Data link analysis method, device, equipment and computer program product

By processing and analyzing the data flow received by the server, and using preset policies for call links and associated call analysis, the limitations of API call relationship analysis in complex distributed systems are solved, and more comprehensive and accurate interface call relationship display and optimization suggestions are achieved.

CN119945926AActive Publication Date: 2025-05-06中国邮政储蓄银行股份有限公司
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202411949255.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-05-06
Estimated Expiration
2044-12-27

AI Technical Summary

Technical Problem

The prior art cannot meet the comprehensive, accurate and efficient analysis requirements of API call relationships in complex distributed systems, and there are limitations.

Method used

By obtaining the data flow received by the server, processing and parsing, using preset call link analysis strategies and association call analysis strategies, calling link analysis and association call analysis are carried out, and the final association call analysis results are determined.

Benefits of technology

It realizes a comprehensive display of the call relationship between interfaces, can discover link call relationships, help identify problems such as the call chain being too deep and loop calling, and provides references for interface and business optimization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945926A_ABST
    Figure CN119945926A_ABST
Patent Text Reader

Abstract

The invention discloses a data link analysis method, device and equipment and a computer program product, and the method comprises the steps: obtaining and processing a data stream received by a server, and obtaining a data stream processing result; according to the data stream processing result, carrying out call link analysis by utilizing a preset call link analysis strategy to obtain a call link analysis result; according to the data stream processing result, performing association call analysis by using a preset association call analysis strategy to obtain an initial association call analysis result; and determining a final association call analysis result according to the call link analysis result and the initial association call analysis result. According to the method, the calling relation between the interfaces is comprehensively displayed through calling link analysis and correlation analysis, the link calling relation can be found through calling link analysis, the situations of too deep calling chain, cyclic calling and the like can be conveniently alarmed, the business correlation degree between interface calling can be found through correlation calling analysis, and the calling efficiency is improved. And a reference is provided for a developer to carry out interface and business optimization.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of data link analysis, and in particular to a data link analysis method, apparatus, device and computer program product. Background Art

[0002] In complex distributed systems, the calling relationships between interfaces (APIs) are intricate, forming a huge calling network. In order to effectively manage and optimize these systems, it is particularly important to accurately map and analyze the application program interface links.

[0003] At present, the existing technology provides some solutions for API link analysis and monitoring, but these solutions have certain limitations in practical applications and cannot meet the needs of comprehensive, accurate and efficient analysis of API call relationships in complex distributed systems. Summary of the invention

[0004] Embodiments of the present application provide a data link analysis method, apparatus, device, and computer program product to improve the comprehensiveness and accuracy of data link analysis.

[0005] The present application embodiment adopts the following technical solutions:

[0006] In a first aspect, an embodiment of the present application provides a data link analysis method, the data link analysis method comprising:

[0007] Obtain the data stream received by the server and process it to obtain the data stream processing result;

[0008] According to the data stream processing result, a call link analysis is performed using a preset call link analysis strategy to obtain a call link analysis result;

[0009] According to the data stream processing result, a correlation call analysis is performed using a preset correlation call analysis strategy to obtain an initial correlation call analysis result;

[0010] The final associated call analysis result is determined according to the call link analysis result and the initial associated call analysis result.

[0011] Optionally, acquiring and processing the data stream received by the server to obtain the data stream processing result includes:

[0012] Obtaining and parsing the data stream received by the server to obtain a data stream parsing result, wherein the data stream parsing result includes a source address, a destination address, a request time, and a response time of the request;

[0013] Generate a unique request identifier according to the request type and request path of the data flow;

[0014] The source address, destination address, request time, response time and unique request identifier of the request constitute the data flow processing result.

[0015] Optionally, performing call link analysis according to the data stream processing result by using a preset call link analysis strategy to obtain the call link analysis result includes:

[0016] Determine whether any two requests meet the request call chain condition based on the data stream processing results of any two requests;

[0017] When two requests satisfy the request call chain condition, generating suspected call chain data according to the data flow processing results and call relationship of the two requests;

[0018] Perform statistical analysis on the suspected call link data within a preset time period, and determine the call link analysis result according to the statistical analysis result.

[0019] Optionally, the data stream processing result includes a source address, a destination address, a request time, a response time, and a unique identifier of the request, and any two requests include a first request and a second request. Determining whether any two requests meet the request call chain condition according to the data stream processing results of any two requests includes:

[0020] Determining whether the destination address of the first request is the source address of the second request;

[0021] Determine whether a request time of the first request is earlier than a request time of the second request, and whether an end time of the first request is later than an end time of the second request, the end time being calculated based on the request time and the response time;

[0022] If so, it is determined that the first request and the second request meet the request call chain condition, and the call relationship is that the first request is the calling request of the second request, and the second request is the called request of the first request;

[0023] Otherwise, it is determined that the first request and the second request do not satisfy the request call chain condition.

