Abnormal data alarm method and device, equipment, storage medium and program product

By building a target model based on machine learning, monitoring and calculating the abnormal probability of network data transmission in real time, the problem of lack of timely detection and alarm in the existing technology is solved, and timely detection and alarm of network data abnormalities in financial applications is realized, and the reliability and user experience of data transmission are improved.

CN120017488AActive Publication Date: 2025-05-16INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510151616.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-05-16
Estimated Expiration
2045-02-11

AI Technical Summary

Technical Problem

The prior art lacks a method to detect abnormalities in network data and alarm in a timely manner, especially in financial applications. When the network environment is poor, data packet loss may be caused, affecting the security of financial information and the reliability of data transmission.

Method used

By obtaining the historical transmission information of the business data of the target business scenario, a target model is constructed. This model is obtained through machine learning multiple groups of sample data, including historical data, data state and the probability of data state change. Monitor data transmission information in real time and input it into the target model to calculate the abnormal probability value. When the probability value of the abnormality is greater than the preset value, determine the data as an abnormality and initiate an alarm.

Benefits of technology

It realizes timely detection of abnormal network data and alarm, improves the reliability and user experience of data transmission in financial applications, reduces the need for manual intervention, and improves processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017488A_ABST
    Figure CN120017488A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an abnormal data alarm method and device, equipment, a storage medium and a program product, and relates to the field of cloud computing. The method comprises the steps that historical transmission information of business data of a target business scene is acquired, a target model is constructed according to historical data carried in the historical transmission information, and the target model is obtained by learning multiple sets of sample data through a machine; each group of data in the multiple groups of sample data comprises historical data, a data state of the historical data and a change probability of the data state; monitoring data transmission information corresponding to a target service scene in real time, and inputting the data transmission information into the target model to obtain an abnormal probability value of the data transmission information; and under the condition that the abnormal probability value is greater than a preset value, determining that the data transmission information is abnormal data, and initiating an abnormal data alarm. According to the method, the effects of timely detecting the abnormity of the network data and giving an alarm are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of cloud computing, and in particular to an abnormal data alarm method, device, equipment, storage medium and program product. Background Art

[0002] Digital transformation has become a major trend in economic development, and all walks of life are exploring and developing digital paths that suit them. However, online financial applications have also caused new problems, such as being heavily dependent on the quality of the network environment. When the network environment is good, financial applications can receive and forward data packets normally. When the network environment is poor, financial applications may not receive complete data packets. Even if there is a timeout retransmission mechanism, it cannot guarantee that the data packet will be transmitted completely next time, and the retransmission time is consumed. Based on the above analysis, fault detection for data packet loss in the network is of great significance to financial information security, financial data transmission, and financial digitization.

[0003] In summary, there is an urgent need for a method to detect anomalies in network data in a timely manner and generate an alarm. Summary of the invention

[0004] The present application provides an abnormal data alarm method, device, equipment, storage medium and program product to solve the current technical problem of lack of a method for timely detecting abnormalities in network data and alarming.

[0005] In a first aspect, the present application provides an abnormal data alarm method, comprising: obtaining historical transmission information of business data of a target business scenario, and constructing a target model based on the historical data carried in the historical transmission information, wherein the target model is obtained by machine learning multiple groups of sample data, and each group of data in the multiple groups of sample data includes: historical data, data status of historical data, and probability of change of data status; real-time monitoring of data transmission information corresponding to the target business scenario, inputting the data transmission information into the target model, and obtaining an abnormal probability value of the data transmission information; when the abnormal probability value is greater than a preset value, determining that the data transmission information is abnormal data, and initiating an abnormal data alarm.

[0006] In the second aspect, the present application provides an abnormal data alarm device, including: an acquisition module, used to acquire historical transmission information of business data of a target business scenario, and build a target model based on the historical data carried in the historical transmission information, wherein the target model is obtained by machine learning multiple groups of sample data, and each group of data in the multiple groups of sample data includes: historical data, data status of historical data, and probability of change of data status; a monitoring module, used to monitor the data transmission information corresponding to the target business scenario in real time, input the data transmission information into the target model, and obtain an abnormal probability value of the data transmission information; an alarm module, used to determine that the data transmission information is abnormal data and initiate an abnormal data alarm when the abnormal probability value is greater than a preset value.

