Monitoring abnormality troubleshooting method and monitoring system

By setting up the basic communication mode after the equipment is disconnected and reconnected and conducting risk assessment, the problem of lack of risk inspection when equipment is disconnected and reconnected in the existing technology is solved, and the safety risk investigation and management of disconnected and reconnected equipment is realized.

CN119814475BActive Publication Date: 2025-05-09YUNBIAN CLOUD TECHNOLOGY (SHANGHAI) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510293969.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-05-09
Estimated Expiration
2045-03-13

AI Technical Summary

Technical Problem

The existing technology lacks an effective mechanism to conduct comprehensive risk investigations on equipment when it is disconnected and reconnected, which may lead to computer systems facing security threats.

Method used

After the disconnected reconnection device completes identity authentication, set the communication mode between it and the target server as the basic communication mode, allowing only the specified type of data upload and download. Obtain the operating data of the disconnected reconnection equipment and the associated computer equipment, and use the risk analysis model to perform risk assessment. If the comprehensive risk value is higher than the threshold, perform secondary identity authentication, otherwise switch to normal communication mode.

Benefits of technology

By comprehensively analyzing the operating data of disconnected reconnect devices and their associated devices, the risk investigation of disconnected reconnect devices can be effectively completed and the security threats posed to the target server are reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814475B_ABST
    Figure CN119814475B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of computer technology, and provides a monitoring anomaly troubleshooting method and a monitoring system thereof. The method comprises: after a disconnection and reconnection device completes an identity authentication, setting a basic communication mode between the disconnection and reconnection device and a target server; obtaining first operation data of the disconnection and reconnection device during the disconnection and reconnection period, and obtaining second operation data of several associated computer devices having a preset association relationship with the disconnection and reconnection device during the disconnection and reconnection period; using a risk analysis model to conduct a risk assessment on the first operation data and the second operation data to obtain a comprehensive risk value, and if the comprehensive risk value is higher than the risk threshold, a secondary identity authentication is performed on the disconnection and reconnection device, otherwise the basic communication mode is switched to a normal communication mode. The present invention can reduce the risk of abnormal disconnection and reconnection devices posing a security threat to the target server by conducting a risk investigation on the disconnection and reconnection device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a monitoring anomaly troubleshooting method and a monitoring system thereof. Background Art

[0002] In today's digital age, various types of devices are widely connected to computer systems, and device disconnection and reconnection occur frequently. When a device is disconnected and reconnected, existing technologies often lack an effective mechanism for comprehensive risk investigation. Traditional methods usually simply authenticate the device and directly restore its normal communication function after the authentication is passed. They do not fully consider the risks that the device may face during disconnection, such as malicious tampering of the device, network attacks, etc., which may cause computer systems to face security threats.

[0003] Therefore, designing a new abnormal troubleshooting solution for disconnected and reconnected devices to ensure the safe and stable operation of computer systems is a technical problem that urgently needs to be solved. Summary of the invention

[0004] In response to the above technical problems, the present invention provides a monitoring anomaly troubleshooting method, a monitoring system, an electronic device, a computer storage medium and a computer program product.

[0005] The present invention discloses a monitoring anomaly troubleshooting method, which is applied to monitoring a cloud, and the method comprises the following steps:

[0006] After the disconnected reconnecting device completes an identity authentication, a basic communication mode is set between the disconnected reconnecting device and the target server; in the basic communication mode, only uploading and downloading of certain specified types of data are allowed;

[0007] Acquiring first operation data of the disconnection and reconnection device during the disconnection and reconnection period, and acquiring second operation data of a plurality of associated computer devices having a preset association relationship with the disconnection and reconnection device during the disconnection and reconnection period;

[0008] A risk analysis model is used to perform risk assessment on the first operating data and the second operating data to obtain a comprehensive risk value. If the comprehensive risk value is higher than the risk threshold, a secondary identity authentication is performed on the disconnected and reconnected device, otherwise the basic communication mode is switched to the normal communication mode.

[0009] Optionally, the obtaining first operation data of the disconnection and reconnection device during the disconnection and reconnection period includes:

[0010] Obtaining historical disconnection records of the disconnection reconnection device, counting the number of types of disconnection reasons in the historical disconnection records, and obtaining a first dynamic adjustment coefficient according to the number of types;

[0011] Using the first dynamic adjustment coefficient, a standard acquisition duration corresponding to the device type to which the disconnection reconnection device belongs is adjusted to obtain a target acquisition duration;

[0012] The first operation data of the disconnection and reconnection device during the disconnection and reconnection period is obtained based on the disconnection time; the duration of the disconnection and reconnection period is the target acquisition duration.

