Node Anomaly Monitoring Method and Alarm Device Based on Access Information Analysis
By collecting and analyzing the access information of the target node in real time, establishing the expected access space of nodes, performing exception analysis and risk assessment, the problem of ignoring the mutual relationship and abnormal propagation of nodes in the existing technology is solved, and accurate identification and real-time monitoring of network exceptions is achieved, and network stability and data security are enhanced.
Patent Information
- Application Number
- CN202411604652.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-12
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2044-11-12
AI Technical Summary
The complex interrelationships and abnormal propagation effects between nodes are ignored in the prior art, which leads to the inability to accurately capture the source of the exception and its propagation path, which affects the stability and data security of the network.
By collecting the access information of the target node in real time, analyzing the access information based on the access scenario registration constraints and calculation channels, establishing the node's access expectation space, performing abnormal analysis and risk assessment, calculating the node's abnormal detection coefficient, and generating an abnormal warning signal.
It accurately captures the interrelationships and abnormal propagation effects between nodes, improves the accuracy of network abnormal identification and real-time monitoring capabilities, thereby enhancing the stability of the network and ensuring data security.
Smart Images

Figure CN119484245B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of anomaly monitoring, and particularly to a node anomaly monitoring method and an alarm device based on access information parsing. Background Art
[0002] With the rapid development of information technology and communication networks, the network scale has been continuously expanding, and various types of nodes in the network (such as servers, switches, routers, etc.) are undertaking increasingly heavy data processing and transmission tasks. However, with the increase in the number of nodes and the improvement of network complexity, the anomaly detection and risk assessment of nodes have become an important issue in network management.
[0003] Currently, traditional network anomaly detection methods usually rely on preset thresholds to determine whether a node is abnormal. However, this method is often too simplistic and ignores the complex interrelationships between nodes in the network. For example, a decrease in the performance of a certain node may not be caused by its own failure, but rather by a chain reaction triggered by the failure of other nodes in the network. Traditional methods fail to effectively consider this phenomenon of anomaly propagation, resulting in some potential anomalies not being detected in a timely manner or being misjudged as non-abnormal, thus affecting the stability of the network and data security. In addition, traditional anomaly detection often ignores the different impacts of different types of anomalies. Some methods only rely on a single detection index, such as the CPU load, memory usage rate, or network latency of a node. However, these single indicators often cannot accurately reflect the comprehensive anomaly situation of a node in a complex network environment.
[0004] In summary, there is a technical problem in the prior art that due to ignoring the complex interrelationships between nodes and the anomaly propagation effect, it is impossible to accurately capture the source and propagation path of anomalies, further affecting the accurate identification and real-time monitoring of network anomalies, and thus reducing the stability of the network and data security. Summary of the Invention
[0005] The purpose of this application is to provide a node anomaly monitoring method and an alarm device based on access information parsing, so as to solve the technical problem in the prior art that due to ignoring the complex interrelationships between nodes and the anomaly propagation effect, it is impossible to accurately capture the source and propagation path of anomalies, further affecting the accurate identification and real-time monitoring of network anomalies, and thus reducing the stability of the network and data security.
[0006] In view of the above problems, this application provides a node anomaly monitoring method and an alarm device based on access information parsing.
[0007] In a first aspect, the present application provides a method for monitoring node anomalies based on access information parsing, which is implemented through a node anomaly alarm device based on access information parsing, and includes: when a target node accesses the network, real-time collecting the access information of the target node to obtain a node access monitoring result; based on access scenario registration constraints and an access scenario registration calculation channel, performing access information expectation parsing on the target node according to the real-time network status information of the network to establish a node access expectation space; performing anomaly parsing on the node access monitoring result according to the node access expectation space to obtain a node access anomaly parsing result; based on the node access anomaly parsing result, performing risk parsing on the target node according to an access anomaly risk parsing channel to obtain a local node anomaly risk coefficient; based on an anomaly propagation risk weight condition, performing risk parsing on multiple other access nodes of the network according to the node access anomaly parsing result to obtain a node anomaly propagation risk coefficient; calculating a node anomaly detection coefficient based on the local node anomaly risk coefficient and the node anomaly propagation risk coefficient; determining whether the node anomaly detection coefficient is greater than or equal to a node anomaly detection threshold, and if the node anomaly detection coefficient is greater than or equal to the node anomaly detection threshold, generating an anomaly warning signal.
[0008] Second aspect, the present application also provides a node anomaly alarm device based on access information parsing, which is used to execute the node anomaly monitoring method based on access information parsing as described in the first aspect, including: a node access monitoring result obtaining module, which is used to collect the access information of the target node in real time when the target node accesses the network to obtain a node access monitoring result; a node access expected space establishing module, which is used to perform access information expectation parsing on the target node based on the access scenario registration constraint and the access scenario registration calculation channel, and establish a node access expected space according to the real-time network status information of the network; a node access anomaly parsing result obtaining module, which is used to perform anomaly parsing on the node access monitoring result according to the node access expected space to obtain a node access anomaly parsing result; a node anomaly local risk coefficient obtaining module, which is used to perform risk parsing on the target node based on the node access anomaly parsing result according to the access anomaly risk parsing channel to obtain a node anomaly local risk coefficient; a node anomaly propagation risk coefficient obtaining module, which is used to perform risk parsing on multiple other access nodes of the network based on the anomaly propagation risk weight condition according to the node access anomaly parsing result to obtain a node anomaly propagation risk coefficient; a node anomaly detection coefficient calculation module, which is used to calculate a node anomaly detection coefficient based on the node anomaly local risk coefficient and the node anomaly propagation risk coefficient; an anomaly early warning signal generating module, which is used to determine whether the node anomaly detection coefficient is greater than or equal to a node anomaly detection threshold, and if the node anomaly detection coefficient is greater than or equal to the node anomaly detection threshold, generate an anomaly early warning signal.
