System anomaly detection method and system based on graph convolution self-attention network

By converting log and tracked data into event nodes and using graph convolutional self-attention network for graph characterization learning, the problem of lack of fused heterogeneous data in the abnormal detection of existing systems is solved, and the abnormality accurate detection of multi-source heterogeneous data systems is achieved.

CN119938374APending Publication Date: 2025-05-06NAT UNIV OF DEFENSE TECH
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411791502.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-06
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

There is a lack of effective fusion heterogeneous data methods in the abnormality detection of existing systems, resulting in inaccurate abnormality detection.

Method used

The method based on graph convolutional self-attention network is adopted to convert logs and tracking data into event nodes, generate directed heterogeneous graphs, and graph characterization learning is performed through graph convolutional self-attention network, and anomaly detection is performed by combining deep support vector data description model.

Benefits of technology

The abnormal accuracy of multi-source heterogeneous data system is realized, and the accuracy and recall rate of detection are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119938374A_ABST
    Figure CN119938374A_ABST
Patent Text Reader

Abstract

The invention discloses a system anomaly detection method and system based on a graph convolution self-attention network. The system anomaly detection method based on the graph convolution self-attention network comprises the following steps: S1, converting logs and tracking data into event nodes, and linking the event nodes into a heterogeneous directed data graph by using time and logic relationships; s2, performing graph representation learning on the directed heterogeneous graph by using a graph convolution self-attention network to obtain graph representation; and S3, performing anomaly detection based on graph representation to obtain an anomaly detection result of whether the multi-source heterogeneous data system is abnormal or not. The method aims at solving the problem that a heterogeneous data fusion method is lacked in the existing system anomaly detection field, system logs are effectively integrated, and data information is tracked to achieve accurate anomaly detection of a data system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security detection of data systems, and in particular to a system anomaly detection method and system based on a graph convolutional self-attention network. Background Art

[0002] Anomaly detection technology research is an important direction in the field of data analysis, which aims to analyze various data samples to distinguish outliers and thus detect abnormal data. This technology has been widely used in many fields, including intrusion detection, malicious application identification, and traffic control. For system anomaly detection, the main goal is to analyze the operation status information contained in different data sources, identify abnormal situations, and help discover system vulnerabilities and failures, as well as provide assistance in the maintenance and diagnosis of system problems. In system anomaly detection, commonly used data types include logs, traces, and measurement information. DeepLog proposed by Du et al. and LogAnomaly introduced by Meng et al. improve the accuracy of system log anomaly detection by using deep learning technology. The former uses the Long Short-Term Memory (LSTM) network, and the latter uses the template vectorization method to provide an effective tool for timely discovery and diagnosis of system problems. TraceAnomaly proposed by Liu et al. is an unsupervised anomaly detection system for microservice tracing. It uses a deep Bayesian network to identify anomalies by learning normal behavior patterns in service-level data. However, it is still a challenge to effectively integrate multi-source heterogeneous data when leveraging information from system logs, traces, and other sources for anomaly detection. Summary of the invention

[0003] Technical problem to be solved by the present invention: In view of the above-mentioned problems in the prior art, a system anomaly detection method and system based on graph convolutional self-attention network are provided. The present invention aims to solve the problem of lack of methods for fusing heterogeneous data in the existing field of system anomaly detection, and effectively integrate the information of system logs and tracking data to realize accurate detection of anomalies in data systems.

[0004] In order to solve the above technical problems, the technical solution adopted by the present invention is: A system anomaly detection method based on graph convolutional self-attention network includes the following steps: S1, converts log and trace data into event nodes and uses time and logical relationships to link them into a heterogeneous directed data graph, extracts semantic information from the event text of each event in the heterogeneous directed data graph and generates a directed heterogeneous graph; S2, the directed heterogeneous graph is represented by graph convolutional self-attention network to obtain graph representation; S3, anomaly detection is performed based on graph representation to obtain anomaly detection results of whether the multi-source heterogeneous data system is abnormal.

[0005] Optionally, when converting log and trace data into event nodes in step S1, converting log data into event nodes includes: using a log parsing tool to parse the logs of each component in the data system to extract corresponding log events, and arranging the log events of each component in chronological order of generation to generate a log event sequence.

