A method and system for identifying and warning of computer information anomalies

By monitoring and analyzing cross-layer event timestamp data and process-level behavior metadata in a multi-layer virtualization environment, evaluating the degree of visibility consistency of resource occupation status and the risk of lock competition anomalies, the problem of misjudgment and missed detection in a multi-layer virtualization environment is solved, and higher abnormal detection accuracy and real-time response capabilities are achieved.

CN119847878BActive Publication Date: 2025-06-17GUIZHOU UNIVERSITY OF FINANCE AND ECONOMICS
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510346115.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-06-17
Estimated Expiration
2045-03-24

AI Technical Summary

Technical Problem

In a multi-layer virtualization environment, traditional single-layer anomaly detection methods are prone to misjudgment or missed detection, which affects the stability and security of the computer system.

Method used

By monitoring the cross-layer event timestamp data generated by the host and container side in a multi-layer virtualization environment, the consistency of the timestamp data is evaluated, and the process-level behavior metadata of the hypervisor layer and the container kernel namespace layer are analyzed to evaluate the degree of visibility consistency of resource occupancy status. Based on these evaluation results, the degree of risk of cross-layer visibility misalignment is determined, and the risk of multi-layer lock competition abnormality is evaluated by analyzing the kernel event tracking sequence, and finally comprehensively analyzing and evaluating the cross-layer visibility misalignment alarm level.

Benefits of technology

Accurately capture abnormal phenomena exposed only at specific levels, avoid misjudgment and missed detection, improve the accuracy and real-time response capabilities of abnormal detection, effectively reduce security risks and operation and maintenance costs, and enhance overall information security protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119847878B_ABST
    Figure CN119847878B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for identifying and warning computer information anomalies, specifically related to the field of anomaly identification and warning; by monitoring the cross-layer event timestamp data generated on the host and container sides, the consistency of time records on both sides is evaluated; at the same time, the process-level behavior metadata captured by the hypervisor layer and the container kernel namespace layer is analyzed to evaluate the visibility consistency of the multi-layer resource occupancy status. And determine the degree of cross-layer visibility misalignment risk. When the risk reaches a high-risk level, the multi-layer lock competition anomaly risk is evaluated by analyzing the kernel event trace sequence. Finally, the time record consistency between the host and container sides, the visibility consistency of the multi-layer resource occupancy status, and the multi-layer lock competition anomaly risk are comprehensively analyzed to evaluate the cross-layer visibility misalignment warning level, so as to achieve accurate identification and warning of computer information anomalies and effectively ensure the operation safety and stability of the computer system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of anomaly recognition and early warning, and more specifically, to a method and system for computer information anomaly recognition and early warning. Background Art

[0002] With the rapid popularization of cloud computing and virtualization technologies, enterprise computer systems adopt multi-layer architectures such as nested virtualization, hybrid deployment of containers and virtual machines. However, in such a complex environment, there are obvious differences in data and event collection at different levels (including operating systems, hypervisors, and container kernels), resulting in some abnormal phenomena being presented only in specific views while appearing normal in other levels. This problem of misalignment of multi-layer data visibility makes traditional single-layer anomaly detection methods prone to false positives or missed detections, seriously affecting the stability and security of computer systems.

[0003] To solve the above problems, a technical solution is provided. Summary of the Invention

[0004] To overcome the above-mentioned defects of the prior art, embodiments of the present invention provide a method and system for computer information anomaly recognition and early warning to solve the problems raised in the above background art.

[0005] To achieve the above object, the present invention provides the following technical solutions:

[0006] A method for computer information anomaly recognition and early warning includes the following steps:

[0007] By monitoring the cross-layer event timestamp data generated on the host and container sides in a multi-layer virtualization environment, evaluate the consistency between the timestamp data of the host and the timestamp data of the container side;

[0008] Analyze the process-level behavior metadata captured by the hypervisor layer and the container kernel namespace layer in the multi-layer virtualization environment, and evaluate the visibility consistency degree of the multi-layer resource occupancy status;

[0009] Capture process behavior metadata at the hypervisor layer and extract process resource occupancy characteristics;

[0010] Capture process behavior metadata at the container kernel namespace layer and extract container resource occupancy characteristics;

[0011] Based on the virtual machine and container data, establish a unified feature space and perform feature vector mapping;

[0012] Use the vector space similarity analysis algorithm to calculate the cross-layer resource state difference degree;

[0013] According to the cross-layer resource state difference degree, evaluate the visibility consistency degree of the multi-layer resource occupancy status;

[0014] Determine the cross-layer visibility misalignment risk level based on the consistency between the host's timestamp data and the container-side timestamp data and the degree of visibility consistency of the multi-layer resource occupancy status;

[0015] When the cross-layer visibility misalignment risk level is a high risk, evaluate the multi-layer lock competition anomaly risk by analyzing the kernel event trace sequence;

[0016] Comprehensively analyze the consistency between the host's timestamp data and the container-side timestamp data, the degree of visibility consistency of the multi-layer resource occupancy status, and the multi-layer lock competition anomaly risk to evaluate the cross-layer visibility misalignment alarm level.

