Event data detection method and device, equipment and medium

By determining feature vectors and matching detection rules for the detection event data, and using misuse classification models and rule attribute models, the problem of the existing technology being unable to detect and avoid abnormal events is solved, and more efficient and reliable event data detection is achieved, which can help users quickly analyze and resolve abnormal events.

CN119988998APending Publication Date: 2025-05-13BEIJING YOUTEJIE INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510090687.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The prior art cannot detect abnormal evasion events occurring in the business system, resulting in low reliability and effectiveness of event data detection.

Method used

By determining the feature vector of the event data to be detected and matching it with each detection rule, combining the pre-trained misuse classification model and rule attribute model, we judge whether the event data is evasive event data, and output the corresponding alarm information and detection rule sorting sequence.

Benefits of technology

It can detect abnormal events that occur in the business system, improve the reliability and effectiveness of event data detection, and assist users in quickly analyzing and solving abnormal events through detection rules sorting sequences.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119988998A_ABST
    Figure CN119988998A_ABST
Patent Text Reader

Abstract

The invention discloses an event data detection method and device, equipment and a medium. The method comprises the following steps: determining a feature vector of event data to be detected; determining whether a detection rule matched with the to-be-detected event data exists or not, and determining whether the to-be-detected event data is evading event data or not through a misuse classification model; if it is determined that the matched detection rule exists, it is determined that the event is an abnormal event, and alarm information is output; and if it is determined that the event data is the evasion event data, determining that the belonging event is an evasion abnormal event, obtaining a corresponding detection rule sorting sequence through a rule belonging model, and outputting alarm information and the detection rule sorting sequence. According to the embodiment of the invention, the event data can be detected in parallel based on the detection rule and the misuse classification model, whether the event to which the event data belongs is an abnormal event and whether the event is an evasion abnormal event is determined, and the detection rule sorting sequence corresponding to the event data of the evasion abnormal event can be output based on the rule affiliation model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to an event data detection method, device, equipment and medium. Background Art

[0002] The business system of an enterprise will record each event that occurs in the business system and generate event data for each event. The event data of an event can be a text used to describe the event. In order to ensure the normal operation of the business system, the event data is usually detected to determine whether the event to which the event data belongs is an abnormal event that will affect the normal operation of the business system, and output an alarm message when it is determined that the event to which the event data belongs is an abnormal event that will affect the normal operation of the business system. In this way, the operation and maintenance personnel can analyze the detected abnormal events based on the alarm information, quickly determine the cause of the abnormal event and form a solution.

[0003] In the related art, the commonly used event data detection scheme is: detect whether the event data generated by the business system contains the abnormal event keywords of the preset detection rules. If the event data contains the abnormal event keywords of the preset detection rules, it is determined that the event data matches the preset detection rules, and the event to which the event data belongs is an abnormal event. If the event data does not contain the abnormal event keywords of the preset detection rules, it is determined that the event data does not match the preset detection rules, and the event to which the event data belongs is not an abnormal event. However, some abnormal events will use circumvention measures, resulting in the event data of the abnormal events no longer containing the abnormal event keywords of the preset detection rules, and the abnormal events using circumvention measures cannot be detected according to the preset detection rules. The event data detection scheme in the related art detects event data based on preset detection rules, cannot detect abnormal events using circumvention measures, and cannot comprehensively and accurately detect event data, resulting in low reliability and effectiveness of event data detection. Summary of the invention

[0004] The present invention provides an event data detection method, device, equipment and medium to solve the problem that the event data detection scheme in the related art cannot detect the avoidance abnormal events occurring in the business system, cannot comprehensively and accurately detect the event data, resulting in low reliability and effectiveness of event data detection.

[0005] According to one aspect of the present invention, there is provided an event data detection method, comprising:

[0006] Determine the feature vector of the event data to be detected;

[0007] Matching the event data to be detected with each detection rule to determine whether there is a detection rule matching the event data to be detected, and determining whether the event data to be detected is avoidance event data through a pre-trained misuse classification model;

[0008] If it is determined that there is a detection rule matching the event data to be detected, determining that the event to which the event data to be detected belongs is an abnormal event, and outputting alarm information;

[0009] If it is determined that the event data to be detected is avoidance event data, then the event to which the event data to be detected belongs is determined to be an abnormal avoidance event. Through the rule attribution model of each pre-trained detection rule, the detection rule sorting sequence corresponding to the event data to be detected is obtained, and the alarm information and the detection rule sorting sequence are output.

