Data backup recovery method and device based on anomaly detection
By using an abnormal detection method in the data backup and recovery process, identifying abnormal states and performing data recovery, the problems of low data backup and recovery efficiency and success rate in the prior art are solved, and more efficient and reliable data recovery is achieved.
Patent Information
- Application Number
- CN202510098126.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-26
- Publication Date
- 2025-05-06
AI Technical Summary
The existing technology has low efficiency and success rate in data backup and recovery, and cannot meet the high requirements of enterprises for data security, reliability and availability.
The data backup and recovery method based on exception detection is adopted. By exporting the data to be backed up in the target database, obtaining the running parameters, and processing the pulse function sub-model and accumulation model, the abnormal state is identified and data recovery is carried out.
It improves the efficiency and success rate of data backup and recovery methods, and can restore data more quickly and reliably, meeting the high requirements of enterprises for data security and availability.
Smart Images

Figure CN119938408A_ABST
Abstract
Description
[0001] This application is filed on September 26, 2024, with application number 202411348867.6 and invention name "Based on The divisional application of the patent application for "Data backup and recovery method and device for abnormal detection" is hereby filed. Incorporated into this application by reference. Technical Field
[0002] The present application relates to the field of database technology, and in particular to a data backup and recovery method and device based on anomaly detection. Background Art
[0003] As a high-performance in-memory database system, SAP HANA database is widely used in various key business scenarios, such as real-time data analysis and online transaction processing. These business scenarios have extremely high requirements for data security, reliability and availability. Once data is lost or damaged, it may lead to serious consequences such as business interruption, customer loss and even legal disputes. Secondly, with the continuous expansion and complexity of corporate business, the amount of data has exploded, and the traditional manual backup and recovery method can no longer meet the needs of enterprises. The manual backup and recovery method is not only inefficient, but also prone to errors, and cannot ensure the integrity of the backup and the success rate of recovery. Therefore, the efficiency and success rate of the data backup and recovery methods in the prior art are both low. Summary of the invention
[0004] The embodiments of the present application provide a data backup and recovery method and device based on anomaly detection, which can improve the efficiency and success rate of the data backup and recovery method.
[0005] In a first aspect, the data backup and recovery method based on anomaly detection provided by the present application includes: Exporting the data to be backed up in the target database to the backup database according to a first preset period; Acquiring the operating parameters of the target database according to a second preset period; Inputting the operating parameters of each of the second preset periods into the pulse function sub-model respectively, and obtaining the abnormal state identification corresponding to each of the second preset periods output by the pulse function sub-model, wherein the pulse function sub-model refers to a model including a pulse function, and is used to perform pulse processing on the input parameters; Inputting the abnormal state identifiers corresponding to each of the second preset periods into an accumulation model to obtain an abnormality detection result output by the accumulation model, wherein the accumulation model refers to a model for accumulating input data; When the abnormality detection result is an abnormal type, data recovery is performed on the target database based on the information of the backup database.
[0006] Optionally, exporting the data to be backed up in the target database to the backup database according to the first preset period includes: Calling the backint plug-in on the target database to export the data to be backed up according to the first preset period; The data to be backed up is encrypted and then uploaded to the backup database.
[0007] Optionally, the number of the backup databases is at least two, and different backup databases have different database identifiers. The encrypting the data to be backed up and uploading it to the backup databases includes: Splitting the data to be backed up into multiple sub-backup data; Selecting some backup databases from the multiple backup databases as candidate databases to obtain multiple candidate databases; Obtaining a database identifier of the candidate database; Allocating a corresponding database identifier to each of the sub-backup data; Generate a private key and a public key corresponding to the database identifier based on the database identifier; Encrypting the sub-backup data corresponding to the database identifier based on the private key to obtain the sub-encrypted backup data corresponding to the database identifier; Uploading the sub-encrypted backup data corresponding to the database identifier to the candidate database corresponding to the database identifier; The public key is sent to the target database.
[0008] Optionally, when the abnormality detection result is an abnormal type, restoring data of the target database based on the information of the backup database includes: When the abnormality detection result is an abnormal type, obtaining a backup recovery time point; Acquire each backup time point, wherein each backup time point is arranged at intervals according to the first preset period; Obtain a target backup time point that matches the backup and restore time point, the target backup time point being the backup time point before the backup and restore time point or the backup time point after the backup and restore time point; Acquire multiple target sub-encrypted backup data corresponding to the target backup time point that matches the backup recovery time point; At least part of the target sub-encrypted backup data is sent to the target database, so that the target database decrypts the target sub-encrypted backup data based on the public key to restore the data.
[0009] Optionally, the acquiring a plurality of target sub-encrypted backup data corresponding to the target backup time point matching the backup recovery time point includes: Obtaining a private key corresponding to the target backup time point, wherein the private keys of the sub-encrypted backup data at different backup time points are different; Parsing the private key corresponding to the target backup time point to obtain multiple target database identifiers; A plurality of target sub-encrypted backup data corresponding to the target backup time point is searched in the backup database corresponding to the plurality of target database identifiers.
[0010] Optionally, splitting the to-be-backed-up data into a plurality of sub-backup data includes: Obtaining a data storage mode and table size of each first data table in the data to be backed up, wherein the data storage mode includes sequential storage, chain storage, index storage and hash storage; Splitting a first data table whose table size exceeds a first preset value into a plurality of data tables whose table sizes do not exceed the first preset value, to obtain a plurality of second data tables; Put multiple second data tables into multiple different data table sets, determine the data in the data table sets as the sub-backup data, and obtain multiple sub-backup data, wherein the data storage method of the data tables in the same data table set is the same, and the variance of the total size of the data in different data table sets is less than a second preset value.
[0011] Optionally, the backup database includes a first local cache database and a second local cache database, wherein the read and write speed of the first local cache database is greater than the read and write speed of the second local cache database, and the data volume storage upper limit of the first local cache database is less than the data volume storage upper limit of the second local cache database, and the data backup and recovery method based on anomaly detection includes: When the amount of data in the first local cache database is greater than a third preset value, part of the sub-encrypted backup data cached in the first local cache database is transferred to the second local cache database.
[0012] In a second aspect, the data backup and recovery device based on anomaly detection provided by the present application includes: An export module, used for exporting the data to be backed up in the target database to the backup database according to a first preset period; A first acquisition module, used for acquiring the operating parameters of the target database according to a second preset period; a second acquisition module, used to input the operating parameters of each of the second preset periods into a pulse function sub-model, respectively, and obtain abnormal state identifiers corresponding to each of the second preset periods output by the pulse function sub-model, wherein the pulse function sub-model refers to a model including a pulse function, and is used to perform pulse processing on the input parameters; a third acquisition module, configured to input the abnormal state identifiers corresponding to each of the second preset periods into an accumulation model, and obtain the abnormality detection result output by the accumulation model, wherein the accumulation model refers to a model for accumulating input data; A recovery module is used to restore data of the target database based on the information of the backup database when the abnormality detection result is an abnormal type.