[0017] In a preferred embodiment, evaluate the consistency between the host's timestamp data and the container-side timestamp data by monitoring the cross-layer event timestamp data generated on the host and the container side in the multi-layer virtualization environment. Specifically:

[0018] Real-time collect the host key event log timestamp data in the multi-layer virtualization environment;

[0019] Synchronously collect the corresponding timestamp data in the container-side key event log;

[0020] Perform standardization and time synchronization processing on the host and container-side timestamp data;

[0021] Use the cross-correlation algorithm to compare the two-side time series and quantify the timing difference;

[0022] Calculate and output the cross-layer timing consistency deviation index.

[0023] In a preferred embodiment, determine the cross-layer visibility misalignment risk level based on the consistency between the host's timestamp data and the container-side timestamp data and the degree of visibility consistency of the multi-layer resource occupancy status. Specifically:

[0024] When the cross-layer timing consistency deviation index is greater than or equal to the cross-layer timing consistency deviation index threshold and the visibility consistency index is less than the visibility consistency index threshold, determine that the cross-layer visibility misalignment risk level is a high risk; otherwise, determine that the cross-layer visibility misalignment risk level is a low risk.

[0025] In a preferred embodiment, evaluate the multi-layer lock competition anomaly risk by analyzing the kernel event trace sequence. Specifically:

[0026] Synchronously capture the kernel event trace data at the hypervisor layer and the container kernel namespace layer;

[0027] Parse the lock competition log and extract the feature vectors;

[0028] Statistically analyze the mutex lock queuing situation and waiting duration based on a multi-level queue model;

[0029] Train using an improved machine learning algorithm and output a lock competition anomaly index;

[0030] Evaluate the abnormal competition risk of multi-level locks according to the lock competition anomaly index.

[0031] In a preferred embodiment, evaluating the abnormal competition risk of multi-level locks according to the lock competition anomaly index specifically includes:

[0032] Compare the lock competition anomaly index with the lock competition anomaly threshold:

[0033] When the lock competition anomaly index is greater than or equal to the lock competition anomaly threshold, it indicates that the lock competition between the hypervisor layer and the container kernel namespace layer reaches the risk critical point;

[0034] When the lock competition anomaly index is less than the lock competition anomaly threshold, it indicates that the lock competition between the hypervisor layer and the container kernel namespace layer does not reach the risk critical point.

[0035] In a preferred embodiment, comprehensively analyze the consistency of the timestamp data of the host and the container side, the visibility consistency degree of the multi-level resource occupancy status, and the multi-level lock competition anomaly risk in the multi-level virtualization environment to evaluate the cross-layer visibility misalignment alarm level, specifically including:

[0036] Compare the comprehensive score with the preset first alarm threshold and second alarm threshold to determine the risk level of cross-layer visibility misalignment:

[0037] When the comprehensive score is less than the first alarm threshold, the risk level of cross-layer visibility misalignment is normal;

[0038] When the comprehensive score is greater than or equal to the first alarm threshold and less than the second alarm threshold, the risk level of cross-layer visibility misalignment is warning;

[0039] When the comprehensive score is greater than or equal to the second alarm threshold, the risk level of cross-layer visibility misalignment is urgent.

[0040] On the other hand, the present invention provides a computer information anomaly recognition and early warning system, including a consistency evaluation module, a metadata analysis module, a risk level determination module, an abnormal risk assessment module, and an alarm level assessment module;

[0041] The consistency evaluation module evaluates the consistency of the timestamp data of the host and the container side by monitoring the cross-layer event timestamp data generated by the host and the container side in the multi-level virtualization environment;

[0042] The metadata analysis module analyzes the process-level behavior metadata captured by the hypervisor layer and the container kernel namespace layer in the multi-layer virtualization environment, and evaluates the visibility consistency of the multi-layer resource occupancy status;

[0043] The risk level determination module determines the cross-layer visibility misalignment risk level based on the consistency between the timestamp data of the host and the container-side timestamp data and the visibility consistency of the multi-layer resource occupancy status;

[0044] When the cross-layer visibility misalignment risk level is a high risk, the abnormal risk assessment module evaluates the multi-layer lock competition abnormal risk by analyzing the kernel event trace sequence;

[0045] The alarm level assessment module comprehensively analyzes the consistency between the timestamp data of the host and the container-side timestamp data, the visibility consistency of the multi-layer resource occupancy status, and the multi-layer lock competition abnormal risk, and evaluates the cross-layer visibility misalignment alarm level.

[0046] The technical effects and advantages of a computer information anomaly recognition and warning method and system of the present invention:

[0047] By collecting the key event timestamps, process behavior metadata, and kernel event trace data on the host and container sides, respectively evaluating the time record consistency, resource occupancy visibility consistency, and lock competition abnormal risk, and then comprehensively determining the cross-layer visibility misalignment risk and alarm level, it overcomes the limitations of traditional single-layer monitoring technologies in complex scenarios such as nested virtualization and hybrid deployment of containers and virtual machines, can accurately capture abnormal phenomena exposed only at specific levels, avoid misjudgment and missed detection, and improve the accuracy and real-time response ability of anomaly detection. Through data normalization, fuzzy comprehensive and non-linear aggregation algorithms, efficient integration and intelligent evaluation of multi-dimensional indicators are realized, providing strong support for rapid fault location and dynamic resource scheduling, effectively reducing security risks and operation and maintenance costs, and enhancing the overall information security protection ability. Brief Description of the Drawings