[0010] According to another aspect of the present invention, there is provided an event data detection device, comprising:

[0011] A vector determination module, used to determine a feature vector of the event data to be detected;

[0012] A data detection module, used to match the event data to be detected with each detection rule, determine whether there is a detection rule matching the event data to be detected, and determine whether the event data to be detected is avoidance event data through a pre-trained misuse classification model;

[0013] A first output module, configured to determine that the event to which the event data to be detected belongs is an abnormal event and output alarm information if it is determined that there is a detection rule matching the event data to be detected;

[0014] The second output module is used to determine that the event data to be detected belongs to an abnormal avoidance event if it is determined that the event data to be detected is event avoidance data, obtain the detection rule sorting sequence corresponding to the event data to be detected through the rule attribution model of each pre-trained detection rule, and output the alarm information and the detection rule sorting sequence.

[0015] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0016] at least one processor;

[0017] and a memory communicatively coupled to the at least one processor;

[0018] The memory stores a computer program executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the event data detection method described in any embodiment of the present invention.

[0019] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the event data detection method described in any embodiment of the present invention when executed.

[0020] According to another aspect of the present invention, a computer program product is provided. The computer program product comprises a computer program. When the computer program is executed by a processor, the event data detection method according to any embodiment of the present invention is implemented.

[0021] The technical solution of the embodiment of the present invention determines the feature vector of the event data to be detected; then matches the event data to be detected with each detection rule to determine whether there is a detection rule matching the event data to be detected, and determines whether the event data to be detected is avoidance event data through a pre-trained misuse classification model; if it is determined that there is a detection rule matching the event data to be detected, then the event to which the event data to be detected belongs is determined to be an abnormal event, and an alarm message is output; if it is determined that the event data to be detected is avoidance event data, then the event to which the event data to be detected belongs is determined to be an avoidance abnormal event, and a detection rule sorting sequence corresponding to the event data to be detected is obtained through a rule attribution model of each pre-trained detection rule, and the alarm message and the detection rule sorting sequence are output, thereby solving the problem that the event data detection scheme in the related art cannot detect the avoidance abnormal events occurring in the business system, and cannot comprehensively and accurately classify the event data. The problem of low reliability and effectiveness of event data detection caused by line detection can be solved by detecting event data in parallel based on detection rules and misuse classification models to determine whether the event to which the event data belongs is an abnormal event or whether it is an abnormal event avoidance, and output alarm information when it is determined that the event to which the event data belongs is an abnormal event or an abnormal event avoidance that will affect the normal operation of the business system. It can detect abnormal event avoidance occurring in the business system, and can comprehensively and accurately detect event data to improve the reliability and effectiveness of event data detection. When it is determined that the event to which the event data belongs is an abnormal event avoidance that will affect the normal operation of the business system, based on the rule attribution model of each detection rule, it can determine and output the detection rule sorting sequence corresponding to the event data of the abnormal event avoidance, so as to assist users to quickly and accurately analyze the detected abnormal event avoidance, determine the cause of the abnormal event avoidance and form a solution.

[0022] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0024] Figure 1 The present invention provides a flowchart of an event data detection method according to the first embodiment of the present invention.

[0025] Figure 2 This is a flow chart of an event data detection method provided in Embodiment 2 of the present invention.

[0026] Figure 3 This is a structural diagram of an event data detection device provided in Embodiment 3 of the present invention.

[0027] Figure 4 A schematic diagram of the structure of an electronic device for implementing the event data detection method according to an embodiment of the present invention. DETAILED DESCRIPTION

[0028] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0029] It should be noted that the terms "target", "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprise", "include" and "have" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0030] Embodiment 1

[0031] Figure 1A flowchart of an event data detection method provided in Embodiment 1 of the present invention. This embodiment can be applied to detect event data to determine whether the event to which the event data belongs is an abnormal event that will affect the normal operation of the business system. The method can be executed by an event data detection device, which can be implemented in the form of hardware and / or software, and the event data detection device can be configured in the business system of an enterprise. The business system of an enterprise can be a server set up in the enterprise for processing the business of the enterprise. Business can refer to the process of producing products and providing products to users. For example Figure 1 As shown, the method includes:

[0032] Step 101: Determine the feature vector of the event data to be detected.

[0033] Optionally, various events occurring in the business system include, but are not limited to: the business system performs business-related operations, the user uses the business system to perform business-related operations, and external devices access the business system. Each time the business system performs a business-related operation is an event. Each time a user uses the business system to perform a business-related operation is an event. Each time an external device accesses the business system is an event. The external device may be an electronic device other than the business system. The business system may record various events occurring in the business system and generate event data for each event. The event data of an event may be text used to describe the event. It is necessary to detect the event data of the event to determine whether the event to which the event data belongs is an abnormal event that may affect the normal operation of the business system, and output an alarm message when it is determined that the event to which the event data belongs is an abnormal event that may affect the normal operation of the business system.

