Alarm data processing method and device and related equipment

By filtering target alarm scenarios that meet preset conditions and dynamically adjusting data storage according to their query duration, the problem of traditional hot and cold data segmentation mismatch is solved, and the efficiency and response speed of alarm data processing are improved.

CN119937924APending Publication Date: 2025-05-06CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411998691.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The traditional hot and cold data slicing method relies on fixed time points, resulting in mismatch between hot and cold data, thereby reducing data processing efficiency.

Method used

By obtaining data from multiple alarm scenarios in the alarm data set, filter out target alarm scenarios that meet preset conditions, and load the relevant data from the cold data buffer area to the hot data buffer area according to its query duration.

Benefits of technology

Dynamically adjusting hot and cold data segmentation improves data processing efficiency, reduces query delays, and optimizes resource utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119937924A_ABST
    Figure CN119937924A_ABST
Patent Text Reader

Abstract

The invention provides an alarm data processing method and device and related equipment, and relates to the technical field of data processing. The method comprises the following steps: acquiring an alarm data set, wherein the alarm data set comprises alarm data of a plurality of alarm scenes; screening out a target alarm scene from the alarm scene data set, the target alarm scene being an alarm scene satisfying a preset condition in a plurality of alarm scenes; obtaining a query duration of the target alarm scene, wherein the query duration of the target alarm scene refers to a time range length covered by alarm data query for the target alarm scene; loading the alarm data of the target alarm scene from the cold data cache region to the hot data cache region based on the query duration of the target alarm scene; wherein the access frequency of the cold data cache region is smaller than that of the hot data cache region. The processing efficiency of the alarm data is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] With the rapid development of modern information technology, timely access to alarm data is crucial to ensuring system security in traffic-based threat detection applications. In order to efficiently manage massive amounts of alarm data, a storage strategy that separates hot and cold data is usually adopted. In related technologies, data is uniformly segmented according to fixed time points. For example, data within 24 hours is defined as hot data, which is stored in fast-access storage media because it may be frequently accessed; data older than 24 hours is considered cold data and is transferred to storage devices with lower costs but slower access speeds.

[0003] However, the traditional hot and cold data segmentation method relies on a fixed time point for unified segmentation. In actual applications, the hot and cold data segmentation time points of different data are often inconsistent. Some information that was originally classified as cold data may be frequently accessed in specific scenarios. This mismatch causes query applications to frequently access cold data partitions, greatly reducing data processing efficiency. Therefore, a technical solution for dynamically adjusting hot and cold data segmentation is needed to improve data processing efficiency.

[0004] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present disclosure, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention

[0005] The present invention provides an alarm data processing method, device and related equipment to improve data processing efficiency.

[0006] Other features and advantages of the present disclosure will become apparent from the following detailed description, or may be learned in part by the practice of the present disclosure.

[0007] According to one aspect of the present disclosure, there is provided an alarm data processing method, the method comprising: obtaining an alarm data set, the alarm data set comprising: alarm data of multiple alarm scenarios; screening out a target alarm scenario from the alarm scenario data set, wherein the target alarm scenario is an alarm scenario that satisfies a preset condition among the multiple alarm scenarios; obtaining a query duration of the target alarm scenario, the query duration of the target alarm scenario refers to the length of a time range covered when performing an alarm data query for the target alarm scenario; based on the query duration of the target alarm scenario, loading the alarm data of the target alarm scenario from a cold data cache area to a hot data cache area; wherein an access frequency of the cold data cache area is less than an access frequency of the hot data cache area.

[0008] In some embodiments, the target alarm scenario corresponds to multiple query durations, and the query duration based on the target alarm scenario is used to load the alarm data of the target alarm scenario from the cold data cache area to the hot data cache area, including: based on the multiple query durations of the target alarm scenario, using Gaussian filtering to filter out query durations that meet preset conditions from the multiple query durations of the target alarm scenario; based on the query duration that meets the preset conditions, loading the alarm data of the target alarm scenario from the cold data cache area to the hot data cache area.

[0009] In some embodiments, the multiple query durations based on the target alarm scenario use Gaussian filtering to filter out the query duration that meets preset conditions from the multiple query durations of the target alarm scenario, including: based on the multiple query durations of the target alarm scenario, calculating the mean and standard deviation corresponding to the Gaussian distribution of the multiple query durations of the target alarm scenario; determining the query duration that meets the preset conditions according to the mean and standard deviation corresponding to the Gaussian distribution.

[0010] In some embodiments, after obtaining the query duration of the target alarm scenario, the method also includes: obtaining an update period of a hot data cache area; updating the query duration of the target alarm scenario according to the update period of the hot data cache area and the query duration of the target alarm scenario; loading the alarm data of the target alarm scenario from the cold data cache area to the hot data cache area includes: based on the updated query duration of the target alarm scenario, loading the alarm data of the target alarm scenario from the cold data cache area to the hot data cache area.

[0011] In some embodiments, before the alarm data of the target alarm scenario is loaded from the cold data cache area to the hot data cache area based on the query duration of the updated target alarm scenario, the method further includes: obtaining the current update time of the hot data cache area and the previous update time of the current update time; determining the time range of the alarm data to be removed in the hot data cache area according to the previous update time of the current update time, the query duration of the target alarm scenario and the query duration of the updated target alarm scenario; moving the alarm data to be removed from the hot data cache area to the cold data cache area based on the time range of the alarm data to be removed; wherein, loading the alarm data of the target alarm scenario from the cold data cache area to the hot data cache area based on the query duration of the updated target alarm scenario includes: determining the time range of the alarm data to be preheated in the cold data cache area according to the current update time and the query duration of the updated target alarm scenario; and loading the alarm data to be preheated from the cold data cache area to the hot data cache area based on the time range of the alarm data to be preheated.

[0012] In some embodiments, the target alarm scenario includes multiple query parameters. After obtaining the query duration of the target alarm scenario, the method also includes: splicing the query parameter information of the multiple query parameters of the target alarm scenario to obtain the query string of the target alarm scenario; performing a hash operation on the query string of the target alarm scenario to obtain a hash value corresponding to the query string of the target alarm scenario; and constructing a hash table based on the hash value corresponding to the query string of the target alarm scenario and the query duration of the target alarm scenario.