[0006] Optionally, when converting log and tracing data into event nodes in step S1, each tracing record of the tracing data includes activity information of the requesting component and the requested component, a timestamp of the start of the activity, and a timestamp of the end of the activity. Converting the tracing data into event nodes includes: splitting each tracing record into two tracing events, a start event and an end event, and arranging the two tracing events in chronological order for the requesting component and the requested component respectively to generate a tracing event sequence.

[0007] Optionally, in step S1, using time and logical relationships to link into a heterogeneous directed data graph includes: inserting the request component and the tracking events in the request component tracking event sequence into the corresponding log event sequence according to the occurrence time, thereby obtaining a heterogeneous directed data graph containing the order of occurrence of log events and tracking events and the time dependency information between different events, wherein the nodes in the heterogeneous directed data graph are log events and tracking events.

[0008] Optionally, in step S1, extracting semantic information from the event text of each event in the heterogeneous directed data graph and generating a directed heterogeneous graph includes: segmenting the event text of each event in the heterogeneous directed data graph into separate words, and then for each word, using a pre-trained encoding model to generate a word vector, combining the word vectors of the words to obtain a sentence vector, using the term frequency-inverse document frequency algorithm TF-IDF to determine the weight of each word in the sentence vector, using the weighted sentence vector as the semantic information of the event, and constructing a sentence vector based on triples. Represents a directed heterogeneous graph, where is a set of vertices, is the adjacency matrix, is a node attribute vector, where ~ They are node attribute vectors Included 1st~ The semantic information of each event, the adjacency matrix Contains temporal and logical relationship information between events.

[0009] Optionally, the graph convolutional self-attention network in step S2 includes a graph convolutional network GCNs and a Transformer model. In step S2, the directed heterogeneous graph is subjected to graph representation learning using the graph convolutional self-attention network to obtain the graph representation, including: extracting a feature matrix from the heterogeneous directed data graph using the graph convolutional network GCNs, sorting the nodes in the heterogeneous directed data graph by time to form a heterogeneous data sequence, and inputting the feature matrix and the heterogeneous data sequence into the Transformer model together, so as to obtain the graph representation through the Transformer model.

[0010] Optionally, step S3 includes: combining the graph representation with a hypersphere of normal data points defined in a pre-trained deep support vector data description model Deep SVDD to calculate an anomaly score according to the following formula: , In the above formula, is the abnormality score, For graph representation, is the radius of the hypersphere of the normal data points.

[0011] Optionally, the function expression of the loss function used by the deep support vector data description model Deep SVDD during training is: , In the above formula, is the loss function, is the radius of the hypersphere, is a hyperparameter, is the number of training samples, Indicates taking the maximum value, is the sequence number of the training sample, is the center of the hypersphere.

[0012] In addition, the present invention also provides a system anomaly detection system based on a graph convolutional self-attention network, comprising a microprocessor and a memory connected to each other, wherein the microprocessor is programmed or configured to execute the system anomaly detection method based on the graph convolutional self-attention network.

[0013] In addition, the present invention also provides a computer-readable storage medium, which stores a computer program or instruction, and the computer program or instruction is programmed or configured to execute the system anomaly detection method based on graph convolutional self-attention network through a processor.

[0014] In addition, the present invention also provides a computer program product, including a computer program or instructions, which are programmed or configured to execute the system anomaly detection method based on graph convolutional self-attention network through a processor.

[0015] Compared with the prior art, the present invention mainly has the following advantages: the present invention includes converting log and tracking data into event nodes and linking them into a heterogeneous directed data graph using time and logical relationships, performing graph representation learning on the directed heterogeneous graph using a graph convolution self-attention network to obtain a graph representation, and performing anomaly detection based on the graph representation to obtain an anomaly detection result of whether the multi-source heterogeneous data system is abnormal. The present invention can solve the problem of lack of methods for fusing heterogeneous data in the field of existing system anomaly detection, and effectively integrate the information of system logs and tracking data to realize accurate detection of anomalies in data systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 Schematic diagram of the basic flow of the method of the embodiment of the present invention.

[0017] Figure 2 The figure is a schematic diagram of the principle of generating a directed isomeric graph in an embodiment of the present invention.

[0018] Figure 3 Schematic diagram of the principles of graph representation learning and anomaly detection in an embodiment of the present invention.

[0019] Figure 4 This is the experimental result of the graph convolutional self-attention network in an embodiment of the present invention without using the Transformer model.

