is a sudden change in the data uploaded by the two first message queue clusters and the continuity of the data uploaded by the two first message queue clusters is abnormal, it means that the data uploaded by the two first message queue clusters is abnormal. At this time, based on the abnormal center switching execution layer, according to the judgment result of the historical data comparison layer, if the data summary of the two clusters does not meet the preset rules, the system will execute the center switching operation, combined with Figure 3 , switch to the data upload module of the second cluster center, and upload the uploaded data of the second message queue cluster to ensure the normal upload of data. Furthermore, the data upload module obtains data from two independent active-active message queue clusters at the same time. For multi-source data, the module will record and track historical upload status. When the data upload module collects current data, it compares and analyzes the newly collected data with historical records. Through comparison and judgment, the system can identify abnormal upload situations in advance and take corresponding preventive measures, such as switching centers, to ensure the continuity and accuracy of uploaded data.
[0127] After step 302 , step 303 or step 304 may be executed.
[0128] 303. If it is determined that the processing result indicates that the data sent by each first message queue cluster does not meet the preset conditions, the data sent by the second message queue cluster is sent to the security situation awareness platform.
[0129] Illustratively, after step 302, this step may refer to step 203 and will not be described in detail here.
[0130] 304. If the processing result indicates that the data sent by each first message queue cluster meets a preset condition, target data to be sent is determined from the data sent by each first message queue cluster.
[0131] For example, after step 302, Figure 10 If, based on a comparison by the historical data comparison and analysis layer of the data upload module, the uploaded data of the two first message queue clusters meets preset conditions, such as being normal, the uploaded data of the two first message queue clusters is forwarded to the cluster comparison and analysis layer. Based on this cluster comparison and analysis layer, the uploaded data of the two first message queue clusters is judged and analyzed to determine the target uploaded data to be uploaded.
[0132] In one example, determining target uploaded data from uploaded data of each first message queue cluster in step 304 includes the following steps:
[0133] In the first step, if it is determined that the running node of the first cluster center is normal, comparison processing is performed on the uploaded data of each first message queue cluster based on the running node.
[0134] In the second step, if it is determined that the corresponding values of the uploaded data of each first message queue cluster are consistent, the uploaded data of any first message queue cluster is determined as the target uploaded data.
[0135] In the third step, if it is determined that the corresponding values of the uploaded data of each first message queue cluster are inconsistent, the uploaded data with a larger corresponding value among the uploaded data of each first message queue cluster is determined as the target uploaded data.
[0136] For example, based on the first cluster center, it is necessary to determine whether the running node currently responsible for sending data is normal. If the running node is normal, then based on the running node, the sent data of the two first message queue clusters are compared, that is, the values corresponding to the sent data of the two first message queue clusters are compared to see if they are consistent. If it is determined that the values corresponding to the sent data of the two first message queue clusters are consistent, then the sent data of any one of the first message queue clusters is determined to be the target sent data. If it is determined that the values corresponding to the sent data of the two first message queue clusters are inconsistent, then the sent data with the larger corresponding value in the sent data of the two first message queue clusters is determined to be the target sent data. Based on the data sending module, the data from these sources will be integrated, processed and analyzed. By accepting multiple data sources, it not only helps to improve the accuracy and quality of the sent data, but also improves the operational flexibility and processing efficiency of the data sending module.
[0137] 305. Based on the first cluster center, the target upload data is uploaded to the security situation awareness platform.
[0138] For example, in combination Figure 10 Based on the data upload module of the first cluster center, the upload layer obtains the target upload data and continuously pushes data to the security situation awareness platform according to the data upload frequency specified by the platform. At the same time, the upload layer stores the uploaded data in the database for subsequent comparison and judgment by the historical data comparison layer.