[0013] In some embodiments, the method also includes: obtaining a query request; the query request includes a hash value corresponding to the query string of the alarm scene to be queried and an actual query duration; matching the hash value corresponding to the query string of the alarm scene to be queried with the hash table; when the hash value corresponding to the query string of the alarm scene to be queried matches the hash value in the hash table, determining the query duration of the alarm scene to be queried from the hash table; when the actual query duration is less than the query duration of the alarm scene to be queried, obtaining the alarm data of the alarm scene to be queried from the hot data cache area.

[0014] According to another aspect of the present disclosure, an alarm data processing device is also provided, the device comprising: a first acquisition module, used to acquire an alarm data set, the alarm data set comprising: alarm data of multiple alarm scenarios; a screening module, used to screen out a target alarm scenario from the alarm scenario data set, wherein the target alarm scenario is an alarm scenario that meets preset conditions among the multiple alarm scenarios; a second acquisition module, used to acquire a query duration of the target alarm scenario, the query duration of the target alarm scenario refers to the length of a time range covered when an alarm data query is performed for the target alarm scenario; a loading module, used to load the alarm data of the target alarm scenario from a cold data cache area to a hot data cache area based on the query duration of the target alarm scenario; wherein the access frequency of the cold data cache area is less than the access frequency of the hot data cache area.

[0015] According to another aspect of the present disclosure, an electronic device is also provided, which includes: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any one of the above-mentioned alarm data processing methods by executing the executable instructions.

[0016] According to another aspect of the present disclosure, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the alarm data processing method described in any one of the above is implemented.

[0017] According to another aspect of the present disclosure, a computer program product is further provided, including: a computer program or instructions, wherein when the computer program or instructions are executed by a processor, any one of the above-mentioned alarm data processing methods is implemented.

[0018] An alarm data processing method, device and related equipment provided in the embodiments of the present disclosure obtain an alarm data set, wherein the alarm data set includes: alarm data of multiple alarm scenarios; filter out a target alarm scenario from the alarm scenario data set, wherein the target alarm scenario is an alarm scenario that meets preset conditions among multiple alarm scenarios; obtain the query duration of the target alarm scenario, wherein the query duration of the target alarm scenario refers to the length of the time range covered when querying alarm data for the target alarm scenario; based on the query duration of the target alarm scenario, load the alarm data of the target alarm scenario from a cold data cache area to a hot data cache area; wherein the access frequency of the cold data cache area is less than the access frequency of the hot data cache area. The present disclosure solves the problems of low query efficiency and slow response speed caused by mismatch of cold and hot data segmentation by filtering the target alarm scenarios that meet preset conditions, and dynamically loads the relevant alarm data from the cold data cache area with a lower access frequency to the hot data cache area with a higher access frequency according to the query duration of the target alarm scenario, thereby improving the processing efficiency of the alarm data.

[0019] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the specification are used to explain the principles of the present disclosure. Obviously, the accompanying drawings described below are only some embodiments of the present disclosure, and for ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without creative work.

[0021] Figure 1 A specific flow chart of implementing alarm data preheating in a prior art in an embodiment of the present disclosure is shown;

[0022] Figure 2 A schematic diagram showing the system architecture of an alarm data processing method according to an embodiment of the present disclosure;

[0023] Figure 3A A method flow chart showing a method for processing alarm data in an embodiment of the present disclosure is shown;

[0024] Figure 3B A flowchart showing a specific implementation of an alarm data processing method in an embodiment of the present disclosure is shown;

[0025] Figure 4A method flow chart showing a method for processing alarm data in an embodiment of the present disclosure is shown;

[0026] Figure 5 A flow chart of a method for screening query duration in an embodiment of the present disclosure is shown;

[0027] Figure 6 A flow chart of a method for updating the query duration of a target alarm scenario in an embodiment of the present disclosure is shown;

[0028] Figure 7 A flow chart of a method for updating thermal data in an embodiment of the present disclosure is shown;

[0029] Figure 8 A schematic diagram of a data queue corresponding to a scenario si in an embodiment of the present disclosure is shown;

[0030] Fig. 9 A method flow chart showing a method for processing alarm data in an embodiment of the present disclosure is shown;

[0031] Fig. 10A A method flow chart of an alarm data processing method in an embodiment of the present disclosure;

[0032] Fig. 10B A flowchart showing a specific implementation of an alarm data processing method in an embodiment of the present disclosure is shown;

[0033] Fig.11 A schematic diagram of an alarm data processing device in an embodiment of the present disclosure is shown;

[0034] Fig.12 A structural block diagram of an electronic device in an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0035] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that the disclosure will be more comprehensive and complete and to fully convey the concepts of the example embodiments to those skilled in the art. The described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.

[0036] In addition, the accompanying drawings are only schematic illustrations of the present disclosure and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and their repeated description will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.

[0037] Figure 1 A specific flow chart of implementing alarm data preheating in the prior art provided by an embodiment of the present disclosure is shown. Figure 1 As shown, the alarm data preheating method provided in the prior art of the embodiment of the present disclosure may include:

[0038] In the traditional hot and cold data segmentation method, data first enters the threat detection system through network traffic. The system is responsible for monitoring network activities and identifying potential security threats. Once a threat is detected, the relevant data will be saved as alarm data.

[0039] Alarm data is divided into hot data and cold data according to the preset time range. Hot data usually refers to frequently accessed or important data in the recent period, while cold data refers to data with low access frequency or long history. However, this segmentation method is often based on a fixed time threshold, such as a 5-minute time range for hot data, without considering the actual access time range of alarm data in different scenarios.

[0040] When users or external API calls need to access this data, if the accessed data exceeds the time range of hot data, the system will query the data in the cold data area. In this case, if the hot and cold data segmentation is not accurate, it will lead to frequent access to the cold data area, resulting in uneven resource utilization, low query efficiency and other problems. In order to improve the efficiency and accuracy of data processing, a more intelligent and flexible hot and cold data segmentation strategy needs to be adopted.

[0041] For ease of understanding, before introducing the embodiments of the present disclosure, several terms involved in the embodiments of the present disclosure are first explained as follows:

[0042] Alarm scenario: refers to the combination of specific conditions in the alarm data according to actual needs to form alarm rules in specific business scenarios. These conditions can include alarm type, alarm level, trigger condition, alarm domain name, etc. Users can flexibly configure according to actual needs.