[0013] Optionally, exporting the data to be backed up in the target database to the backup database according to the first preset period includes: Calling the backint plug-in on the target database to export the data to be backed up according to the first preset period; The data to be backed up is encrypted and then uploaded to the backup database.
[0014] Optionally, the number of the backup databases is at least two, and different backup databases have different database identifiers. The encrypting the data to be backed up and uploading it to the backup databases includes: Splitting the data to be backed up into multiple sub-backup data; Selecting some backup databases from the multiple backup databases as candidate databases to obtain multiple candidate databases; Obtaining a database identifier of the candidate database; Allocating a corresponding database identifier to each of the sub-backup data; Generate a private key and a public key corresponding to the database identifier based on the database identifier; Encrypting the sub-backup data corresponding to the database identifier based on the private key to obtain the sub-encrypted backup data corresponding to the database identifier; Uploading the sub-encrypted backup data corresponding to the database identifier to the candidate database corresponding to the database identifier; The public key is sent to the target database.
[0015] Optionally, when the abnormality detection result is an abnormal type, restoring data of the target database based on the information of the backup database includes: When the abnormality detection result is an abnormal type, obtaining a backup recovery time point; Acquire each backup time point, wherein each backup time point is arranged at intervals according to the first preset period; Obtain a target backup time point that matches the backup and restore time point, the target backup time point being the backup time point before the backup and restore time point or the backup time point after the backup and restore time point; Acquire multiple target sub-encrypted backup data corresponding to the target backup time point that matches the backup recovery time point; At least part of the target sub-encrypted backup data is sent to the target database, so that the target database decrypts the target sub-encrypted backup data based on the public key to restore the data.
[0016] Optionally, the acquiring a plurality of target sub-encrypted backup data corresponding to the target backup time point matching the backup recovery time point includes: Obtaining a private key corresponding to the target backup time point, wherein the private keys of the sub-encrypted backup data at different backup time points are different; Parsing the private key corresponding to the target backup time point to obtain multiple target database identifiers; A plurality of target sub-encrypted backup data corresponding to the target backup time point is searched in the backup database corresponding to the plurality of target database identifiers.
[0017] Optionally, splitting the to-be-backed-up data into a plurality of sub-backup data includes: Obtaining a data storage mode and table size of each first data table in the data to be backed up, wherein the data storage mode includes sequential storage, chain storage, index storage and hash storage; Splitting a first data table whose table size exceeds a first preset value into a plurality of data tables whose table sizes do not exceed the first preset value, to obtain a plurality of second data tables; Put multiple second data tables into multiple different data table sets, determine the data in the data table sets as the sub-backup data, and obtain multiple sub-backup data, wherein the data storage method of the data tables in the same data table set is the same, and the variance of the total size of the data in different data table sets is less than a second preset value.
[0018] Optionally, the backup database includes a first local cache database and a second local cache database, wherein the read and write speed of the first local cache database is greater than the read and write speed of the second local cache database, and the data volume storage upper limit of the first local cache database is less than the data volume storage upper limit of the second local cache database, and the data backup and recovery method based on anomaly detection includes: When the amount of data in the first local cache database is greater than a third preset value, part of the sub-encrypted backup data cached in the first local cache database is transferred to the second local cache database.
[0019] In a third aspect, the electronic device provided in the present application includes a memory and a processor, the memory stores a computer program, and the processor is used to run the computer program in the memory to implement the steps in the data backup and recovery method based on anomaly detection provided in the present application.
[0020] In a fourth aspect, the computer-readable storage medium provided in the present application stores a plurality of instructions, which are suitable for loading by a processor to implement the steps in the data backup and recovery method based on anomaly detection provided in the present application.
[0021] In a fifth aspect, the computer program product provided in the present application includes a computer program or instructions, which, when executed by a processor, implements the steps in the data backup and recovery method based on anomaly detection provided in the present application.
[0022] In the present application, compared with the related art, the data to be backed up in the target database is exported to the backup database according to the first preset period; the operating parameters of the target database are obtained according to the second preset period; the operating parameters of each second preset period are respectively input into the pulse function sub-model, and the abnormal state identification corresponding to each second preset period output by the pulse function sub-model is obtained, wherein the pulse function sub-model refers to a model containing a pulse function, which is used to pulse the input parameters; the abnormal state identification corresponding to each second preset period is input into the accumulation model, and the abnormal detection result output by the accumulation model is obtained, and the accumulation model refers to a model for accumulating the input data; when the abnormal detection result is an abnormal type, the target database is restored based on the information of the backup database. The present application can improve the efficiency and success rate of the data backup and recovery method. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0024] Figure 1 This is a schematic diagram of a scenario of a data backup and recovery system based on anomaly detection provided by an embodiment of the present application; Figure 2 It is a flowchart of an embodiment of a data backup and recovery method based on anomaly detection provided by an embodiment of the present application; Figure 3 It is a structural schematic diagram of a data backup and recovery device based on anomaly detection provided in an embodiment of the present application; Figure 4 It is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0025] It should be noted that the principles of the present application are illustrated by implementing them in an appropriate computing environment. The following description is based on the illustrated specific embodiments of the present application and should not be considered as limiting other specific embodiments of the present application that are not described in detail herein.
[0026] In the following description of the present application, reference is made to “some embodiments”, which describe a subset of all possible embodiments, but it can be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0027] In the following description of the present application, the terms "first\second\third" involved are merely used to distinguish similar objects and do not represent a specific ordering of the objects. It can be understood that "first\second\third" can be interchanged with a specific order or sequence where permitted, so that the embodiments of the present application described here can be implemented in an order other than that illustrated or described here.
[0028] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0029] In order to improve the effect of data backup and recovery based on anomaly detection, the embodiments of the present application provide a data backup and recovery method based on anomaly detection, a data backup and recovery device based on anomaly detection, an electronic device, a computer-readable storage medium, and a computer program product. The data backup and recovery method based on anomaly detection can be executed by a data backup and recovery device based on anomaly detection, or by an electronic device integrated with the data backup and recovery device based on anomaly detection.
[0030] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of this application.
[0031] Please refer to Figure 1 , the present application also provides a data backup and recovery system based on anomaly detection, such as Figure 1 As shown, the data backup and recovery system based on anomaly detection includes an electronic device 100, and the data backup and recovery device based on anomaly detection provided by the present application is integrated in the electronic device 100.
[0032] Among them, the electronic device 100 can be any device equipped with a processor and has processing capabilities, such as mobile electronic devices with processors such as smart phones, tablet computers, PDAs, laptops, smart speakers, or fixed electronic devices with processors such as desktop computers, televisions, servers, industrial equipment, etc.
[0033] In addition, if Figure 1 As shown, the data backup and recovery system based on anomaly detection may also include a memory 200 for storing original data, intermediate data and result data.
[0034] In the embodiment of the present application, the memory may be a cloud memory. Cloud storage is a new concept extended and developed from the concept of cloud computing. A distributed cloud storage system (hereinafter referred to as the storage system) refers to a storage system that uses cluster applications, grid technology, and distributed storage file systems to bring together a large number of storage devices of various types (storage devices are also called storage nodes) in the network through application software or application interfaces to work together and provide external data storage and business access functions.