[0024] Optionally, the performing statistical analysis on the suspected call link data within a preset time period, and determining the call link analysis result according to the statistical analysis result includes:

[0025] According to the suspected call link data within the preset time period, the number of suspected calls between the calling request and the called request within the preset time period and the total number of calls of the calling request are counted;

[0026] The call link analysis result is determined according to the suspected call number and the total call number.

[0027] Optionally, performing correlation call analysis according to the data stream processing result by using a preset correlation call analysis strategy to obtain an initial correlation call analysis result includes:

[0028] Dividing the data stream processing result into request data sets in multiple time zones;

[0029] Based on the request data sets of multiple time zones, the association degree is calculated using the association rule mining algorithm to obtain the association degree between the requests;

[0030] An initial correlation call analysis result is determined according to the correlation between the requests.

[0031] Optionally, the call link analysis result includes an associated request set corresponding to the request, and determining the final associated call analysis result according to the call link analysis result and the initial associated call analysis result includes:

[0032] Determining, according to the call link analysis result and the initial associated call analysis result, whether the associated request set corresponding to the request includes the called request corresponding to the request;

[0033] In the case of inclusion, the called request corresponding to the request is removed from the associated request set to obtain a final associated request set corresponding to the request.

[0034] Optionally, the data link analysis method further includes:

[0035] Generate a call link directed graph according to the call link analysis result;

[0036] Performing call alarm analysis according to the call link directed graph to obtain a call alarm analysis result, wherein the call alarm analysis result includes at least one of a call depth analysis result and a loop call analysis result;

[0037] Determine whether to issue a call alarm according to the call alarm analysis result.

[0038] In a second aspect, an embodiment of the present application further provides a data link analysis device, the data link analysis device comprising:

[0039] An acquisition unit is used to acquire and process the data stream received by the server to obtain a data stream processing result;

[0040] A call link analysis unit, configured to perform call link analysis according to the data stream processing result and using a preset call link analysis strategy to obtain a call link analysis result;

[0041] An associated call analysis unit, configured to perform associated call analysis according to the data stream processing result and using a preset associated call analysis strategy to obtain an initial associated call analysis result;

[0042] The determination unit is used to determine the final associated call analysis result according to the call link analysis result and the initial associated call analysis result.

[0043] In a third aspect, an embodiment of the present application further provides a device, including:

[0044] A processor; and a memory arranged to store computer executable instructions, which, when executed, cause the processor to perform any of the aforementioned data link analysis methods.

[0045] In a fourth aspect, an embodiment of the present application further provides a computer program product, comprising a computer program / instruction, which, when executed by a processor, implements any of the aforementioned data link analysis methods.

[0046] At least one of the above technical solutions adopted in the embodiments of the present application can achieve the following beneficial effects: the data link analysis method in the embodiments of the present application first obtains the data stream received by the server and processes it to obtain the data stream processing result; then, based on the data stream processing result, a call link analysis is performed using a preset call link analysis strategy to obtain a call link analysis result; then, based on the data stream processing result, an associated call analysis is performed using a preset associated call analysis strategy to obtain an initial associated call analysis result; finally, the final associated call analysis result is determined based on the call link analysis result and the initial associated call analysis result. The data link analysis method in the embodiments of the present application more comprehensively displays the call relationship between interfaces through call link analysis and correlation analysis. The call link analysis can discover the link call relationship, which is helpful to warn of the occurrence of situations such as too deep call chains and circular calls. The associated call analysis can discover the degree of business association between interface calls, providing a reference for developers to optimize interfaces and businesses. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0048] Figure 1 A schematic diagram of a data link analysis method in an embodiment of the present application;

[0049] Figure 2 This is a schematic diagram of the structure of a data link analysis device in an embodiment of the present application;

[0050] Figure 3 This is a schematic diagram of the structure of a device in an embodiment of the present application. DETAILED DESCRIPTION

[0051] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in combination with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.

[0052] The technical solutions provided by various embodiments of the present application are described in detail below in conjunction with the accompanying drawings.

[0053] At present, there are many technologies for API link mapping and monitoring. For example, patent document CN202410027783.6 proposes a data feature-based API application interface link mapping method, which obtains traffic access logs through traffic probes and uses the deep traversal algorithm of the graph to restore the upstream and downstream relationships of the application interface in a single request. However, when faced with complex call relationships that may form loops, this method avoids infinite loops by limiting the stack depth and marking the nodes that have appeared, but it cannot effectively discover and handle loop calls, and the analysis scope is limited to upstream and downstream call relationships, lacking a more comprehensive link analysis.