[0034] Optionally, the feature vector of the event data may be event data converted into a text vector after vectorization processing. The event data to be detected may be event data that needs to be detected at the current moment. The feature vector of the event data to be detected may be event data to be detected that is converted into a text vector after vectorization processing.

[0035] Optionally, determining the feature vector of the event data to be detected includes: deleting special characters and meaningless information in the event data to be detected; and vectorizing the event data to be detected after the deletion to obtain the feature vector of the event data to be detected.

[0036] Optionally, event data usually contains special characters and meaningless information. Special characters may refer to characters such as quotation marks and backslashes that are irrelevant to the process of determining whether the event to which the event data belongs is an abnormal event that may affect the normal operation of the business system. Meaningless information may refer to information such as timestamps and identification data that are irrelevant to the process of determining whether the event to which the event data belongs is an abnormal event that may affect the normal operation of the business system. Identification data may be data used to uniquely identify a specified device or user. Special characters and meaningless information contained in the event data to be detected may be deleted to obtain the event data to be detected after the deletion processing, and then the event data to be detected after the deletion processing may be vectorized, and the event data to be detected after the deletion processing may be converted into a text vector to obtain a feature vector of the event data to be detected.

[0037] Optionally, the term frequency-inverse document frequency algorithm (TF-IDF algorithm) may be used to vectorize the event data to be detected after the deletion processing, convert the event data to be detected after the deletion processing into a text vector, and obtain a feature vector of the event data to be detected.

[0038] Step 102: Match the event data to be detected with each detection rule to determine whether there is a detection rule matching the event data to be detected, and determine whether the event data to be detected is avoidance event data through a pre-trained misuse classification model.

[0039] Optionally, a plurality of detection rules and abnormal event keywords of each detection rule are pre-stored in the business system. Each detection rule can be used to describe a text of an abnormal event that may affect the normal operation of the business system. The abnormal event keyword of the detection rule can be one or more pre-set words. Generally, the event to which the event data containing the abnormal event keyword of the detection rule belongs is the abnormal event described by the detection rule.

[0040] Optionally, the event data to be detected and each detection rule are matched to determine whether there is a detection rule that matches the event data to be detected, including: respectively detecting whether the event data to be detected contains the abnormal event keywords of each detection rule; if it is detected that the event data to be detected contains the abnormal event keywords of any detection rule, it is determined that there is a detection rule that matches the event data to be detected; if it is detected that the event data to be detected does not contain the abnormal event keywords of any detection rule, it is determined that there is no detection rule that matches the event data to be detected.

[0041] Optionally, the avoidance abnormal event may refer to an abnormal event using an avoidance means. The avoidance event data is event data of the avoidance abnormal event. The avoidance means may refer to hiding information related to the detection rule. The avoidance abnormal event uses an avoidance means, resulting in that the event data of the avoidance abnormal event no longer contains the abnormal event keyword of the detection rule.

[0042] Optionally, determining whether the event data to be detected is avoidance event data is performed through a pre-trained misuse classification model, including: inputting the feature vector of the event data to be detected into the pre-trained misuse classification model, and obtaining the vector type of the feature vector of the event data to be detected output by the misuse classification model; wherein the input of the misuse classification model is the feature vector of the event data, and the output of the misuse classification model is the vector type of the feature vector of the event data, and the vector type is regular or benign; if the vector type of the feature vector of the event data to be detected is regular, determining that the event data to be detected is avoidance event data; if the vector type of the feature vector of the event data to be detected is benign, determining that the event data to be detected is not avoidance event data.

[0043] Optionally, the feature vector of the event data to be detected can be input into a pre-trained misuse classification model to obtain the vector type of the feature vector of the event data to be detected output by the misuse classification model. If the vector type of the feature vector of the event data to be detected is regular, it indicates that the feature vector of the event data to be detected is closer to the regular feature vector, and it can be determined that the event data to be detected is avoidance event data. If the vector type of the feature vector of the event data to be detected is benign, it indicates that the feature vector of the event data to be detected is closer to the benign event feature vector, and it can be determined that the event data to be detected is not avoidance event data.

[0044] Optionally, a pre-trained misuse classification model and a rule attribution model for each detection rule are provided in the business system.

[0045] Optionally, the rule feature vector may be a detection rule that is converted into a text vector after vectorization processing. A benign event is an event that does not affect the normal operation of a business system. Benign event data is event data of a benign event. A benign event feature vector may be benign event data that is converted into a text vector after vectorization processing. The pre-trained misuse classification model is used to analyze and detect the feature vector of the event data and determine the vector type of the feature vector of the event data. The input of the misuse classification model is the feature vector of the event data, and the output of the misuse classification model is the vector type of the feature vector of the event data. The vector type is rule or benign. The vector type of the feature vector of the event data is information used to characterize whether the feature vector of the event data is closer to the rule feature vector or closer to the benign event feature vector. The vector type of the feature vector of the event data is rule, indicating that the feature vector of the event data is closer to the rule feature vector. The vector type of the feature vector of the event data is benign, indicating that the feature vector of the event data is closer to the benign event feature vector. Generally, if the feature vector of the event data is closer to the rule feature vector, it can be determined that the event data is avoidance event data. If the feature vector of the event data is closer to the feature vector of the benign event, it can be determined that the event data is not avoidance event data.