[0009] One or more technical solutions provided in the present application have at least the following technical effects or advantages:
[0010] When the target node accesses the network, the access information of the target node is collected in real time to obtain the node access monitoring result; based on the access scenario registration constraint and the access scenario registration calculation channel, the expected parsing of the access information of the target node is performed according to the real-time network status information of the network, and the node access expected space is established; the abnormal parsing of the node access monitoring result is performed according to the node access expected space to obtain the node access abnormal parsing result; based on the node access abnormal parsing result, the risk parsing of the target node is performed according to the access abnormal risk parsing channel to obtain the local risk coefficient of node abnormality; based on the abnormal propagation risk weight condition, the risk parsing of multiple other access nodes of the network is performed according to the node access abnormal parsing result to obtain the abnormal propagation risk coefficient of the node; based on the local risk coefficient of node abnormality and the abnormal propagation risk coefficient of the node, the abnormal detection coefficient of the node is calculated; it is judged whether the abnormal detection coefficient of the node is greater than or equal to the abnormal detection threshold of the node. If the abnormal detection coefficient of the node is greater than or equal to the abnormal detection threshold of the node, an abnormal warning signal is generated. That is to say, by achieving the technical goal of accurately capturing the mutual relationship and abnormal propagation effect between nodes, the accuracy of network anomaly recognition and the real-time monitoring ability are improved, thereby enhancing the stability of the network and ensuring the technical effect of data security.
[0011] The above description is only an overview of the technical solution of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the following specifically illustrates the specific embodiments of the present application. It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] In order to more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings described below are only exemplary, and for those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0013] Figure 1 It is a schematic flowchart of the node anomaly monitoring method based on access information parsing of the present application;
[0014] Figure 2 It is a schematic structural diagram of the node anomaly alarm device based on access information parsing of the present application.
[0015] Description of the reference numerals:
[0016] Node access monitoring result acquisition module 11, node access expected space establishment module 12, node access anomaly analysis result acquisition module 13, node anomaly local risk coefficient acquisition module 14, node anomaly propagation risk coefficient acquisition module 15, node anomaly detection coefficient calculation module 16, anomaly early warning signal generation module 17. Detailed implementation mode
[0017] By providing a node anomaly monitoring method and an alarm device based on access information parsing, the present application solves the technical problem in the prior art that due to ignoring the complex mutual relationship between nodes and the anomaly propagation effect, it is impossible to accurately capture the source of the anomaly and its propagation path, further affecting the accurate identification and real-time monitoring of network anomalies, and then reducing the stability and data security of the network. The technical goal of accurately capturing the mutual relationship between nodes and the anomaly propagation effect is realized, and the technical effect of improving the accuracy of network anomaly identification and real-time monitoring ability, thereby enhancing the stability of the network and ensuring data security is achieved.
[0018] Next, the technical solutions in the present application will be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. It should be understood that the present application is not limited by the exemplary embodiments described herein. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts belong to the scope of protection of the present application. In addition, it should be noted that for the sake of description, only the parts related to the present application are shown in the accompanying drawings rather than all.
[0019] Embodiment 1, please refer to the attached Figure 1 , the present application provides a node anomaly monitoring method based on access information parsing, which is applied to a node anomaly alarm device based on access information parsing, and specifically includes the following steps:
[0020] Step 1: When a target node accesses the network, the access information of the target node is collected in real time to obtain a node access monitoring result.
[0021] Specifically, when a target node accesses the network, the access information of the target node is collected in real time to obtain relevant access data. The access information includes the IP address, device type, connection time, etc. of the node, which helps the network system identify and record the basic attributes of the target node. Through the access information collected in real time, the connection status of the target node is analyzed, and thus a node access monitoring result is generated, including information such as whether the node successfully accesses, whether the signal strength is within the specified range, and whether the network delay is lower than the preset delay.
[0022] Step 2: Based on the access scenario registration constraint and the access scenario registration calculation channel, perform an expected analysis of the access information for the target node according to the real-time network status information of the network, and establish a node access expectation space.
[0023] Specifically, based on the access scenario registration constraint and the access scenario registration calculation channel, combined with the real-time network status information, perform an expected analysis of the access information for the target node. The access scenario registration constraint refers to the preset satisfaction conditions required when a node accesses, such as the minimum requirements for bandwidth, signal strength, latency, etc. The access scenario registration calculation channel is a calculation path that comprehensively analyzes the access scenario registration constraint and real-time data. Through the expected analysis, determine the ideal access conditions of the target node under the current network state. Finally, obtain the node access expectation space by comparing these conditions, and determine the network parameter range of the target node in the optimal access state to ensure that the task execution of the node can meet the performance requirements and the stability of the network environment.
[0024] Step 3: According to the node access expectation space, perform an anomaly analysis on the node access monitoring result to obtain a node access anomaly analysis result.
[0025] Specifically, according to the node access expectation space, perform an anomaly analysis on the actual node access monitoring result to determine whether the node meets the expected access conditions. Anomaly analysis is to compare the actual monitoring data with the expected conditions. If the actual data exceeds the set range, it is regarded as an anomaly, and a node access anomaly analysis result is generated to help locate and adjust the access state that does not meet the expectations.
[0026] Step 4: Based on the node access anomaly analysis result, perform a risk analysis on the target node according to the access anomaly risk analysis channel to obtain a node anomaly local risk coefficient.
[0027] Specifically, based on the node access anomaly analysis result, use the access anomaly risk analysis channel to perform a detailed risk analysis on the access situation of the target node, including probability assessment, impact assessment, and weighted calculation, to obtain a node anomaly local risk coefficient, so as to evaluate the occurrence probability of the anomaly, the degree of impact on the system stability, and the overall risk level, and use it to measure the potential impact of the access situation of this node on the system, thereby helping to determine whether corresponding risk control measures need to be taken.
[0028] Step 5: Based on the abnormal propagation risk weight condition, perform a risk analysis on multiple other access nodes of the network according to the node access anomaly analysis result to obtain a node abnormal propagation risk coefficient.
[0029] Specifically, based on the abnormal propagation risk weight conditions, risk analysis is performed on multiple other access nodes in the network to evaluate the potential risk of abnormal propagation from the current node to other nodes. The abnormal propagation risk weight conditions are a set of parameters for weighting, which define the contribution of the affected probability and impact degree of different nodes to the final risk coefficient during the abnormal propagation process. Combining the node access abnormal analysis results, calculate the risk degree of abnormal propagation to each node, and obtain the node abnormal propagation risk coefficient, indicating the risk level of each node under abnormal diffusion. Through risk analysis, high-risk nodes can be better identified and appropriate prevention and control measures can be formulated.