[0007] In a third aspect, the present application provides an electronic device, including: a memory, a processor;

[0008] The memory stores computer-executable instructions;

[0009] The processor executes the computer-executable instructions stored in the memory, so that the processor executes the above first aspect and / or various possible implementations of the first aspect.

[0010] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the first aspect above and / or various possible implementations of the first aspect.

[0011] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the above first aspect and / or various possible implementation methods of the first aspect.

[0012] The abnormal data alarm method, device, equipment, storage medium and program product provided by the present application obtain historical transmission information of business data of the target business scenario, and build a target model according to the historical data carried in the historical transmission information, wherein the target model is obtained by machine learning multiple groups of sample data, and each group of data in the multiple groups of sample data includes: historical data, data status of historical data, and probability of change of data status; real-time monitoring of data transmission information corresponding to the target business scenario, inputting the data transmission information into the target model, and obtaining an abnormal probability value of the data transmission information; when the abnormal probability value is greater than a preset value, determining that the data transmission information is abnormal data, initiating an abnormal data alarm, and achieving the effect of timely detecting network data anomalies and issuing an alarm. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0014] Figure 1 This is a schematic diagram of an application scenario of the abnormal data alarm method;

[0015] Figure 2 A flow chart of the abnormal data alarm method provided for this application;

[0016] Figure 3 A schematic diagram of the structure of the abnormal data alarm device provided in this application;

[0017] Figure 4 A schematic diagram of the structure of a device for determining a solution for processing abnormal data provided in this application.

[0018] The above drawings have shown clear embodiments of the present application, which will be described in more detail later. These drawings and text descriptions are not intended to limit the scope of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0019] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0020] It should be noted that the abnormal data alarm method, device, equipment, storage medium and product provided in the present application can be used in the field of cloud computing, and can also be used in any field other than the field of cloud computing. The application field of the abnormal data alarm method, device, equipment, storage medium and program product in the present application is not limited.

[0021] The specific application scenario of this application is in daily banking operations, where users initiate requests through online financial applications. Figure 1This is a schematic diagram of the application scenario of the abnormal data alarm method. In the early days, banks relied on manual bookkeeping, and the efficiency of withdrawals and deposits was low. With the development of the digital economy, a series of online financial applications have emerged to replace some manual operations, thereby greatly improving work efficiency. However, online financial applications have also caused new problems, such as heavy dependence on the quality of the network environment. When the network environment is good, financial applications can receive and forward data packets normally. When the network environment is poor, financial applications may not receive complete data packets. Even if there is a timeout retransmission mechanism, it cannot guarantee that the data packet will be transmitted completely next time, and the retransmission time is consumed.

[0022] like Figure 1 As shown in the figure, when a user initiates a request through the client, such as a transaction request, query request, or access request, if the Internet environment is poor, the user's request will not be completely forwarded to the server (bank system server). Or the response data of the server in response to the user's request will not be completely sent to the client. When data abnormality information is sent to the user after it appears, it will seriously affect the user experience.

[0023] The abnormal data alarm method provided in this application is intended to solve the above technical problems in the prior art.

[0024] The technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0025] Figure 2 The flowchart of the abnormal data alarm method provided by this application is as follows: Figure 2 As shown, the method includes:.

[0026] S201: Obtain historical transmission information of business data of a target business scenario, and build a target model according to the historical data carried in the historical transmission information, wherein the target model is obtained by machine learning multiple groups of sample data, and each group of data in the multiple groups of sample data includes: historical data, data status of the historical data, and probability of change of the data status;

[0027] First, you need to collect historical data transmission information for the target business scenario. This data may include various types of business data, such as user behavior logs. Useful features are extracted from the historical data. These features can include the data value itself, timestamp, data status (such as normal or abnormal), and any other relevant contextual information.

[0028] Use a machine learning algorithm to train a Markov jump model. This model learns the probability of data transitioning from one state to another. Specifically, the Markov jump model assumes that the current state depends only on the previous state and has nothing to do with earlier states.