[0046] Optionally, for each detection rule, the rule feature vector of the detection rule is a detection rule converted into a text vector after vectorization processing. The rule attribution model of the detection rule is used to analyze and detect the feature vector of the event data, and determine the similarity between the rule feature vector of the detection rule and the feature vector of the event data. The input of the rule attribution model of the detection rule is the feature vector of the event data, and the output of the rule attribution model of the detection rule is the similarity between the rule feature vector of the detection rule and the feature vector of the event data.

[0047] Optionally, before determining the feature vector of the event data to be detected, it also includes: obtaining each benign event data in the benign event file, and determining the benign event feature vector of each benign event data; determining the rule feature vector of each detection rule; using each benign event feature vector and each rule feature vector as training samples, training the machine learning model, and obtaining a misuse classification model; for each detection rule, using the rule feature vector of the detection rule as a training sample, training the machine learning model, and obtaining a rule attribution model of the detection rule.

[0048] Optionally, the benign event file may be a file pre-set for storing benign event data. The benign event file stores a plurality of pre-collected benign event data. The benign event feature vector of the benign event data may be the benign event data converted into a text vector after vectorization processing. Each benign event data in the benign event file may be obtained to determine the benign event feature vector of each benign event data.

[0049] Optionally, determining the benign event feature vector of each benign event data includes: performing the following operations on each benign event data: deleting special characters and meaningless information in the benign event data; and vectorizing the benign event data after deletion to obtain the benign event feature vector of the benign event data.

[0050] Optionally, determining the rule feature vector of each detection rule includes: performing the following operations for each detection rule: deleting special characters and meaningless information in the detection rule; and vectorizing the deleted detection rule to obtain the rule feature vector of the detection rule.

[0051] Optionally, after determining the benign event feature vector of each benign event data and the rule feature vector of each detection rule, the determined benign event feature vector and the determined rule feature vector can be used as training samples to train the machine learning model to obtain the misuse classification model. For each detection rule, after determining the rule feature vector of the detection rule, the determined rule feature vector can be used as a training sample to train the machine learning model to obtain the rule attribution model of the detection rule.

[0052] Optionally, the pre-trained misuse classification model and the rule attribution model of each detection rule can also be trained by a technician and set in the electronic device. The technician uses the benign event feature vectors of multiple benign event data and the rule feature vectors of each detection rule to train the machine learning model to obtain the misuse classification model, and then sets the misuse classification model in the business system. For each detection rule, the technician uses the rule feature vector of the detection rule to train the machine learning model to obtain the rule attribution model of the detection rule, and then sets the rule attribution model of the detection rule in the business system.

[0053] Step 103: If it is determined that there is a detection rule matching the event data to be detected, then the event to which the event data to be detected belongs is determined to be an abnormal event, and alarm information is output.

[0054] Optionally, under normal circumstances, if it is determined that there is a detection rule matching the event data, the event to which the event data belongs can be determined to be an abnormal event. After determining that there is a detection rule matching the event data to be detected, the event to which the event data to be detected belongs can be determined to be an abnormal event, and an alarm message can be output.

[0055] Optionally, the alarm information may be pre-set information for prompting that an abnormal event has been detected. Outputting the alarm information includes: sending the alarm information to a terminal device of a target user. The target user may be an operation and maintenance personnel responsible for handling abnormal events. The terminal device of the target user may be a terminal device used by the target user. The target user may analyze the abnormal event to which the event data to be detected belongs based on the alarm information, quickly determine the cause of the abnormal event to which the event data to be detected belongs, and form a solution.

[0056] Step 104: If it is determined that the event data to be detected is avoidance event data, then determine that the event to which the event data to be detected belongs is an abnormal avoidance event, obtain a detection rule sorting sequence corresponding to the event data to be detected through a rule attribution model of each pre-trained detection rule, and output alarm information and the detection rule sorting sequence.

[0057] Optionally, the event to which the event data belongs is the event described by the event data. Generally, if it is determined that the event data is avoidance event data, it indicates that the event to which the event data belongs is an avoidance abnormal event. After determining that the event data to be detected is avoidance event data, it can be determined that the event to which the event data to be detected belongs is an avoidance abnormal event, and the detection rule sorting sequence corresponding to the event data to be detected can be obtained through the rule attribution model of each pre-trained detection rule, and the alarm information and the detection rule sorting sequence corresponding to the event data to be detected are output.