[0043] Cold data: refers to data with low access frequency and long history. Cold data is usually not frequently used, so it can be stored in storage media with lower cost and slower access speed.

[0044] Hot data: refers to data that is frequently accessed and recently generated or updated. Because hot data is frequently accessed, it needs to be stored in fast-access storage media to ensure efficient response.

[0045] Cold data cache: A storage area used to store cold data. This area usually uses more cost-effective storage solutions, such as tape libraries or cloud archive storage, which are characterized by large capacity but relatively slow access speed.

[0046] Hot data cache: A storage area for hot data. This area is configured with high-performance storage devices, such as solid-state drives or high-speed memory, to provide fast data access and processing capabilities to meet the needs of real-time and high-concurrency access.

[0047] Preheating: The process of loading low-frequency access data originally stored in the cold data cache into the hot data cache in advance based on specific conditions.

[0048] Alarm type: In traffic-based threat detection applications, different types of alarms are generated according to different types of attacks.

[0049] Alert level: Generally, alerts are divided into multiple levels such as severe, medium, and normal according to the severity of the threat.

[0050] Attack phase: Based on the phase in which the threat occurs, the threat can be divided into different attack phases: reconnaissance, payload delivery, malicious activity, etc.

[0051] The specific implementation of the embodiment of the present disclosure is described in detail below with reference to the accompanying drawings.

[0052] Figure 2 FIG. 2 shows an exemplary application system architecture diagram to which the alarm data processing method in the embodiment of the present disclosure can be applied. Figure 2 As shown, the system architecture may include a terminal device 201 , a network 202 and a server 203 .

[0053] The network 202 is a medium for providing a communication link between the terminal device 201 and the server 203, and can be a wired network or a wireless network.

[0054] Optionally, the wireless network or wired network described above uses standard communication technology and / or protocol. The network is usually the Internet, but it can also be any network, including but not limited to a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a dedicated network or any combination of a virtual private network). In some embodiments, the data exchanged through the network is represented by technologies and / or formats including Hyper Text Mark-up Language (HTML), Extensible Markup Language (XML), etc. In addition, conventional encryption technologies such as Secure Socket Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), Internet Protocol Security (IPSec) can also be used to encrypt all or some links. In other embodiments, customized and / or dedicated data communication technologies can also be used to replace or supplement the above data communication technologies.

[0055] The terminal device 201 can be various electronic devices, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, smart speakers, smart watches, wearable devices, augmented reality devices, virtual reality devices, etc.

[0056] Optionally, the client of the application installed in different terminal devices 201 is the same, or the client of the same type of application based on different operating systems. Based on the different terminal platforms, the specific form of the client of the application can also be different, for example, the application client can be a mobile client, a PC client, etc.

[0057] The server 203 may be a server that provides various services, such as a background management server that provides support for the device operated by the user using the terminal device 201. The background management server may analyze and process the received request and other data, and feed back the processing results to the terminal device.

[0058] Optionally, the server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), as well as big data and artificial intelligence platforms.

[0059] Those skilled in the art will know that Figure 2 The number of terminal devices, networks and servers in the embodiment is only for illustration, and any number of terminal devices, networks and servers may be provided according to actual needs, and the embodiments of the present disclosure do not limit this.

[0060] Under the above system architecture, an alarm data processing method is provided in an embodiment of the present disclosure, and the method can be executed by any electronic device with computing and processing capabilities.

[0061] In some embodiments, the alarm data processing method provided in the embodiments of the present disclosure may be executed by a terminal device of the above-mentioned system architecture; in other embodiments, the alarm data processing method provided in the embodiments of the present disclosure may be executed by a server in the above-mentioned system architecture; in other embodiments, the alarm data processing method provided in the embodiments of the present disclosure may be implemented by a terminal device and a server in the above-mentioned system architecture through interaction.

[0062] Figure 3A A flow chart of a method for processing alarm data in an embodiment of the present disclosure is shown as follows: Figure 3A As shown, the alarm data processing method provided in the embodiment of the present disclosure includes the following steps:

[0063] S302: Obtain an alarm data set.

[0064] In this embodiment, the alarm data set includes: alarm data of multiple alarm scenarios. Among them, the alarm scenario can be customized in advance according to the needs, and the query parameters of an alarm scenario can specifically include but are not limited to one or more combinations such as alarm type, alarm level, trigger condition and duration. The alarm data of multiple alarm scenarios can be realized by embedding points in the application that generates the alarm data.

[0065] There are many possible implementation methods for defining and identifying alarm scenarios. For example, alarm scenarios can be defined by security analysis business experts, automatically identified by application front-end queries, or automatically identified by API (Application Programming Interface) calls.

[0066] Specifically, in traffic-based alarm applications, the query parameters that define alarm scenarios may include attack IP (A), malicious domain name (D), malicious MD5 (M), alarm type (W), alarm level (L), attack stage (P), etc., and may also include query duration (T). In order to obtain alarm data from the front end and API calls, data from front-end user access and API calls are embedded to record the attack IP (A), malicious domain name (D), malicious MD5 (M), alarm type (W), alarm level (L), attack stage (P), query duration (T) and other query parameter combinations corresponding to various alarm scenarios from front-end user access and API calls, forming a historical alarm database for alarm scenario analysis.

[0067] Assume that the alarm scenario is defined as S, and different alarm scenarios correspond to different query parameter values ​​as shown in the example above: s1 = {a l ,d1,m1,w1,l1,p1,t1}; s2={a2,d2,m2,w2,l2,p2,t2}; s3={a3,d3,m3,w3,l3,p3,t3}.

[0068] S304, screening out a target alarm scenario from the alarm scenario data set, wherein the target alarm scenario is an alarm scenario that meets a preset condition among multiple alarm scenarios.

[0069] In this embodiment, the target alarm scenario refers to those alarm scenarios that meet specific preset conditions. The preset conditions are rules or standards used to filter alarm scenarios. The preset conditions may be based on the severity of the alarm, the frequency of occurrence, a specific event type, the correlation with other events, etc. By traversing the alarm scenario data set, applying the preset conditions to each scenario, and determining whether it meets these conditions.