[0030] Step Six: Calculate the node abnormal detection coefficient based on the node abnormal local risk coefficient and the node abnormal propagation risk coefficient.
[0031] Specifically, calculate the node abnormal detection coefficient based on the node abnormal local risk coefficient and the node abnormal propagation risk coefficient to evaluate the comprehensive risk of the node's abnormality in the current network. The node abnormal local risk coefficient represents the risk degree of the node's own abnormality, such as problems in aspects such as signal strength, data delay, or bandwidth stability on the node. The node abnormal propagation risk coefficient reflects the possibility and impact degree of the abnormality spreading from this node to other parts of the network. Combining these two coefficients, the node abnormal detection coefficient is obtained through weighted calculation. The higher the node abnormal detection coefficient, the higher the comprehensive risk of the node in the current environment, and closer monitoring and management are required.
[0032] Step Seven: Determine whether the node abnormal detection coefficient is greater than or equal to the node abnormal detection threshold. If the node abnormal detection coefficient is greater than or equal to the node abnormal detection threshold, generate an abnormal warning signal.
[0033] Specifically, determine whether the node abnormal detection coefficient is greater than or equal to the node abnormal detection threshold to determine whether an abnormal warning signal needs to be issued. The node abnormal detection coefficient is a comprehensive value reflecting the potential risk of the node. The higher the node abnormal detection coefficient, the higher the abnormal risk of the node, and vice versa. The node abnormal detection threshold is a preset reference value used to measure the risk degree that needs to trigger a warning in the system. If the node abnormal detection coefficient is greater than or equal to the node abnormal detection threshold, it means that the risk of the node has reached the warning standard, and an abnormal warning signal is generated to remind the management personnel to take measures to reduce the risk of the node. Through this judgment mechanism, high-risk nodes can be discovered and processed in a timely manner, thus ensuring the stability and security of the network.
[0034] The node anomaly monitoring method based on access information parsing is applied to a node anomaly alarm device based on access information parsing, which can achieve the technical goal of accurately capturing the mutual relationship between nodes and the anomaly propagation effect, improve the accuracy of network anomaly recognition and real-time monitoring ability, and thus enhance the stability of the network and ensure the technical effect of data security.
[0035] Furthermore, this application also includes:
[0036] Retrieve normal access monitoring samples for the target node based on the network to obtain multiple groups of access monitoring samples. Each group of access monitoring samples includes network status samples, access task samples, and normal access monitoring samples. Obtain the real-time access task information of the target node. Based on the access scenario registration calculation channel, perform access scenario registration evaluation on the multiple groups of access monitoring samples according to the real-time access task information and the real-time network status information to obtain multiple access scenario registration coefficients. Determine whether the multiple access scenario registration coefficients meet the access scenario registration constraints to obtain multiple access scenario registration judgment results. Based on the multiple access scenario registration judgment results, select access monitoring samples from the multiple groups of access monitoring samples to establish an access monitoring sample selection space. Identify the trigger interval according to the access monitoring sample selection space to generate the node access expectation space.
[0037] Specifically, the normal samples are valid data samples. Monitor the access situation of the target node based on the network, and retrieve normal samples for access monitoring to collect multiple groups of access monitoring samples, so as to provide a reference for the stability of node access. Each group of access monitoring samples contains network status samples, access task samples, and normal access monitoring samples. Network status samples mainly include the signal strength, bandwidth, and latency of the current network. Access task samples refer to the specific tasks executed by the node in the network (such as data transmission, control instructions, etc.), and normal access monitoring samples are the normal ranges set based on past experience data. For example, the preset signal strength, bandwidth, latency, etc.
[0038] Next, obtain the real-time access task information of the target node in real time. Real-time access task information refers to the tasks executed by the node when it is currently connected to the network, such as data upload, remote access, etc. By obtaining the access task information in real time, the specific operation requirements of the target node in the network can be obtained.
[0039] Then, based on the access scenario registration calculation channel, the real-time access task information and the real-time network status information are subjected to registration analysis, registered and compared with the information in each access monitoring sample group, and a corresponding access scenario registration coefficient is generated for each sample group. The access scenario registration coefficient is a value used to represent the matching degree between the current access task and the sample group. For example, assuming that the higher the access scenario registration coefficient, the higher the matching degree between the current access task and a certain sample group.
[0040] After obtaining multiple access scenario registration coefficients, it is judged whether the multiple access scenario registration coefficients meet the constraint conditions of access scenario registration. The access scenario registration coefficient constraint is set according to the requirements of the network environment, such as signal stability, latency, etc. By making judgments, multiple judgment results of access scenario registration are obtained, which are used to determine whether the current access conforms to the expected state.
[0041] According to the access scenario registration judgment result, screening is performed in the access monitoring sample group, and the access monitoring normal samples corresponding to the access scenario registration coefficients that meet the access scenario registration constraints are added to the access monitoring sample selection space. The access monitoring sample selection space contains all access monitoring normal samples that highly match the current access situation, so as to provide a reference basis for subsequent access monitoring.
[0042] Finally, based on the access monitoring sample selection space, the trigger interval of node access is identified, and a node access expectation space is generated. The node access expectation space is a set of target states used to define the operating environment of the target node in an ideal access situation to ensure the smooth progress of the data transmission task.
[0043] Through multiple steps such as access monitoring, sample retrieval, real-time task acquisition, registration calculation, judgment, and selection, the ideal state of node access is gradually screened and optimized, thereby providing a reliable basis and guarantee for the stable operation of the target node in the network.
[0044] Furthermore, this application also includes:
[0045] Traverse the multiple access monitoring sample groups, and extract the first access monitoring sample group, where the first access monitoring sample group includes a first network status sample, a first access task sample, and a first access monitoring normal sample; perform similarity analysis on the real-time access task information and the first access task sample based on a siamese neural network to obtain a first access task registration coefficient; based on the siamese neural network, perform similarity analysis on the real-time network status information and the first network status sample to obtain a first access network status registration coefficient; activate the access scenario registration calculation channel, where the access scenario registration calculation channel includes an access task registration weight and an access network status registration weight; input the first access task registration coefficient and the first access network status registration coefficient into the access scenario registration calculation channel, and output a first access scenario registration coefficient; add the first access scenario registration coefficient to the multiple access scenario registration coefficients.