[0035] At present, the storage method of the storage system is: create a logical volume, and when creating a logical volume, allocate physical storage space for each logical volume, and the physical storage space may be composed of disks of a storage device or several storage devices. The client stores data on a logical volume, that is, stores the data on the file system. The file system divides the data into many parts, each of which is an object. The object contains not only data but also additional information such as data identification (ID, ID entity). The file system writes each object into the physical storage space of the logical volume, and the file system records the storage location information of each object, so that when the client requests to access the data, the file system can allow the client to access the data according to the storage location information of each object.
[0036] The process of the storage system allocating physical storage space to a logical volume is as follows: based on the estimated capacity of the objects stored in the logical volume (this estimate often has a large margin relative to the actual capacity of the objects to be stored) and the grouping of independent redundant disk arrays (RAID, Redundant Array of Independent Disks), the physical storage space is divided into stripes in advance. A logical volume can be understood as a stripe, thereby allocating physical storage space to the logical volume.
[0037] It should be noted that Figure 1The scenario diagram of the anomaly detection-based data backup and recovery system shown is merely an example. The anomaly detection-based data backup and recovery system and scenario described in the embodiment of the present application are intended to more clearly illustrate the technical solution of the embodiment of the present application, and do not constitute a limitation on the technical solution provided in the embodiment of the present application. A person of ordinary skill in the art can appreciate that, with the evolution of the anomaly detection-based data backup and recovery system and the emergence of new business scenarios, the technical solution provided in the embodiment of the present application is equally applicable to similar technical problems.
[0038] It should be noted that the serial numbers of the following embodiments are not intended to limit the preferred order of the embodiments.
[0039] Please refer to Figure 2 , Figure 2 FIG. 1 is a flow chart of an embodiment of a data backup and recovery method based on anomaly detection provided in an embodiment of the present application. Figure 2 As shown, the process of the data backup and recovery method based on anomaly detection provided by this application is as follows: 201. Export the data to be backed up in the target database to a backup database according to a first preset period.
[0040] In the embodiment of the present application, the target database may be a HANA (High-Performance Analytic Appliance) database or other types of databases. The data of the HANA in-memory database is not only in the memory, but also continuously written to the hard disk, which requires a replication server Replication Server, including Log-based, Trigger-based and ETL-based. These replication servers require Sybase Replication Server, Sybase Replication Server Agent, Sybase Adaptive Server Enterprise (AES, applicability server), etc., as well as HANA Load Controller and BO Data Services. In view of the growing demand of the domestic HANA talent market, a complete HANA training system has also been established.
[0041] In the embodiment of the present application, the backup database is a database for storing backup information. The number of backup databases can be multiple. Each backup database can include a multi-level database.
[0042] In the embodiment of the present application, the data to be backed up is data at a certain moment, and the log file records the database operations between two adjacent data to be backed up.
[0043] Among them, the first preset period can be 12 hours, 24 hours, etc., and the interface is set according to the specific situation.
[0044] In the embodiment of the present application, the target database is a HANA database. The backint plug-in of the HANA database is called according to a first preset period to export the data to be backed up; and the data to be backed up is encrypted and uploaded to the backup database.
[0045] Catalog backup uses Backint to achieve cross-instance recovery. Catalog is the part of the SAP HANA database that maintains metadata, including object definitions (such as the structure of tables and views) and related information about the database system. Catalog backup allows you to rebuild the database structure during disaster recovery. Catalog backup uses Backint: Backint is an API for interfacing with third-party backup software. SAP HANA supports the use of Backint to connect to enterprise-level backup solutions, so that some special backup and recovery requirements (such as Catalog backup) can be implemented through third-party software.
[0046] In the embodiment of the present application, the number of backup databases is at least two, and different backup databases have different database identifiers. Encrypting the data to be backed up and uploading it to the backup database includes: (1) Split the data to be backed up into multiple sub-backup data.
[0047] In a specific embodiment, the data to be backed up is randomly divided into a plurality of sub-backup data.
[0048] In another specific embodiment, the data to be backed up is split into multiple sub-backup data, including: obtaining the data storage method and table size of each first data table in the data to be backed up; splitting the first data table whose table size exceeds a first preset value into multiple data tables whose table sizes do not exceed the first preset value, to obtain multiple second data tables; placing the multiple second data tables into multiple different data table sets, determining the data in the data table sets as sub-backup data, to obtain multiple sub-backup data, wherein the data storage method of the data tables in the same data table set is the same, and the variance of the total size of the data in different data table sets is less than the second preset value.
[0049] The second preset value can be set according to specific circumstances. The data volumes of the sub-backup data are relatively small, and the data storage methods are the same, which can improve storage efficiency.
[0050] Among them, data storage methods include sequential storage, chain storage, index storage and hash storage, etc. Operations between data include insertion, deletion, search, update and sorting operations.
[0051] (2) Selecting some backup databases from the multiple backup databases as candidate databases to obtain multiple candidate databases.
[0052] In a specific embodiment, some backup databases are selected from multiple backup databases as candidate databases to obtain multiple candidate databases, wherein the number of candidate databases is equal to the number of sub-backup databases.
[0053] In another specific embodiment, the remaining space of each backup database is obtained, and a preset number of backup databases with the largest remaining space being ranked first are selected as candidate databases. The preset number can be set according to specific circumstances.
[0054] (3) Obtain the database identifier of the candidate database.
[0055] In the embodiment of the present application, a candidate database has a corresponding database identifier.
[0056] (4) Assign a corresponding database identifier to each sub-backup data.
[0057] Specifically, the total size of the sub-backup data is obtained, and the sub-backup data are sorted from large to small based on the total size to obtain a plurality of sorted sub-backup data. The sub-backup data with a larger total size has a larger remaining space of the candidate database of the database identifier allocated thereto.
[0058] (5) Generate the private key and public key corresponding to the database identifier based on the database identifier.
[0059] The public key is the non-secret half of a key pair used with a private key algorithm. Public keys are often used to encrypt session keys, verify digital signatures, or encrypt data that can be decrypted with the corresponding private key. The public key and private key are a key pair (i.e., a public key and a private key) obtained through an algorithm, one of which is made public to the outside world, called the public key; the other is kept to oneself, called the private key. The key pair obtained by this algorithm is guaranteed to be unique worldwide. When using this key pair, if one of the keys is used to encrypt a piece of data, the other key must be used to decrypt it. If the data is encrypted with the public key, it must be decrypted with the private key. If it is encrypted with the private key, it must also be decrypted with the public key, otherwise the decryption will not be successful.
[0060] In a specific embodiment, a private key corresponding to the database identifier is generated based on the database identifier, and a public key corresponding to the database identifier is generated based on the private key corresponding to the database identifier.
[0061] In a specific embodiment, a random number is randomly generated, and the database identifier is inserted into a specified position of the random number to obtain a private key corresponding to the database identifier. A public key corresponding to the database identifier is generated based on the private key corresponding to the database identifier.