[0054] Patent document CN202110911652.0 proposes a cross-interface link monitoring method, which transforms the business interface process relationship into a complete visual link model by combing key business interfaces, and realizes the establishment of cross-interface request relationships and assignment of business attributes. Although this method can parse out a link of actual request, it relies on a lot of manual combing work, which is not only inefficient, but also difficult to discover some hidden or complex call relationships.

[0055] In addition, patent document CN201710962192.8 provides a method for constructing a link call relationship, which focuses on the visual display of the call link and generates a link call relationship diagram through icons and call time. Although this method has certain advantages in displaying call links, it is incapable of link call analysis and cannot provide developers with in-depth interface and business optimization suggestions.

[0056] In summary, the existing API link mapping and monitoring methods have certain limitations in practical applications and cannot meet the needs of comprehensive, accurate and efficient analysis of API call relationships in complex distributed systems.

[0057] Based on this, the embodiment of the present application provides a data link analysis method, such as Figure 1 As shown, a flow chart of a data link analysis method in an embodiment of the present application is provided, and the data link analysis method at least includes the following steps S110 to S140:

[0058] Step S110, obtaining and processing the data stream received by the server to obtain a data stream processing result.

[0059] When performing data link analysis, it is necessary to first obtain the data streams received by each server. For example, the port of each service that needs to be analyzed can be monitored, including HTTP services and other RPC services, etc., and the network data stream of each service port can be captured using a network traffic capture program, or the program package can be directly inserted through an agent during the service launch to capture the data stream. Of course, the specific method of collecting the data stream of the server can be flexibly set by those skilled in the art according to actual needs, and is not specifically limited here.

[0060] Step S120: Perform call link analysis according to the data stream processing result using a preset call link analysis strategy to obtain a call link analysis result.

[0061] After obtaining the data stream processing results, it is necessary to use the defined call link analysis strategy to perform call link analysis on the data stream processing results. For example, the call link relationship between requests can be analyzed based on the request parameter information contained in the data stream processing results, thereby providing a reliable basis for avoiding subsequent problems such as interface response timeouts and interface anomalies. For example, if the call link analysis shows that request A calls request B, it means that the processing of request B is included in the process of request A being processed.

[0062] Step S130, performing correlation call analysis according to the data flow processing result using a preset correlation call analysis strategy to obtain an initial correlation call analysis result.

[0063] Based on the data stream processing results obtained in the previous steps, it is also necessary to use the defined association call analysis strategy to perform association call analysis on the data stream processing results. The association call analysis can be implemented based on the association rule mining algorithm to obtain the initial association call analysis results. The association call analysis results reflect the degree of association between requests at the business level and can be used as a reference for subsequent developers to optimize interfaces and businesses.

[0064] Step S140, determining a final associated call analysis result according to the call link analysis result and the initial associated call analysis result.

[0065] The ultimate goal of the association call analysis is to achieve optimized design at the interface and business level. For example, if the correlation between two requests is high, it means that the interface or business level design corresponding to the two requests may be highly repeated, so the repeated parts can be optimized uniformly. In the analysis results of the association calls in the above steps, there may be a high degree of correlation between two requests with a call relationship. Therefore, it is necessary to further eliminate the situation where there is a call relationship between the requests from the above initial association call analysis results, so as to obtain the final association call analysis results.

[0066] The data link analysis method of the embodiment of the present application more comprehensively displays the calling relationship between interfaces through call link analysis and correlation analysis. The call link analysis can discover the link call relationship, which helps to warn of situations such as too deep call chains and circular calls. The correlation call analysis can discover the degree of business correlation between interface calls, providing a reference for developers to optimize interfaces and businesses.

[0067] In some embodiments of the present application, the method of acquiring the data stream received by the server and processing it to obtain the data stream processing result includes: acquiring the data stream received by the server and parsing it to obtain the data stream parsing result, the data stream parsing result including the source address, destination address, request time and response time of the request; generating a unique request identifier according to the request type and request path of the data stream; and constituting the source address, destination address, request time, response time and unique request identifier of the request into the data stream processing result.

[0068] The processing of the original data stream received by the server in the embodiment of the present application mainly includes two aspects: on the one hand, the data stream received by each server is parsed using a stream processing framework such as Flink or Spark to parse out the source address, destination address, request time, response time and other information of the request end. On the other hand, a unique identifier is generated for each data stream request. For example, for an HTTP request, the request type (referring to GET, POST, etc.) and the path in the URL can be concatenated into a unique request identifier, and the rest of the source address and destination address and other information can be parsed out through the HTTP protocol.