[0058] Optionally, a detection rule sorting sequence corresponding to the event data to be detected is obtained through pre-trained rule attribution models of each detection rule, including: respectively inputting the feature vectors of the event data to be detected into the pre-trained rule attribution models of each detection rule, and obtaining the similarity between the rule feature vectors of each detection rule output by the rule attribution model of each detection rule and the feature vector of the event data to be detected; wherein, the input of the rule attribution model of the detection rule is the feature vector of the event data, and the output of the rule attribution model of the detection rule is the similarity between the rule feature vector of the detection rule and the feature vector of the event data; and arranging each detection rule in descending order according to the similarity between the rule feature vector and the feature vector of the event data to be detected, to obtain the detection rule sorting sequence corresponding to the event data to be detected.

[0059] Optionally, for each detection rule, the feature vector of the event data to be detected can be input into the rule attribution model of the detection rule to obtain the similarity between the rule feature vector of the detection rule output by the rule attribution model of the detection rule and the feature vector of the event data to be detected. Then, the detection rules are arranged in order from large to small according to the similarity between the rule feature vector and the feature vector of the event data to be detected, to obtain a detection rule sequence. The obtained detection rule sequence is the detection rule sorting sequence corresponding to the event data to be detected. The detection rule with a higher ranking in the detection rule sorting sequence corresponding to the event data to be detected is more likely to be used to describe the abnormal event avoidance to which the event data to be detected belongs.

[0060] Optionally, outputting the alarm information and the detection rule sorting sequence includes: sending the alarm information and the detection rule sorting sequence to a terminal device of a target user. The target user can analyze the detected abnormal event avoidance to which the event data to be detected belongs based on the alarm information and the detection rule sorting sequence corresponding to the event data to be detected, quickly determine the cause of the abnormal event avoidance to which the event data to be detected belongs, and form a solution.

[0061] Optionally, the method further includes: after detecting the detection rule update information or the benign event data update information, updating the pre-trained misuse classification model and the rule attribution model of each detection rule. The detection rule update information may be information used to indicate that each detection rule has been updated. The benign event data update information may be information used to indicate that the benign event data in the benign event file has been updated.

[0062] Optionally, after detecting the detection rule update information, the pre-trained misuse classification model and the rule attribution model of each detection rule are updated, including: determining the rule feature vectors of each updated detection rule; using each benign event feature vector and each updated rule feature vector as training samples to train the machine learning model to obtain a new misuse classification model; for each detection rule, using the rule feature vector of the updated detection rule as a training sample to train the machine learning model to obtain a new rule attribution model for the detection rule.

[0063] Optionally, after detecting the benign event data update information, the pre-trained misuse classification model and the rule attribution model of each detection rule are updated, including: obtaining each benign event data in the updated benign event file, and determining the benign event feature vector of each benign event data; using each benign event feature vector and each rule feature vector as training samples, training the machine learning model, and obtaining a new misuse classification model.

[0064] Optionally, the cache hit rate, false alarm rate, and detection rate of the pre-trained misuse classification model and the rule attribution model of each detection rule can be counted regularly, and the cache hit rate, false alarm rate, and detection rate can be output. The cache hit rate can be the ratio of the total number of abnormal events detected to the total number of times the model performs detection. The false alarm rate can be the ratio of the total number of abnormal events detected with errors to the total number of times the model performs detection. The detection rate can be the total number of times the model performs detection.

[0065] The technical solution of the embodiment of the present invention determines the feature vector of the event data to be detected; then matches the event data to be detected with each detection rule to determine whether there is a detection rule matching the event data to be detected, and determines whether the event data to be detected is avoidance event data through a pre-trained misuse classification model; if it is determined that there is a detection rule matching the event data to be detected, then the event to which the event data to be detected belongs is determined to be an abnormal event, and an alarm message is output; if it is determined that the event data to be detected is avoidance event data, then the event to which the event data to be detected belongs is determined to be an avoidance abnormal event, and a detection rule sorting sequence corresponding to the event data to be detected is obtained through a rule attribution model of each pre-trained detection rule, and the alarm message and the detection rule sorting sequence are output, thereby solving the problem that the event data detection scheme in the related art cannot detect the avoidance abnormal events occurring in the business system, and cannot comprehensively and accurately classify the event data. The problem of low reliability and effectiveness of event data detection caused by line detection can be solved by detecting event data in parallel based on detection rules and misuse classification models to determine whether the event to which the event data belongs is an abnormal event or whether it is an abnormal event avoidance, and output alarm information when it is determined that the event to which the event data belongs is an abnormal event or an abnormal event avoidance that will affect the normal operation of the business system. It can detect abnormal event avoidance occurring in the business system, and can comprehensively and accurately detect event data to improve the reliability and effectiveness of event data detection. When it is determined that the event to which the event data belongs is an abnormal event avoidance that will affect the normal operation of the business system, based on the rule attribution model of each detection rule, it can determine and output the detection rule sorting sequence corresponding to the event data of the abnormal event avoidance, so as to assist users to quickly and accurately analyze the detected abnormal event avoidance, determine the cause of the abnormal event avoidance and form a solution.