[0048] Figure 1 It is a schematic diagram of a computer information anomaly recognition and warning method of the present invention;

[0049] Figure 2 It is a schematic diagram of the structure of a computer information anomaly recognition and warning system of the present invention. Detailed Embodiments

[0050] Next, in combination with the accompanying drawings in the embodiments of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0051] Embodiment 1

[0052] Figure 1 A computer information anomaly recognition and warning method of the present invention is provided, which includes the following steps:

[0053] By monitoring the cross-layer event timestamp data generated on the host and container sides in a multi-layer virtualization environment, evaluate the consistency between the timestamp data of the host and the timestamp data of the container side;

[0054] Analyze the process-level behavior metadata captured by the hypervisor layer and the container kernel namespace layer in the multi-layer virtualization environment, and evaluate the visibility consistency degree of the multi-layer resource occupancy status;

[0055] Based on the consistency between the timestamp data of the host and the timestamp data of the container side and the visibility consistency degree of the multi-layer resource occupancy status, determine the cross-layer visibility misalignment risk degree;

[0056] When the cross-layer visibility misalignment risk degree is a high risk, by analyzing the kernel event trace sequence, evaluate the multi-layer lock competition anomaly risk;

[0057] Comprehensively analyze the consistency between the timestamp data of the host and the timestamp data of the container side, the visibility consistency degree of the multi-layer resource occupancy status, and the multi-layer lock competition anomaly risk, and evaluate the cross-layer visibility misalignment warning level.

[0058] Specifically, by monitoring the cross-layer event timestamp data generated on the host and container sides in a multi-layer virtualization environment, evaluating the consistency between the timestamp data of the host and the timestamp data of the container side includes:

[0059] Collect the host key event log timestamp data in the multi-layer virtualization environment: In the multi-layer virtualization environment, the host is responsible for overall resource scheduling and virtual machine management. The time information of its key events (such as process startup, file operations, network connection establishment, etc.) is very important for the calculator system status. Real-time capture and record the exact time when all key events occur. The collected data is recorded in milliseconds to form a host key event timestamp data sequence, and its expression is

[0060] ; where Represents the set of all key event timestamp data of the host, where the set contains the time points when each key event recorded by the host occurred within a predetermined collection period; Represents the timestamp of the th key event recorded by the host;

[0061] Synchronously collect the corresponding timestamp data in the key event logs on the container side: In a virtualized environment, as an independent running instance inside the host, the container also generates key event logs. To ensure the consistency of cross-layer data, a lightweight log collection agent is deployed inside each container to capture the timestamp data of key events occurring inside the container in real time. Its collection process uses the same time reference as the host to ensure the comparability of the data on both sides for direct comparison. The expression for the timestamp data sequence on the container side is:

[0062] ; where represents the set of all key event timestamp data on the container side, and the set contains the time points of key events recorded by each container instance within the same collection period as the host; represents the th key event timestamp recorded on the container side; represents the total number of key events recorded on the container side within the same collection period as the host.

[0063] Standardize and synchronize the timestamp data between the host and the container side: Due to factors such as hardware differences, clock drift, and acquisition delays between the host and the container side devices, to eliminate the inherent biases between each data source, the collected timestamp data is standardized. First, perform format conversion on the data on each side, uniformly using Greenwich Mean Time or Coordinated Universal Time as the time reference; second, according to the correction data obtained from the Network Time Protocol service, compensate and correct the timestamps on each side, and the correction formula is:

[0064] ; where represents the timestamp recorded by the host when the th key event occurs after correction; represents the timestamp recorded by the host when the th key event occurs, ; represents the compensation value of the host clock, which is calculated by the Network Time Protocol correction on the host.

[0065] ; where represents the timestamp on the container side after correction when the Timestamps recorded at the occurrence of secondary critical events; Indicates the timestamp recorded at the occurrence of the th secondary critical event on the container side, ; Indicates the compensation value of the container side clock, calculated by the container built-in or an external Network Time Protocol agent, and is used to correct the timestamps collected inside the container.

[0066] Through compensation and correction processing, ensure that all collected timestamps on the host and container sides are under a unified time reference, eliminate errors caused by device differences, and provide accurate data for cross-comparison.

[0067] Use the cross-correlation algorithm to compare the time series on both sides and quantify the timing difference: To accurately quantify the timing difference between the timestamp data on the host and container sides, the cross-correlation analysis method is used. By comparing the standardized time series on both sides, the correlation and delay deviation between the host and container sides are obtained, thereby reflecting the cross-layer timing consistency. The expression defining the cross-correlation function is:

[0068] ; where, Indicates the cross-correlation value between the corrected timestamp data sequences on the host and container sides under the given delay condition. The cross-correlation value is used to measure the similarity degree of the data sequences on both sides under the given delay condition. A higher cross-correlation value indicates that the data on both sides is more consistent under the delay ; Indicates the time delay parameter, which is used to offset the data sequence on the container side in the cross-correlation calculation. By adjusting the value, find the delay that makes the time series on the host and container sides most matched; Indicates the index variable in the data sequence, which is used to traverse the corrected timestamp data on the host and container sides. Each corresponds to a data point in the host sequence, and the corresponding data point on the container side is the value at the index ; Indicates the th timestamp on the host side after standardization and time synchronization processing. After compensation and correction, it can reflect the real event occurrence time on the host; Indicates the arithmetic mean of all timestamps on the host side after standardization and time synchronization processing. It is obtained by summing all data on the host and then dividing by to eliminate the mean offset; Indicates the timestamp data on the container side at the index . By delaying the original data in the container side data sequence by The corresponding value after offset Represents the arithmetic mean of all timestamp data after correction on the container side.