[0013] Optionally, the using a risk analysis model to perform risk assessment on the first operating data and the second operating data to obtain a comprehensive risk value includes:

[0014] Using a risk analysis model to perform risk assessment on the business data in the first operation data and the second operation data to obtain a business risk value;

[0015] If the business risk value is higher than the business risk threshold, setting the comprehensive risk value to a preset value;

[0016] If the business risk value is not higher than the business risk threshold, then: extract the first disconnection operation data of the disconnection and reconnection device from the first operation data, extract the second disconnection operation data of the associated computer device from the second operation data, and perform risk assessment on the first disconnection operation data and the second disconnection operation data according to preset logical rules to obtain a comprehensive risk value.

[0017] Optionally, extracting first disconnection operation data of a disconnection reconnection device from the first operation data, extracting second disconnection operation data of an associated computer device from the second operation data, and performing risk assessment on the first disconnection operation data and the second disconnection operation data according to a preset logical rule to obtain a comprehensive risk value includes:

[0018] Extracting a first disconnection moment and a first disconnection reconnection moment of the disconnection reconnection device from the first operation data, and calculating a first reconnection waiting time according to the first disconnection moment and the first disconnection reconnection moment; determining the first disconnection moment and the first reconnection waiting time as the first disconnection operation data;

[0019] Extracting a second disconnection time and a second disconnection reconnection time of the associated computer device from the second operation data, calculating a second reconnection waiting time according to the second disconnection time and the second disconnection reconnection time; determining the second disconnection time and the second reconnection waiting time as the second disconnection operation data;

[0020] Determine the disconnection order between the disconnection reconnection device and each associated computer device according to the first disconnection time and each of the second disconnection times;

[0021] Determine the overall matching degree between the disconnection sequence and the standard disconnection sequence, and obtain a first risk value according to the overall matching degree; wherein the standard disconnection sequence corresponds to a disconnection reconnection device;

[0022] Compare the first reconnection waiting time and each of the second reconnection waiting time with the corresponding standard reconnection waiting time for deviation, and determine a second risk value according to the deviation comparison result;

[0023] The first risk value and the second risk value are combined to obtain the comprehensive risk value.

[0024] Optionally, the fusing the first risk value and the second risk value to obtain the comprehensive risk value includes:

[0025] Merging the first risk value and the second risk value to obtain a preliminary comprehensive risk value;

[0026] Retrieving a second dynamic adjustment coefficient of the disconnection and reconnection device, and using the second dynamic adjustment coefficient to adjust the preliminary comprehensive risk value to obtain the comprehensive risk value;

[0027] The second dynamic adjustment coefficient is obtained according to the historical execution degree of the standard disconnection sequence.

[0028] The present invention also discloses a monitoring system, which is applied to monitoring the cloud. The system includes a processing device and a storage device. The computer code stored in the storage device is called and executed by the processing device to implement the following steps:

[0029] After the disconnected reconnecting device completes an identity authentication, a basic communication mode is set between the disconnected reconnecting device and the target server; in the basic communication mode, only uploading and downloading of certain specified types of data are allowed;

[0030] Acquiring first operation data of the disconnection and reconnection device during the disconnection and reconnection period, and acquiring second operation data of a plurality of associated computer devices having a preset association relationship with the disconnection and reconnection device during the disconnection and reconnection period;

[0031] A risk analysis model is used to perform risk assessment on the first operating data and the second operating data to obtain a comprehensive risk value. If the comprehensive risk value is higher than the risk threshold, a secondary identity authentication is performed on the disconnected and reconnected device, otherwise the basic communication mode is switched to the normal communication mode.

[0032] The present invention also discloses an electronic device, comprising: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, wherein the processor executes the computer program to implement any of the methods described above.

[0033] The present invention also discloses a computer storage medium, wherein the computer-readable storage medium stores a computer program, and the computer program is executed by a processor to implement any of the above methods.

[0034] The present invention also discloses a computer program product, which includes computer codes. When the computer codes are executed by a processor of an electronic device, any of the above methods is implemented.