[0020] Figure 5 This is the experimental result of using the Transformer model in the graph convolutional self-attention network in an embodiment of the present invention. DETAILED DESCRIPTION

[0021] The following will take the anomaly detection of a computing system as an example, and further explain the present invention in detail in combination with the accompanying drawings and specific embodiments. The computing system contains multiple components. If the anomaly detection is performed solely based on logs, there will be a problem of insufficient accuracy. The present invention aims to combine the logs and trace multimodal data in the computing system to improve the accuracy of anomaly detection in the data system. Figure 1 and Figure 2 As shown, the system anomaly detection method based on graph convolutional self-attention network in this embodiment includes the following steps: S1, converts log and trace data into event nodes and uses time and logical relationships to link them into a heterogeneous directed data graph, extracts semantic information from the event text of each event in the heterogeneous directed data graph and generates a directed heterogeneous graph; S2, using a graph convolutional self-attention network (named GCTformer in this embodiment) to learn the graph representation of the directed heterogeneous graph to obtain a graph representation; S3, anomaly detection is performed based on graph representation to obtain anomaly detection results of whether the multi-source heterogeneous data system is abnormal.

[0022] As an optional implementation, the system anomaly detection method based on the graph convolutional self-attention network in this embodiment is logically divided into a heterogeneous data fusion program module, a graph representation learning program module and anomaly detection program module, wherein: the heterogeneous data fusion program module is used to convert log and tracking data into event nodes and link them into a heterogeneous directed data graph using time and logical relationships; the graph representation learning program module is used to use the graph convolutional self-attention network to perform graph representation learning on the directed heterogeneous graph to obtain a graph representation; the anomaly detection program module is used to perform anomaly detection based on the graph representation to obtain an anomaly detection result of whether the multi-source heterogeneous data system is abnormal.

[0023] When converting log and tracking data into event nodes in step S1 of this embodiment, converting log data into event nodes includes: using a log parsing tool to perform log parsing on the log of each component in the data system to extract the corresponding log event, and arranging the log event of each component in the order of generation time to generate a log event sequence. Specifically, in order to generate events from logs, in this embodiment, the log parsing tool Drain is used to parse the log text, and the results extracted by Drain are used as the events corresponding to each log statement. Then all log nodes are arranged in the order of their generation time to form a log event sequence.

[0024] In addition to activity information, typical tracing data also includes the start and end time of the tracing process, that is, the timestamps of the start and end of the call or request activity corresponding to each trace. Using this information, start and end nodes can be generated for the tracing record based on the start and end timestamps, representing two corresponding events. In distributed and microservice scenarios, different system components run relatively independently, and the content of the tracing record includes not only the start and end events, but also the sender and processor of the request. Logs are recorded in parallel in different independent components. Therefore, following the practice of previous studies, this embodiment constructs an independent sequence for the logs generated by each component. For each tracing record, a set of event nodes are generated at both the sender and the processor to identify the event process of sending and processing the request. Specifically, when converting log and trace data into event nodes in step S1 of this embodiment, each trace record of the trace data includes activity information of the requesting component (sender) and the requested component (processor), the timestamp of the start of the activity and the timestamp of the end of the activity. Converting the trace data into event nodes includes: splitting each trace record into two trace events, namely a start event and an end event, and arranging the two trace events in the order of occurrence for the requesting component and the requested component respectively to generate a trace event sequence.

[0025] Subsequently, in order to integrate the tracking data with the sequential structure of the log, the tracking event records are inserted between the log nodes according to the time information in the tracking data. Just like the connection between log nodes, the event nodes adjacent in time are connected by directed edges, from the earlier event node to the later one. For the event text content corresponding to the tracking, the semantic content of the tracking itself is directly used without being processed by the parsing tool. Specifically, in step S1 of this embodiment, the use of time and logical relationships to link into a heterogeneous directed data graph includes: inserting the tracking events in the request component and the tracking event sequence of the request component into the corresponding log event sequence according to the occurrence time, thereby obtaining a heterogeneous directed data graph containing the order of occurrence of log events and tracking events and the time dependency relationship information between different events, and the nodes in the heterogeneous directed data graph are log events and tracking events. After these two steps of processing, the log and tracking data are finally integrated into a complete heterogeneous data graph, which not only contains the order of occurrence of events, but also contains the dependency relationship information between different events.