[0069] By traversing different delay values , a series of cross-correlation values can be obtained. Finally, select the delay when reaches the maximum value, denoted as , satisfying: ; where represents the optimal delay parameter that makes the cross-correlation function achieve the maximum value. By solving , select the best time offset to reflect the best alignment state between the two data sequences.

[0070] represents the delay deviation of the optimal match between the two time series. Through the cross-correlation analysis method, the systematic difference in cross-layer time records can be accurately quantified.

[0071] Calculate and output the quantization index of the cross-layer timing consistency deviation: After obtaining the optimal delay , construct the cross-layer timing consistency deviation index to reflect the overall consistency in time between the host and container side event records. Define the cross-layer timing consistency deviation index as: ; where represents the cross-layer timing consistency deviation index, which is used to quantify the consistency of time records between the host and the container side; represents the standard deviation of all corrected timestamp data.

[0072] The larger the cross-layer timing consistency deviation index, the greater the systematic difference in the corrected time records between the host and the container side, that is, the worse the alignment degree of the two-side event records, meaning:

[0073] The timing deviation is obvious: The absolute value of the optimal match delay accounts for a large proportion in the overall data fluctuation, reflecting an obvious delay or offset in the comparison of the log times between the host and the container side.

[0074] The data consistency is low: A higher cross-layer timing consistency deviation index value indicates that the cross-layer data is not consistent enough in timing, which may lead to risks of information lag or misjudgment during anomaly detection or warning.

[0075] Specifically, analyze the process-level behavior metadata captured by the hypervisor layer and the container kernel namespace layer in a multi-layer virtualization environment, and evaluate the visibility consistency degree of the multi-layer resource occupancy status, including:

[0076] Capture process behavior metadata at the hypervisor layer and extract process resource occupancy characteristics: In the hypervisor layer, all process-level behavior metadata, including information such as process startup, running, exit, CPU utilization, memory consumption, disk and network I / O, etc., are captured through the built-in monitoring module. Through the preprocessing module, the original monitoring data is converted into a structured resource occupancy feature vector. Define the obtained set of feature vectors as: ; where represents the set of all process resource occupancy feature vectors collected at the hypervisor layer; represents the th process's corresponding resource occupancy feature vector in the hypervisor layer, including various metrics (such as CPU usage rate, memory consumption, I / O operation rate, etc.); represents the number of process behavior metadata successfully captured by the hypervisor layer during the collection period.

[0077] Capture process behavior metadata at the container kernel namespace layer and extract container resource occupancy characteristics: In the container kernel namespace layer, a lightweight monitoring agent is also deployed to monitor the behavior of all running processes within the container. The collected content includes data such as process startup, running status, resource occupancy, etc. After passing through the data parsing module, it is converted into a standardized resource occupancy feature vector. Define the obtained set of feature vectors as: ; where represents the set of all process resource occupancy feature vectors collected at the container kernel namespace layer; represents the th process's corresponding resource occupancy feature vector in the container layer, including similar resource consumption information; represents the total number of process behavior data captured by the container layer during the collection period.

[0078] Establish a unified feature space based on virtual machine and container data and perform feature vector mapping: To achieve consistent comparison of cross-layer data, map the feature vectors collected from the hypervisor layer and the container kernel namespace layer into the same unified feature space. Using a pre-designed feature mapping function, perform non-linear or linear mapping on the data of each layer, so that feature vectors from different sources are comparable within a unified dimensional space. Define the mapping functions as and , then the data of the hypervisor layer after mapping is:

[0079] ; where represents the function for mapping the data of the hypervisor layer; represents the th A hypervisor layer feature vector; indicating the resource occupancy feature vector corresponding to the th process in the container kernel namespace layer.

[0080] The data in the container kernel namespace layer after mapping is: ; where represents a function for mapping the container layer data, and its mapping result is in the same feature space as the features output by the mapping function ; represents the th container kernel namespace layer feature vector obtained after passing through the mapping function ; indicates the th resource occupancy feature vector corresponding to the th process in the container layer.

[0081] The construction of the unified feature space eliminates the differences in dimension and scale of the original data, and at the same time enables similarity analysis to be carried out under the same measurement standard.

[0082] Using the vector space similarity analysis algorithm, calculate the cross-layer resource state difference degree: The two sets of feature vectors after mapping reflect their respective resource occupancy states in the unified feature space. To evaluate the consistency of the data on both sides in terms of overall resource usage, the vector space similarity analysis method is adopted.

[0083] Calculate the centroids (mean vectors) of the two sets of vectors respectively:

[0084] The centroid of the hypervisor layer is ; where represents the mean of all the mapped feature vectors in the hypervisor layer, reflecting the central tendency of the overall resource usage state.