[0139] For example, Figure 12 Schematic diagram of the dual-active dual-center data transmission deployment structure provided in the embodiment of this application, combined with Figure 10 、 12As shown, the active-active, dual-center data upload deployment structure includes Cluster A, Cluster B, and Cluster C. If the transaction volume, success rate, and latency values calculated for the same consumption data at a 1-minute granularity are consistent after processing by the conversion module, pre-statistics module, and summary module, then both message queue clusters, Cluster A and Cluster B, are intact. Therefore, only one copy of the indicator data at the same time granularity needs to be uploaded to the security situation awareness platform. To ensure real-time and accurate data upload, these modules determine data selection and rejection based on the timestamp corresponding to the consumption data during processing: if the current time slice and the data timestamp differ by more than 10 seconds, data loss will occur. When a message queue cluster fails, it affects the production and consumption of the message queue cluster by each module. Data loss due to the message queue cluster anomaly causes the calculated indicators in the summary results to be low or zero. If the calculated transaction volume, success rate, and latency values for the uploaded data corresponding to the 1-minute granularity are inconsistent, the data upload module can compare the output results of various indicators of the two message queue clusters within the same time slice. The data output of the faulty cluster is usually smaller. In this case, the larger result value is used to send data to the upload layer. If both clusters A and B in the first cluster center fail, to ensure the normal upload of data, a multi-center deployment is adopted, and the data upload module C uploads the data uploaded by cluster C for processing. This way, if any center fails completely and causes data upload anomalies, the other center can still continue to upload data, thus ensuring real-time and continuous data upload.
[0140] 306. If it is determined that an abnormality exists in the running node and an abnormality exists in the cold standby node, the uploaded data of the second message queue cluster is uploaded to the security situation awareness platform.
[0141] For example, after step 301, Figure 12 Based on the self-check mechanism, if there are abnormalities in the running nodes and corresponding cold standby nodes in the first cluster center that are sending data, a center switching operation will be performed. Based on the data sending module of the second cluster center, the uploaded data of the second message queue cluster will be sent to the security situation awareness platform to ensure the normal upload of data.
[0142] In this embodiment, building on the previous one, multiple message queue clusters simultaneously send data to the data upload module, which integrates, processes, and analyzes the data from these sources. This improves the operational flexibility and processing efficiency of the data upload module. Furthermore, through intelligent analysis of multi-source data, combined with customizable threshold rules, it is possible to promptly identify accuracy issues in cluster data and quickly switch to a backup backup solution, thus ensuring the continuity, accuracy, and real-time nature of data upload.
[0143] Figure 13A structural diagram of a data uploading device provided in an embodiment of the present application is shown as follows: Figure 13 As shown, the apparatus is applied to a computing device, which deploys a first cluster center and a second cluster center; the first cluster center includes two first message queue clusters; the second cluster center includes a second message queue cluster; the apparatus includes:
[0144] The first processing module 401 is configured to process the currently pending consumption data based on the first message queue cluster to obtain the uploaded data of the first message queue cluster; and simultaneously process the consumption data based on the second message queue cluster to obtain the uploaded data of the second message queue cluster; wherein the uploaded data represents the operational security status of the business organization to which the consumption data belongs;
[0145] The second processing module 402 is used to process the data sent by each first message queue cluster to obtain corresponding processing results of the data sent by each first message queue cluster;
[0146] The sending module 403 is configured to send the sent data of the second message queue cluster to the security situation awareness platform if it is determined that the processing result indicates that the sent data of each first message queue cluster does not meet the preset conditions.
[0147] In one possible implementation, the first cluster center includes a running node and a cold standby node; the second processing module 402 is specifically used to: if it is determined that there is an abnormality in the running node, then based on the cold standby node, process the uploaded data of each first message queue cluster to obtain the corresponding processing results of the uploaded data of each first message queue cluster.
[0148] In one possible implementation, the second processing module 402 is specifically used to: obtain historical uploaded data based on the processing time slice of the uploaded data of each first message queue cluster; wherein, the processing time slice of the uploaded data of each first message queue cluster is the same; the historical uploaded data is the uploaded data that has been uploaded to the security situation awareness platform within the historical time period; determine the processing result based on the uploaded data of each first message queue cluster and the historical uploaded data.