[0069] In addition, in order to be compatible with more types of service requests, the corresponding stream processing method can be extended according to the connected service protocol. For example, for some custom RPC requests, request parsing and identifier generation can be performed through extended stream processing. The information in the request that can be used to distinguish the same request can be selected as the unique identifier.

[0070] Finally, the source address, destination address, request time, response time and unique request identifier of the request obtained after the above processing constitute the data flow processing result of the request.

[0071] In some embodiments of the present application, the above data stream processing results are diverted. On the one hand, the data stream processing results are persistently stored. The storage database is required to be able to store billions of data and has high requirements for new addition and query performance. For example, ElasticSearch or other databases with these characteristics can be used. This part of the data is used as the data stream processing result of the original request for subsequent related call analysis. On the other hand, the data stream processing result directly enters the call link analysis link.

[0072] In some embodiments of the present application, the call link analysis is performed according to the data flow processing result using a preset call link analysis strategy to obtain the call link analysis result, including: determining whether any two requests meet the request call chain condition according to the data flow processing results of any two requests; when two requests meet the request call chain condition, generating suspected call link data according to the data flow processing results and call relationship of the two requests; performing statistical analysis on the suspected call link data within a preset time period, and determining the call link analysis result according to the statistical analysis result.

[0073] The embodiment of the present application sets a judgment condition for the request call chain based on parameter information such as the source address, destination address, request time, and response time of the request contained in the data flow processing results. The judgment condition for the request call chain is used to determine whether there is a call relationship between the two requests based on the above-mentioned parameter information corresponding to each two requests. If there is a call relationship, that is, the request call chain condition is met, suspected call link data can be generated based on the parameter information corresponding to the two requests, such as the unique identifier of the request.

[0074] It should be noted that, considering the actual scenario, it is possible that two requests happen to meet the set request call chain conditions, but in fact there is no call relationship between the two requests. Therefore, the number of times the above two requests meet the request call chain conditions within a period of time can be statistically analyzed to eliminate the influence of low-probability events, thereby obtaining the final call chain data and improving the accuracy of call chain analysis.

[0075] In some embodiments of the present application, the data flow processing result includes the source address, destination address, request time, response time and request unique identifier of the request, and any two requests include a first request and a second request. The determining whether any two requests meet the request call chain condition based on the data flow processing results of any two requests includes: determining whether the destination address of the first request is the source address of the second request; determining whether the request time of the first request is earlier than the request time of the second request, and whether the end time of the first request is later than the end time of the second request, and the end time is calculated based on the request time and the response time; if so, determining that the first request and the second request meet the request call chain condition, and the calling relationship is that the first request is the calling request of the second request, and the second request is the called request of the first request; otherwise, determining that the first request and the second request do not meet the request call chain condition.

[0076] When judging whether there is a call relationship between two requests A and B, the following two judgment conditions can be used for judgment:

[0077] 1) The destination address of request A is the source address of request B;

[0078] 2) The request time of request A is earlier than the request time of request B, and the end time of request A is later than the end time of request B.

[0079] If request A and request B meet both of the above conditions, it is considered that there is a suspected call relationship between request A and request B, and the call relationship is request A calling request B, or request B is called by request A. If any of the conditions is not met, it is considered that there is no call relationship between request A and request B.

[0080] After determining that the two requests may have a call relationship based on the above judgment conditions, the request unique identifiers of requests A and B can be stored as the calling interface field and the called interface field of a piece of data, respectively, and this part is the suspected call link data. Of course, the specific data of other dimensions can be flexibly set by technicians in this field according to actual needs, and no specific limitation is made here.

[0081] In some embodiments of the present application, the statistical analysis of suspected call link data within a preset time period and determining the call link analysis result based on the statistical analysis result include: based on the suspected call link data within the preset time period, counting the number of suspected calls between the calling request and the called request within the preset time period and the total number of calls of the calling request; determining the call link analysis result based on the suspected number of calls and the total number of calls.

[0082] When confirming whether the suspected call link data in the above embodiment is accurate, a judgment threshold can be set first, and then the total amount of data with the request unique identifier A within a period of time is extracted from the stored original data stream processing results as the total number of calls of request A, and then the amount of data of the suspected call link data with the calling interface field being the request unique identifier of request A and the called interface field being the request unique identifier of request B within the same time period is extracted as the suspected number of calls between requests A and B.

[0083] Calculate the ratio of the number of suspected calls between requests A and B to the total number of calls of request A, and compare the ratio with the above judgment threshold. If it is greater than the threshold, it means that the suspected call relationship between requests A and B is not an accidental event. It can be determined that request B is in the call chain of request A, and request B is the downstream call of request A. The result is stored as the final call link data.