[0035] The beneficial effects of the present invention are at least:

[0036] The solution of the present invention can comprehensively analyze abnormal risks by combining the operating data of the disconnection and reconnection device and its associated computer equipment during the disconnection and reconnection period, and then complete the risk investigation of the disconnection and reconnection device, thereby reducing the risk of abnormal disconnection and reconnection devices posing a security threat to the target server. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0038] Figure 1 It is a flow chart of a monitoring abnormality troubleshooting method disclosed in an embodiment of the present invention;

[0039] Figure 2 It is a structural schematic diagram of a monitoring system disclosed in an embodiment of the present invention. DETAILED DESCRIPTION

[0040] The following is a description of the implementation of the present application by specific specific embodiments. People familiar with the technology can easily understand other advantages and effects of the present application from the contents disclosed in this specification. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without creative work are within the scope of protection of the present application.

[0041] In addition, the technical features involved in the different embodiments of the present application described below can be combined with each other as long as they do not conflict with each other.

[0042] In response to the above technical issues, such as Figure 1 As shown, an embodiment of the present invention discloses a monitoring anomaly troubleshooting method, which is applied to monitoring a cloud, and the method comprises the following steps:

[0043] S101, after the disconnection reconnection device completes an identity authentication, a basic communication mode is set between the disconnection reconnection device and a target server; in the basic communication mode, only uploading and downloading of certain specified types of data are allowed.

[0044] The monitoring cloud can communicate with each connected computer device through the eBPF (Extended Berkeley Packet Filter) technology, so as to receive the communication data of these computer devices, thereby realizing the status monitoring of large-scale computer devices. For example, the computer devices are multiple financial transaction computers in the financial transaction system, which are distributed in various securities business departments, bank branches and financial data centers; the monitoring cloud is used to monitor the operating status of the computer devices and manage the communication connection between them and the target server.

[0045] The monitored computer device will lose communication connection with the monitoring cloud due to communication failure and other reasons. The disconnected computer device will try to re-establish connection with the monitoring cloud by restarting the whole machine, restarting the communication module, etc. At this time, the computer device is a disconnected reconnecting device. The disconnected reconnecting device needs to first send identity data (including key information such as device number, affiliated organization code, digital certificate, etc.) to the monitoring cloud for verification by the monitoring cloud. Considering that the device may face security risks during disconnection, the monitoring cloud will not immediately restore all its communication functions. After verification, the monitoring cloud will first limit its communication with the target server to the basic communication mode, that is, only data that meets the specified type (device identity data, current basic operating status data, such as CPU temperature, remaining available memory space, etc., these data do not involve sensitive transaction information) is allowed to be uploaded and downloaded, to prevent devices that may be at risk from large-scale data interaction without sufficient investigation, and avoid security threats to computer systems.

[0046] S102, obtaining first operation data of the disconnection and reconnection device during the disconnection and reconnection period, and obtaining second operation data of a plurality of associated computer devices having a preset association relationship with the disconnection and reconnection device during the disconnection and reconnection period.

[0047] The monitoring cloud further obtains the first operating data of the disconnection and reconnection device during the disconnection and reconnection period. The disconnection and reconnection period refers to the period from a certain moment before the disconnection moment (for example, 10 seconds before the disconnection) to the moment of reconnection. Still taking the trading computer of the above-mentioned securities business department as an example, the monitoring cloud obtains detailed log records of its trading software during the disconnection period through the secure communication channel pre-established with the trading computer. Screen these logs to see if there are any abnormal login attempts, such as using the wrong password to log in to different trading accounts multiple times in a short period of time, or whether there are unauthorized programs trying to modify the default parameters of trading orders, such as trading price limits, trading quantity limits, etc.

[0048] At the same time, the monitoring cloud will also obtain the second operation data of several associated computer devices that have a preset association relationship (pre-designated manually) with the disconnection and reconnection device in the same time period. The associated computer device here can be an auxiliary device used to support the transaction computer, such as a data storage server, a monitoring and early warning server, an associated business exchange server, etc., or a computer or server of other financial systems (such as a banking system) that have business dealings with the transaction computer. Whether there are abnormalities in the operation data of these associated computer devices in the same period can be used to assist in analyzing whether there are abnormalities in the disconnection and reconnection behavior of the transaction computer.

[0049] S103, using the risk analysis model to perform risk assessment on the first operating data and the second operating data to obtain a comprehensive risk value. If the comprehensive risk value is higher than the risk threshold, a secondary identity authentication is performed on the disconnected and reconnected device, otherwise the basic communication mode is switched to the normal communication mode.