[0062] (6) Encrypt the sub-backup data corresponding to the database identifier based on the private key to obtain the sub-encrypted backup data corresponding to the database identifier.
[0063] (7) Upload the sub-encrypted backup data corresponding to the database identifier to the candidate database corresponding to the database identifier.
[0064] Furthermore, the sub-encrypted backup data corresponding to the database identifier is compressed and uploaded to the candidate database corresponding to the database identifier.
[0065] (8) Send the public key to the target database.
[0066] In an embodiment of the present application, the public key is sent to the target database.
[0067] 202. Obtain operating parameters of the target database according to a second preset period.
[0068] The second preset period may be a preset time period, such as 30 seconds, that is, the operation is repeated every 30 seconds.
[0069] In the embodiment of the present application, the operating parameters of the target database include parameters of database heartbeat, port service or business instruction execution, etc. The operating parameters are used to identify or quantify the normality of the heartbeat, port service or business instruction execution, etc.
[0070] 203. Input the operating parameters of each second preset period into the pulse function sub-model respectively, and obtain the abnormal state identifier corresponding to each second preset period output by the pulse function sub-model.
[0071] In the embodiment of the present application, the pulse function sub-model refers to a model including a pulse function, which is used to perform pulse processing on input parameters.
[0072] In the embodiment of the present application, the pulse function sub-model can be expressed by the following formula:
[0073]
[0074] Among them, y represents the abnormal state flag output by the impulse function sub-model, y=1 represents the abnormal state, y=0 represents the normal state, among which, is the sign function of the impulse function. for The result of the abnormal state identification corresponding to the operating parameters within the time period (a second preset period). t is the time independent variable.
[0075] in, is a pulse function. Each parameter index corresponds to an abnormal standard value , the parameter index corresponds to an operating parameter For example, if the parameter indicator is database heartbeat, if the running parameter Indicates that the database heartbeat link is abnormal. If it cannot be pinged, confirm the operating parameters. Greater than abnormal standard value ; When the parameter indicator is a port service, if the running parameter If the port service cannot be connected, determine the running parameters Greater than abnormal standard value ; When the parameter indicator is a business instruction, if the running parameter If the service instruction is not executed, the operation parameters are determined. Greater than abnormal standard value .
[0076] 204. Input the abnormal state identifiers corresponding to each second preset period into an accumulation model to obtain an abnormality detection result output by the accumulation model, where the accumulation model refers to a model used to accumulate input data.
[0077] The cumulative model refers to a model used to accumulate input data.
[0078] In the embodiment of the present application, the cumulative model can be expressed by the following formula:
[0079] in, To represent the abnormal detection result, if =1, indicating that the anomaly detection result is an anomaly type; if =0, indicating that the abnormal detection result is of normal type; It is expressed as the threshold of the number of times the abnormal state is marked as 1, that is, The abnormal number threshold represents the number of times the abnormal state is marked as an abnormal state. It can be set according to specific circumstances. n represents the number of the second preset cycle.
[0080] In a specific embodiment, historical operation information of the target database is obtained, wherein the historical operation information includes the statistical number of abnormal states within the second preset period before each failure of the target database was identified as an abnormal state, and the product of the average number of statistical times counted when multiple failures occurred and the currently accumulated number n of the second preset periods is determined as the abnormal number threshold.
[0081] 205. When the anomaly detection result is an abnormal type, data recovery is performed on the target database based on the information of the backup database.
[0082] In the embodiment of the present application, when the anomaly detection result is an abnormal type, data recovery of the target database is performed based on the information of the backup database, including: (1) When the anomaly detection result is an abnormal type, obtain the backup recovery time point.
[0083] In the embodiment of the present application, the backup and recovery time point can be 10:20, 10:30, etc., which can be set according to the specific situation. The backup and recovery time point can be a time point of a preset time before the time point when the abnormal detection result is detected as an abnormal type. Among them, the preset time can be set according to the specific situation.
[0084] (2) Obtaining each backup time point, wherein each backup time point is arranged at intervals of a first preset period.
[0085] In the embodiment of the present application, the backup time point is the time point when the backup is started. Therefore, each backup time point corresponds to a data to be backed up. Each first preset period will generate a data to be backed up. For example, the first preset period is one hour, and the backup time points are 10 o'clock, 11 o'clock and 12 o'clock respectively.
[0086] Furthermore, since the data to be backed up is split and encrypted into a plurality of sub-encrypted backup data, one backup time point corresponds to a plurality of sub-encrypted backup data.
[0087] (3) Obtain a target backup time point that matches the backup recovery time point, where the target backup time point is a backup time point before the backup recovery time point or a backup time point after the backup recovery time point.
[0088] In the embodiment of the present application, the backup database stores data in an incremental storage manner.
[0089] In a specific embodiment, the backup time point closest to the backup recovery time point after the backup recovery time point is determined as the first backup time point, and the backup time point closest to the backup recovery time point before the backup recovery time point is determined as the second backup time point. The first backup time point and the second backup time point are randomly determined as target backup time points that match the backup recovery time points.
[0090] (4) Obtain multiple target sub-encrypted backup data corresponding to the target backup time point that matches the backup recovery time point.
[0091] In a specific embodiment, multiple target sub-encrypted backup data corresponding to the target backup time point are searched in each backup database.
[0092] In a specific embodiment, obtaining multiple target sub-encrypted backup data corresponding to a target backup time point that matches a backup recovery time point includes: obtaining a private key corresponding to the target backup time point, wherein the private keys of the sub-encrypted backup data at different backup time points are different; parsing the private key corresponding to the target backup time point to obtain multiple target database identifiers; and searching for multiple target sub-encrypted backup data corresponding to the target backup time point in a backup database corresponding to the multiple target database identifiers.
[0093] Since the private keys at different backup time points are different, the private key is determined according to the target backup time point. Since the private key is determined according to the database identifier, the private key corresponding to the target backup time point is parsed to obtain multiple target database identifiers; multiple target sub-encrypted backup data corresponding to the target backup time point are searched in the backup database corresponding to the multiple target database identifiers.
[0094] (5) Sending at least part of the multiple target sub-encrypted backup data to the target database, so that the target database decrypts the multiple target sub-encrypted backup data based on the public key to restore the data.
[0095] In a specific embodiment, the multiple target sub-encrypted backup data are sent to the target database, so that the target database decrypts the multiple target sub-encrypted backup data based on the public key to restore the data.
[0096] Since the public key has been sent to the target database, after the target database obtains the target sub-encrypted backup data, it can decrypt it to obtain the original data.
[0097] Further, in order to accurately restore the data at the backup recovery time point, when the target backup time point is the first backup time point, a first database operation sequence between the backup recovery time point and the first backup time point is obtained, and the first database operation sequence includes multiple database operations. In the embodiment of the present application, the type of database operation can be an insert operation, a delete operation, a modify operation, etc., which is set according to the specific situation.