[0085] The centroid of the container kernel namespace layer is ; where represents the mean of all the mapped feature vectors in the container kernel namespace layer.

[0086] Use the Euclidean distance to calculate the distance between the two centroids as a preliminary measure of the cross-layer resource state difference, and define the difference degree as: ; where represents the Euclidean distance between the centroids of the mapped feature vectors of the hypervisor layer and the container kernel namespace layer.

[0087] To reflect the degree of dispersion within the data of each layer, calculate the average dispersion of all the mapped vectors in the unified feature space, that is, define the dispersion degree as: ; Among them, represents the average Euclidean distance between all mapping vectors and their corresponding centroids in the unified feature space, reflecting the discreteness of the data.

[0088] By comparing the distances between the centroids and the overall dispersion , the differences in the resource occupancy status of cross-layer data can be reflected.

[0089] According to the cross-layer resource status difference degree, evaluate the visibility consistency degree of the multi-layer resource occupancy status: Define the visibility consistency index, which is used to evaluate the visibility consistency degree of the multi-layer resource occupancy status, and its calculation formula is: ; Among them, represents the visibility consistency index, and its value range is from 0 to 1.

[0090] The larger the visibility consistency index, the higher the consistency of the resource occupancy data captured in the hypervisor layer and the container kernel namespace layer, indicating that the cross-layer resource status is well-aligned, the computer system runs stably, and there is no obvious deviation in the monitoring data.

[0091] Specifically, based on the consistency of the timestamp data on the host and the timestamp data on the container side and the visibility consistency degree of the multi-layer resource occupancy status, determine the cross-layer visibility misalignment risk degree, including:

[0092] Preset the cross-layer timing consistency deviation index threshold, and compare the cross-layer timing consistency deviation index with the cross-layer timing consistency deviation index threshold:

[0093] When the cross-layer timing consistency deviation index is greater than or equal to the cross-layer timing consistency deviation index threshold, it indicates that the consistency of the time records between the host and the container side is high, meaning that the degree of out-of-sync of the time records between the host and the container side exceeds the critical range; at this time, problems such as misaligned log order and difficult event replay may occur in the computer system, which may further lead to inaccurate anomaly diagnosis or even disorder in distributed component communication;

[0094] When the cross-layer timing consistency deviation index is less than the cross-layer timing consistency deviation index threshold, it indicates that the consistency of the time records between the host and the container side is low, meaning that the difference in the time records between the host and the container side is within the normal range; at this time, the computer system as a whole maintains a high timing accuracy, and anomaly diagnosis and distributed collaboration can proceed normally, and minor timing drifts will not cause serious consequences;

[0095] The setting of the cross-layer timing consistency deviation index threshold is usually based on the statistical analysis results of a series of empirical measurement values obtained from the timestamp data of the host and container sides under the historical normal operating state. Under normal working conditions, by long-term collecting the timestamp data of the corresponding events on the host and container sides, a stable historical deviation distribution is obtained using statistical analysis methods (such as quantile analysis method or robust statistics method), ensuring that the threshold has statistical significance and practical applicability.

[0096] Preset the visibility consistency index, and compare the visibility consistency index with the visibility consistency index threshold:

[0097] When the visibility consistency index is greater than or equal to the visibility consistency index threshold, it indicates that the visibility consistency degree of the multi-layer resource occupancy state is high, that is, the hypervisor layer and the container kernel namespace layer in the multi-layer virtualization environment are highly consistent in terms of the visibility of resource occupancy information; at this time, the monitoring results of the host and container sides for the process-level behavior metadata can corroborate each other, and the overall computer system operation state tends to be stable;

[0098] When the visibility consistency index is less than the visibility consistency index threshold, it indicates that the visibility consistency degree of the multi-layer resource occupancy state is low, meaning that there are obvious differences in the resource occupancy views between the hypervisor layer and the container kernel namespace layer; at this time, there may be alignment imbalances, index chaos, or hidden abnormal process occupancy situations in the cross-layer data, which are likely to lead to deviations in computer system operation and maintenance and problem diagnosis;

[0099] The setting of the visibility consistency index threshold is determined based on the actual operation of the computer system, the resource scheduling strategy, and the statistical results of historical monitoring data. By long-term tracking and experimental analysis of the resource occupancy state data of each layer in the multi-layer virtualization environment, a reasonable threshold range is obtained using statistical methods.

[0100] When the cross-layer timing consistency deviation index is greater than or equal to the cross-layer timing consistency deviation index threshold, and the visibility consistency index is less than the visibility consistency index threshold, it is determined that the risk degree of cross-layer visibility misalignment is high risk; otherwise, it is determined that the risk degree of cross-layer visibility misalignment is low risk.

[0101] Specifically, by analyzing the kernel event trace sequence, evaluate the multi-layer lock competition abnormal risk, including:

[0102] Synchronously capture kernel event trace data at the hypervisor layer and the container kernel namespace layer: Deploy kernel event trace modules at the hypervisor layer and the container kernel namespace layer simultaneously to achieve real-time capture of kernel event data at the hypervisor layer and the container kernel namespace layer. Set: ; ; where, Represents a set of kernel event trace sequences captured in the hypervisor layer. Each element in the set represents a record, which contains information such as event type and lock operation status; Represents the th kernel event record in the hypervisor layer; Represents the total number of kernel event records captured in the hypervisor layer within a predetermined collection period; Represents a set of kernel event trace sequences captured in the container kernel namespace layer; Represents the th kernel event record in the container kernel namespace layer; Represents the total number of kernel event records captured in the container kernel namespace layer within the same predetermined collection period.