[0070] It should be noted that the alarm data time length (T) required for different alarm scenarios is different. For example, some alarm scenarios only need to view the alarm data in the last few minutes or hours to quickly respond to emergencies; while other scenarios may need to view the alarm data in the past few days, weeks or even months for long-term trend analysis and prediction.

[0071] In some embodiments, Figure 3B A flowchart of a specific implementation method of an alarm data processing method provided by an embodiment of the present disclosure. Figure 3B As shown, random sampling can be used from the historical alarm database to obtain alarm data samples of N alarm scenarios, and the occurrence frequency of each query parameter value combination of the alarm data samples of the N alarm scenarios except the query duration T is counted. Table 1 is an example table of the occurrence frequency of an alarm scenario query parameter value combination provided by an embodiment of the present disclosure.

[0072] Table 1

[0073]

[0074]

[0075] Combined with the above table, we can define the preset conditions: the frequency of occurrence exceeding R is defined as a high-frequency alarm scenario, that is, the target alarm scenario. Assume r1 r2 r3, … … r n ≥R, it is concluded that {s1, s2, s3, ... sn} are the target alarm scenarios.

[0076] Table 2 is an example table of occurrence frequencies of a specific alarm scenario query parameter value combination provided by an embodiment of the present disclosure.

[0077] Table 2

[0078]

[0079] The scenarios with a proportion exceeding 10% are set as target alarm scenarios, and {s1, s2, s3, s4} are obtained as high-frequency scenarios.

[0080] It should be noted that the above preset conditions are exemplary descriptions. In actual application, other methods can also be used to define the preset conditions. For example, the number of occurrences exceeding 50 times can be defined as a target alarm scenario, or the attack IP as IP1 can be defined as a target alarm scenario. The present disclosure does not impose any restrictions on this.

[0081] In some embodiments, after counting the occurrence frequencies of other query parameter combinations of each alarm scenario except the query duration through probability statistics, the occurrence frequencies of other query parameter combinations of the alarm scenarios are sorted in reverse order to obtain high-frequency alarm scenarios.

[0082] In this embodiment, the alarm scene with high frequency is set as the target alarm scene, and the data of the high-frequency alarm scene is loaded into the hot data cache in advance, so that subsequent queries on these data can be responded quickly, avoiding the delay of loading data from the cold data cache or slower storage media (such as hard disk). At the same time, since these data are frequently accessed, memory resources can be used more effectively.

[0083] S306: Obtain the query duration of the target alarm scenario.

[0084] In this embodiment, the query duration of the target alarm scenario refers to the length of the time range covered when the alarm data query is performed for the target alarm scenario.

[0085] S308 , based on the query duration of the target alarm scenario, load the alarm data of the target alarm scenario from the cold data cache area to the hot data cache area.

[0086] In this embodiment, the cold data cache is usually located on a slower storage medium, such as a hard disk, and is used to store data that is less frequently accessed or is not frequently used. The hot data cache is usually located in the memory and is used to store data that is frequently accessed and needs to be accessed quickly. That is, the access frequency of the cold data cache is less than the access frequency of the hot data cache.

[0087] In this embodiment, based on the query duration of the target alarm scenario, the alarm data of the target alarm scenario is loaded from the cold data cache area to the hot data cache area. The method of loading the alarm data from the cold data area to the hot data area according to different alarm scenarios can realize accurate preheating of the alarm data, avoid the problem of inconsistency between the cold and hot data segmentation and the actual hot and cold conditions of data access caused by the traditional method of segmenting cold and hot data at a unified time node, and provide efficient alarm data query services.

[0088] In the historical alarm database, the query duration of the target alarm scenario may be one or more. There are many possible factors that may cause the query duration of the same target alarm scenario to be different, such as system load, database performance, and data size and complexity. Figure 4 A method flow chart of an alarm data processing method disclosed in the present invention is shown. Figure 4 As shown, based on the query duration of the target alarm scenario, loading the alarm data of the target alarm scenario from the cold data cache area to the hot data cache area may include:

[0089] S402 , based on multiple query durations of target alarm scenarios, using Gaussian filtering to filter out query durations that meet preset conditions from the multiple query durations of the target alarm scenarios.

[0090] Gaussian filtering is a mathematical process used to smooth data and remove noise. It performs a weighted average on the data based on the shape of the Gaussian function (also known as the normal distribution function).

[0091] In this embodiment, after multiple query durations of the target alarm scenario are processed by Gaussian filtering, statistical indicators such as the range, average value, and standard deviation of the query duration of the target alarm scenario are obtained. Through screening, a query duration set that can cover most query durations and meet business requirements and system performance is obtained. A final query duration is determined from the screened query duration set. This query duration should be able to cover the query requirements of most users, while taking into account the optimization of system performance and resource utilization.

[0092] S404: Based on the query duration that meets the preset condition, the alarm data of the target alarm scenario is loaded from the cold data cache area to the hot data cache area.

[0093] Figure 5 A flow chart of a method for screening query duration in an embodiment of the present disclosure is shown. Figure 5 As shown, based on the multiple query durations of the target alarm scene, a query duration that meets a preset condition is screened out from the multiple query durations of the target alarm scene using Gaussian filtering, including:

[0094] S502 , based on multiple query durations of the target alarm scenario, calculate a mean and a standard deviation corresponding to a Gaussian distribution of multiple query durations of the target alarm scenario.

[0095] In this embodiment, it is assumed that the i-th target alarm scenario s i The corresponding query duration is That is, the query duration value corresponding to the i-th target alarm scenario is

[0096] Calculate the mean and standard deviation of multiple query duration Gaussian distributions of the target alarm scenario.

[0097] The mean is

[0098] The standard deviation is:

[0099] S504: Determine a query duration that meets a preset condition according to the mean and standard deviation corresponding to the Gaussian distribution.

[0100] In this embodiment, according to the Gaussian distribution principle, more than 95% of the query duration will be concentrated in Selecting the mean plus 1.96 times the standard deviation can cover more than 95% of the data, that is, determine the query duration that meets the preset conditions: This time range can cover s i It should be noted that the above values ​​are only examples, and in actual application, the preset condition may also be to satisfy more than 98% of the query durations, and this embodiment does not limit this.