[0050] After successfully acquiring the first operating data of the disconnected and reconnected device and the second operating data of the associated device, the monitoring cloud enables a pre-trained risk analysis model to perform in-depth analysis and risk assessment on these data.

[0051] For example, based on past security incidents and risk assessment experience, the risk threshold is pre-set to 75 points. When the calculated comprehensive risk value is 85 points, which is significantly higher than the risk threshold, the monitoring cloud will immediately trigger the secondary identity authentication process. This includes but is not limited to requiring the staff of the securities business department to scan the dynamic QR code displayed on the device through the mobile authentication APP exclusive to the financial system, enter a randomly generated one-time password, and combine biometric technology such as fingerprint recognition or facial recognition to perform multiple identity authentication. Through this strict secondary identity authentication method, the legitimacy of the device and the true identity of the operator are further confirmed, thereby effectively preventing illegal devices or malicious personnel from exploiting vulnerabilities during device disconnection to conduct financial transactions.

[0052] If the calculated comprehensive risk value is 65 points, which is lower than the risk threshold, the monitoring cloud will determine that the disconnected and reconnected device did not have any abnormal situation that was sufficient to threaten the security of financial transactions during the disconnection and reconnection period. At this time, the monitoring cloud will smoothly switch the basic communication mode between the device and the monitoring cloud to the normal communication mode. The trading computer of the securities business department can then resume normal financial trading operations, such as receiving stock market data in real time, placing stock buying and selling orders for customers, executing fund transfers and other complex and high-frequency financial trading businesses, ensuring the efficient and smooth development of financial trading businesses.

[0053] The solution of the present invention can comprehensively analyze abnormal risks by combining the operating data of the disconnection and reconnection device and its associated computer equipment during the disconnection and reconnection period, and then complete the risk investigation of the disconnection and reconnection device, thereby reducing the risk of abnormal disconnection and reconnection devices posing a security threat to the target server.

[0054] It should be noted that the above scheme of the present invention is not only used in financial transaction systems, but also in industrial control systems, intelligent transportation systems, medical information systems, etc. These systems have a variety of computer devices (such as order data import computers, signal control machines, doctor terminals, etc.), which need to communicate with the corresponding target server under the supervision of the monitoring cloud. In addition, the aforementioned risk analysis model is also pre-trained using the actual operating data in the corresponding application system, and can be constructed using, for example, Transformer, general large models (such as the GPT series), etc., and will not be described in detail.

[0055] Optionally, the obtaining first operation data of the disconnection and reconnection device during the disconnection and reconnection period includes:

[0056] Obtaining historical disconnection records of the disconnection reconnection device, counting the number of types of disconnection reasons in the historical disconnection records, and obtaining a first dynamic adjustment coefficient according to the number of types;

[0057] Using the first dynamic adjustment coefficient, a standard acquisition duration corresponding to the device type to which the disconnection reconnection device belongs is adjusted to obtain a target acquisition duration;

[0058] The first operation data of the disconnection and reconnection device during the disconnection and reconnection period is obtained based on the disconnection time; the duration of the disconnection and reconnection period is the target acquisition duration.

[0059] In this embodiment, the operation data of the disconnection and reconnection device within a period of time before the disconnection can be used to reflect whether there is an abnormality. For example, if the disconnection and reconnection device has obvious characteristics of data transmission failure before the disconnection, it means that the area where the disconnection and reconnection device is located may have problems such as electromagnetic interference and line failure, resulting in unstable data transmission. If the disconnection and reconnection device is operating normally before the disconnection, the disconnection and reconnection device may suddenly encounter an abnormal situation, and its risk value is higher. In addition, the "abnormality" of the present invention can also include abnormalities in business content, which will be described in detail later.

[0060] The acquisition duration of the first operation data is based on the disconnection time, upward to the reconnection time, downward (i.e., historical direction) to the preset time, and the period between the reconnection time and the preset time is the above acquisition duration. Specifically:

[0061] First, obtain the historical disconnection records of the disconnection and reconnection device, which includes multiple disconnection records of the disconnection and reconnection device, and each disconnection record also includes the corresponding disconnection cause, such as line aging, electromagnetic interference, software failure, etc. When the diversity of the fault causes is higher, it is necessary to obtain more operating data before the disconnection, so that the risk analysis model can accurately analyze whether the disconnection and reconnection device is still disconnected due to conventional reasons, or whether it is disconnected due to unconventional abnormal reasons (such as intentional unplugging by an intruder); otherwise, it is only necessary to obtain less operating data before the disconnection within a shorter time. Then, first count the number of types of various disconnection reasons (that is, how many types of disconnection reasons there are in total), and then match the number of types to obtain the first dynamic adjustment coefficient, and the first dynamic adjustment coefficient is positively correlated with the number of types.