[0098] In an embodiment of the present application, a first database operation sequence between the backup recovery time point and the first backup time point is obtained from a log file. Specifically, when the backup database is running, when operations on the data of the backup database are monitored, each database operation performed on the backup database is recorded. For example, the backup recovery time point is 11:10, the first backup time point is 11, an insert operation is performed on the backup database at 11:05, and a delete operation is performed on the backup database at 11:09. The first database operation sequence from the backup recovery time point to the first backup time point includes an insert operation and a delete operation.
[0099] Then, a first database inverse operation sequence of the first database operation sequence is determined based on the first database operation sequence, where the first database inverse operation sequence includes a plurality of database inverse operations corresponding to the plurality of database operations.
[0100] In the embodiment of the present application, the operation time of the multiple database inverse operations corresponding to the multiple database operations is the same, and the operation contents are opposite.
[0101] In an embodiment of the present application, the inverse operation of the insert operation is a delete operation, and the inverse operation of the delete operation is an insert operation. The multiple database inverse operations of the first database inverse operation sequence are delete operations and insert operations, respectively. For example, the backup recovery time point is 11:10, the first backup time point is 11, an insert operation is performed on the backup database at 11:05, and a delete operation is performed on the backup database at 11:09. The first database operation sequence from the backup recovery time point to the first backup time point includes an insert operation at 11:05 and a delete operation at 11:09. The first database inverse operation sequence includes a delete operation at 11:05 and an insert operation at 11:09.
[0102] Finally, the first database reverse operation sequence is sent to the target database, so that the target database performs the decrypted target sub-encrypted backup data according to the first database reverse operation sequence to complete the data recovery.
[0103] When the target backup time point is the second backup time point, a second database operation sequence between the second backup time point and the backup recovery time point is obtained, and the second database operation sequence includes multiple database operations; the second database operation sequence is sent to the target database, so that the target database operates the decrypted target sub-encrypted backup data according to the second database operation sequence to complete the recovery of the data.
[0104] In another specific embodiment, in order to further improve the recovery efficiency, when the target backup time point is the second backup time point, the second database operation sequence between the second backup time point and the backup recovery time point is obtained, and the second database operation sequence includes multiple database operations; the second database operation sequence is split into a first sub-database operation sequence and a second sub-database operation sequence, and the operation time of the first sub-database operation sequence is earlier than that of the second sub-database operation sequence. A first sub-encrypted backup data set composed of the target sub-encrypted backup data operated by the database operation in the first sub-database operation sequence is obtained, and a second sub-encrypted backup data set composed of the target sub-encrypted backup data operated by the database operation in the second sub-database operation sequence is obtained. The first sub-encrypted backup data set and the first sub-database operation sequence are sent to the target database, so that the target database completes partial data recovery according to the first sub-database operation sequence operation of the first sub-encrypted backup data set. The electronic device operates the decrypted second sub-encrypted backup data set according to the second sub-database operation sequence, and sends it to the target database to complete another part of the data recovery. By decrypting and recovering the data separately by the electronic device and the target database, the recovery efficiency can be improved.
[0105] In another specific embodiment, in order to further improve the recovery efficiency, when the target backup time point is the first backup time point, a first database operation sequence between the first backup time point and the backup recovery time point is obtained, and the first database operation sequence includes multiple database operations; a first database inverse operation sequence of the first database operation sequence is determined based on the first database operation sequence, and the first database inverse operation sequence includes multiple database inverse operations corresponding to multiple database operations. The first database inverse operation sequence is split into a third sub-database operation sequence and a fourth sub-database operation sequence, and the operation time of the third sub-database operation sequence is earlier than that of the fourth sub-database operation sequence. A third sub-encrypted backup data set composed of the target sub-encrypted backup data operated by the database operation in the third sub-database operation sequence is obtained, and a fourth sub-encrypted backup data set composed of the target sub-encrypted backup data operated by the database operation in the fourth sub-database operation sequence is obtained. The third sub-encrypted backup data set and the third sub-database operation sequence are sent to the target database, so that the target database operates the third sub-encrypted backup data set decrypted according to the third sub-database operation sequence, and completes partial data recovery. The electronic device operates the fourth sub-encrypted backup data set decrypted according to the fourth sub-database operation sequence, and sends it to the target database to complete another part of the data recovery. By decrypting and recovering data separately through the electronic device and the target database, the recovery efficiency can be improved.
[0106] In order to accurately improve the recovery efficiency, in another specific embodiment, obtaining a target backup time point that matches the backup recovery time point includes: (1) The backup time point closest to the backup recovery time point after the backup recovery time point is determined as the first backup time point, and the backup time point closest to the backup recovery time point before the backup recovery time point is determined as the second backup time point.
[0107] For example, the first preset period is 1 hour. The backup time points in the backup database are 10:00, 11:00, and 12:00. If the backup recovery time point is 11:10, the first backup time point is 11:00, and the second backup time point is 12:00.
[0108] (2) The first backup time point and the second backup time point are respectively determined as candidate backup time points.
[0109] (3) Obtaining a preset weight coefficient of the candidate backup time point and a time difference between the candidate backup time point and the backup recovery time point.
[0110] In the embodiment of the present application, the preset weight coefficient of the first backup time point is less than the preset weight coefficient of the second backup time point. The preset weight coefficient of the first backup time point and the preset weight coefficient of the second backup time point can be set according to the specific situation. For example, the preset weight coefficient of the first backup time point is 1, and the preset weight coefficient of the second backup time point is 1.5, which can be set according to the specific situation. Since the first backup time point is after the backup recovery time point, a reverse operation is required to recover, so a smaller weight is set.
[0111] (4) Obtain the operation position of the database operation between the candidate backup time point and the backup recovery time point.
[0112] In the embodiment of the present application, the operation location of the database operation can be obtained by searching the log file.
[0113] In an embodiment of the present application, the data in the backup database is stored in a data structure of multiple data tables, and the data tables are sequential tables, and the elements of the data structure in the backup database are stored continuously. Since the elements of the data structure in the backup database are stored continuously, and each element can be directly accessed using a subscript. When inserting or deleting elements in the data table of the backup database, it is necessary to move the positions of subsequent elements to maintain the orderliness of the sequential table. For inserting an element with a value of x at subscript position i, it is necessary to move all elements with subscripts i~n-1 to the right by one position, and then insert x into the element at position i. For the deletion operation, it is necessary to move all elements with subscripts i+1~n-1 to the left by one position, and then leave the element with subscript n-1 blank.
[0114] (5) Determine the operational complexity of the database operation based on the operation location of the database operation.
[0115] When the operation position of the database operation is different, the movement of the database operation elements under the operation is different and the operation complexity is different.
[0116] Specifically, the operation position of the database operation in the data table to be operated is obtained, the number of elements between the operation position and the element at the end of the data table to be operated is obtained, and the operation complexity of the database operation is determined based on the number of elements between the operation position and the element at the end of the data table to be operated. The more the number of elements between the operation position and the element at the end of the data table to be operated, the higher the operation complexity.