[0149] In one possible embodiment, the second processing module 402 is specifically used to: compare the uploaded data of the first message queue cluster with the first data and the second data in the historical uploaded data to determine the first comparison result of the first message queue cluster; wherein the first data is the uploaded data corresponding to the processing time slice within the previous day; the second data is the uploaded data corresponding to the processing time slice one week ago; the first comparison result represents the sudden change of the uploaded data of the first message queue cluster; compare the uploaded data of the first message queue cluster with at least one third data in the historical uploaded data to determine the second comparison result of the first message queue cluster; wherein the third data is the uploaded data corresponding to each processing time slice in the previous time period within the time period of the processing time slice within the day; the second comparison result represents the continuity of the uploaded data of the first message queue cluster; and determine the processing result based on each first comparison result and each second comparison result.
[0150] In one possible implementation, the second processing module 402 is specifically used to: determine the absolute value of the difference between the uploaded data of the first message queue cluster and the first data, which is the first amplification difference; determine the absolute value of the difference between the uploaded data of the first message queue cluster and the second data, which is the second amplification difference; and determine the first comparison result based on the first amplification difference and the second amplification difference.
[0151] In one possible embodiment, the second processing module 402 is further specifically used to: determine the difference between the uploaded data of the first message queue cluster and the adjacent uploaded data, which is the third amplification difference; and determine the absolute value of the difference between the third data with the latest processing time slice in each third data and the adjacent uploaded data, which is the fourth amplification difference; wherein, the processing time slice of the adjacent uploaded data is the previous processing time slice of the processing time slice of the uploaded data of the first message queue cluster; determine the absolute value of the difference between every two adjacent third data in each third data processing time slice, which is at least one fifth amplification difference; and determine the average value between each fifth amplification difference and the fourth amplification difference, which is the amplification average value; determine the second comparison result based on the third amplification difference and the amplification average value.
[0152] In one possible implementation, the second processing module 402 is further specifically used to: if it is determined that each first comparison result indicates that there is a sudden change in the uploaded data of the first message queue cluster, and it is determined that each second comparison result indicates that the continuity of the uploaded data of the first message queue cluster is abnormal, then it is determined that the processing result indicates that the uploaded data of each first message queue cluster does not meet the preset conditions.
[0153] In a possible implementation, the second processing module 402 is further specifically configured to: if it is determined that an abnormality exists in the running node and an abnormality exists in the cold standby node, upload the uploaded data of the second message queue cluster to the security situation awareness platform.
[0154] In one possible embodiment, the device is also used to: if it is determined that the processing result indicates that the uploaded data of each first message queue cluster meets the preset conditions, then determine the target uploaded data from the uploaded data of each first message queue cluster; based on the first cluster center, upload the target uploaded data to the security situation awareness platform.
[0155] In one possible embodiment, the device is further specifically used to: if it is determined that the operating node of the first cluster center is normal, then based on the operating node, compare and process the uploaded data of each first message queue cluster; if it is determined that the corresponding values of the uploaded data of each first message queue cluster are consistent, then determine that the uploaded data of any first message queue cluster is the target uploaded data; if it is determined that the corresponding values of the uploaded data of each first message queue cluster are inconsistent, then determine that the uploaded data with a larger corresponding value among the uploaded data of each first message queue cluster is the target uploaded data.
[0156] In a possible implementation, the uploaded data includes but is not limited to: transaction volume, transaction success rate, and latency.
[0157] The device of this embodiment can execute the technical solution in the above method. Its specific implementation process and technical principles are the same and will not be repeated here.
[0158] Figure 14 A schematic diagram of the structure of a computing device provided in an embodiment of the present application is shown in FIG. Figure 14 As shown, the computing device includes: a memory 501 and a processor 502; the memory 501 is a memory for storing instructions executable by the processor 502.
[0159] The processor 502 is configured to execute the method provided in the above embodiment.
[0160] The computing device 500 further includes a receiver 503 and a transmitter 504. The receiver 503 is used to receive instructions and data sent by other devices, and the transmitter 504 is used to send instructions and data to external devices.
[0161] The specific implementation process of the processor can be found in the above method embodiment. Its implementation principle and technical effects are similar and will not be repeated here in this embodiment.
[0162] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly executed by a hardware processor or by a combination of hardware and software modules in the processor.