[0062] Different computer devices are grouped in advance, and each computer device corresponds to a device type, such as transaction devices and data management devices. Different device types correspond to different standard acquisition durations (such as 5s and 10s). Then, the first dynamic adjustment coefficient (such as 1.2 and 1.5) is used to adjust the standard acquisition duration corresponding to the device type to which the disconnection and reconnection device belongs to obtain the target acquisition duration. The adjustment method is, for example, multiplying the first dynamic adjustment coefficient by the standard acquisition duration.

[0063] Finally, the first operation data of the disconnection and reconnection device during the disconnection and reconnection period is obtained based on the target acquisition time.

[0064] It should be noted that the disconnection and reconnection period corresponding to the second operation data of the associated computer device is the same as that of the disconnection and reconnection device, that is, the operation data of the disconnection and reconnection device and the associated computer device during the same disconnection and reconnection period are obtained simultaneously.

[0065] Optionally, the using a risk analysis model to perform risk assessment on the first operating data and the second operating data to obtain a comprehensive risk value includes:

[0066] Using a risk analysis model to perform risk assessment on the business data in the first operation data and the second operation data to obtain a business risk value;

[0067] If the business risk value is higher than the business risk threshold, setting the comprehensive risk value to a preset value;

[0068] If the business risk value is not higher than the business risk threshold, then: extract the first disconnection operation data of the disconnection and reconnection device from the first operation data, extract the second disconnection operation data of the associated computer device from the second operation data, and perform risk assessment on the first disconnection operation data and the second disconnection operation data according to preset logical rules to obtain a comprehensive risk value.

[0069] In this embodiment, the first operation data and the second operation data obtained above include both the business data and disconnection operation data of each computer device. Among them, the business data refers to a specific type of data processing business undertaken by the computer device, such as securities trading data (trading time, transaction amount, transaction object, transaction type, etc.), account login data (such as multiple login password errors, multiple changes to other login accounts), etc. The risk analysis model is used to analyze whether there are abnormal business contents in these business data, so as to obtain the corresponding business risk value. Among them, the risk analysis model is implemented by using actual business risk data for training, so as to identify whether the current business data has a specified type of business risk, and to evaluate the specific business risk value.

[0070] The disconnection operation data mainly includes the disconnection time, the disconnection reconnection time, etc. Since the disconnection reconnection device has an association relationship with the associated computer device, this association relationship is reflected in the standard operation rules. The normal disconnection reconnection operation of the disconnection reconnection device needs to rely on the assistance and cooperation of other associated computer devices to be realized. Based on this standard operation rule, the above-mentioned logical rules are formed. Therefore, the present invention also performs risk assessment on the first disconnection operation data and the second disconnection operation data according to the preset logical rules to obtain a comprehensive risk value.

[0071] It should be noted that the above preset value is a fixed value, which is higher than the risk threshold. When the comprehensive risk value is the preset value, it is determined that the disconnection and reconnection device has a business anomaly. At this time, the disconnection and reconnection behavior of the disconnection and reconnection device can be directly determined as abnormal behavior, and secondary identity verification is required.

[0072] Optionally, extracting first disconnection operation data of a disconnection reconnection device from the first operation data, extracting second disconnection operation data of an associated computer device from the second operation data, and performing risk assessment on the first disconnection operation data and the second disconnection operation data according to a preset logical rule to obtain a comprehensive risk value includes:

[0073] Extracting a first disconnection moment and a first disconnection reconnection moment of the disconnection reconnection device from the first operation data, and calculating a first reconnection waiting time according to the first disconnection moment and the first disconnection reconnection moment; determining the first disconnection moment and the first reconnection waiting time as the first disconnection operation data;

[0074] Extracting a second disconnection time and a second disconnection reconnection time of the associated computer device from the second operation data, calculating a second reconnection waiting time according to the second disconnection time and the second disconnection reconnection time; determining the second disconnection time and the second reconnection waiting time as the second disconnection operation data;

[0075] Determine the disconnection order between the disconnection reconnection device and each associated computer device according to the first disconnection time and each of the second disconnection times;

[0076] Determine the overall matching degree between the disconnection sequence and the standard disconnection sequence, and obtain a first risk value according to the overall matching degree; wherein the standard disconnection sequence corresponds to a disconnection reconnection device;

[0077] Compare the first reconnection waiting time and each of the second reconnection waiting time with the corresponding standard reconnection waiting time for deviation, and determine a second risk value according to the deviation comparison result;

[0078] The first risk value and the second risk value are combined to obtain the comprehensive risk value.