[0029] S202: monitoring data transmission information corresponding to a target business scenario in real time, inputting the data transmission information into the target model, and obtaining an abnormal probability value of the data transmission information;

[0030] While the system is running, data transmission information is monitored in real time. This can be achieved by setting triggers or using a stream processing framework. The data transmission information captured in real time is input into the previously trained Markov jump model. The model calculates an abnormal probability value based on the current data and historical status.

[0031] S203: When the abnormal probability value is greater than a preset value, determine that the data transmission information is abnormal data, and initiate an abnormal data alarm.

[0032] The automated anomaly detection and alarm process reduces the need for manual intervention and improves processing efficiency. By monitoring data transmission information in real time, the probability of anomalies can be predicted based on the monitoring results. Before the abnormal data is sent to users, an alarm can be raised so that administrators can understand and handle the abnormal data in the first place, improving the user experience.

[0033] Through the above method, by acquiring the historical transmission information of the business data of the target business scenario, a target model is constructed according to the historical data carried in the historical transmission information, wherein the target model is obtained by machine learning multiple groups of sample data, and each group of data in the multiple groups of sample data includes: historical data, data status of historical data, and probability of change of data status; the data transmission information corresponding to the target business scenario is monitored in real time, and the data transmission information is input into the target model to obtain the abnormal probability value of the data transmission information; when the abnormal probability value is greater than a preset value, the data transmission information is determined to be abnormal data, and an abnormal data alarm is initiated to achieve the effect of timely detecting network data anomalies and issuing an alarm.

[0034] A threshold of abnormal probability is set in advance. If the abnormal probability value output by the model exceeds this threshold, the data is considered abnormal. Once abnormal data is detected, the system will trigger an alarm mechanism. This may include sending email notifications, SMS reminders, or displaying warning information on the dashboard.

[0035] In an optional embodiment, the data tag carried by the historical data is determined, and the transition probability of the transmission state of the historical data is determined according to the number of changes of the data tag of the historical data in the historical transmission information within a preset time period, wherein the data tag includes at least one of the following: normal transmission data, abnormal transmission data, wherein the data tag is used to indicate the data transmission state of the historical data; a state transfer matrix is ​​constructed according to the transition probabilities corresponding to all historical data, and the state transfer matrix is ​​determined as the target model.

[0036] Normal data transmission: indicates that no errors or abnormalities occur during data transmission.

[0037] Abnormal transmission data: indicates that errors or abnormalities occurred during data transmission, such as data loss, corruption, excessive delay, etc. Count the number of times each data point changes from one state to another within a preset time period. For example, if a data point is "normal transmission data" at the previous moment and becomes "abnormal transmission data" at the next moment, then count one state change.

[0038] According to the number of changes in the statistical data label, the probability of each state transitioning to other states is calculated. For example, if the number of transitions from "normal transmission data" to "abnormal transmission data" is N times, and the total number of "normal transmission data" states is M times, then the transition probability is N / M.

[0039] Fill all the calculated state transition probabilities into a matrix, where the rows represent the current state and the columns represent the next state. This matrix is ​​the state transition matrix in the Markov jump model.

[0040] Once the state transfer matrix is ​​constructed, it can be used as the target model of the Markov jump model to predict the state changes of future data.

[0041] In general, through the above steps, a Markov jump model can be constructed based on historical data to monitor data anomalies in network communication systems. This method can help to detect and handle potential faults in a timely manner and improve the stability and reliability of the system.

[0042] In an optional embodiment, the data response time carried by the historical data is determined; when the data response time is greater than a threshold, the data label of the historical data is determined to be abnormal transmission data; when the data response time is less than or equal to a threshold, the data label of the historical data is determined to be normal transmission data.

[0043] To determine the data response time carried by the historical data, first, the response time of each data point needs to be extracted from the historical data transmission information. The response time refers to the time interval between sending a request and receiving a response.

[0044] According to business needs and system performance, set a reasonable response time threshold. This threshold can be adjusted according to actual conditions to ensure that abnormal situations can be detected in time without causing false alarms due to oversensitivity.

[0045] If the data response time is longer than the preset threshold, the data point is marked as "abnormal transmission data".