[0163] The memory may include a high-speed memory (Random Access Memory, referred to as RAM), and may also include a non-volatile memory (NVM), such as at least one disk storage.
[0164] An embodiment of the present application also provides a chip for executing instructions, which is used to execute the technical solution of the processing method in the above embodiment.
[0165] An embodiment of the present application further provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed on a computer, the computer executes the technical solution of the processing method of the above embodiment.
[0166] The readable storage medium may be implemented by any type of volatile or non-volatile memory device, or a combination thereof, such as static random access memory, electrically erasable programmable read-only memory, erasable programmable read-only memory, programmable read-only memory, read-only memory, magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium may be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0167] An exemplary readable storage medium is coupled to a processor, such that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application-specific integrated circuit. Of course, the processor and the readable storage medium can also exist as discrete components in a device.
[0168] An embodiment of the present application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium, and when at least one processor executes the computer program, it can implement the technical solution of the processing method in the above embodiment.
[0169] The present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.
[0170] The present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above method is implemented.
[0171] Those skilled in the art will appreciate that all or part of the steps in the above-described method embodiments can be implemented by hardware associated with program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments.
[0172] Finally, it should be noted that those skilled in the art will readily identify other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not disclosed herein. The present invention is not limited to the precise structure described above and illustrated in the accompanying drawings, and various modifications and variations may be made without departing from the scope thereof. The scope of the present invention is limited solely by the appended claims.
Claims
1. A data uploading method, characterized in that: The method is applied to a computing device, wherein the computing device deploys a first cluster center and a second cluster center; the first cluster center includes two first message queue clusters; The second cluster center includes a second message queue cluster; the method includes: Based on the first message queue cluster, the currently pending consumption data is processed to obtain the uploaded data of the first message queue cluster; at the same time, based on the second message queue cluster, the consumption data is processed to obtain the uploaded data of the second message queue cluster; wherein the uploaded data represents the operational security status of the business organization to which the consumption data belongs; Comparing the uploaded data of the first message queue cluster with the first data and the second data in the historical uploaded data to determine a first comparison result of the first message queue cluster; Comparing the data uploaded by the first message queue cluster with at least one third data in the historical uploaded data to determine a second comparison result of the first message queue cluster; Determining corresponding processing results of the uploaded data of each first message queue cluster according to each of the first comparison results and each of the second comparison results; If it is determined that each of the first comparison results indicates that there is a sudden change in the data uploaded by the first message queue cluster, and it is determined that each of the second comparison results indicates that the continuity of the data uploaded by the first message queue cluster is abnormal, then it is determined that the processing result indicates that the data uploaded by each of the first message queue clusters does not meet the preset conditions; the data uploaded by the second message queue cluster is uploaded to the security situation awareness platform.
2. The method according to claim 1, characterized in that The first cluster center includes a running node and a cold standby node; processing the data sent by each of the first message queue clusters to obtain corresponding processing results of the data sent by each of the first message queue clusters, including: If it is determined that the running node is abnormal, the data sent by each first message queue cluster is processed based on the cold standby node to obtain corresponding processing results of the data sent by each first message queue cluster.
3. The method according to claim 2, characterized in that Based on the cold standby node, processing the data sent by each of the first message queue clusters to obtain corresponding processing results of the data sent by each of the first message queue clusters includes: Obtain historical uploaded data based on a processing time slice of uploaded data of each of the first message queue clusters; wherein the processing time slice of uploaded data of each of the first message queue clusters is the same; and the historical uploaded data is uploaded data that has been uploaded to the security situation awareness platform within a historical time period; The processing result is determined according to the uploaded data of each of the first message queue clusters and the historical uploaded data.
4. The method according to claim 3, characterized in that The first data is the data sent in the previous day corresponding to the processing time slice; the second data is the data sent in the previous week corresponding to the processing time slice; The third data is the uploaded data corresponding to each processing time slice in the previous time period within the time period of the processing time slice on the same day.