[0079] In this embodiment, as mentioned above, the disconnection operation data of each computer device mainly includes the disconnection time and the disconnection reconnection time, based on which the reconnection waiting time of the disconnection reconnection device and the associated computer device can be calculated respectively, that is, how long these devices wait after the disconnection before reconnecting to the monitoring cloud.

[0080] In view of the business association relationship and data security factors between various computer devices, when a computer device needs to be disconnected and reconnected due to communication anomalies, it cannot directly perform operations such as restarting, but should coordinate with other related computer devices in accordance with a predetermined standard disconnection order. Each computer device, including the disconnection and reconnection device, disconnects the communication connection with the monitoring cloud in turn according to the standard disconnection order (for example, by restarting the entire machine or restarting the communication module or disconnecting and reconnecting the communication through software operation). In addition, in order to ensure the standardization of transactions and data security, this standard disconnection order is generally encouraged for staff to refer to and execute, but it does not have to be strictly enforced. In fact, some orders in the standard disconnection order can be executed without reference. The present invention analyzes the first risk value of the reconnection behavior of the disconnection and reconnection device by analyzing the overall matching degree between the disconnection order of these computer devices and the standard disconnection and reconnection order. The first risk value is negatively correlated with the overall matching degree. For example, when it is found that only the disconnection and reconnection device has been disconnected from the monitoring cloud, while other related computer devices have not been disconnected from the monitoring cloud, it is determined that the disconnection and reconnection device has a greater risk. For example, an illegal person directly unplugs the disconnection and reconnection device from the connection interface with the monitoring cloud; and when the disconnection order of all key computer devices conforms to the standard disconnection order, it is determined that the disconnection and reconnection device has a smaller risk.

[0081] At the same time, in addition to the disconnection order, considering that restarting, disconnecting and reconnecting operations all require time, the reconnection waiting time of different computer devices is generally regular. Therefore, the present invention further compares the deviation of the reconnection waiting time of each computer device involved with the corresponding standard reconnection waiting time, and then analyzes the second risk value of the reconnection behavior of the disconnected and reconnected device. For example, the above-mentioned deviation of each computer device involved is calculated, and the average value or median value of these deviations is calculated, and the second risk value is obtained based on the median value and the preset control data. Among them, the standard reconnection waiting time is obtained by statistically analyzing multiple groups of disconnection moments and first reconnection moments of the corresponding computer devices. For example, the standard reconnection waiting time for a disconnected and reconnected device is 10 seconds, but the monitoring cloud found that the reconnection waiting time for the disconnected and reconnected device this time was only 5 seconds, which indicates that the disconnected and reconnected device may be another computer device that is ready for communication connection. For example, this computer device is a counterfeit device equipped with a trusted digital certificate (obtained through illegal means), and the intruder quickly unplugs the original computer device and inserts the counterfeit other computer device. At this time, it is determined that the disconnected and reconnected device has a greater risk.

[0082] Finally, the first risk value and the second risk value obtained above are merged (for example, summed up or maximized) to obtain a comprehensive risk value.

[0083] Optionally, the fusing the first risk value and the second risk value to obtain the comprehensive risk value includes:

[0084] Merging the first risk value and the second risk value to obtain a preliminary comprehensive risk value;

[0085] Retrieving a second dynamic adjustment coefficient of the disconnection and reconnection device, and using the second dynamic adjustment coefficient to adjust the preliminary comprehensive risk value to obtain the comprehensive risk value;

[0086] The second dynamic adjustment coefficient is obtained according to the historical execution degree of the standard disconnection sequence.

[0087] In this embodiment, as mentioned above, although the standard disconnection order is beneficial for transaction standardization, data security, etc., it is not necessary to strictly implement all of them. In actual operation, relevant personnel may only execute some of the key orders, and may not execute some non-key orders. Taking this actual situation into consideration, the present invention further obtains the historical execution degree of the corresponding standard disconnection order based on the actual operation records of relevant personnel. The higher the historical execution degree, the higher the proportion of the standard disconnection order being strictly implemented, and vice versa. The historical execution degree can be the proportion of the standard disconnection order being strictly implemented, or the ratio of each node in the standard disconnection order involved in the most adopted disconnection order to all nodes in the standard disconnection order. For example, the standard disconnection order involves 8 nodes, and the most adopted disconnection order involves 6 of them, then the historical execution degree is 75%.