[0103] Parse the lock contention log and extract feature vectors: After obtaining the kernel event trace data, process the log information related to lock contention in the records. Extract key features: lock request frequency and lock holding duration. Define a set of feature vectors ; where Represents the set of all lock contention feature vectors parsed from the kernel event records, covering data from both the hypervisor layer and the container kernel namespace layer; Represents the th feature vector, in the form of: , ; where Represents the th feature vector; Represents the lock request frequency corresponding to the th lock event; Represents the lock holding duration corresponding to the th lock event, reflecting the time elapsed from lock application to release; Represents the total number of feature vectors obtained after parsing, reflecting the number of events involving lock contention within a predetermined collection period.

[0104] By parsing the kernel event trace data, accurate lock contention metrics are extracted from the log, providing high-dimensional feature data.

[0105] Statistically analyze the mutex lock queuing situation and waiting duration based on a multi-level queue model: Use a multi-level queue model to statistically analyze lock requests in different priority queues. Define that there are queue levels in the computer system, and each queue records the mutex lock queuing situation and the corresponding waiting duration. Define that for each queue level ( ), there is: Represents the queue level The total waiting duration of all lock requests; Indicates the queue level The total number of lock requests in

[0106] Based on the total number of lock requests at each queue level and the total waiting duration of all lock requests, calculate the average waiting duration for each queue level as ; where Indicates the queue level The average waiting duration of

[0107] Based on the different importance of each queue level, set the weight factor ; where Indicates the weight assigned to the queue level Satisfies the normalization condition and reflects the contribution degree of this level to the overall lock competition risk.

[0108] Combining the statistical results of each queue level, define the overall lock competition queuing waiting index as: ; where Indicates the overall average waiting duration index obtained from the multi-level queue model; Indicates the total number of queue levels.

[0109] Use an improved machine learning algorithm for training and output the lock competition anomaly index: Combine the lock competition feature vector set with the overall lock competition queuing waiting index to form a comprehensive feature vector for machine learning training. Define the combined feature vector as: ; where Indicates the combined and processed comprehensive feature vector; Indicates the dimension of the comprehensive feature vector.

[0110] Introduce an improved machine learning algorithm, defined as ; where Indicates a machine learning model that has been specially designed and optimized, which can be a supervised learning or unsupervised anomaly detection model, and its training goal is to capture the hidden anomaly patterns in the data.

[0111] Use the machine learning model to process the input comprehensive feature vector to obtain the multi-level lock competition anomaly coefficient, and its expression is: ; where Indicates the output lock competition anomaly index.

[0112] Machine learning model Through training on a large amount of historical data, it can map the input comprehensive feature vector to an index reflecting the degree of anomaly risk.

[0113] Evaluate the abnormal competition risk of multi - layer locks according to the lock competition abnormal index: Set the lock competition abnormal threshold, which is determined and calibrated based on historical data and actual business requirements.

[0114] Compare the lock competition abnormal index with the lock competition abnormal threshold to evaluate the abnormal competition risk of multi - layer locks:

[0115] When the lock competition abnormal index is greater than or equal to the lock competition abnormal threshold, it indicates that the lock competition between the hypervisor layer and the container kernel namespace layer reaches the risk critical point; at this time, the queuing and waiting situation of each process when competing for the same resource or mutex lock is serious, which may lead to long - term thread blocking;

[0116] When the lock competition abnormal index is less than the lock competition abnormal threshold, it indicates that the lock competition between the hypervisor layer and the container kernel namespace layer does not reach the risk critical point, the overall operation of the computer system is relatively stable, and the shared resources and mutex locks required by each process can be allocated and released within a reasonable time.

[0117] Specifically, comprehensively analyze the consistency of the timestamp data of the host and the container - side timestamp data, the visibility consistency degree of the multi - layer resource occupancy status, and the multi - layer lock competition abnormal risk to evaluate the cross - layer visibility misalignment alarm level, including:

[0118] Define the cross - layer timing consistency deviation index as , the visibility consistency index as , the lock competition abnormal index as .

[0119] Normalize the cross - layer timing consistency deviation index corresponding to the consistency of the time records of the host and the container - side, the visibility consistency index corresponding to the visibility consistency degree of the multi - layer resource occupancy status, and the lock competition abnormal index corresponding to the multi - layer lock competition abnormal risk respectively. The normalized cross - layer timing consistency deviation index, visibility consistency index, and lock competition abnormal index represent the performance of cross - layer timing consistency, resource occupancy visibility, and multi - layer lock abnormal competition risk on the same numerical scale.

[0120] In order to comprehensively reflect the cross - layer visibility misalignment situation, design fuzzy membership functions for the normalized cross - layer timing consistency deviation index, visibility consistency index, and lock competition abnormal index respectively. Specifically:

[0121] , ; where represents the fuzzy membership of the th index or index; represents the The slope parameter of an index or exponent; Denote the Original value of an index or exponent; Denote the Central parameter or critical value of an index or exponent.