[0117] (6) Determine the total complexity of database operations between the candidate backup time point and the backup recovery time point based on the operation complexity of each database operation.
[0118] In a specific embodiment, the operation complexity of each database operation is added together to obtain the total complexity of the database operation.
[0119] In another specific embodiment, the operation type of the database operation is obtained, wherein the operation type is a deletion operation, an insertion operation, and a modification operation. The complexity weight of the database operation is determined based on the operation type of the database operation, wherein different operation types correspond to different complexity weights; the operation complexity of the database operation is weighted and summed based on the complexity weight of the database operation to obtain the total complexity of the database operation. Different operation types correspond to different complexity weights, which can be set according to specific circumstances. Specifically, database operations of different operation types are performed on the same operation position of the same data table to be operated in advance to obtain the operation completion time, and the complexity weight of the database operation is determined based on the operation completion time of the database operations of different operation types. Among them, the longer the operation completion time, the higher the complexity weight.
[0120] (7) Determine target evaluation parameters of the candidate backup time point based on a preset weight coefficient of the candidate backup time point, a time difference between the candidate backup time point and the backup recovery time point, and a total complexity of database operations between the candidate backup time point and the backup recovery time point.
[0121] Among them, the smaller the time difference, the larger the target evaluation parameter; the greater the total complexity of database operations, the smaller the number of database operations.
[0122] Furthermore, the number of database operations between the candidate backup time point and the backup recovery time point is obtained, and the target evaluation parameter of the candidate backup time point is determined based on the preset weight coefficient of the candidate backup time point, the time difference between the candidate backup time point and the backup recovery time point, the number of database operations between the candidate backup time point and the backup recovery time point, and the total complexity of database operations between the candidate backup time point and the backup recovery time point. Among them, the smaller the time difference, the larger the target evaluation parameter; the smaller the number of database operations, the larger the target evaluation parameter; the greater the total complexity of database operations, the smaller the number of database operations.
[0123] (6) If the target evaluation parameter of the first backup time point is greater than the target evaluation parameter of the second backup time point, the first backup time point is determined as the target backup time point that matches the backup recovery time point.
[0124] If the target evaluation parameter of the first backup time point is not greater than the target evaluation parameter of the second backup time point, the second backup time point is determined as the target backup time point that matches the backup recovery time point.
[0125] In the embodiment of the present application, the backup database can be a Redis database, a SQLite database, etc., which is set according to the specific situation.
[0126] Furthermore, in order to reduce the amount of target sub-encrypted backup data in the backup database. In a specific embodiment, the backup database includes a first local cache database and a second local cache database, wherein the read and write speed of the first local cache database is greater than the read and write speed of the second local cache database, and the data volume storage upper limit of the first local cache database is less than the data volume storage upper limit of the second local cache database. For example, the first local cache database is Redis data, and the second local cache database is an Hbase database. When the amount of data in the first local cache database is greater than the third preset value, part of the sub-encrypted backup data cached in the first local cache database is transferred to the second local cache database.
[0127] Correspondingly, obtaining multiple target sub-encrypted backup data corresponding to the target backup time point that matches the backup recovery time point includes: first searching the target sub-encrypted backup data at the target backup time point in the first local cache database, and if the target sub-encrypted backup data at the target backup time point does not exist in the first local cache database, searching the target sub-encrypted backup data at the target backup time point in the second local cache database. The first local cache database with a higher read and write speed and the second local cache database with a larger storage capacity cooperate to store data, which can improve the speed of finding data.
[0128] Furthermore, in order to further improve the speed of sub-encrypted backup data, the cache time of each sub-encrypted backup data in the first local cache database is obtained, and the transfer priority of each sub-encrypted backup data is determined based on the cache time of each sub-encrypted backup data, wherein the longer the cache time of the sub-encrypted backup data is, the higher the transfer priority of the sub-encrypted backup data is. When the amount of sub-encrypted backup data cached in the first local cache database is greater than a third preset value, the sub-encrypted backup data with the highest transfer priority is transferred from the first local cache database to the second local cache database.
[0129] Furthermore, in order to further improve the speed of searching for sub-encrypted backup data, the cache time of each sub-encrypted backup data in the first local cache database and the number of times each sub-encrypted backup data is used are obtained, wherein the operation of using the sub-encrypted backup data is sequentially recorded as a number of times used, and the transfer priority of each sub-encrypted backup data is determined based on the cache time and the number of times used of each sub-encrypted backup data, wherein the shorter the cache time of the sub-encrypted backup data, the higher the transfer priority of the sub-encrypted backup data, and the shorter the cache time of the number of times used, the higher the transfer priority of the sub-encrypted backup data. When the amount of sub-encrypted backup data cached in the first local cache database is greater than the third preset value, the sub-encrypted backup data with the highest transfer priority is transferred from the first local cache database to the second local cache database.
[0130] Furthermore, the backup time points of each sub-encrypted backup data in the first local cache database are obtained according to a preset period, each backup time point is determined as a target backup time point, and the backup time point whose time difference with the target backup time point is within a preset time range is determined as a neighborhood time point of the target backup time point, and the number of neighborhood time points of the target backup time point is obtained, and the number of neighborhood time points of each backup time point is obtained. If the target backup time point is the backup time point with the largest number of neighborhood time points, the sub-encrypted backup data corresponding to some of the neighborhood time points of the target backup time point are transferred from the first local cache database to the second local cache database. The preset time range can be less than 3 hours, etc., which can be set according to the specific situation.
[0131] Furthermore, the sub-encrypted backup data corresponding to the neighboring time point closest to the target backup time point is transferred from the first local cache database to the second local cache database.
[0132] In order to facilitate better implementation of the data backup and recovery method based on anomaly detection provided in the embodiment of the present application, the embodiment of the present application also provides a data backup and recovery device based on anomaly detection based on the above-mentioned data backup and recovery method based on anomaly detection. The meaning of the terms is the same as that in the above-mentioned data backup and recovery method based on anomaly detection. For specific implementation details, please refer to the description in the above method embodiment.
[0133] Please refer to Figure 3 , Figure 3 A schematic diagram of the structure of a data backup and recovery device based on anomaly detection provided in an embodiment of the present application, the data backup and recovery device based on anomaly detection may include: The export module 701 is used to export the data to be backed up in the target database to the backup database according to a first preset period; A first acquisition module 702, configured to acquire operating parameters of a target database according to a second preset period; The second acquisition module 703 is used to input the operating parameters of each second preset period into the pulse function sub-model respectively, and obtain the abnormal state identification corresponding to each second preset period output by the pulse function sub-model, wherein the pulse function sub-model refers to a model including a pulse function, and is used to perform pulse processing on the input parameters; The third acquisition module 704 is used to input the abnormal state identification corresponding to each second preset period into the accumulation model to obtain the abnormality detection result output by the accumulation model, where the accumulation model refers to a model used to accumulate input data; The recovery module 705 is used to restore data of the target database based on the information of the backup database when the abnormality detection result is an abnormal type.
[0134] The specific implementation of each of the above modules can be found in the previous embodiments and will not be described in detail here.