[0088] Therefore, the present invention obtains the corresponding second dynamic adjustment coefficient based on the historical execution degree matching, and uses the second dynamic adjustment coefficient to appropriately correct the preliminary comprehensive risk value obtained above, so as to obtain the final comprehensive risk value. This can reduce unnecessary secondary identity authentication and improve user experience. Among them, the second dynamic adjustment coefficient is positively correlated with the historical execution degree, and the sensitivity of risk analysis can be adjusted by the second dynamic adjustment coefficient.

[0089] like Figure 2 As shown, an embodiment of the present invention further discloses a monitoring system, which is applied to monitoring a cloud. The system includes a processing device and a storage device. The computer code stored in the storage device is called and executed by the processing device to implement the following steps:

[0090] After the disconnected reconnecting device completes an identity authentication, a basic communication mode is set between the disconnected reconnecting device and the target server; in the basic communication mode, only uploading and downloading of certain specified types of data are allowed;

[0091] Acquiring first operation data of the disconnection and reconnection device during the disconnection and reconnection period, and acquiring second operation data of a plurality of associated computer devices having a preset association relationship with the disconnection and reconnection device during the disconnection and reconnection period;

[0092] A risk analysis model is used to perform risk assessment on the first operating data and the second operating data to obtain a comprehensive risk value. If the comprehensive risk value is higher than the risk threshold, a secondary identity authentication is performed on the disconnected and reconnected device, otherwise the basic communication mode is switched to the normal communication mode.

[0093] The monitoring system of the present invention may be embedded in a monitoring cloud, or may be located outside the monitoring cloud but may be called by the monitoring cloud.

[0094] An embodiment of the present invention further discloses an electronic device, comprising: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, wherein the processor executes the computer program to implement the method described in the above embodiment.

[0095] An embodiment of the present invention further discloses a computer storage medium, wherein the computer storage medium stores a computer program, and the computer program is executed by a processor to implement the method described in the above embodiment.

[0096] An embodiment of the present invention further discloses a computer program product, which includes computer code. When the computer code is executed by a processor of an electronic device, the method described in the above embodiment is implemented.

[0097] The computer-readable storage medium described above may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the above. Alternatively, the computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media may include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above.

[0098] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.

[0099] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A monitoring anomaly troubleshooting method, applied to monitoring cloud, characterized in that: The method comprises the following steps: After the disconnected reconnecting device completes an identity authentication, a basic communication mode is set between the disconnected reconnecting device and the target server; in the basic communication mode, only uploading and downloading of certain specified types of data are allowed; Acquiring first operation data of the disconnection and reconnection device during the disconnection and reconnection period, and acquiring second operation data of a plurality of associated computer devices having a preset association relationship with the disconnection and reconnection device during the disconnection and reconnection period; A risk analysis model is used to perform risk assessment on the first operating data and the second operating data to obtain a comprehensive risk value. If the comprehensive risk value is higher than the risk threshold, a secondary identity authentication is performed on the disconnected and reconnected device, otherwise the basic communication mode is switched to the normal communication mode.

2. A monitoring anomaly troubleshooting method according to claim 1, characterized in that: The obtaining of first operation data of the disconnection and reconnection device during the disconnection and reconnection period includes: Obtaining historical disconnection records of the disconnection reconnection device, counting the number of types of disconnection reasons in the historical disconnection records, and obtaining a first dynamic adjustment coefficient according to the number of types; Using the first dynamic adjustment coefficient, a standard acquisition duration corresponding to the device type to which the disconnection reconnection device belongs is adjusted to obtain a target acquisition duration; The first operation data of the disconnection and reconnection device during the disconnection and reconnection period is obtained based on the disconnection time; the duration of the disconnection and reconnection period is the target acquisition duration.

3. A monitoring anomaly troubleshooting method according to claim 1, characterized in that: The using the risk analysis model to perform risk assessment on the first operation data and the second operation data to obtain a comprehensive risk value includes: Using a risk analysis model to perform risk assessment on the business data in the first operation data and the second operation data to obtain a business risk value; If the business risk value is higher than the business risk threshold, setting the comprehensive risk value to a preset value; If the business risk value is not higher than the business risk threshold, then: extract the first disconnection operation data of the disconnection and reconnection device from the first operation data, extract the second disconnection operation data of the associated computer device from the second operation data, and perform risk assessment on the first disconnection operation data and the second disconnection operation data according to preset logical rules to obtain a comprehensive risk value.