[0122] The normalized value is converted into a fuzzy membership degree through a fuzzy membership function. The geometric mean method is used to non-linearly aggregate each fuzzy membership degree to obtain a comprehensive score ; where Denote the comprehensive score, Denote the fuzzy membership degree of the cross-layer time series consistency deviation index; Denote the fuzzy membership degree of the visibility consistency index; Denote the fuzzy membership degree of the abnormal lock competition of lock competition.

[0123] Compare the comprehensive score with a preset first warning threshold and a second warning threshold to determine the risk level of cross-layer visibility misalignment:

[0124] When the comprehensive score is less than the first warning threshold, the risk level of cross-layer visibility misalignment is normal;

[0125] When the comprehensive score is greater than or equal to the first warning threshold and less than the second warning threshold, the risk level of cross-layer visibility misalignment is warning;

[0126] When the comprehensive score is greater than or equal to the second warning threshold, the risk level of cross-layer visibility misalignment is urgent.

[0127] Embodiment 2

[0128] The difference between Embodiment 2 and Embodiment 1 of the present invention is that this embodiment introduces a computer information anomaly recognition and warning system.

[0129] Figure 2 The structural schematic diagram of a computer information anomaly recognition and warning system of the present invention is given. A computer information anomaly recognition and warning system includes a consistency evaluation module, a metadata analysis module, a risk level determination module, an abnormal risk assessment module, and an alarm level assessment module;

[0130] The consistency evaluation module evaluates the consistency between the timestamp data of the host and the container side by monitoring the cross-layer event timestamp data generated in the multi-layer virtualization environment;

[0131] The metadata analysis module analyzes the process-level behavior metadata captured by the hypervisor layer and the container kernel namespace layer in the multi-layer virtualization environment to evaluate the visibility consistency degree of the multi-layer resource occupancy status;

[0132] The risk level determination module determines the risk level of cross-layer visibility misalignment based on the consistency between the timestamp data of the host and the container side and the visibility consistency degree of the multi-layer resource occupancy status;

[0133] When the risk level of cross-layer visibility misalignment is a high risk, the abnormal risk assessment module evaluates the abnormal risk of multi-layer lock contention by analyzing the kernel event trace sequence;

[0134] The alarm level assessment module comprehensively analyzes the consistency between the timestamp data of the host and the container side, the visibility consistency degree of the multi-layer resource occupancy status, and the abnormal risk of multi-layer lock contention, and evaluates the cross-layer visibility misalignment alarm level.

[0135] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the real situation. The preset parameters and threshold selection in the formulas are set by those skilled in the art according to the actual situation.

[0136] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more collections of available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0137] Those of ordinary skill in the art will appreciate that the modules and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.

[0138] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and modules described above can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0139] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or modules can be in electrical, mechanical, or other forms.

[0140] The modules described as separate components may or may not be physically separated. The components shown as modules may or may not be physical modules. They can be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0141] In addition, the functional modules in each embodiment of this application can be integrated in a processing module, or each module can exist physically alone, or two or more modules can be integrated in one module.

[0142] If the above-mentioned functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0143] As described above, the above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0144] Finally: The above is only the preferred embodiment of the present invention and is not used to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A computer information anomaly identification and early warning method, characterized in that: The steps include: By monitoring the cross-layer event timestamp data generated by the host and container in a multi-layer virtualization environment, the consistency of the timestamp data of the host and the timestamp data of the container can be evaluated. Analyze the process-level behavior metadata captured by the hypervisor layer and the container kernel namespace layer in a multi-layer virtualization environment to evaluate the visibility consistency of resource occupancy status in multiple layers; Capture process behavior metadata at the hypervisor layer and extract process resource usage characteristics; Capture process behavior metadata at the container kernel namespace layer and extract container resource usage characteristics; Establish a unified feature space based on virtual machine and container data to perform feature vector mapping; Use the vector space similarity analysis algorithm to calculate the difference between cross-layer resource states; According to the difference of cross-layer resource status, the visibility consistency of multi-layer resource occupancy status is evaluated: the visibility consistency index is defined, and the calculation formula is: ;in, represents the visibility consistency index; represents the average Euclidean distance between all mapped vectors and the corresponding mean vector; represents the Euclidean distance between the feature vector and the mean vector after mapping between the hypervisor layer and the container kernel namespace layer; Based on the consistency between the timestamp data of the host machine and the timestamp data of the container side and the consistency of the visibility of the multi-layer resource occupancy status, the risk level of cross-layer visibility misalignment is determined; When the risk level of cross-layer visibility misalignment is high, the risk of multi-layer lock contention anomaly is evaluated by analyzing the kernel event tracing sequence: the expression of the lock contention anomaly coefficient is: ;in, Indicates the lock contention anomaly index; It represents the comprehensive feature vector after combining the lock contention feature vector set with the overall lock contention queue waiting index; Represents a specially designed and optimized machine learning model; Comprehensively analyze the consistency of the timestamp data of the host machine and the timestamp data on the container side, the consistency of the visibility of multi-layer resource occupancy status, and the risk of multi-layer lock competition anomalies to evaluate the cross-layer visibility misalignment alarm level.