[0046] Specifically, visit all access monitoring sample groups in sequence, and randomly select a qualified sample group from them as the first access monitoring sample group. The first access monitoring sample group includes a first network status sample, a first access task sample, and a first access monitoring normal sample. The first network status sample records information such as the signal strength, latency, and bandwidth of the network, the first access task sample describes the specific task of the access node, and the first access monitoring normal sample provides the expected status of task completion.
[0047] Next, a siamese neural network is a model that can evaluate the similarity of different task features. By comparing the features of two tasks, the siamese neural network can calculate a registration coefficient. Perform similarity analysis on the real-time access task information and the first access task sample based on the siamese neural network to obtain a first access task registration coefficient. For example, if the similarity between the first real-time access task and the first access task sample reaches 0.85, then the first access task registration coefficient is 0.85, indicating that the requirements and features of these two tasks have a high degree of similarity.
[0048] Perform similarity analysis on the real-time network status information and the first network status sample based on the siamese neural network to calculate a first access network status registration coefficient. The first access network status registration coefficient is used to evaluate the similarity between the current network environment and the network status of the sample group, ensuring that the access environment conditions are suitable for the current task.
[0049] Then, the access scenario registration calculation channel is custom-set by those skilled in the art according to the actual situation. Activate the access scenario registration calculation channel, where the access scenario registration calculation channel includes an access task registration weight and an access network status registration weight, which are used to balance the influence of the first access task registration coefficient and the first access network status registration coefficient.
[0050] Next, input the first access task registration coefficient and the first access network status registration coefficient into the access scenario registration calculation channel, calculate them according to their respective weights, and sum up the calculation results to output a comprehensive first access scenario registration coefficient. The first access scenario registration coefficient integrates the similarity of task requirements and network status, and is a numerical value used to measure the adaptation degree of the current access situation to the sample group.
[0051] Finally, add the first access scenario registration coefficient to the set of multiple access scenario registration coefficients. That is, according to the method of obtaining the first access scenario registration coefficient, calculate multiple access scenario registration coefficients based on multiple access monitoring sample groups, which are used as the basis for subsequent judgment of access scenario adaptability.
[0052] By traversing the sample groups, performing similarity analysis, activating the registration channel and calculating the registration coefficient, find the scenario that best matches the current access condition among multiple sample groups, so as to achieve the best adaptation of node access and ensure the stability of node task execution effect and network status.
[0053] Furthermore, this application also includes:
[0054] The access anomaly risk analysis channel includes an access anomaly risk probability assessment channel, an access anomaly risk impact assessment channel, and an access anomaly risk weighting channel; input the node access anomaly analysis result into the access anomaly risk probability assessment channel to obtain an access anomaly risk probability coefficient; input the node access anomaly analysis result into the access anomaly risk impact assessment channel to obtain an access anomaly risk impact coefficient; input the access anomaly risk probability coefficient and the access anomaly risk impact coefficient into the access anomaly risk weighting channel to output the node anomaly local risk coefficient.
[0055] Specifically, the access anomaly risk analysis channel is used to comprehensively evaluate the access anomaly situation of the node, including the access anomaly risk probability assessment channel, the access anomaly risk impact assessment channel, and the access anomaly risk weighting channel. By collecting the historical data of the node, using statistical analysis methods to model the frequency and distribution of abnormal events, calculate the probability of the current node having an anomaly, and then obtain the access anomaly risk probability assessment channel. Based on the risk impact assessment theory, that is, quantitatively evaluating the possible consequences caused by the anomaly, obtain the access anomaly risk impact assessment channel. Adopt the method of weighted calculation to comprehensively consider the factors of probability and impact, and obtain the access anomaly risk weighting channel, making the risk assessment result more representative. Among them, the allocation of weights can be customized and adjusted according to user needs or by those skilled in the art according to the actual situation.
[0056] The access anomaly risk probability assessment channel is used to calculate the likelihood of an anomaly occurring. By inputting the parsing results of node access anomalies, the access anomaly risk probability coefficient is obtained, which reflects the occurrence probability of the anomaly.
[0057] The access anomaly risk impact assessment channel is used to evaluate the actual impact size of an anomaly. By inputting the parsing results of node access anomalies, the access anomaly risk impact coefficient is obtained. The access anomaly risk impact coefficient indicates the potential impact degree of the anomaly on node performance or the system. For example, if the anomaly has a greater impact on system stability, the access anomaly risk impact coefficient is higher; conversely, it is lower.
[0058] Finally, input the access anomaly risk probability coefficient and the access anomaly risk impact coefficient into the access anomaly risk weighting channel. This channel synthesizes the weights of the two and outputs the local risk coefficient of node anomalies to measure the overall anomaly risk degree.
[0059] Through probability, impact, and weighting evaluations, the access anomalies risks of nodes can be effectively quantified and identified, helping to achieve targeted risk control.
[0060] Furthermore, this application also includes:
[0061] Collect the topological parameters of the network to obtain a network topology dataset; based on the network topology dataset, build a network topology model; based on the anomaly propagation risk weight conditions and the parsing results of node access anomalies, according to the network topology model, conduct risk predictions on the multiple other access nodes to obtain multiple node spread risk coefficients; based on the network topology model, conduct importance evaluations on the multiple other access nodes to obtain multiple node importance evaluation coefficients; based on the multiple node importance evaluation coefficients, allocate spread risk weights to the multiple other access nodes and output multiple spread risk weight coefficients; according to the multiple spread risk weight coefficients, conduct weighted calculations on the multiple node spread risk coefficients and output the node anomaly propagation risk coefficient.
[0062] Specifically, collect the topological parameters of the network. The topological parameters describe the connection relationships between nodes in the network, such as information like the number of connections of each node, data flow direction, and path length. Integrating all topological parameters can generate a network topology dataset, providing a data basis for analyzing the network structure.
[0063] Next, build a network topology model based on the collected network topology dataset. The network topology model is used to visually present the relative positions and connection situations of each node in the network. The network topology model can display the connection patterns of nodes and the data circulation paths, helping to analyze the structural characteristics of the network and the influence relationships between nodes. For example, in the network topology model, node A may be the central node, connecting 5 other nodes, thus becoming the key hub of the network.