[0026] After the initial integration of heterogeneous data, a directed graph consisting of event nodes is obtained from the original log and trace records, namely: heterogeneous data graph. However, this graph structure only reflects some of the interconnections between events, and does not yet represent the information contained in each event itself. In this embodiment, following the general method of semantic embedding of logs and traces, a language model is used to generate word embeddings for log templates and text representations of traces. Based on the word embeddings that constitute the text, sentence vectors are further generated, and these sentence vectors are used to represent the attributes of event nodes. First, for each processed event text, it is segmented into separate words according to the structure of the text; subsequently, for each word, a pre-trained GloVe model is used to generate a word vector. In this embodiment, a GloVe model pre-trained on the Wikipedia 2014 and Gigaword 5 datasets is selected. The vocabulary length of this version of the GloVe pre-trained model is 400,000, and the model generates a 300-dimensional word vector for each queried word. With the word vector, a sentence vector needs to be created in this embodiment to represent the entire event text. Since different words contribute differently to the meaning of the text, this difference should be captured when forming the sentence vector. In this embodiment, the term frequency-inverse document frequency (TF-IDF) algorithm is used to determine the weight of each word in the sentence vector. Higher TF scores indicate more frequent words, while lower IDF scores reduce the weight of common words, ensuring that less distinctive terms do not dominate the sentence representation. After the above heterogeneous data fusion step, a directed heterogeneous graph containing two types of information is generated from the original logs and trajectories. This directed heterogeneous graph is essentially mapped to a triple {V, A, F}, where V is a vertex set, A is an adjacency matrix, is a collection of node attribute vectors. The node attribute F contains the semantic information of the event, and the adjacency matrix A contains the time and logical association information between events. Specifically, in step S1, the semantic information is extracted from the event text of each event in the heterogeneous directed data graph and a directed heterogeneous graph is generated, including: the event text of each event in the heterogeneous directed data graph is divided into separate words, and then for each word, a pre-trained encoding model is used to generate a word vector, the word vectors of the words are combined to obtain a sentence vector, and the term frequency-inverse document frequency algorithm TF-IDF is used to determine the weight of each word in the sentence vector, and the sentence vector after adjusting the weight is used as the semantic information of the event, and a sentence vector composed of triples is constructed. Represents a directed heterogeneous graph, where is a set of vertices, is the adjacency matrix, is a node attribute vector, where ~ They are node attribute vectors Included 1st~ The semantic information of each event, the adjacency matrix Contains temporal and logical relationship information between events.

[0027] To transform the graph structure into a representation in a continuous space, we use graph convolutional networks (GCNs) to learn representations for directed heterogeneous graphs. Graph convolutional networks (GCNs) perform well in analyzing graph-structured data, are particularly good at capturing local neighborhood features, have simple model structures, and are computationally efficient. However, graph convolutional networks (GCNs) typically rely on local neighbor information to aggregate features through a fixed number of neighboring nodes. This local connectivity may limit the model's ability to capture global temporal dependencies in the graph, especially long-distance dependencies that are common in log and trace data. To address this issue, we adopt a method that combines the Transformer model and graph convolutional networks (GCNs). The Transformer model was originally designed to process sequence data, and through its self-attention module, it is able to capture the relationship between any two elements in a sequence without distance restrictions. This ability to grasp global dependencies makes the Transformer an ideal complement to the local feature learning of graph convolutional networks (GCNs). Specifically, the graph convolutional self-attention network (GCTformer) in this embodiment is composed of a graph convolutional network GCNs and a self-attention module, and is used to integrate the feature matrix obtained by the graph convolutional network GCNs and the heterogeneous directed data graph based on the self-attention module, wherein the self-attention module can adopt the required network model or module as needed. As an optional implementation, if Figure 3As shown, the graph convolution self-attention network (GCTformer) in step S2 of this embodiment includes a graph convolution network GCNs and a Transformer model. In step S2, the directed heterogeneous graph is subjected to graph representation learning using the graph convolution self-attention network to obtain the graph representation, including: extracting a feature matrix from the heterogeneous directed data graph using the graph convolution network GCNs, sorting the nodes in the heterogeneous directed data graph by time to form a heterogeneous data sequence, and inputting the feature matrix and the heterogeneous data sequence into the Transformer model together to obtain the graph representation through the Transformer model. Graph convolution networks GCNs are a type of neural network designed for learning graph structured data. They use the topology of the graph to perform convolution operations, aggregate information from node neighbors, and allow the network to learn node representations that indicate the graph structure. The graph convolution operation formula in the graph convolution network GCNs is: , In the above formula, and Respectively and The node feature matrix of the layer, is the activation function, and the ReLU activation function is used here. represents an adjacency matrix with self-loops, Represents the adjacency matrix The degree matrix of This is for The weight matrix of the layer. Therefore, the node feature matrix output by the graph convolutional network GCNs is fed into the self-attention module. Graph convolutional networks GCNs express the relationship between adjacent nodes, and long-term dependencies are very important for anomaly detection. Therefore, the attention-based Transformer model is introduced to capture global features. The process of the self-attention mechanism of the self-attention module can be formulated as: , In the above formula, is the output of the self-attention module, Q (query), K (key), and V (value) are linear transformations of the node feature matrix. Perform Softmax operation, is the length of each vector Q, K and V. The product operation evaluates the correlation between different tags as weighted Attention score. In addition, in order to enhance the diversity of representation, the Transformer model introduces a multi-head mechanism. The node feature matrix is ​​evenly divided into n parts and then fed into the self-attention module. This multi-head attention mechanism allows the model to learn information in parallel in different representation subspaces, thereby capturing different aspects of dependencies in the data. The above description process is the calculation process of a single attention mechanism. For the multi-head attention mechanism, it is to use different weights to calculate multiple times, concatenate the results of multiple calculations, and finally scale them to the dimension of the original input by scaling the dot product method to obtain the final attention result.