2. A computer information anomaly identification and early warning method according to claim 1, characterized in that: By monitoring the cross-layer event timestamp data generated by the host and container in a multi-layer virtualization environment, the consistency of the timestamp data of the host and the timestamp data of the container is evaluated. Specifically: Collect host machine key event log timestamp data in real time in a multi-layer virtualization environment; Synchronously collect the corresponding timestamp data in the key event log on the container side; Standardize and synchronize timestamp data on the host and container sides; The cross-correlation algorithm is used to compare the time series on both sides and quantify the time series differences; Calculate and output the cross-layer timing consistency deviation index.

3. A computer information anomaly identification and early warning method according to claim 2, characterized in that: Based on the consistency between the timestamp data of the host and the timestamp data of the container side and the consistency of the visibility of the multi-layer resource occupancy status, the risk level of cross-layer visibility misalignment is determined, specifically: When the cross-layer timing consistency deviation index is greater than or equal to the cross-layer timing consistency deviation index threshold, and the visibility consistency index is less than the visibility consistency index threshold, the cross-layer visibility misalignment risk level is judged to be high risk; otherwise, the cross-layer visibility misalignment risk level is judged to be low risk.

4. A computer information anomaly identification and early warning method according to claim 3, characterized in that: By analyzing the kernel event trace sequence, the risk of multi-layer lock contention anomalies is assessed, specifically: Synchronously capture kernel event trace data at the hypervisor layer and the container kernel namespace layer; Parse lock contention logs and extract feature vectors; Statistics on mutex lock queue status and waiting time based on multi-level queue model; Use the improved machine learning algorithm to train and output the lock contention anomaly index; Evaluate the multi-layer lock abnormal contention risk based on the lock contention abnormality index.

5. A computer information anomaly identification and early warning method according to claim 4, characterized in that: The multi-layer lock abnormal competition risk is evaluated based on the lock competition abnormality index, specifically: Compare the lock contention anomaly index with the lock contention anomaly threshold: When the lock contention anomaly index is greater than or equal to the lock contention anomaly threshold, it indicates that the lock contention between the hypervisor layer and the container kernel namespace layer has reached a risk critical point; When the lock contention anomaly index is less than the lock contention anomaly threshold, it indicates that the lock contention between the hypervisor layer and the container kernel namespace layer has not reached the risk critical point.

6. A computer information anomaly identification and early warning method according to claim 5, characterized in that: Comprehensively analyze the consistency of the timestamp data of the host machine and the timestamp data of the container side, the consistency of the visibility of the multi-layer resource occupancy status, and the risk of multi-layer lock competition anomalies, and evaluate the cross-layer visibility misalignment alarm level, specifically: Compare the comprehensive score with the preset first alarm threshold and second alarm threshold to determine the risk level of cross-layer visibility misalignment: When the comprehensive score is less than the first alarm threshold, the risk level of cross-layer visibility misalignment is normal; When the comprehensive score is greater than or equal to the first warning threshold and less than the second warning threshold, the risk level of cross-layer visibility misalignment is warning; When the comprehensive score is greater than or equal to the second alarm threshold, the risk level of cross-layer visibility misalignment is urgent.

7. A computer information anomaly identification and early warning system, used to implement a computer information anomaly identification and early warning method according to any one of claims 1 to 6, characterized in that: It includes consistency assessment module, metadata analysis module, risk level determination module, abnormal risk assessment module and alarm level assessment module; The consistency assessment module monitors the cross-layer event timestamp data generated by the host and container sides in a multi-layer virtualization environment to assess the consistency of the timestamp data of the host and the timestamp data of the container side. The metadata analysis module analyzes the process-level behavior metadata captured by the hypervisor layer and the container kernel namespace layer in the multi-layer virtualization environment to evaluate the visibility consistency of the multi-layer resource occupancy status: the visibility consistency index is defined and the calculation formula is: ;in, represents the visibility consistency index; represents the average Euclidean distance between all mapped vectors and the corresponding mean vector; represents the Euclidean distance between the feature vector and the mean vector after mapping between the hypervisor layer and the container kernel namespace layer; The risk level determination module determines the risk level of cross-layer visibility misalignment based on the consistency between the timestamp data of the host machine and the timestamp data of the container side and the visibility consistency of the multi-layer resource occupancy status; Abnormal risk assessment module When the risk level of cross-layer visibility misalignment is high, the abnormal risk of multi-layer lock contention is assessed by analyzing the kernel event tracking sequence: the expression of the lock contention abnormality coefficient is: ;in, Indicates the lock contention anomaly index; It represents the comprehensive feature vector after combining the lock contention feature vector set with the overall lock contention queue waiting index; Represents a specially designed and optimized machine learning model; The alarm level assessment module conducts a comprehensive analysis of the consistency between the timestamp data of the host machine and the timestamp data of the container side, the consistency of the visibility of multi-layer resource occupancy status, and the risk of multi-layer lock competition anomalies, and assesses the cross-layer visibility misalignment alarm level.

Citation Information

Patent Citations

  • Method and apparatus for high performance page error handling for multi-tenant scalable accelerators

    CN115686626A

  • Fault analysis method and device, electronic equipment, storage medium and product

    CN119094330A