4. A monitoring anomaly troubleshooting method according to claim 3, characterized in that: Extracting first disconnection operation data of the disconnection reconnection device from the first operation data, extracting second disconnection operation data of the associated computer device from the second operation data, and performing risk assessment on the first disconnection operation data and the second disconnection operation data according to a preset logical rule to obtain a comprehensive risk value, including: Extracting a first disconnection moment and a first disconnection reconnection moment of the disconnection reconnection device from the first operation data, and calculating a first reconnection waiting time according to the first disconnection moment and the first disconnection reconnection moment; determining the first disconnection moment and the first reconnection waiting time as the first disconnection operation data; Extracting a second disconnection time and a second disconnection reconnection time of the associated computer device from the second operation data, calculating a second reconnection waiting time according to the second disconnection time and the second disconnection reconnection time; determining the second disconnection time and the second reconnection waiting time as the second disconnection operation data; Determine the disconnection order between the disconnection reconnection device and each associated computer device according to the first disconnection time and each of the second disconnection times; Determine the overall matching degree between the disconnection sequence and the standard disconnection sequence, and obtain a first risk value according to the overall matching degree; wherein the standard disconnection sequence corresponds to a disconnection reconnection device; Compare the first reconnection waiting time and each of the second reconnection waiting time with the corresponding standard reconnection waiting time for deviation, and determine a second risk value according to the deviation comparison result; The first risk value and the second risk value are combined to obtain the comprehensive risk value.

5. A monitoring anomaly troubleshooting method according to claim 4, characterized in that: The fusing the first risk value and the second risk value to obtain the comprehensive risk value includes: Merging the first risk value and the second risk value to obtain a preliminary comprehensive risk value; Retrieving a second dynamic adjustment coefficient of the disconnection and reconnection device, and using the second dynamic adjustment coefficient to adjust the preliminary comprehensive risk value to obtain the comprehensive risk value; The second dynamic adjustment coefficient is obtained according to the historical execution degree of the standard disconnection sequence.

6. A monitoring system, applied to monitoring the cloud, comprising a processing device and a storage device, characterized in that: The computer code stored in the storage device is called and executed by the processing device to implement the following steps: After the disconnected reconnecting device completes an identity authentication, a basic communication mode is set between the disconnected reconnecting device and the target server; in the basic communication mode, only uploading and downloading of certain specified types of data are allowed; Acquiring first operation data of the disconnection and reconnection device during the disconnection and reconnection period, and acquiring second operation data of a plurality of associated computer devices having a preset association relationship with the disconnection and reconnection device during the disconnection and reconnection period; A risk analysis model is used to perform risk assessment on the first operating data and the second operating data to obtain a comprehensive risk value. If the comprehensive risk value is higher than the risk threshold, a secondary identity authentication is performed on the disconnected and reconnected device, otherwise the basic communication mode is switched to the normal communication mode.

7. A monitoring system according to claim 6, characterized in that: The obtaining of first operation data of the disconnection and reconnection device during the disconnection and reconnection period includes: Obtaining historical disconnection records of the disconnection reconnection device, counting the number of types of disconnection reasons in the historical disconnection records, and obtaining a first dynamic adjustment coefficient according to the number of types; Using the first dynamic adjustment coefficient, a standard acquisition duration corresponding to the device type to which the disconnection reconnection device belongs is adjusted to obtain a target acquisition duration; The first operation data of the disconnection and reconnection device during the disconnection and reconnection period is obtained based on the disconnection time; the duration of the disconnection and reconnection period is the target acquisition duration.

8. An electronic device comprising: At least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, wherein the processor executes the computer program to implement the method according to any one of claims 1 to 5.

9. A computer storage medium storing a computer program, characterized in that: The computer program is executed by a processor to implement the method according to any one of claims 1 to 5.

10. A computer program product, characterized in that: The computer program product includes computer codes, and when the computer codes are executed by a processor of an electronic device, the method according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • PROTECTION DEVICE AND METHOD FOR ELECTRICAL AND / OR ELECTRONIC APPLIANCES AGAINST SHORT-TERM ELECTRICAL SHOCKS

    AR106568A1

  • Data processing method, device, equipment and system for realizing disconnection reconnection

    CN111510492A