[0084] Through the above statistical analysis process, the calling relationship between requests can be further confirmed, thereby improving the accuracy of the call link analysis.

[0085] In some embodiments of the present application, the associated call analysis is performed based on the data stream processing results using a preset associated call analysis strategy to obtain an initial associated call analysis result, including: dividing the data stream processing results into request data sets in multiple time zones; based on the request data sets in multiple time zones, an association degree is calculated using an association rule mining algorithm to obtain the association degree between the requests; and the initial associated call analysis result is determined based on the association degree between the requests.

[0086] When performing the associated call analysis, an association rule mining algorithm may be used to perform association rule mining on the data stream processing results based on the data stream processing results stored in the aforementioned embodiments to mine the association degree between the requests.

[0087] Based on the implementation principle of the association rule mining algorithm, the embodiment of the present application can first set the sampling interval time t, and sample the original data stream processing results, for example, by using a sliding time window and other methods to take data in several time zones such as 0-t, 0.5t-1.5t, t-2t, 1.5t-2.5t, etc. For all data in each time zone, each request unique identifier corresponds to a request, forming a request data set, and each time zone corresponds to a request data set, and multiple request data sets such as I1 = {A, B, C, D...}, I2 = {B, D, E...}... are obtained. Then, the above request data is processed using the association rule mining algorithm, and the requests with higher correlation for each request are calculated to form an associated request set for each request as the initial associated call analysis result.

[0088] The above association rule mining algorithm can be implemented by, for example, the Apriori algorithm. Of course, those skilled in the art can flexibly select the specific association rule mining algorithm to be adopted according to actual needs, and no specific limitation is made here.

[0089] In some embodiments of the present application, the call link analysis result includes an associated request set corresponding to the request, and determining the final associated call analysis result based on the call link analysis result and the initial associated call analysis result includes: determining whether the associated request set corresponding to the request includes the called request corresponding to the request based on the call link analysis result and the initial associated call analysis result; if included, removing the called request corresponding to the request from the associated request set to obtain a final associated request set corresponding to the request.

[0090] During the associated call analysis, the correlation between two requests A and B that have a calling relationship may be relatively high. Therefore, the associated request set corresponding to request A may include the called request B, that is, the downstream calling request of request A. Therefore, the called request B may be removed from the associated request set corresponding to request A, and the remaining requests are the associated calling requests of request A.

[0091] Through the above-mentioned associated call analysis process, the problem that associated calls cannot be analyzed manually in a multi-node high-availability architecture is solved. Business requests with high relevance can be found quickly, and by eliminating call links, the interference of downstream call interfaces on associated calls is eliminated, making it easier for developers to make corresponding optimization adjustments to interfaces and business pages.

[0092] In some embodiments of the present application, the data link analysis method also includes: generating a call link directed graph based on the call link analysis results; performing a call alarm analysis based on the call link directed graph to obtain a call alarm analysis result, wherein the call alarm analysis result includes at least one of a call depth analysis result and a loop call analysis result; and determining whether to issue a call alarm based on the call alarm analysis result.

[0093] The call alarm analysis of the embodiment of the present application can be divided into two aspects: alarm analysis of call chain depth and alarm analysis of cyclic calls. In the call alarm analysis stage, a directed graph can be drawn based on the call link data in the aforementioned embodiment, with each request as a node of the directed graph. If request B in the call link data is a downstream call request of request A, a directed edge pointing from request A to request B is drawn. Traverse all call link data and draw all edges to obtain the call relationship graph of the request.

[0094] On the one hand, in the interface call, the layered calls of the interface will cause the risk of interface timeout, and also increase the occurrence of interface exceptions, so special attention should be paid to the situation where the call chain is too deep. The call depth threshold can be set according to the business scenario. The value of the edge between the nodes represents the depth of the node. For example, request A calls request B, and request B calls request C. Then the value of the edge between request A and request B is 1, and the value of the edge between request B and request C is 2, and so on. When the value of the edge between the nodes in the directed graph is greater than the set depth threshold, an alarm is issued that the call chain depth is too deep.

[0095] On the other hand, if there is a circular call request in the interface call, it will cause the risk of interface timeout, and the interface thread cannot be released and keeps increasing, causing the program to crash. Therefore, it is necessary to discover the interface circular call and handle it in time. You can use algorithms such as DFS (depth-first search algorithm) and Tarjan algorithm to find the ring in the call relationship graph, so as to issue a circular call alarm in time.