[0064] Then, based on the abnormal propagation risk weight conditions and the node access anomaly analysis results, use the network topology model to predict the risks of other access nodes to obtain multiple node spread risk coefficients. The spread risk coefficient represents the probability that an anomaly may spread from one node to other nodes.
[0065] Subsequently, based on the network topology model, conduct importance assessments on these nodes to obtain multiple node importance assessment coefficients. Importance assessment measures the key degree of a node in the network. For example, by analyzing the number of node connections and the impact on data streams, determine the importance of the node.
[0066] Next, assign spread risk weights to other nodes based on the node importance assessment coefficients, which reflects the impact degree of different nodes on the overall network during abnormal propagation. The spread risk weight coefficient can adjust the priorities of each node during abnormal propagation. For example, nodes with higher importance coefficients will receive higher spread risk weights, making it easier for anomalies to spread between these nodes.
[0067] Finally, perform weighted calculations on the node spread risk coefficients, apply the spread risk weight coefficients to each spread risk coefficient to obtain the node abnormal propagation risk coefficients. The node abnormal propagation risk coefficient indicates the risk degree of an anomaly possibly spreading throughout the network.
[0068] By collecting topology parameters, building a topology model, conducting risk predictions, importance assessments, and weighted calculations, it is possible to comprehensively analyze the propagation possibility and impact degree of node anomalies in the network, effectively identify potential high-risk areas, so as to take more targeted management measures.
[0069] Furthermore, this application also includes:
[0070] Based on the network topology model, conduct propagation simulations according to the node access anomaly analysis results to obtain access anomaly propagation simulation results; based on the access anomaly risk propagation simulation results, respectively conduct spread probability risk predictions on the multiple other access nodes to obtain multiple node spread probability risk coefficients; based on the access anomaly risk propagation simulation results, respectively conduct spread impact risk predictions on the multiple other access nodes to obtain multiple node spread impact risk coefficients; according to the abnormal propagation risk weight conditions, respectively conduct weighted calculations on the multiple node spread probability risk coefficients and the multiple node spread impact risk coefficients, and output the multiple node spread risk coefficients, where the abnormal propagation risk weight conditions include spread probability risk weights and spread impact risk weights.
[0071] Specifically, based on the network topology model and combined with the parsing results of node access anomalies, propagation simulation is carried out to obtain the propagation simulation results of access anomalies in the network. Propagation simulation analyzes how abnormal signals or faults spread from one node to other nodes on the network structure.
[0072] Then, based on the propagation simulation results of access anomalies, the risk prediction of the affected probability is carried out for other access nodes respectively, and the risk coefficient of the affected probability of each node is calculated. The risk coefficient of the affected probability represents the likelihood of the anomaly spreading to a specific node. For example, the closer node B is to the abnormal node A, the higher its risk coefficient of the affected probability; conversely, it is lower.
[0073] Next, based on the propagation simulation results of access anomaly risk, the risk prediction of the affected impact is carried out for other access nodes respectively to obtain the risk coefficient of the affected impact of each node. The risk coefficient of the affected impact reflects the degree of impact that may be caused after the anomaly reaches this node. Suppose node C is connected to the network center node and has a large data traffic, its risk coefficient of the affected impact may be higher.
[0074] After that, according to the abnormal propagation risk weight conditions, the risk coefficient of the affected probability and the risk coefficient of the affected impact of each node are weighted and calculated to output the final node affected risk coefficient. The abnormal propagation risk weight conditions are defined by those skilled in the art according to the actual situation with the weight ratios of different risk coefficients, including the risk weight of the affected probability and the risk weight of the affected impact, so as to output a more comprehensive affected risk coefficient for a specific node.
[0075] Through propagation simulation, risk prediction and weighted calculation, it is possible to predict and quantify in detail the propagation risk of abnormal events in the network, generate specific affected risk coefficients for each node, help identify high-risk nodes and improve the overall risk control level of the network.
[0076] Furthermore, this application also includes:
[0077] Activating an anomaly detection weighted network, where the anomaly detection weighted network includes a local risk weight of node anomalies and a propagation risk weight of node anomalies; calculating the proportion according to the local risk coefficient of node anomalies and the propagation risk coefficient of node anomalies to generate an anomaly detection enhancement weight condition; optimizing the weight of the anomaly detection weighted network according to the anomaly detection enhancement weight condition to generate an optimized anomaly detection weighted network; inputting the local risk coefficient of node anomalies and the propagation risk coefficient of node anomalies into the optimized anomaly detection weighted network, and outputting the node anomaly detection coefficient.
[0078] Specifically, activate the anomaly detection weighted network, which includes the local risk weight of node anomalies and the propagation risk weight of node anomalies. The local risk weight of node anomalies is used to measure the risk of internal anomalies in a node, such as the connection quality and load condition of the node; while the propagation risk weight of node anomalies evaluates the propagation risk of node anomalies to other parts of the entire network, such as the possibility and impact degree of a fault spreading from this node to other nodes. Through these weights, comprehensively consider the anomaly risk of the node itself and the impact of the anomaly on the entire network.
[0079] Next, perform a proportion calculation based on the local risk coefficient of node anomalies and the propagation risk coefficient of node anomalies to generate the weight improvement conditions for anomaly detection. The weight improvement conditions for anomaly detection include the local risk improvement weight and the propagation risk improvement weight. Exemplarily, when performing the proportion calculation based on the local risk coefficient of node anomalies and the propagation risk coefficient of node anomalies, the sum of the local risk coefficient of node anomalies and the propagation risk coefficient of node anomalies is recorded as the total anomaly risk coefficient. The ratio of the local risk coefficient of node anomalies to the total anomaly risk coefficient is output as the local risk improvement weight. Similarly, the ratio of the propagation risk coefficient of node anomalies to the total anomaly risk coefficient is output as the propagation risk improvement weight.
[0080] Then, based on the weight improvement conditions for anomaly detection, optimize the weights of the anomaly detection weighted network to generate an optimized anomaly detection weighted network. The optimized anomaly detection weighted network includes the optimized local risk weight of node anomalies and the optimized propagation risk weight of node anomalies. Exemplarily, when optimizing the weights of the anomaly detection weighted network according to the weight improvement conditions for anomaly detection, the sum of the local risk improvement weight, the propagation risk improvement weight, the local risk weight of node anomalies, and the propagation risk weight of node anomalies is output as the total anomaly detection weight. The sum of the local risk improvement weight and the local risk weight of node anomalies is recorded as the total local risk weight. The ratio of the total local risk weight to the total anomaly detection weight is output as the optimized local risk weight of node anomalies. The sum of the propagation risk improvement weight and the propagation risk weight of node anomalies is recorded as the total propagation risk weight. The ratio of the total propagation risk weight to the total anomaly detection weight is output as the optimized propagation risk weight of node anomalies.