[0066] Embodiment 2

[0067] Figure 2 This is a flow chart of an event data detection method provided in Embodiment 2 of the present invention. This embodiment of the present invention can be combined with each optional solution in one or more of the above embodiments. Figure 2 As shown, the method includes:

[0068] Step 201: Acquire each benign event data in a benign event file, and determine a benign event feature vector of each benign event data.

[0069] Step 202: Determine the rule feature vector of each detection rule.

[0070] Step 203: Use each benign event feature vector and each rule feature vector as training samples to train the machine learning model to obtain a misuse classification model.

[0071] Step 204: For each detection rule, the rule feature vector of the detection rule is used as a training sample to train the machine learning model to obtain a rule attribution model of the detection rule.

[0072] Step 205: Determine the feature vector of the event data to be detected.

[0073] Step 206: Match the event data to be detected with each detection rule to determine whether there is a detection rule matching the event data to be detected, and determine whether the event data to be detected is avoidance event data through a pre-trained misuse classification model.

[0074] Step 207: If it is determined that there is a detection rule matching the event data to be detected, determine that the event to which the event data to be detected belongs is an abnormal event, and output alarm information.

[0075] Step 208: If it is determined that the event data to be detected is avoidance event data, then determine that the event to which the event data to be detected belongs is an abnormal avoidance event, and obtain the detection rule sorting sequence corresponding to the event data to be detected through the rule attribution model of each pre-trained detection rule, and output the alarm information and the detection rule sorting sequence.

[0076] The technical solution of the embodiment of the present invention can detect event data in parallel based on detection rules and misuse classification models, determine whether the event to which the event data belongs is an abnormal event or an abnormal avoidance event, and output alarm information when it is determined that the event to which the event data belongs is an abnormal event or an abnormal avoidance event that will affect the normal operation of the business system. It can detect abnormal avoidance events occurring in the business system, and can comprehensively and accurately detect event data to improve the reliability and effectiveness of event data detection. When it is determined that the event to which the event data belongs is an abnormal avoidance event that will affect the normal operation of the business system, based on the rule attribution model of each detection rule, it can determine and output the detection rule sorting sequence corresponding to the event data of the abnormal avoidance event, assisting users to quickly and accurately analyze the detected abnormal avoidance events, determine the causes of the abnormal avoidance events and form solutions.

[0077] Embodiment 3

[0078] Figure 3 FIG. 1 is a schematic diagram of the structure of an event data detection device provided in Embodiment 3 of the present invention. The device may be configured in an electronic device. Figure 3 As shown, the device includes: a vector determination module 301, a data detection module 302, a first output module 303 and a second output module 304.

[0079] Among them, the vector determination module 301 is used to determine the characteristic vector of the event data to be detected; the data detection module 302 is used to match the event data to be detected with each detection rule, determine whether there is a detection rule matching the event data to be detected, and determine whether the event data to be detected is avoidance event data through a pre-trained misuse classification model; the first output module 303 is used to determine that the event to which the event data to be detected belongs is an abnormal event if it is determined that there is a detection rule matching the event data to be detected, and output alarm information; the second output module 304 is used to determine that the event to which the event data to be detected belongs is an avoidance abnormal event if it is determined that the event data to be detected is avoidance event data, obtain the detection rule sorting sequence corresponding to the event data to be detected through the rule attribution model of each pre-trained detection rule, and output alarm information and the detection rule sorting sequence.