[0096] The present application embodiment also provides a data link analysis device 200, such as Figure 2 As shown, a schematic diagram of the structure of a data link analysis device in an embodiment of the present application is provided, wherein the data link analysis device 200 includes: an acquisition unit 210, a call link analysis unit 220, an associated call analysis unit 230, and a determination unit 240, wherein:

[0097] The acquisition unit 210 is used to acquire and process the data stream received by the server to obtain a data stream processing result;

[0098] A call link analysis unit 220 is used to perform call link analysis according to the data stream processing result using a preset call link analysis strategy to obtain a call link analysis result;

[0099] The associated call analysis unit 230 is used to perform associated call analysis according to the data stream processing result using a preset associated call analysis strategy to obtain an initial associated call analysis result;

[0100] The determination unit 240 is used to determine the final associated call analysis result according to the call link analysis result and the initial associated call analysis result.

[0101] In some embodiments of the present application, the acquisition unit 210 is specifically used to: acquire the data stream received by the server and parse it to obtain a data stream parsing result, wherein the data stream parsing result includes a source address, a destination address, a request time, and a response time of the request; generate a request unique identifier according to a request type and a request path of the data stream; and constitute the data stream processing result by the source address, destination address, request time, response time, and request unique identifier of the request.

[0102] In some embodiments of the present application, the call link analysis unit 220 is specifically used to: determine whether any two requests meet the request call chain condition based on the data flow processing results of any two requests; when two requests meet the request call chain condition, generate suspected call link data based on the data flow processing results and call relationship of the two requests; perform statistical analysis on the suspected call link data within a preset time period, and determine the call link analysis result based on the statistical analysis result.

[0103] In some embodiments of the present application, the data flow processing result includes the source address, destination address, request time, response time and request unique identifier of the request, and any two requests include a first request and a second request. The call link analysis unit 220 is specifically used to: determine whether the destination address of the first request is the source address of the second request; determine whether the request time of the first request is earlier than the request time of the second request, and whether the end time of the first request is later than the end time of the second request, and the end time is calculated based on the request time and the response time; if so, determine that the first request and the second request meet the request call chain condition, and the call relationship is that the first request is the calling request of the second request, and the second request is the called request of the first request; otherwise, determine that the first request and the second request do not meet the request call chain condition.

[0104] In some embodiments of the present application, the call link analysis unit 220 is specifically used to: count the number of suspected calls between the calling request and the called request within the preset time period and the total number of calls of the calling request based on the suspected call link data within the preset time period; determine the call link analysis result based on the suspected number of calls and the total number of calls.

[0105] In some embodiments of the present application, the association call analysis unit 230 is specifically used to: divide the data flow processing results into request data sets in multiple time zones; calculate the correlation degree using an association rule mining algorithm based on the request data sets in multiple time zones to obtain the correlation degree between the requests; and determine the initial association call analysis results based on the correlation degree between the requests.

[0106] In some embodiments of the present application, the call link analysis result includes an associated request set corresponding to the request, and the determination unit 240 is specifically used to: determine whether the associated request set corresponding to the request contains the called request corresponding to the request based on the call link analysis result and the initial associated call analysis result; if contained, remove the called request corresponding to the request from the associated request set to obtain a final associated request set corresponding to the request.

[0107] In some embodiments of the present application, the data link analysis device 200 also includes: a generation unit, which is used to generate a call link directed graph according to the call link analysis result; a call alarm analysis unit, which is used to perform a call alarm analysis according to the call link directed graph to obtain a call alarm analysis result, wherein the call alarm analysis result includes at least one of a call depth analysis result and a loop call analysis result; and a call alarm unit, which is used to determine whether to issue a call alarm according to the call alarm analysis result.

[0108] It can be understood that the above-mentioned data link analysis device can implement the various steps of the data link analysis method provided in the aforementioned embodiment, and the relevant explanations about the data link analysis method are applicable to the data link analysis device and will not be repeated here.

[0109] Figure 3 Schematic diagram of the structure of a device in the embodiment of the present application. Figure 3 As shown, the device includes one or more processors (or processing units), may further include one or more memories coupled to the processors, and may further include a communication module coupled to the processors.

[0110] The communication module can be used to communicate with other devices or apparatuses, such as the transmission or reception of data and / or signals. The communication module can have at least one communication module for communication. The communication module can include any interface necessary for communicating with other devices. Exemplarily, the communication module can be a transceiver, a circuit, a bus, a module, or other types of communication modules.

[0111] The processor may include, but is not limited to, at least one of the following: a general-purpose computer, a special-purpose computer, a microcontroller, a digital signal controller (DSP), or one or more of a controller-based multi-core controller architecture. The device may have multiple processors, such as application-specific integrated circuit chips, which are time-dependent and synchronized with a clock of a main processor.