[0028] In step S3 of this embodiment, the anomaly detection result of whether the multi-source heterogeneous data system is abnormal is obtained by performing anomaly detection based on the graph representation, which is to use the deep support vector data description model Deep SVDD for anomaly detection. Specifically, step S3 of this embodiment includes: combining the graph representation with the hypersphere of normal data points defined in the pre-trained deep support vector data description model Deep SVDD to calculate the anomaly score according to the following formula: , In the above formula, is the abnormality score, For graph representation, is the radius of the hypersphere of the normal data points.

[0029] After encoding multi-source heterogeneous data into graph representation vectors, normal samples are input into Deep Support Vector Data Description (DeepSVDD) to train the classifier. The purpose of training is to learn a distribution center c and a distribution radius R, ensuring that the distance from normal samples to c is less than R, while the distance from abnormal samples to c is greater than R. Therefore, the function expression of the loss function used by the Deep Support Vector Data Description model Deep SVDD during training in this embodiment is: , In the above formula, is the loss function, R is the radius of the hypersphere, is a hyperparameter, is the number of training samples, Indicates taking the maximum value, is the sequence number of the training sample, is the center of the hypersphere. These parameters are used in the Deep SVDD model to define the hypersphere of normal data points in order to distinguish normal and abnormal data points. During the test phase, the model calculates the distance from each sample to the center of the distribution and compares it with the distribution radius to detect anomalies. That is, the anomaly score is calculated according to the following formula: , In the above formula, is the abnormality score, For graph representation, is the radius of the hypersphere of normal data points. As an optional embodiment, if the calculated score (i.e., the square of the distance minus the square of the radius) is greater than 0, the sample is considered to be sufficiently far away from the distribution center of the normal data and is therefore classified as an anomaly. This approach allows the model to identify anomalies without explicit labels because it is based on the difference between the data point and the defined normal data distribution. In an optional embodiment, it can be determined whether a component in the data system is abnormal. In another optional embodiment, it can be further determined whether the data system is abnormal. For example, if any component is abnormal, it can be determined that the data system is abnormal. As an optional embodiment, the anomaly in this embodiment indicates a system failure. In addition, it can also be used to detect other anomalies, such as attacks.

[0030] In order to verify the system anomaly detection method based on graph convolutional self-attention network in this embodiment, based on the log and trace public dataset collected in the open source microservice system TrainTicket V0.2.0, experiments were carried out in this embodiment to verify the feasibility and effectiveness of the method. This system is designed for train ticket booking services and consists of dozens of services written in various programming languages, including Java, Python, and JavaScript. This dataset contains 14 types of anomalies, and all logs and trace data are timestamped. It contains a total of 7,705,050 logs and 132,485 trace data, corresponding to 23,334 anomaly instances.