[0080] The technical solution of the embodiment of the present invention determines the feature vector of the event data to be detected; then matches the event data to be detected with each detection rule to determine whether there is a detection rule matching the event data to be detected, and determines whether the event data to be detected is avoidance event data through a pre-trained misuse classification model; if it is determined that there is a detection rule matching the event data to be detected, then the event to which the event data to be detected belongs is determined to be an abnormal event, and an alarm message is output; if it is determined that the event data to be detected is avoidance event data, then the event to which the event data to be detected belongs is determined to be an avoidance abnormal event, and a detection rule sorting sequence corresponding to the event data to be detected is obtained through a rule attribution model of each pre-trained detection rule, and the alarm message and the detection rule sorting sequence are output, thereby solving the problem that the event data detection scheme in the related art cannot detect the avoidance abnormal events occurring in the business system, and cannot comprehensively and accurately classify the event data. The problem of low reliability and effectiveness of event data detection caused by line detection can be solved by detecting event data in parallel based on detection rules and misuse classification models to determine whether the event to which the event data belongs is an abnormal event or whether it is an abnormal event avoidance, and output alarm information when it is determined that the event to which the event data belongs is an abnormal event or an abnormal event avoidance that will affect the normal operation of the business system. It can detect abnormal event avoidance occurring in the business system, and can comprehensively and accurately detect event data to improve the reliability and effectiveness of event data detection. When it is determined that the event to which the event data belongs is an abnormal event avoidance that will affect the normal operation of the business system, based on the rule attribution model of each detection rule, it can determine and output the detection rule sorting sequence corresponding to the event data of the abnormal event avoidance, so as to assist users to quickly and accurately analyze the detected abnormal event avoidance, determine the cause of the abnormal event avoidance and form a solution.

[0081] In an optional implementation of an embodiment of the present invention, optionally, the vector determination module 301 is specifically used to: delete special characters and meaningless information in the event data to be detected; vectorize the event data to be detected after the deletion process to obtain a feature vector of the event data to be detected.

[0082] In an optional implementation of an embodiment of the present invention, optionally, when the data detection module 302 performs an operation of determining whether the event data to be detected is avoidance event data through a pre-trained misuse classification model, it is specifically used to: input the feature vector of the event data to be detected into the pre-trained misuse classification model, and obtain the vector type of the feature vector of the event data to be detected output by the misuse classification model; wherein the input of the misuse classification model is the feature vector of the event data, and the output of the misuse classification model is the vector type of the feature vector of the event data, and the vector type is regular or benign; if the vector type of the feature vector of the event data to be detected is regular, it is determined that the event data to be detected is avoidance event data; if the vector type of the feature vector of the event data to be detected is benign, it is determined that the event data to be detected is not avoidance event data.

[0083] In an optional implementation of the embodiment of the present invention, optionally, when the second output module 304 executes the operation of obtaining the detection rule sorting sequence corresponding to the event data to be detected through the pre-trained rule attribution model of each detection rule, it is specifically used to: input the feature vector of the event data to be detected into the pre-trained rule attribution model of each detection rule, respectively, to obtain the similarity between the rule feature vector of each detection rule output by the rule attribution model of each detection rule and the feature vector of the event data to be detected; wherein, the input of the rule attribution model of the detection rule is the feature vector of the event data, and the output of the rule attribution model of the detection rule is the similarity between the rule feature vector of the detection rule and the feature vector of the event data; and arrange the detection rules in descending order according to the similarity between the rule feature vector and the feature vector of the event data to be detected, to obtain the detection rule sorting sequence corresponding to the event data to be detected.

[0084] In an optional implementation of an embodiment of the present invention, optionally, the event data detection device also includes: a benign event data processing module, which is used to obtain each benign event data in a benign event file and determine the benign event feature vector of each benign event data; a detection rule processing module, which is used to determine the rule feature vector of each detection rule; a first training module, which is used to use each benign event feature vector and each rule feature vector as training samples to train a machine learning model to obtain a misuse classification model; and a second training module, which is used to use the rule feature vector of the detection rule as a training sample for each detection rule to train the machine learning model to obtain a rule attribution model for the detection rule.

[0085] In an optional implementation of an embodiment of the present invention, optionally, the event data detection device also includes: an updating module, which is used to update the pre-trained misuse classification model and the rule attribution model of each detection rule after detecting the detection rule update information or the benign event data update information.

[0086] The event data detection device provided in the embodiment of the present invention can execute the event data detection method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0087] Embodiment 4

[0088] Figure 4 A schematic diagram of the structure of an electronic device 10 that can be used to implement the event data detection method of an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workbenches, personal digital assistants, electronic devices, blade electronic devices, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.

[0089] like Figure 4 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0090] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0091] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 performs the various methods and processes described above, such as the event data detection method.

[0092] In some embodiments, the event data detection method can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit. In some embodiments, part or all of the computer program can be loaded and / or installed on a heterogeneous hardware accelerator via a ROM and / or a communication unit. When the computer program is loaded into RAM and executed by a processor, one or more steps of the event data detection method described above can be performed. Alternatively, in other embodiments, the processor can be configured to perform the event data detection method by any other appropriate means (e.g., by means of firmware).

[0093] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0094] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or electronic device.

[0095] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in combination with an instruction execution system, device or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0096] To provide interaction with a user, the systems and techniques described herein may be implemented on a heterogeneous hardware accelerator having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to a user; and a keyboard and pointing device (e.g., a mouse or trackball) through which a user can provide input to the heterogeneous hardware accelerator. Other types of devices may also be used to provide interaction with a user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).