[0135] An embodiment of the present application also provides an electronic device, including a memory and a processor, wherein the processor is used to execute the steps in the data backup and recovery method based on anomaly detection provided in this embodiment by calling a computer program stored in the memory.
[0136] Please refer to Figure 4 , Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.
[0137] The electronic device may include components such as a processor 101 with one or more processing cores, a memory 102 with one or more computer-readable storage media, a power supply 103, and an input unit 104. Those skilled in the art will appreciate that the electronic device structure shown in the figure does not constitute a limitation on the electronic device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently. Among them: The processor 101 is the control center of the electronic device, which uses various interfaces and lines to connect various parts of the entire electronic device, and executes various functions of the electronic device and processes data by running or executing software programs and / or modules stored in the memory 102, and calling data stored in the memory 102. Optionally, the processor 101 may include one or more processing cores; optionally, the processor 101 may integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, user interface, and application programs, and the modem processor mainly processes wireless communications. It is understandable that the above-mentioned modem processor may not be integrated into the processor 101.
[0138] The memory 102 can be used to store software programs and modules. The processor 101 executes various functional applications and data processing by running the software programs and modules stored in the memory 102. The memory 102 may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc.; the data storage area may store data created according to the use of the electronic device, etc. In addition, the memory 102 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage devices. Accordingly, the memory 102 may also include a memory controller to provide the processor 101 with access to the memory 102.
[0139] The electronic device also includes a power supply 103 for supplying power to each component. Optionally, the power supply 103 can be logically connected to the processor 101 through a power management system, so as to manage charging, discharging, and power consumption through the power management system. The power supply 103 can also include one or more DC or AC power supplies, recharging systems, power failure detection circuits, power converters or inverters, power status indicators, and other arbitrary components.
[0140] The electronic device may further include an input unit 104, which may be used to receive input digital or character information and generate keyboard, mouse, joystick, optical or trackball signal input related to user settings and function control.
[0141] Although not shown, the electronic device may also include a display unit, an image acquisition component, etc., which will not be described in detail here. Specifically in this embodiment, the processor 101 in the electronic device will load the executable code corresponding to one or more computer programs into the memory 102 according to the following instructions, and the processor 101 will execute the steps in the data backup and recovery method based on abnormal detection provided by the present application, such as: The data to be backed up in the target database is exported to the backup database according to the first preset period; the operating parameters of the target database are obtained according to the second preset period; the operating parameters of each second preset period are respectively input into the pulse function sub-model, and the abnormal state identification corresponding to each second preset period output by the pulse function sub-model is obtained, wherein the pulse function sub-model refers to a model including a pulse function, which is used to perform pulse processing on the input parameters; the abnormal state identification corresponding to each second preset period is input into the accumulation model, and the abnormal detection result output by the accumulation model is obtained, and the accumulation model refers to a model used to accumulate the input data; when the abnormal detection result is an abnormal type, the target database is restored based on the information of the backup database.
[0142] It should be noted that the electronic device provided in the embodiment of the present application and the data backup and recovery method based on anomaly detection in the above embodiment belong to the same concept, and its specific implementation process is detailed in the above related embodiments and will not be repeated here.
[0143] The present application also provides a computer-readable storage medium on which a computer program is stored. When the computer program stored therein is executed on the processor of the electronic device provided in the embodiment of the present application, the processor of the electronic device executes the steps in the data backup and recovery method based on abnormal detection provided in the present application. The storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM), etc.
[0144] The present application also provides a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium. A processor of a computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes various optional implementations of the above-mentioned data backup and recovery method based on anomaly detection.
[0145] The above is a detailed introduction to a data backup and recovery method and device based on anomaly detection provided by the present application. This article uses specific examples to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for technical personnel in this field, according to the idea of the present application, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
[0146] It should be noted that when the above embodiments of the present application are applied to specific products or technologies, the relevant data of the user is involved, and the user's permission or consent is required, and the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
Claims
1. A data backup and recovery method based on anomaly detection, characterized in that: include: Export the data to be backed up in the target database to a backup database according to a first preset period, wherein the number of the backup databases is at least two, and different backup databases have different database identifiers, wherein the backint plug-in on the target database is called according to the first preset period to export the data to be backed up; encrypt the data to be backed up and upload it to the backup database, wherein the data to be backed up is split into a plurality of sub-backup data; select some backup databases from the plurality of backup databases as candidate databases to obtain a plurality of candidate databases, wherein the remaining space amount of each backup database is obtained, and a preset number of backup databases with the largest remaining space amount sorted in descending order are used as candidate databases; obtain the number of the candidate databases database identifier; assigning a corresponding database identifier to each of the sub-backup data, wherein the total data size of the sub-backup data is obtained, and the sub-backup data are sorted from large to small based on the total data size to obtain a plurality of sorted sub-backup data, and the sub-backup data with a larger total data size is assigned a larger amount of remaining space of the candidate database of the database identifier; generating a private key and a public key corresponding to the database identifier based on the database identifier; encrypting the sub-backup data corresponding to the database identifier based on the private key to obtain the sub-encrypted backup data corresponding to the database identifier; uploading the sub-encrypted backup data corresponding to the database identifier to the candidate database corresponding to the database identifier; and sending the public key to the target database; Acquiring the operating parameters of the target database according to a second preset period; Inputting the operating parameters of each of the second preset periods into the pulse function sub-model respectively, and obtaining the abnormal state identification corresponding to each of the second preset periods output by the pulse function sub-model, wherein the pulse function sub-model refers to a model including a pulse function, and is used to perform pulse processing on the input parameters; Inputting the abnormal state identifiers corresponding to each of the second preset periods into an accumulation model to obtain an abnormality detection result output by the accumulation model, wherein the accumulation model refers to a model for accumulating input data; When the abnormality detection result is an abnormal type, restoring data of the target database based on the information of the backup database; Wherein, when the abnormal detection result is an abnormal type, a backup recovery time point is obtained; Obtain each backup time point, wherein each backup time point is arranged at the first preset periodic interval; obtain a target backup time point that matches the backup recovery time point, wherein the target backup time point is the backup time point before the backup recovery time point or the backup time point after the backup recovery time point; wherein the backup time point after the backup recovery time point that is closest to the backup recovery time point is determined as the first backup time point, the backup time point before the backup recovery time point that is closest to the backup recovery time point is determined as the second backup time point, the first backup time point and the second backup time point are respectively determined as candidate backup time points, a preset weight coefficient of the candidate backup time point and a time difference between the candidate backup time point and the backup recovery time point are obtained, the preset weight coefficient of the first backup time point is less than the preset weight coefficient of the second backup time point, and the target backup time point and the backup recovery time point are obtained. determining the operation position of the database operation between the candidate backup time point and the backup recovery time point based on the operation position of the database operation, determining the operation complexity of the database operation based on the operation complexity of each database operation, determining the total complexity of the database operation between the candidate backup time point and the backup recovery time point based on the preset weight coefficient of the candidate backup time point, the time difference between the candidate backup time point and the backup recovery time point, and the total complexity of the database operation between the candidate backup time point and the backup recovery time point, and determining the target evaluation parameter of the candidate backup time point based on the preset weight coefficient of the candidate backup time point, the time difference between the candidate backup time point and the backup recovery time point, and the total complexity of the database operation between the candidate backup time point and the backup recovery time point; if the target evaluation parameter of the first backup time point is greater than the target evaluation parameter of the second backup time point, then determining the first backup time point as the target backup time point that matches the backup recovery time point; if the target evaluation parameter of the first backup time point is not greater than the target evaluation parameter of the second backup time point, then determining the second backup time point as the target backup time point that matches the backup recovery time point; Acquire multiple target sub-encrypted backup data corresponding to the target backup time point that matches the backup recovery time point, wherein a private key corresponding to the target backup time point is acquired, wherein the private keys of the sub-encrypted backup data at different backup time points are different; parse the private key corresponding to the target backup time point to obtain multiple target database identifiers; search for multiple target sub-encrypted backup data corresponding to the target backup time point in the backup database corresponding to the multiple target database identifiers; At least part of the target sub-encrypted backup data is sent to the target database, so that the target database decrypts the target sub-encrypted backup data based on the public key to restore the data.