[0081] Finally, input the local risk coefficient of node anomaly and the propagation risk coefficient of node anomaly into the anomaly detection weighted optimization network, and output the node anomaly detection coefficient. Preferably, the local risk coefficient of node anomaly × the local risk optimization weight of node anomaly + the propagation risk coefficient of node anomaly × the propagation risk optimization weight of node anomaly = the node anomaly detection coefficient. The numerical value of the node anomaly detection coefficient reflects the intensity of the anomaly detection risk of the node in the current network environment. For example, if the local risk coefficient of node A's anomaly is 0.8 and the propagation risk coefficient of node A's anomaly is 0.6, the detection network after weighted optimization may output the anomaly detection coefficient of node A as 0.75, indicating that the anomaly detection risk of this node in the current network is relatively high and further monitoring is required.
[0082] By activating the anomaly detection weighted network and combining the local risk and propagation risk of the node, the weight allocation of the detection network is optimized. Through proportion calculation and weight optimization, the node anomaly detection coefficient is finally obtained, so as to accurately evaluate the possible anomaly risk of the node in the network, providing more effective support for early warning and management.
[0083] In summary, the node anomaly monitoring method based on access information parsing provided by this application has the following technical effects:
[0084] When the target node accesses the network, the access information of the target node is collected in real time to obtain the node access monitoring result; based on the access scenario registration constraint and the access scenario registration calculation channel, the expected parsing of the access information of the target node is performed according to the real-time network status information of the network, and the node access expected space is established; the anomaly parsing of the node access monitoring result is performed according to the node access expected space to obtain the node access anomaly parsing result; based on the node access anomaly parsing result, the risk parsing of the target node is performed according to the access anomaly risk parsing channel to obtain the local risk coefficient of node anomaly; based on the anomaly propagation risk weight condition, the risk parsing of multiple other access nodes of the network is performed according to the node access anomaly parsing result to obtain the propagation risk coefficient of node anomaly; based on the local risk coefficient of node anomaly and the propagation risk coefficient of node anomaly, the node anomaly detection coefficient is calculated; it is judged whether the node anomaly detection coefficient is greater than or equal to the node anomaly detection threshold. If the node anomaly detection coefficient is greater than or equal to the node anomaly detection threshold, an anomaly warning signal is generated. That is to say, by achieving the technical goal of accurately capturing the mutual relationship and anomaly propagation effect between nodes, the technical effects of improving the accuracy of network anomaly recognition and real-time monitoring ability are achieved, thereby enhancing the stability of the network and ensuring data security.
[0085] Embodiment 2. Based on the node anomaly monitoring method based on access information parsing in the foregoing embodiment and with the same inventive concept, the present application further provides a node anomaly alarm device based on access information parsing. Please refer to the appendix Figure 2 , including:
[0086] A node access monitoring result obtaining module 11, which is configured to, when a target node accesses the network, collect the access information of the target node in real time to obtain a node access monitoring result; a node access expected space establishing module 12, which is configured to perform access information expectation parsing on the target node based on the access scenario registration constraint and the access scenario registration calculation channel according to the real-time network status information of the network to establish a node access expected space; a node access anomaly parsing result obtaining module 13, which is configured to perform anomaly parsing on the node access monitoring result according to the node access expected space to obtain a node access anomaly parsing result; a node anomaly local risk coefficient obtaining module 14, which is configured to perform risk parsing on the target node based on the node access anomaly parsing result according to the access anomaly risk parsing channel to obtain a node anomaly local risk coefficient; a node anomaly propagation risk coefficient obtaining module 15, which is configured to perform risk parsing on multiple other access nodes of the network based on the anomaly propagation risk weight condition according to the node access anomaly parsing result to obtain a node anomaly propagation risk coefficient; a node anomaly detection coefficient calculation module 16, which is configured to calculate a node anomaly detection coefficient based on the node anomaly local risk coefficient and the node anomaly propagation risk coefficient; and an anomaly early warning signal generating module 17, which is configured to determine whether the node anomaly detection coefficient is greater than or equal to a node anomaly detection threshold, and if the node anomaly detection coefficient is greater than or equal to the node anomaly detection threshold, generate an anomaly early warning signal.
[0087] Further, the node anomaly alarm device based on access information parsing is further configured to:
[0088] Retrieve normal access monitoring samples for the target node based on the network, obtaining multiple access monitoring sample groups, where each access monitoring sample group includes network status samples, access task samples, and normal access monitoring samples; obtain the real-time access task information of the target node; based on the access scenario registration calculation channel, perform access scenario registration evaluation on the multiple access monitoring sample groups according to the real-time access task information and the real-time network status information, obtaining multiple access scenario registration coefficients; determine whether the multiple access scenario registration coefficients meet the access scenario registration constraints, obtaining multiple access scenario registration judgment results; perform access monitoring sample selection on the multiple access monitoring sample groups based on the multiple access scenario registration judgment results, establishing an access monitoring sample selection space; identify a trigger interval according to the access monitoring sample selection space, generating the node access expectation space.
[0089] Furthermore, the node abnormal alarm device based on access information parsing is further configured to:
[0090] Traverse the multiple access monitoring sample groups, extract the first access monitoring sample group, where the first access monitoring sample group includes a first network status sample, a first access task sample, and a first normal access monitoring sample; perform similarity analysis on the real-time access task information and the first access task sample based on a siamese neural network, obtaining a first access task registration coefficient; based on the siamese neural network, perform similarity analysis on the real-time network status information and the first network status sample, obtaining a first access network status registration coefficient; activate the access scenario registration calculation channel, where the access scenario registration calculation channel includes an access task registration weight and an access network status registration weight; input the first access task registration coefficient and the first access network status registration coefficient into the access scenario registration calculation channel, outputting a first access scenario registration coefficient; add the first access scenario registration coefficient to the multiple access scenario registration coefficients.