[0031] Following the method used in previous studies, in this embodiment, 60% of the normal samples in the data set will be used to train the model, 10% will be used as a validation set, and the remaining samples will be used as a test data set. Based on Python 3.9.18 and PyTorch 2.2.2, GCTformer was implemented in this embodiment on a Linux (Ubuntu20.04.4 LTS) server equipped with an Intel Core i7-12700X 4.90GHz processor, 16GB of memory, and an RTX 4080 graphics card with 16GB of GPU memory. The embedding dimension is 300, the number of hidden layers of GCNs is 3, the number of heads n is 10, and the hyperparameter μ is 0.05. The initial learning rate is 1e -4In this example, Adam is used as the optimizer, the batch size is 32, and after 100 epochs of training, the test results are 0.930 in accuracy, 0.978 in recall, and 0.954 in F1 score. This result is better than other methods based on a single data source. This means that integrating multi-source data can significantly improve the overall performance of anomaly detection.

[0032] Furthermore, in this embodiment, an ablation experiment is performed to verify the effectiveness of the Transformer model in GCTformer. In this embodiment, the results of the ablation experiment are visualized by t-SNE (t-Distributed Stochastic Neighbor Embedding). The visualization results are shown in Figure 4 and Figure 5 As shown. Figure 4 and Figure 5 It can be seen that without the help of the Transformer model, the features of normal and abnormal data obtained by the GCTformer model are relatively close, and there is a significant overlap between categories. However, after adding the Transformer model, the inter-class distance in the results obtained by the GCTformer model increases, while the intra-class distance decreases, thus forming a tighter hypersphere. In general, the GCTformer model in this embodiment effectively improves the anomaly detection effect due to the addition of the Transformer model, and has obvious advantages over the traditional anomaly detection method based on a single data source.

[0033] In summary, in response to the problem of lack of methods for fusing heterogeneous data in the existing field of system anomaly detection, this embodiment provides a system anomaly detection method based on graph convolutional self-attention network, which is used to integrate log and trace data for system anomaly detection. First, the log and trace data are converted into event nodes, and they are linked into a heterogeneous directed graph using time and logical relationships. Subsequently, the model GCTformer based on graph convolutional networks GCNs and Transformer models generates feature vectors for anomaly detection, integrating the information of these two data types. Finally, the anomaly detection model using deep support vector data description (deep SVDD) identifies outliers as anomalies in an unsupervised manner by comparing the data point distance with the learned radius. The method of this embodiment converts log and tracking data into event nodes and uses time and logical relationships to link them into a heterogeneous directed data graph, uses a graph convolutional self-attention network to perform graph representation learning on the directed heterogeneous graph to obtain a graph representation, and performs anomaly detection based on the graph representation to obtain an anomaly detection result of whether the multi-source heterogeneous data system is abnormal. The present invention can solve the problem of lack of methods for fusing heterogeneous data in the field of existing system anomaly detection, and effectively integrate the information of system logs and tracking data to realize accurate detection of anomalies in data systems.

[0034] In addition, this embodiment also provides a system anomaly detection system based on a graph convolutional self-attention network, comprising a microprocessor and a memory connected to each other, wherein the microprocessor is programmed or configured to execute the system anomaly detection method based on the graph convolutional self-attention network.

[0035] In addition, this embodiment also provides a computer-readable storage medium, which stores a computer program or instruction, and the computer program or instruction is programmed or configured to execute the system anomaly detection method based on graph convolutional self-attention network through a processor.

[0036] In addition, this embodiment also provides a computer program product, including a computer program or instructions, which are programmed or configured to execute the system anomaly detection method based on graph convolutional self-attention network through a processor.

[0037] Those skilled in the art should understand that the technical solutions provided by the embodiments of the present application may be in the form of methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may take the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes. The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the process Figure 1 A process or multiple processes and / or boxes Figure 1 These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing device to work in a specific way, so that the instructions stored in the computer-readable memory produce a product including an instruction device, which implements the functions specified in the process. Figure 1 A process or multiple processes and / or boxes Figure 1 These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide for implementing the process in the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0038] The above is only a preferred embodiment of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions under the concept of the present invention belong to the protection scope of the present invention. It should be pointed out that for ordinary technicians in this technical field, some improvements and modifications without departing from the principle of the present invention should also be regarded as the protection scope of the present invention.

Claims

1. A system anomaly detection method based on graph convolutional self-attention network, characterized in that: The steps include: S1, converts log and trace data into event nodes and links them into heterogeneous directed data graphs using time and logical relationships, extracts semantic information from the event text of each event in the heterogeneous directed data graph and generates a directed heterogeneous graph; S2, the directed heterogeneous graph is represented by graph convolutional self-attention network to obtain graph representation; S3, anomaly detection is performed based on graph representation to obtain anomaly detection results of whether the multi-source heterogeneous data system is abnormal.