2. The data backup and recovery method based on anomaly detection according to claim 1 is characterized in that: The step of splitting the to-be-backed-up data into a plurality of sub-backup data includes: Obtaining a data storage mode and table size of each first data table in the data to be backed up, wherein the data storage mode includes sequential storage, chain storage, index storage and hash storage; Splitting a first data table whose table size exceeds a first preset value into a plurality of data tables whose table sizes do not exceed the first preset value, to obtain a plurality of second data tables; Put multiple second data tables into multiple different data table sets, determine the data in the data table sets as the sub-backup data, and obtain multiple sub-backup data, wherein the data storage method of the data tables in the same data table set is the same, and the variance of the total size of the data in different data table sets is less than a second preset value.
3. The data backup and recovery method based on anomaly detection according to claim 1 is characterized in that: The backup database includes a first local cache database and a second local cache database, wherein the read and write speed of the first local cache database is greater than the read and write speed of the second local cache database, and the data volume storage upper limit of the first local cache database is less than the data volume storage upper limit of the second local cache database, and the data backup and recovery method based on abnormality detection includes: When the amount of data in the first local cache database is greater than a third preset value, part of the sub-encrypted backup data cached in the first local cache database is transferred to the second local cache database.
4. A data backup and recovery device based on anomaly detection, characterized in that: include: An export module is used to export the data to be backed up in the target database to a backup database according to a first preset period, the number of the backup databases is at least two, and different backup databases have different database identifiers, wherein the backint plug-in on the target database is called according to the first preset period to export the data to be backed up; the data to be backed up is encrypted and uploaded to the backup database, wherein the data to be backed up is split into multiple sub-backup data; some backup databases are selected from the multiple backup databases as candidate databases to obtain multiple candidate databases, wherein the remaining space amount of each backup database is obtained, and the backup databases with the preset number of remaining space amounts sorted from large to small are used as candidate databases; the candidate data is obtained. The database identifier of the database; assigning a corresponding database identifier to each of the sub-backup data, wherein the total data size of the sub-backup data is obtained, and the sub-backup data are sorted from large to small based on the total data size to obtain a plurality of sorted sub-backup data, and the sub-backup data with a larger total data size has a larger remaining space amount of the candidate database of the database identifier assigned; generating a private key and a public key corresponding to the database identifier based on the database identifier; encrypting the sub-backup data corresponding to the database identifier based on the private key to obtain the sub-encrypted backup data corresponding to the database identifier; uploading the sub-encrypted backup data corresponding to the database identifier to the candidate database corresponding to the database identifier; and sending the public key to the target database; A first acquisition module, used for acquiring the operating parameters of the target database according to a second preset period; a second acquisition module, used to input the operating parameters of each of the second preset periods into a pulse function sub-model, respectively, and obtain abnormal state identifiers corresponding to each of the second preset periods output by the pulse function sub-model, wherein the pulse function sub-model refers to a model including a pulse function, and is used to perform pulse processing on the input parameters; a third acquisition module, configured to input the abnormal state identifiers corresponding to each of the second preset periods into an accumulation model, and obtain the abnormality detection result output by the accumulation model, wherein the accumulation model refers to a model for accumulating input data; A recovery module, used for, when the anomaly detection result is an anomaly type, performing data recovery on the target database based on the information of the backup database, wherein, when the anomaly detection result is an anomaly type, obtaining a backup recovery time point; obtaining each backup time point, wherein each backup time point is arranged at intervals of the first preset period; obtaining a target backup time point matching the backup recovery time point, wherein the target backup time point is the backup time point before the backup recovery time point or the backup time point after the backup recovery time point; wherein the backup time point closest to the backup recovery time point after the backup recovery time point is determined as the first backup time point, determine the backup time point closest to the backup recovery time point before the backup recovery time point as the second backup time point, determine the first backup time point and the second backup time point as candidate backup time points respectively, obtain a preset weight coefficient of the candidate backup time point and a time difference between the candidate backup time point and the backup recovery time point, the preset weight coefficient of the first backup time point is less than the preset weight coefficient of the second backup time point, obtain an operation position of the database operation between the candidate backup time point and the backup recovery time point, determine the operation complexity of the database operation based on the operation position of the database operation, and determine the candidate backup time point and the backup recovery time point based on the operation complexity of each database operation. The total complexity of database operations between time points, based on the preset weight coefficient of the candidate backup time point, the time difference between the candidate backup time point and the backup recovery time point, and the total complexity of database operations between the candidate backup time point and the backup recovery time point, determine the target evaluation parameter of the candidate backup time point; if the target evaluation parameter of the first backup time point is greater than the target evaluation parameter of the second backup time point, the first backup time point is determined as the target backup time point that matches the backup recovery time point; if the target evaluation parameter of the first backup time point is not greater than the target evaluation parameter of the second backup time point, the second backup time point is determined as the target backup time point that matches the backup recovery time point; obtain A plurality of target sub-encrypted backup data corresponding to the target backup time point that matches the backup recovery time point, wherein a private key corresponding to the target backup time point is obtained, wherein the private keys of the sub-encrypted backup data at different backup time points are different; the private key corresponding to the target backup time point is parsed to obtain a plurality of target database identifiers; the plurality of target sub-encrypted backup data corresponding to the target backup time point are searched in the backup database corresponding to the plurality of target database identifiers; at least part of the plurality of target sub-encrypted backup data is sent to the target database, so that the target database decrypts the plurality of target sub-encrypted backup data based on the public key to restore the data.
5. An electronic device, characterized in that: It comprises a memory and a processor, wherein the memory stores a computer program, and the processor is used to run the computer program in the memory to execute the steps in the data backup and recovery method based on anomaly detection as described in any one of claims 1 to 3.
6. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor to execute the steps in the data backup and recovery method based on anomaly detection as described in any one of claims 1 to 3.