[0101] For example, assume that the query duration corresponding to the target alarm scenario s1 is: {1440, 2880, 600, 400, 50, 1440, 1440, 14400}.

[0102] The calculated mean value of the target alarm scenario s1 is:

[0103]

[0104] The standard deviation of the target alarm scenario s1 is calculated as:

[0105]

[0106] Therefore, the value that can cover more than 95% of the query duration is: 2956.25+1.96*4404.567=11589.202, rounded to 11589.

[0107] By calculating the query duration of n target alarm scenarios, we can obtain the query duration value that can cover 95% of the situations corresponding to n target alarm scenarios, such as

[0108] Table 3 is an example table of complete query parameters for various scenarios after the query duration condition is supplemented, provided in an embodiment of the present disclosure:

[0109] Table 3

[0110]

[0111] In this embodiment, the Gaussian filtering method is used to filter out interfering query duration noise data from massive sample data to obtain a value that can cover the query duration of most target alarm scenario data, thereby avoiding loading too much low-frequency access data into the hot data area, and achieving accurate preheating.

[0112] In some embodiments, since the current time is constantly changing, in order to ensure that within a certain period of time, the current query time range does not exceed the time range of the alarm data cached in each target alarm scene, the cached data in the hot data cache area needs to be updated regularly. Figure 6 A flow chart of a method for updating the query duration of a target alarm scenario provided by an embodiment of the present disclosure, combined with Figure 6 As shown, after obtaining the query duration of the target alarm scenario, the method may further include:

[0113] S602, obtaining an update period of the hot data cache area.

[0114] The update period of the hot data cache is Δt.

[0115] S604: Update the query duration of the target alarm scenario according to the update cycle of the hot data cache area and the query duration of the target alarm scenario.

[0116] In this embodiment, according to the update cycle of the hot data cache area and the query duration of the target alarm scene, the query duration of the target alarm scene is determined to be Table 4 is a new query duration table for each target alarm scenario provided by the disclosed embodiment:

[0117] Table 4

[0118]

[0119] Specifically, assuming that the data update period is: Δt=1440, the target alarm scenario s1 The query time range is the current time [T,T-(13092)], where T is the current time.

[0120] S606: Based on the updated query duration of the target alarm scenario, the alarm data of the target alarm scenario is loaded from the cold data cache area to the hot data cache area.

[0121] In this embodiment, according to the query parameters corresponding to Table 4, the alarm data of the target alarm scenario is retrieved from the cold data cache area and saved in the hot data cache area for storage, so as to quickly respond to the retrieval and matching requirements from users and API calls later.

[0122] Continuing with the example of S604, the following query parameters are needed to query the alarm data of the target scenario s1 in the cold data cache and save it to the hot data cache: attack ip: 10.x.33.18; malicious domain name: www.abc.com; malicious MD5: 181edef4057c30cb****e91d47e68ac4; alarm type: brute force cracking; alarm level: h; attack stage: attack penetration.

[0123] In some embodiments, the cached hot data of each target alarm scenario may be updated based on a sliding window algorithm. Figure 7 A flow chart of a method for updating thermal data provided by an embodiment of the present disclosure. Figure 7 As shown, the method also includes:

[0124] S702, obtaining the current update time of the hot data cache area and the previous update time of the current update time.

[0125] In this embodiment, the current update time of the hot data cache area is T′, and the previous update time of the current update time is T. Wherein, T′=T+Δt, Δt is the update period of the hot data.

[0126] S704: Determine a time range of the alarm data to be removed in the hot data cache area according to the last update time of the current update time, the query duration of the target alarm scenario, and the query duration of the updated target alarm scenario.

[0127] In this embodiment, when the update period of hot data is Δt, a portion of old data needs to be removed from the hot data cache every Δt. When the current update time is T, the target alarm scenario s i The event time range of the data to be eliminated is in

[0128] Specifically, Figure 8A scenario provided by the embodiment of the present disclosure i The corresponding data queue diagram, where Qs i Indicates the queue head. For target alarm scenario s i Contains alarm data, using data x Indicates, where x represents the xth data, x can specifically include {1, 2, 3, ..., i, ..., n}, and the event corresponding to the xth data is represented by et x Indicates that the specific correspondence includes {et1, et2, et3, ..., et i ,……,et n}, for the data in the hot data cache, each scenario is stored in a separate queue. The time range for eliminating events from the hot data area is T≥et i Data ≥T-Δt.

[0129] S706: Move the alarm data to be removed from the hot data cache area to the cold data cache area based on the time range of the alarm data to be removed.

[0130] S708, determining the time range of the alarm data to be preheated in the cold data cache area according to the current update time and the query duration of the updated target alarm scenario; and loading the alarm data to be preheated from the cold data cache area to the hot data cache area based on the time range of the alarm data to be preheated.

[0131] In this embodiment, combined with Figure 8 As shown, the time range required to reload from the cold data cache is T′>=et i >=T′-Δt data to the hot data area.

[0132] In this embodiment, the hot data cache area can be continuously updated according to the time window (update cycle) Δt, so that the hot data in the hot data cache area can be adaptively and automatically updated continuously over time.

[0133] The target alarm scenario includes multiple query parameters to further improve the query efficiency. Fig. 9 A method flow chart of an alarm data processing method is provided for an embodiment of the present disclosure. Fig. 9 As shown, after obtaining the query duration of the target alarm scenario, the method further includes:

[0134] S902: Concatenate query parameter information of multiple query parameters of the target alarm scenario to obtain a query string of the target alarm scenario.

[0135] It should be noted that concatenation refers to connecting multiple elements or strings together to form a new string. The query string is a part attached to the end of the URL to pass additional retrieval or filtering conditions to the server. It usually consists of multiple query parameters, each of which can be separated by an & symbol.

[0136] In this embodiment, the query parameters of each target alarm scenario (attack IP (A), malicious domain name (D), malicious MD5 (M), alarm type (W), alarm level (L), attack stage (P)) are concatenated into a query string, for example: i ={a i |d i |m i |w i |l i |p i}.

[0137] S904: Perform a hash operation on the query string of the target alarm scenario to obtain a hash value corresponding to the query string of the target alarm scenario.