2. The system anomaly detection method based on graph convolutional self-attention network according to claim 1, characterized in that: When converting log and tracking data into event nodes in step S1, converting log data into event nodes includes: using a log parsing tool to parse the log of each component in the data system to extract the corresponding log event, and arranging the log event of each component in the order of generation time to generate a log event sequence.

3. The system anomaly detection method based on graph convolutional self-attention network according to claim 2 is characterized in that: When converting log and tracing data into event nodes in step S1, each tracing record of the tracing data includes activity information of the requesting component and the requested component, a timestamp of the start of the activity, and a timestamp of the end of the activity. Converting the tracing data into event nodes includes: splitting each tracing record into two tracing events, a start event and an end event, and arranging the two tracing events in the order of occurrence for the requesting component and the requested component respectively to generate a tracing event sequence.

4. The system anomaly detection method based on graph convolutional self-attention network according to claim 3 is characterized in that: In step S1, using time and logical relationships to link into a heterogeneous directed data graph includes: inserting the request component and the tracking events in the request component tracking event sequence into the corresponding log event sequence according to the occurrence time, thereby obtaining a heterogeneous directed data graph containing the order of occurrence of log events and tracking events and the time dependency relationship information between different events, and the nodes in the heterogeneous directed data graph are log events and tracking events.

5. The system anomaly detection method based on graph convolutional self-attention network according to claim 4, characterized in that: In step S1, the semantic information of the event text of each event in the heterogeneous directed data graph is extracted and a directed heterogeneous graph is generated, including: the event text of each event in the heterogeneous directed data graph is divided into separate words, and then for each word, a word vector is generated using a pre-trained encoding model, and the word vectors of the words are combined to obtain a sentence vector, and the term frequency-inverse document frequency algorithm TF-IDF is used to determine the weight of each word in the sentence vector, and the sentence vector after adjusting the weight is used as the semantic information of the event, and a sentence vector composed of triples is constructed. Represents a directed heterogeneous graph, where is a set of vertices, is the adjacency matrix, is a node attribute vector, where ~ They are node attribute vectors Included 1st~ The semantic information of each event, the adjacency matrix Contains temporal and logical relationship information between events.

6. The system anomaly detection method based on graph convolutional self-attention network according to claim 1, characterized in that: The graph convolution self-attention network in step S2 includes a graph convolution network GCNs and a Transformer model. In step S2, the directed heterogeneous graph is subjected to graph representation learning using the graph convolution self-attention network to obtain the graph representation, including: extracting a feature matrix from the heterogeneous directed data graph using the graph convolution network GCNs, sorting the nodes in the heterogeneous directed data graph by time to form a heterogeneous data sequence, and inputting the feature matrix and the heterogeneous data sequence into the Transformer model together, so as to obtain the graph representation through the Transformer model for graph representation learning.

7. The system anomaly detection method based on graph convolutional self-attention network according to claim 1, characterized in that: Step S3 includes: combining the graph representation with the hypersphere of normal data points defined in the pre-trained deep support vector data description model Deep SVDD to calculate the anomaly score according to the following formula: , In the above formula, is the abnormality score, For graph representation, is the radius of the hypersphere of the normal data point, and the function expression of the loss function used by the deep support vector data description model Deep SVDD during training is: , In the above formula, is the loss function, is the radius of the hypersphere, is a hyperparameter, is the number of training samples, Indicates taking the maximum value, is the sequence number of the training sample, is the center of the hypersphere.

8. A system anomaly detection system based on a graph convolutional self-attention network, comprising a microprocessor and a memory connected to each other, characterized in that: The microprocessor is programmed or configured to execute the system anomaly detection method based on graph convolutional self-attention network as described in any one of claims 1 to 7.

9. A computer-readable storage medium having a computer program or instruction stored therein, characterized in that: The computer program or instruction is programmed or configured to execute the system anomaly detection method based on graph convolutional self-attention network described in any one of claims 1 to 7 through a processor.

10. A computer program product comprising a computer program or instructions, characterized in that The computer program or instruction is programmed or configured to execute the system anomaly detection method based on graph convolutional self-attention network described in any one of claims 1 to 7 through a processor.

Citation Information

Cited By

  • Abnormal behavior detection system and method based on attitude optimization strategy

    CN120853269A