[0091] Furthermore, the node abnormal alarm device based on access information parsing is further configured to:
[0092] The access abnormal risk parsing channel includes an access abnormal risk probability evaluation channel, an access abnormal risk impact evaluation channel, and an access abnormal risk weighting channel; input the node access abnormal parsing result into the access abnormal risk probability evaluation channel, obtaining an access abnormal risk probability coefficient; input the node access abnormal parsing result into the access abnormal risk impact evaluation channel, obtaining an access abnormal risk impact coefficient; input the access abnormal risk probability coefficient and the access abnormal risk impact coefficient into the access abnormal risk weighting channel, outputting the node abnormal local risk coefficient.
[0093] Further, the node anomaly alarm device based on access information parsing is further configured to:
[0094] Collect the topology parameters of the network to obtain a network topology data set; build a network topology model according to the network topology data set; based on the abnormal propagation risk weight condition and the node access anomaly parsing result, perform risk prediction on the multiple other access nodes according to the network topology model to obtain multiple node affected risk coefficients; perform importance evaluation on the multiple other access nodes based on the network topology model to obtain multiple node importance evaluation coefficients; perform affected risk weight allocation on the multiple other access nodes based on the multiple node importance evaluation coefficients, and output multiple affected risk weight coefficients; perform weighted calculation on the multiple node affected risk coefficients according to the multiple affected risk weight coefficients, and output the node abnormal propagation risk coefficient.
[0095] Further, the node anomaly alarm device based on access information parsing is further configured to:
[0096] Based on the network topology model, perform propagation simulation according to the node access anomaly parsing result to obtain an access anomaly propagation simulation result; based on the access anomaly risk propagation simulation result, perform affected probability risk prediction on the multiple other access nodes respectively to obtain multiple node affected probability risk coefficients; based on the access anomaly risk propagation simulation result, perform affected impact risk prediction on the multiple other access nodes respectively to obtain multiple node affected impact risk coefficients; according to the abnormal propagation risk weight condition, perform weighted calculation on the multiple node affected probability risk coefficients and the multiple node affected impact risk coefficients respectively, and output the multiple node affected risk coefficients, where the abnormal propagation risk weight condition includes an affected probability risk weight and an affected impact risk weight.
[0097] Further, the node anomaly alarm device based on access information parsing is further configured to:
[0098] Activate an anomaly detection weighted network, where the anomaly detection weighted network includes a node anomaly local risk weight and a node anomaly propagation risk weight; perform ratio calculation according to the node anomaly local risk coefficient and the node anomaly propagation risk coefficient to generate an anomaly detection improvement weight condition; optimize the weight of the anomaly detection weighted network according to the anomaly detection improvement weight condition to generate an anomaly detection weighted optimized network; input the node anomaly local risk coefficient and the node anomaly propagation risk coefficient into the anomaly detection weighted optimized network, and output the node anomaly detection coefficient.
[0099] The various embodiments in this specification are described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The method and specific examples of node anomaly monitoring based on access information parsing in the foregoing first embodiment are equally applicable to the node anomaly alarm device based on access information parsing in this embodiment. Through the detailed description of the method of node anomaly monitoring based on access information parsing above, those skilled in the art can clearly understand the node anomaly alarm device based on access information parsing in this embodiment. Therefore, for the sake of brevity of the specification, it will not be elaborated here.
[0100] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0101] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the present application and its equivalent technologies, the present application is also intended to include these changes and variations.
Claims
1. A node anomaly monitoring method based on access information analysis, characterized in that: include: When the target node accesses the network, the access information of the target node is collected in real time to obtain the node access monitoring result; Based on the access scenario registration constraint and the access scenario registration calculation channel, performing access information expectation analysis on the target node according to the real-time network status information of the network, and establishing a node access expectation space; Performing an abnormal analysis on the node access monitoring result according to the node access expected space to obtain a node access abnormal analysis result; Based on the node access anomaly analysis result, performing risk analysis on the target node according to the access anomaly risk analysis channel to obtain a node anomaly local risk coefficient; Based on the abnormal propagation risk weight condition, risk analysis is performed on multiple other access nodes of the network according to the node access abnormality analysis result to obtain a node abnormal propagation risk coefficient; Calculating a node anomaly detection coefficient based on the node anomaly local risk coefficient and the node anomaly propagation risk coefficient; Determine whether the node anomaly detection coefficient is greater than or equal to the node anomaly detection threshold, and if the node anomaly detection coefficient is greater than or equal to the node anomaly detection threshold, generate an anomaly warning signal; Based on the abnormal propagation risk weight condition, risk analysis is performed on multiple other access nodes of the network according to the node access abnormality analysis result to obtain a node abnormal propagation risk coefficient, including: Collecting topological parameters of the network to obtain a network topology data set; Building a network topology model according to the network topology dataset; Based on the abnormal propagation risk weight condition and the node access abnormality analysis result, risk prediction is performed on the multiple other access nodes according to the network topology model to obtain multiple node impact risk coefficients; Performing importance evaluation on the multiple other access nodes based on the network topology model to obtain multiple node importance evaluation coefficients; Allocating contagion risk weights to the multiple other access nodes based on the multiple node importance assessment coefficients, and outputting multiple contagion risk weight coefficients; The multiple node spread risk coefficients are weighted and calculated according to the multiple spread risk weight coefficients, and the node abnormal propagation risk coefficient is output.
2. The method according to claim 1, characterized in that Based on the access scenario registration constraint and the access scenario registration calculation channel, the access information expectation of the target node is parsed according to the real-time network status information of the network, and the node access expectation space is established, including: Performing access monitoring normal sample retrieval on the target node based on the network to obtain multiple access monitoring sample groups, wherein each access monitoring sample group includes a network status sample, an access task sample, and a normal access monitoring sample; Obtaining real-time access task information of the target node; Based on the access scenario registration calculation channel, performing access scenario registration evaluation on the multiple access monitoring sample groups according to the real-time access task information and the real-time network status information to obtain multiple access scenario registration coefficients; Determine whether the multiple access scene registration coefficients meet the access scene registration constraints, and obtain multiple access scene registration judgment results; Selecting access monitoring samples from the multiple access monitoring sample groups based on the multiple access scenario registration judgment results, and establishing an access monitoring sample selection space; A trigger interval is identified based on the access monitoring sample selection space to generate the node access expectation space.