[0112] The memory may include one or more non-volatile memories and one or more volatile memories. Examples of non-volatile memories include, but are not limited to, at least one of the following: read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, hard disk, compact disc (CD), digital video disc (DVD), or other magnetic storage and / or optical storage. Examples of volatile memories include, but are not limited to, at least one of the following: random access memory (RAM), or other volatile memories that do not persist during the duration of a power outage.

[0113] The computer program includes computer executable instructions executed by an associated processor. The program can be stored in ROM. The processor can perform any suitable actions and processes by loading the program into RAM.

[0114] The possible implementation of the present application can be implemented by means of a program, so that the communication device can perform any process discussed in the above embodiments. The possible implementation of the present application can also be implemented by hardware or by a combination of software and hardware.

[0115] In some embodiments, the program may be tangibly contained in a computer-readable storage medium, which may be included in the device (such as in a memory) or other storage device accessible by the device. The program may be loaded from the computer-readable storage medium to the RAM for execution. The computer-readable storage medium may include any type of tangible non-volatile memory, such as ROM, EPROM, flash memory, hard disk, CD, DVD, etc.

[0116] The present application embodiment also provides a computer-readable storage medium, on which computer instructions or program codes are stored, and when the processor runs the instructions or the program codes, the processor executes the methods and functions involved in any of the above embodiments. Computer-readable media can be any tangible medium containing or storing programs for or related to instruction execution systems, devices or equipment. Computer-readable media can be computer-readable signal media or computer-readable storage media. Computer-readable media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or devices, or any suitable combination thereof. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrations. More detailed examples of computer-readable storage media include electrical connections with one or more wires, magnetic media (e.g., disks, floppy disks, hard disks, tapes, magnetic storage devices), optical media (e.g., optical storage devices, DVDs), semiconductor media (e.g., solid-state hard drives), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), or any suitable combination thereof, etc.

[0117] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The embodiment of the present application also provides at least one computer program product tangibly stored on a non-temporary computer-readable storage medium. The computer program product includes one or more computer executable instructions, such as instructions included in a program module, which are executed in a device on a real or virtual processor of the target to perform the process, method and function involved in any of the above embodiments. When the computer program instruction is loaded and executed on a computer, a process or function according to an embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instruction can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instruction can be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center.

[0118] The present application embodiment also proposes a computer program product, including a computer program or instruction, when the computer program or instruction is run on a computer, the computer is made to perform the process, method and function in the above-mentioned embodiment. Usually, a program module includes routines, programs, libraries, objects, classes, components, data structures, etc. that perform specific tasks or realize specific abstract data types. In various embodiments, the functions of program modules can be combined or divided between program modules as needed. Machine executable instructions for program modules can be executed in local or distributed devices. In distributed devices, program modules can be located in local and remote storage media.

[0119] In general, various embodiments of the present application may be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software, which may be performed by a controller, microprocessor, or other computing device. Although various aspects of the embodiments of the present disclosure are shown and described as block diagrams, flow charts, or using some other graphical representations, it should be understood that the boxes, devices, systems, techniques, or methods described herein may be implemented as, for example, non-limiting examples, hardware, software, firmware, dedicated circuits or logic, general hardware or controllers or other computing devices, or some combination thereof.

[0120] It should be noted that although the embodiments of the present application are described above in conjunction with the accompanying drawings, the above embodiments are not independent of each other, and they can also be combined to obtain other embodiments. The division of the modes, situations, categories and embodiments in the embodiments of the present application is only for the convenience of description and should not constitute a special limitation. The features in the various modes, categories, situations and embodiments can be combined with each other in a logical manner. The various implementation methods of the present application can be combined arbitrarily to achieve different technical effects. The embodiments of the present application no longer list various combinations.

[0121] In addition, although the operation of the method of the present disclosure is described in a particular order in the accompanying drawings, this does not require or imply that these operations must be performed in this particular order, or that all the operations shown must be performed to achieve the desired result. On the contrary, the steps depicted in the flow chart can change the order of execution. Additionally or alternatively, some steps can be omitted, multiple steps can be combined into one step for execution, and / or one step can be decomposed into multiple steps for execution. It should also be noted that the features and functions of two or more devices according to the present disclosure can be embodied in one device. Conversely, the features and functions of a device described above can be further divided into being embodied by multiple devices.

[0122] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0123] The above is only the embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.

Claims

1. A data link analysis method, characterized in that: The data link analysis method comprises: Obtain the data stream received by the server and process it to obtain the data stream processing result; According to the data stream processing result, a call link analysis is performed using a preset call link analysis strategy to obtain a call link analysis result; According to the data stream processing result, a correlation call analysis is performed using a preset correlation call analysis strategy to obtain an initial correlation call analysis result; The final associated call analysis result is determined according to the call link analysis result and the initial associated call analysis result.