[0097] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data electronic device), or a computing system that includes middleware components (e.g., an application electronic device), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0098] The computing system may include a client and an electronic device. The client and the electronic device are generally remote from each other and usually interact through a communication network. The relationship between the client and the electronic device is generated by computer programs running on corresponding computers and having a client-electronic device relationship with each other. The electronic device may be a cloud electronic device, also known as a cloud computing electronic device or a cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.

[0099] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.

[0100] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A method for detecting event data, characterized in that: include: Determine the feature vector of the event data to be detected; Matching the event data to be detected with each detection rule to determine whether there is a detection rule matching the event data to be detected, and determining whether the event data to be detected is avoidance event data through a pre-trained misuse classification model; If it is determined that there is a detection rule matching the event data to be detected, determining that the event to which the event data to be detected belongs is an abnormal event, and outputting alarm information; If it is determined that the event data to be detected is avoidance event data, then the event to which the event data to be detected belongs is determined to be an abnormal avoidance event. Through the rule attribution model of each pre-trained detection rule, the detection rule sorting sequence corresponding to the event data to be detected is obtained, and the alarm information and the detection rule sorting sequence are output.

2. The event data detection method according to claim 1, characterized in that: Determine the feature vector of the event data to be detected, including: Delete special characters and meaningless information in the event data to be detected; Vectorization processing is performed on the event data to be detected after the deletion processing to obtain a feature vector of the event data to be detected.

3. The event data detection method according to claim 1, characterized in that: Determining whether the event data to be detected is avoidance event data by using a pre-trained misuse classification model includes: Inputting the feature vector of the event data to be detected into a pre-trained misuse classification model to obtain the vector type of the feature vector of the event data to be detected output by the misuse classification model; wherein the input of the misuse classification model is the feature vector of the event data, the output of the misuse classification model is the vector type of the feature vector of the event data, and the vector type is regular or benign; If the vector type of the feature vector of the event data to be detected is a rule, determining that the event data to be detected is avoidance event data; If the vector type of the feature vector of the event data to be detected is benign, it is determined that the event data to be detected is not avoidance event data.

4. The event data detection method according to claim 1, characterized in that: By using the pre-trained rule attribution model of each detection rule, a detection rule sorting sequence corresponding to the event data to be detected is obtained, including: Input the feature vectors of the event data to be detected into the pre-trained rule attribution models of each detection rule respectively, and obtain the similarity between the rule feature vectors of each detection rule output by the rule attribution model of each detection rule and the feature vector of the event data to be detected; wherein the input of the rule attribution model of the detection rule is the feature vector of the event data, and the output of the rule attribution model of the detection rule is the similarity between the rule feature vector of the detection rule and the feature vector of the event data; The detection rules are arranged in descending order according to the similarity between the rule feature vector and the feature vector of the event data to be detected, so as to obtain a detection rule sorting sequence corresponding to the event data to be detected.

5. The event data detection method according to claim 1, characterized in that: Before determining the feature vector of the event data to be detected, it also includes: Acquire each benign event data in the benign event file, and determine the benign event feature vector of each benign event data; Determine the rule feature vector of each detection rule; Each benign event feature vector and each rule feature vector are used as training samples to train the machine learning model and obtain a misuse classification model; For each detection rule, the rule feature vector of the detection rule is used as a training sample to train the machine learning model to obtain the rule attribution model of the detection rule.

6. The event data detection method according to claim 1, characterized in that: Also includes: After detecting the detection rule update information or the benign event data update information, the pre-trained misuse classification model and the rule attribution model of each detection rule are updated.

7. An event data detection device, characterized in that: include: A vector determination module, used to determine a feature vector of the event data to be detected; A data detection module, used to match the event data to be detected with each detection rule, determine whether there is a detection rule matching the event data to be detected, and determine whether the event data to be detected is avoidance event data through a pre-trained misuse classification model; A first output module, configured to determine that the event to which the event data to be detected belongs is an abnormal event and output alarm information if it is determined that there is a detection rule matching the event data to be detected; The second output module is used to determine that the event data to be detected belongs to an abnormal avoidance event if it is determined that the event data to be detected is event avoidance data, obtain the detection rule sorting sequence corresponding to the event data to be detected through the rule attribution model of each pre-trained detection rule, and output the alarm information and the detection rule sorting sequence.

8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively coupled to the at least one processor; The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the event data detection method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the event data detection method according to any one of claims 1 to 6 when executed.

10. A computer program product, characterized in that The computer program product comprises a computer program, which, when executed by a processor, implements the event data detection method according to any one of claims 1 to 6.