3. The method according to claim 2, characterized in that Based on the access scenario registration calculation channel, access scenario registration evaluation is performed on the multiple access monitoring sample groups according to the real-time access task information and the real-time network status information to obtain multiple access scenario registration coefficients, including: Traversing the multiple access monitoring sample groups, extracting a first access monitoring sample group, wherein the first access monitoring sample group includes a first network status sample, a first access task sample, and a first access monitoring normal sample; Performing a similarity analysis on the real-time access task information and the first access task sample based on a twin neural network to obtain a first access task registration coefficient; Based on the twin neural network, performing a similarity analysis on the real-time network status information and the first network status sample to obtain a first access network status alignment coefficient; Activating the access scenario registration calculation channel, wherein the access scenario registration calculation channel includes an access task registration weight and an access network state registration weight; Inputting the first access task registration coefficient and the first access network state registration coefficient into the access scenario registration calculation channel, and outputting the first access scenario registration coefficient; The first access scenario registration coefficient is added to the multiple access scenario registration coefficients.
4. The method according to claim 1, characterized in that Based on the node access anomaly analysis result, risk analysis is performed on the target node according to the access anomaly risk analysis channel to obtain a node anomaly local risk coefficient, including: The access abnormality risk analysis channel includes an access abnormality risk probability assessment channel, an access abnormality risk impact assessment channel and an access abnormality risk weighting channel; Inputting the node access anomaly analysis result into the access anomaly risk probability assessment channel to obtain an access anomaly risk probability coefficient; Inputting the node access anomaly analysis result into the access anomaly risk impact assessment channel to obtain an access anomaly risk impact coefficient; The access abnormality risk probability coefficient and the access abnormality risk impact coefficient are input into the access abnormality risk weighted channel, and the node abnormality local risk coefficient is output.
5. The method according to claim 1, characterized in that Based on the abnormal propagation risk weight condition and the node access abnormality analysis result, risk prediction is performed on the multiple other access nodes according to the network topology model to obtain multiple node contagion risk coefficients, including: Based on the network topology model, a propagation simulation is performed according to the node access anomaly analysis result to obtain an access anomaly propagation simulation result; Based on the access abnormality risk propagation simulation result, respectively predicting the risk of spreading probability of the multiple other access nodes to obtain the risk coefficients of spreading probability of multiple nodes; Based on the access abnormality risk propagation simulation result, respectively predicting the impact risk of the other multiple access nodes to obtain the impact risk coefficients of multiple nodes; According to the abnormal propagation risk weight condition, weighted calculations are performed on the multiple node spread probability risk coefficients and the multiple node spread impact risk coefficients respectively, and the multiple node spread risk coefficients are output, wherein the abnormal propagation risk weight condition includes the spread probability risk weight and the spread impact risk weight.
6. The method according to claim 1, characterized in that Calculating a node anomaly detection coefficient based on the node anomaly local risk coefficient and the node anomaly propagation risk coefficient includes: activating an anomaly detection weighted network, wherein the anomaly detection weighted network includes a node anomaly local risk weight and a node anomaly propagation risk weight; Calculate the proportion of the node abnormal local risk coefficient and the node abnormal propagation risk coefficient to generate an abnormal detection improvement weight condition; Optimizing the weight of the anomaly detection weighted network according to the anomaly detection weight enhancement condition to generate an anomaly detection weighted optimization network; The node anomaly local risk coefficient and the node anomaly propagation risk coefficient are input into the anomaly detection weighted optimization network, and the node anomaly detection coefficient is output.
7. A node abnormality alarm device based on access information analysis, characterized in that: The steps for implementing the node anomaly monitoring method based on access information parsing according to any one of claims 1 to 6 include: A node access monitoring result acquisition module, wherein the node access monitoring result acquisition module is used to collect access information of the target node in real time when the target node accesses the network, and obtain the node access monitoring result; A node access expected space establishment module, the node access expected space establishment module is used to perform access information expectation analysis on the target node according to the real-time network status information of the network based on the access scenario registration constraint and the access scenario registration calculation channel, and establish the node access expected space; A node access anomaly analysis result obtaining module, wherein the node access anomaly analysis result obtaining module is used to perform anomaly analysis on the node access monitoring result according to the node access expected space to obtain a node access anomaly analysis result; A node abnormality local risk coefficient obtaining module, wherein the node abnormality local risk coefficient obtaining module is used to perform risk analysis on the target node according to the access abnormality risk analysis channel based on the node access abnormality analysis result, and obtain the node abnormality local risk coefficient; A node abnormal propagation risk coefficient obtaining module, the node abnormal propagation risk coefficient obtaining module is used to perform risk analysis on multiple other access nodes of the network according to the node access abnormality analysis result based on the abnormal propagation risk weight condition, and obtain the node abnormal propagation risk coefficient; A node anomaly detection coefficient calculation module, the node anomaly detection coefficient calculation module is used to calculate the node anomaly detection coefficient based on the node anomaly local risk coefficient and the node anomaly propagation risk coefficient; An abnormal warning signal generation module, the abnormal warning signal generation module is used to determine whether the node abnormality detection coefficient is greater than or equal to the node abnormality detection threshold, if the node abnormality detection coefficient is greater than or equal to the node abnormality detection threshold, generate an abnormal warning signal; Further, the node abnormality alarm device based on access information analysis is also used for: Collect the topological parameters of the network to obtain a network topology data set; build a network topology model based on the network topology data set; based on the abnormal propagation risk weight condition and the node access abnormality analysis result, perform risk prediction on the multiple other access nodes according to the network topology model to obtain multiple node impact risk coefficients; perform importance assessment on the multiple other access nodes based on the network topology model to obtain multiple node importance assessment coefficients; assign impact risk weights to the multiple other access nodes based on the multiple node importance assessment coefficients, and output multiple impact risk weight coefficients; perform weighted calculation on the multiple node impact risk coefficients according to the multiple impact risk weight coefficients, and output the node abnormal propagation risk coefficient.
Citation Information
Patent Citations
Micro-service abnormity diagnosis method based on attribute relation graph
CN114201326A
Risk propagation detection method and device, electronic equipment and storage medium
CN114386861A