[0138] A hash operation is a process of converting input data of any length into a fixed-length output through an algorithm. The hash value is the output of the hash operation, which is a fixed-length string or integer that uniquely represents the input data. The hash value has the characteristics of uniqueness, fixed length, and irreversibility. Performing a hash operation on the query string of the target alarm scenario means taking the query string of the target alarm scenario as the input data of the hash operation, and calculating it through a specific hash algorithm (such as MD5, SHA-1, SHA-256, etc.) to obtain the hash value corresponding to the query string, that is, hash(s i )=hash(a i |d i |m i |w i |l i |p i ).

[0139] S906: Construct a hash table based on the hash value corresponding to the query character string of the target alarm scenario and the query duration of the target alarm scenario.

[0140] Table 5 is a query hash table for a target alarm scenario provided by an embodiment of the present disclosure.

[0141] Table 5

[0142]

[0143] In this embodiment, the hash table can be used to quickly search and locate the alarm data, thereby significantly improving the query efficiency.

[0144] Fig. 10A A method flow chart of a method for processing alarm data is provided for an embodiment of the present disclosure. Fig. 10A As shown, the method also includes:

[0145] S1002, obtaining a query request.

[0146] In this embodiment, the query request includes a hash value corresponding to the query string of the alarm scenario to be queried and an actual query duration.

[0147] S1004: Match the hash value corresponding to the query character string of the alarm scenario to be queried with the hash table.

[0148] S1006: When the hash value corresponding to the query character string of the alarm scenario to be queried matches the hash value in the hash table, the query duration of the alarm scenario to be queried is determined from the hash table.

[0149] In this embodiment, if there is an entry in the hash table that matches the query string hash value (assuming it is s i ), then further determine whether the time range in the query request (actual query duration) is less than the valid time range recorded or associated with the entry (target alarm scenario s i Updated query duration).

[0150] S1008: When the actual query duration is less than the query duration of the alarm scene to be queried, the alarm data of the alarm scene to be queried is obtained from the hot data buffer area.

[0151] In this embodiment, if the above conditions are met, that is, the hash value matches and the query duration is within a valid range, the application can directly query the relevant data from the hot data cache without accessing a slower storage medium (such as a cold data cache).

[0152] In this embodiment, the possible related data entries can be quickly located through the fast matching of the hash table, avoiding the full table scan or complex index search process. And when the actual query time is within the effective range, the data is directly queried from the hot data area, further reducing the delay of data access.

[0153] Fig. 10B A flowchart of a specific implementation method of an alarm data processing method in an embodiment of the present disclosure is shown. Fig. 10B As shown, a method for processing alarm data may include:

[0154] Application tracking means tracking the access from front-end users and API calls, recording the data of various scenarios (attack IP (A), malicious domain name (D), malicious MD5 (M), alarm type (W), alarm level (L), attack stage (P), query duration (T)) and query condition combinations from the front-end and API calls, and forming a historical library for hot scenario data analysis.

[0155] Sampling scene data, using random sampling from the historical database, extract N samples. Through probability statistics, count the frequency of other dimensional combinations of each scene except the time length, sort them in reverse order, and obtain popular scenes. Use the Gaussian filter method to filter out the interfering query duration noise data from the massive sample data, and obtain a value that can cover 95% of the access duration of each popular scene data, avoiding loading too much low-frequency access data into the hot data area, and achieving accurate preheating.

[0156] Since the current time is constantly changing, in order to ensure that within a certain period of time, the current query time range will not exceed the time range of the data cached in each scene, the update cycle of the hot data cache area is used as the window length, and the query time of each scene is superimposed on the window length to obtain a new query time length table for each scene. Then the popular scene data is cached in the hot data area. The scene hash value is calculated to obtain the hash value of each popular scene. A fast retrieval query method based on a hash table updates the cached hot data of each scene based on a sliding window algorithm. In order to ensure the validity of the sample, this embodiment can also regularly update the sample at regular intervals, re-sample, re-train, and re-start the cycle from step one to ensure that the analyzed samples are continuously updated over time.

[0157] Based on the same inventive concept, the present disclosure also provides an alarm data processing device, as described in the following embodiments. Since the principle of solving the problem in the device embodiment is similar to that in the above method embodiment, the implementation of the device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0158] Fig.11 A schematic diagram of an alarm data processing device in an embodiment of the present disclosure is shown. Fig.11 As shown, the device includes: a first acquisition module 111, a screening module 112, a second acquisition module 113 and a loading module 114.

[0159] The first acquisition module 111 is used to acquire an alarm data set, where the alarm data set includes: alarm data of multiple alarm scenarios;

[0160] A screening module 112 is used to screen out a target alarm scene from the alarm scene data set, wherein the target alarm scene is an alarm scene that meets a preset condition among multiple alarm scenes;

[0161] The second acquisition module 113 is used to acquire the query duration of the target alarm scenario, where the query duration of the target alarm scenario refers to the length of the time range covered when the alarm data query is performed for the target alarm scenario;

[0162] The loading module 114 is used to load the alarm data of the target alarm scenario from the cold data cache area to the hot data cache area based on the query duration of the target alarm scenario; wherein the access frequency of the cold data cache area is less than the access frequency of the hot data cache area.

[0163] In some embodiments, the target alarm scenario corresponds to multiple query durations, and the loading module 114 is specifically used to: based on the multiple query durations of the target alarm scenario, use Gaussian filtering to filter out the query durations that meet preset conditions from the multiple query durations of the target alarm scenario; based on the query durations that meet the preset conditions, load the alarm data of the target alarm scenario from the cold data cache area to the hot data cache area.

[0164] In some embodiments, the loading module 114 is specifically used to: calculate the mean and standard deviation corresponding to the Gaussian distribution of multiple query durations of the target alarm scenario based on multiple query durations of the target alarm scenario; determine the query duration that meets the preset conditions according to the mean and standard deviation corresponding to the Gaussian distribution.

[0165] In some embodiments, the second acquisition module 113 is also used to: obtain the update period of the hot data cache area; update the query duration of the target alarm scene according to the update period of the hot data cache area and the query duration of the target alarm scene; load the alarm data of the target alarm scene from the cold data cache area to the hot data cache area, including: based on the updated query duration of the target alarm scene, loading the alarm data of the target alarm scene from the cold data cache area to the hot data cache area.