5. The method according to claim 4, characterized in that Comparing the uploaded data of the first message queue cluster with the first data and the second data in the historical uploaded data to determine a first comparison result of the first message queue cluster, including: Determine an absolute value of a difference between the data sent by the first message queue cluster and the first data as a first increase difference; Determine an absolute value of a difference between the data sent by the first message queue cluster and the second data as a second increase difference; The first comparison result is determined according to the first amplification difference and the second amplification difference.
6. The method according to claim 4, characterized in that Comparing the uploaded data of the first message queue cluster with at least one third data in the historical uploaded data to determine a second comparison result of the first message queue cluster, including: Determine the difference between the uploaded data of the first message queue cluster and the adjacent uploaded data as the third increase difference; and determine the absolute value of the difference between the third data with the latest processing time slice in each of the third data and the adjacent uploaded data as the fourth increase difference; wherein the processing time slice of the adjacent uploaded data is the previous processing time slice of the processing time slice of the uploaded data of the first message queue cluster; Determine the absolute value of the difference between every two adjacent third data in each processing time slice in each of the third data as at least one fifth amplification difference; and determine the average value between each of the fifth amplification difference and the fourth amplification difference as the amplification average value; The second comparison result is determined according to the third increase difference and the increase average value.
7. The method according to claim 2, characterized in that The method further comprises: If it is determined that an abnormality exists in the running node and an abnormality exists in the cold standby node, the uploaded data of the second message queue cluster is uploaded to the security situation awareness platform.
8. The method according to claim 1, characterized in that The method further comprises: If it is determined that the processing result indicates that the data sent by each of the first message queue clusters meets a preset condition, determining target data from the data sent by each of the first message queue clusters; Based on the first cluster center, the target uploaded data is uploaded to the security situation awareness platform.
9. The method according to claim 8, characterized in that Determining target uploaded data from the uploaded data of each of the first message queue clusters includes: If it is determined that the running node of the first cluster center is normal, then comparing and processing the uploaded data of each first message queue cluster based on the running node; If it is determined that the corresponding values of the uploaded data of each of the first message queue clusters are consistent, determining the uploaded data of any one of the first message queue clusters as the target uploaded data; If it is determined that the corresponding values of the uploaded data of each first message queue cluster are inconsistent, the uploaded data with a larger corresponding value among the uploaded data of each first message queue cluster is determined as the target uploaded data.
10. The method according to any one of claims 1 to 9, characterized in that The uploaded data includes but is not limited to: transaction volume, transaction success rate and latency.
11. A data uploading device, characterized in that: The apparatus is applied to a computing device, wherein the computing device deploys a first cluster center and a second cluster center; the first cluster center includes two first message queue clusters; The second cluster center includes a second message queue cluster; the device includes: A first processing module is configured to process the currently pending consumption data based on the first message queue cluster to obtain the uploaded data of the first message queue cluster; and simultaneously process the consumption data based on the second message queue cluster to obtain the uploaded data of the second message queue cluster; wherein the uploaded data represents the operational security status of the business organization to which the consumption data belongs; a second processing module, configured to compare the uploaded data of the first message queue cluster with the first data and the second data in the historical uploaded data to determine a first comparison result of the first message queue cluster; compare the uploaded data of the first message queue cluster with at least one third data in the historical uploaded data to determine a second comparison result of the first message queue cluster; and determine, based on each of the first comparison results and each of the second comparison results, corresponding processing results of the uploaded data of each of the first message queue clusters; The uploading module is used to determine that if it is determined that each of the first comparison results indicates that there is a sudden change in the uploaded data of the first message queue cluster, and if it is determined that each of the second comparison results indicates that the continuity of the uploaded data of the first message queue cluster is abnormal, then determine that the processing result indicates that the uploaded data of each of the first message queue clusters does not meet the preset conditions; and upload the uploaded data of the second message queue cluster to the security situation awareness platform.
12. A computing device, characterized in that include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 1 to 10.
13. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 10 when executed by a processor.
14. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the method according to any one of claims 1 to 10 is implemented.
Citation Information
Patent Citations
Cluster data reporting method, system and device and storage medium
CN113572696A
Self-adaptive cluster scheduling method and device, computer storage medium and electronic equipment
CN116414564A