2. The data link analysis method according to claim 1, characterized in that: The acquiring and processing of the data stream received by the server to obtain the data stream processing result includes: Obtaining and parsing the data stream received by the server to obtain a data stream parsing result, wherein the data stream parsing result includes a source address, a destination address, a request time, and a response time of the request; Generate a unique request identifier according to the request type and request path of the data flow; The source address, destination address, request time, response time and unique request identifier of the request constitute the data flow processing result.

3. The data link analysis method according to claim 1, characterized in that: The step of performing call link analysis based on the data stream processing result using a preset call link analysis strategy to obtain a call link analysis result includes: Determine whether any two requests meet the request call chain condition based on the data stream processing results of any two requests; When two requests satisfy the request call chain condition, generating suspected call chain data according to the data flow processing results and call relationship of the two requests; Perform statistical analysis on the suspected call link data within a preset time period, and determine the call link analysis result according to the statistical analysis result.

4. The data link analysis method according to claim 3, characterized in that: The data stream processing result includes the source address, destination address, request time, response time and unique identifier of the request, any two requests include a first request and a second request, and determining whether any two requests meet the request call chain condition according to the data stream processing results of any two requests includes: Determining whether the destination address of the first request is the source address of the second request; Determine whether a request time of the first request is earlier than a request time of the second request, and whether an end time of the first request is later than an end time of the second request, the end time being calculated based on the request time and the response time; If so, it is determined that the first request and the second request meet the request call chain condition, and the call relationship is that the first request is the calling request of the second request, and the second request is the called request of the first request; Otherwise, it is determined that the first request and the second request do not satisfy the request call chain condition.

5. The data link analysis method according to claim 4, characterized in that: The performing statistical analysis on the suspected call link data within a preset time period and determining the call link analysis result according to the statistical analysis result includes: According to the suspected call link data within the preset time period, the number of suspected calls between the calling request and the called request within the preset time period and the total number of calls of the calling request are counted; The call link analysis result is determined according to the suspected call number and the total call number.

6. The data link analysis method according to claim 1, characterized in that: The step of performing correlation call analysis based on the data stream processing result and using a preset correlation call analysis strategy to obtain an initial correlation call analysis result includes: Dividing the data stream processing result into request data sets in multiple time zones; Based on the request data sets of multiple time zones, the association degree is calculated using the association rule mining algorithm to obtain the association degree between the requests; An initial correlation call analysis result is determined according to the correlation between the requests.

7. The data link analysis method according to claim 1, characterized in that: The call link analysis result includes a set of associated requests corresponding to the request, and determining the final associated call analysis result according to the call link analysis result and the initial associated call analysis result includes: Determining, according to the call link analysis result and the initial associated call analysis result, whether the associated request set corresponding to the request includes the called request corresponding to the request; In the case of inclusion, the called request corresponding to the request is removed from the associated request set to obtain a final associated request set corresponding to the request.

8. The data link analysis method according to any one of claims 1 to 7, characterized in that: The data link analysis method further comprises: Generate a call link directed graph according to the call link analysis result; Performing call alarm analysis according to the call link directed graph to obtain a call alarm analysis result, wherein the call alarm analysis result includes at least one of a call depth analysis result and a loop call analysis result; Determine whether to issue a call alarm according to the call alarm analysis result.

9. A data link analysis device, characterized in that: The data link analysis device comprises: An acquisition unit is used to acquire and process the data stream received by the server to obtain a data stream processing result; A call link analysis unit, configured to perform call link analysis according to the data stream processing result and using a preset call link analysis strategy to obtain a call link analysis result; An associated call analysis unit, configured to perform associated call analysis according to the data stream processing result and using a preset associated call analysis strategy to obtain an initial associated call analysis result; The determination unit is used to determine the final associated call analysis result according to the call link analysis result and the initial associated call analysis result.

10. A device comprising: processor; and a memory arranged to store computer executable instructions, which, when executed, cause the processor to perform the data link analysis method of any one of claims 1 to 8.

11. A computer-readable storage medium having a computer program / instruction stored thereon, characterized in that: When the computer program / instructions are executed by a processor, the data link analysis method according to any one of claims 1 to 8 is implemented.

12. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the data link analysis method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Link call relation creating method and device, computer device and storage medium

    CN107733710A

  • Cross-interface link monitoring method

    CN113641554A

  • API (Application Program Interface) link surveying and mapping method based on data characteristics

    CN117544423A

  • Service calling dependency relationship analysis method and related device

    CN114285756A

  • Service call chain analysis method and apparatus, and electronic device

    CN115185794A