[0166] In some embodiments, the second acquisition module 113 is also used to: obtain the current update time of the hot data cache area and the previous update time of the current update time; determine the time range of the alarm data to be removed in the hot data cache area according to the previous update time of the current update time, the query duration of the target alarm scenario and the query duration of the updated target alarm scenario; move the alarm data to be removed from the hot data cache area to the cold data cache area based on the time range of the alarm data to be removed; wherein, based on the query duration of the updated target alarm scenario, load the alarm data of the target alarm scenario from the cold data cache area to the hot data cache area, including: determining the time range of the alarm data to be preheated in the cold data cache area according to the current update time and the query duration of the updated target alarm scenario; loading the alarm data to be preheated from the cold data cache area to the hot data cache area based on the time range of the alarm data to be preheated.

[0167] In some embodiments, the target alarm scenario includes multiple query parameters, and the second acquisition module 113 is also used to: splice the query parameter information of the multiple query parameters of the target alarm scenario to obtain the query string of the target alarm scenario; perform a hash operation on the query string of the target alarm scenario to obtain a hash value corresponding to the query string of the target alarm scenario; and construct a hash table based on the hash value corresponding to the query string of the target alarm scenario and the query duration of the target alarm scenario.

[0168] In some embodiments, the device also includes a query module, which is used to: obtain a query request; the query request includes a hash value corresponding to the query string of the alarm scene to be queried and an actual query duration; the hash value corresponding to the query string of the alarm scene to be queried is matched with a hash table; when the hash value corresponding to the query string of the alarm scene to be queried matches the hash value in the hash table, the query duration of the alarm scene to be queried is determined from the hash table; when the actual query duration is less than the query duration of the alarm scene to be queried, the alarm data of the alarm scene to be queried is obtained from the hot data cache area.

[0169] It should be noted that the examples and application scenarios implemented by the modules in the above-mentioned device embodiment are the same as those of the corresponding steps in the method embodiment, but are not limited to the contents disclosed in the above-mentioned method embodiment. It should be noted that the above-mentioned modules as part of the device can be executed in a computer system such as a set of computer executable instructions.

[0170] Those skilled in the art will appreciate that various aspects of the present disclosure may be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation that combines hardware and software aspects, which may be collectively referred to herein as a "circuit," "module," or "system."

[0171] Based on the same inventive concept, an electronic device is also provided in an embodiment of the present disclosure, the electronic device comprising: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute any one of the above alarm data processing methods by executing the executable instructions. Since the principle of solving the problem in the electronic device embodiment is similar to that in the above method embodiment, the implementation of the electronic device embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0172] Refer to the following Fig.12 1200 according to this embodiment of the present disclosure is described. Fig.12 The electronic device 1200 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0173] like Fig.12As shown, the electronic device 1200 is in the form of a general computing device. The components of the electronic device 1200 may include but are not limited to: at least one processing unit 1210, at least one storage unit 1220, and a bus 1230 connecting different system components (including the storage unit 1220 and the processing unit 1210).

[0174] Wherein, the storage unit stores a program code, and the program code can be executed by the processing unit 1210, so that the processing unit 1210 executes the steps described in the above "Exemplary Method" section of this specification according to various exemplary embodiments of the present disclosure. For example, the processing unit 1210 can execute the following steps of the above method embodiment: obtain an alarm data set, the alarm data set contains: alarm data of multiple alarm scenarios; filter out a target alarm scenario from the alarm scenario data set, wherein the target alarm scenario is an alarm scenario that meets a preset condition among the multiple alarm scenarios; obtain the query duration of the target alarm scenario, the query duration of the target alarm scenario refers to the length of the time range covered when querying alarm data for the target alarm scenario; based on the query duration of the target alarm scenario, load the alarm data of the target alarm scenario from the cold data cache area to the hot data cache area; wherein the access frequency of the cold data cache area is less than the access frequency of the hot data cache area.

[0175] The storage unit 1220 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 12201 and / or a cache storage unit 12202 , and may further include a read-only storage unit (ROM) 12203 .

[0176] The storage unit 1220 may also include a program / utility 12204 having a set (at least one) of program modules 12205, such program modules 12205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0177] Bus 1230 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0178] The electronic device 1200 may also communicate with one or more external devices 1240 (e.g., keyboards, pointing devices, Bluetooth devices, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 1200, and / or communicate with any device that enables the electronic device 1200 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed via an input / output (I / O) interface 1250. Furthermore, the electronic device 1200 may also communicate with one or more networks (e.g., local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) via a network adapter 1260. As shown, the network adapter 1260 communicates with other modules of the electronic device 1200 via a bus 1230. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 1200, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0179] Through the description of the above implementation, it is easy for those skilled in the art to understand that the example implementation described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the implementation of the present disclosure.

[0180] Based on the same inventive concept, a computer-readable storage medium is also provided in the embodiment of the present disclosure, on which a computer program is stored, and when the computer program is executed by a processor, any of the above-mentioned alarm data processing methods is implemented. Since the principle of solving the problem in the embodiment of the computer-readable storage medium is similar to that in the above-mentioned method embodiment, the implementation of the embodiment of the computer-readable storage medium can refer to the implementation of the above-mentioned method embodiment, and the repeated parts will not be repeated.

[0181] More specific examples of computer-readable storage media in the present disclosure may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0182] In the present disclosure, a computer readable storage medium may include a data signal propagated in baseband or as part of a carrier wave, wherein a readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A readable signal medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0183] Alternatively, the program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the foregoing.

[0184] In a specific implementation, the program code for performing the operations of the present disclosure may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, etc., and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., using an Internet service provider to connect through the Internet).

[0185] Based on the same inventive concept, a computer program product is also provided in an embodiment of the present disclosure, including a computer program product, including: a computer program or an instruction, wherein when the computer program or the instruction is executed by a processor, the alarm data processing method of any one of the above method embodiments is implemented. Since the principle of solving the problem in the computer program product embodiment is similar to that in the above method embodiment, the implementation of the computer program product embodiment can refer to the implementation of the above method embodiment, and the repeated parts will not be repeated.

[0186] It should be noted that, although several modules or units of the device for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into multiple modules or units to be embodied.

[0187] In addition, although the steps of the method in the present disclosure are described in a specific order in the drawings, this does not require or imply that the steps must be performed in this specific order, or that all the steps shown must be performed to achieve the desired results. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step, and / or one step may be decomposed into multiple steps, etc.

[0188] Through the description of the above implementation, it is easy for those skilled in the art to understand that the example implementation described here can be implemented by software, or by software combined with necessary hardware. Therefore, the technical solution according to the implementation of the present disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the implementation of the present disclosure.

[0189] Those skilled in the art will readily appreciate other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure, which follow the general principles of the present disclosure and include common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The description and examples are intended to be exemplary only, and the true scope and spirit of the present disclosure are indicated by the appended claims.

Claims

1. A method for processing alarm data, characterized in that: The method comprises: Acquire an alarm data set, wherein the alarm data set includes: alarm data of multiple alarm scenarios; Filtering a target alarm scene from the alarm scene data set, wherein the target alarm scene is an alarm scene that meets a preset condition among the multiple alarm scenes; Obtaining the query duration of the target alarm scenario, where the query duration of the target alarm scenario refers to the length of the time range covered when querying alarm data for the target alarm scenario; Based on the query duration of the target alarm scenario, the alarm data of the target alarm scenario is loaded from the cold data cache area to the hot data cache area; wherein the access frequency of the cold data cache area is less than the access frequency of the hot data cache area.

2. The alarm data processing method according to claim 1, characterized in that: The target alarm scenario corresponds to a plurality of query durations, and the loading of the alarm data of the target alarm scenario from the cold data cache area to the hot data cache area based on the query duration of the target alarm scenario includes: Based on the multiple query durations of the target alarm scenario, a query duration that meets a preset condition is screened out from the multiple query durations of the target alarm scenario by using Gaussian filtering; Based on the query duration that meets the preset condition, the alarm data of the target alarm scenario is loaded from the cold data cache area to the hot data cache area.

3. The alarm data processing method according to claim 2, characterized in that: The method of filtering out a query duration that meets a preset condition from the multiple query durations of the target alarm scenario based on the multiple query durations of the target alarm scenario by using Gaussian filtering includes: Based on the multiple query durations of the target alarm scenario, calculating the mean and standard deviation corresponding to the Gaussian distribution of the multiple query durations of the target alarm scenario; The query duration that meets the preset conditions is determined according to the mean and standard deviation corresponding to the Gaussian distribution.

4. The alarm data processing method according to claim 1, characterized in that: After obtaining the query duration of the target alarm scenario, the method further includes: Get the update cycle of the hot data cache; According to the update cycle of the hot data cache area and the query duration of the target alarm scenario, updating the query duration of the target alarm scenario; The step of loading the alarm data of the target alarm scenario from the cold data buffer area to the hot data buffer area includes: Based on the updated query duration of the target alarm scenario, the alarm data of the target alarm scenario is loaded from the cold data cache area to the hot data cache area.

5. The alarm data processing method according to claim 4, characterized in that: Before loading the alarm data of the target alarm scenario from the cold data cache area to the hot data cache area based on the query duration of the updated target alarm scenario, the method further includes: Get the current update time of the hot data cache area and the previous update time of the current update time; Determine the time range of the alarm data to be removed in the hot data cache area according to the last update time of the current update time, the query duration of the target alarm scene, and the query duration of the updated target alarm scene; Moving the alarm data to be removed from the hot data buffer area to the cold data buffer area based on the time range of the alarm data to be removed; Among them, based on the query duration of the updated target alarm scene, the alarm data of the target alarm scene is loaded from the cold data cache area to the hot data cache area, including: determining the time range of the alarm data to be preheated in the cold data cache area according to the current update time and the query duration of the updated target alarm scene; based on the time range of the alarm data to be preheated, loading the alarm data to be preheated from the cold data cache area to the hot data cache area.

6. The alarm data processing method according to claim 4, characterized in that: The target alarm scenario includes multiple query parameters. After obtaining the query duration of the target alarm scenario, the method further includes: Concatenating query parameter information of multiple query parameters of the target alarm scenario to obtain a query string of the target alarm scenario; Performing a hash operation on the query string of the target alarm scenario to obtain a hash value corresponding to the query string of the target alarm scenario; A hash table is constructed based on the hash value corresponding to the query character string of the target alarm scenario and the query duration of the target alarm scenario.

7. The alarm data processing method according to claim 6, characterized in that: The method further comprises: Obtain a query request; the query request includes a hash value corresponding to the query string of the alarm scenario to be queried and an actual query duration; Matching the hash value corresponding to the query string of the alarm scenario to be queried with the hash table; When the hash value corresponding to the query character string of the alarm scenario to be queried matches the hash value in the hash table, determining the query duration of the alarm scenario to be queried from the hash table; When the actual query duration is less than the query duration of the alarm scene to be queried, the alarm data of the alarm scene to be queried is acquired from the hot data cache area.

8. An alarm data processing device, characterized in that: The device comprises: A first acquisition module is used to acquire an alarm data set, wherein the alarm data set includes: alarm data of multiple alarm scenarios; A screening module, used to screen out a target alarm scene from the alarm scene data set, wherein the target alarm scene is an alarm scene that meets a preset condition among the multiple alarm scenes; A second acquisition module is used to acquire the query duration of the target alarm scenario, where the query duration of the target alarm scenario refers to the length of a time range covered when querying alarm data for the target alarm scenario; A loading module is used to load the alarm data of the target alarm scenario from the cold data cache area to the hot data cache area based on the query duration of the target alarm scenario; wherein the access frequency of the cold data cache area is less than the access frequency of the hot data cache area.

9. An electronic device, characterized in that: include: processor; as well as A memory, configured to store executable instructions of the processor; Wherein, the processor is configured to execute the alarm data processing method described in any one of claims 1 to 7 by executing the executable instructions.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the alarm data processing method according to any one of claims 1 to 7 is implemented.

11. A computer program product comprising: A computer program or instruction, characterized in that when the computer program or instruction is executed by a processor, it implements the alarm data processing method described in any one of claims 1 to 7.