[0046] If the data response is less than or equal to the preset threshold, the data point is marked as "normal transmission data".

[0047] The state transition matrix of the Markov jump model is constructed using historical data with data labels. The specific method is to count the number of transitions from each state to other states and calculate the transition probability. In this way, the data response time can be effectively used to assist in judging whether the data transmission is normal or not, thereby improving the accuracy of anomaly detection.

[0048] In an optional embodiment, a first timestamp when the abnormal data alarm is triggered for the first time within a first time period and a second timestamp when the abnormal data alarm is triggered for the second time within the first time period are determined; a difference between the first timestamp and the second timestamp is determined; and if the difference is less than a second preset value, it is determined that the abnormal data alarm will not be initiated.

[0049] It should be noted that the abnormal data represents the difference between the output signal sampled by the adaptive event trigger and the original output information.

[0050] The first and second triggering events of the abnormal data alarm within the first time period are captured by the monitoring or logging system. The two triggers correspond to two different time points, namely the first timestamp and the second timestamp. The first timestamp and the second timestamp are compared to calculate the time difference between the two. This time difference reflects the situation that the abnormal data alarm is triggered continuously in a very short period of time. According to the set second preset value (a time threshold), it is determined whether the time difference is less than the preset value. If the time difference is less than the second preset value, it indicates that the interval between the two triggers is very short, which may be caused by a short-term, non-continuous abnormality. In this case, in order to avoid false alarms or overreactions, the system will decide not to initiate an abnormal data alarm. In this way, frequent alarms caused by short-term fluctuations or transient errors can be effectively reduced, thereby improving the stability and reliability of the system.

[0051] In an optional embodiment, the historical data is input into a preset filter model to obtain noise information corresponding to the historical data; and a noise model is established according to the noise information.

[0052] Input historical data transmission information into the preset filter model. After the historical data is processed by the filter model, the filter will analyze and operate the data according to its internal algorithms and rules. In this process, it will identify which parts of the data may be noise, as well as the characteristics and distribution of these noises. By analyzing and modeling the noise in historical data, we can more accurately understand the characteristics and laws of noise, so as to take corresponding measures to reduce or eliminate the impact of noise on data and improve the quality and credibility of data.

[0053] Based on the results of the data quality assessment, determine whether to allow the target data transmission information to be input into the target model. If the data quality meets the requirements, you can continue with the subsequent analysis and processing; if the data quality does not meet the requirements, you need to return to re-collect or process the data.

[0054] In an optional embodiment, the abnormal transmission node currently corresponding to the abnormal data is determined, and the network status of the abnormal transmission node is monitored; when the network status is abnormal, the previous normal transmission node corresponding to the abnormal data is determined; and a reminder instruction is sent to the normal transmission node to prompt the normal transmission node to forward subsequent data to the backup node corresponding to the abnormal transmission node.

[0055] When abnormal data is detected, the abnormal transmission node corresponding to the abnormal data is first determined. This step is the basis for ensuring the accuracy of subsequent monitoring and processing measures. The network status of the determined abnormal transmission node is monitored. By real-time monitoring of indicators such as network traffic, delay and packet loss rate, it is determined whether there is a problem with the network so that timely countermeasures can be taken. If the network status is abnormal, it is necessary to further determine the previous normal transmission node corresponding to the abnormal data. This helps to understand the specific location and possible causes of the abnormality and provide a basis for subsequent processing. Send a reminder instruction to the determined previous normal transmission node, prompting it to forward subsequent data to the backup node of the abnormal transmission node. This step is to ensure the continuity of data transmission and the reliability of the system. After receiving the reminder instruction, the previous normal transmission node forwards the subsequent data to the backup node of the abnormal transmission node. This can effectively avoid data transmission interruption caused by single point failure and improve the overall stability of the system.

[0056] In an optional embodiment, after the data transmission information is input into the target model, the abnormality type corresponding to the data transmission information and the original abnormality probability corresponding to the abnormality type are determined; based on the weight value corresponding to the abnormality type, the target abnormality probability corresponding to the original abnormality probability is determined; and the target abnormality probability is determined as the abnormality probability value of the data transmission information.

[0057] First, the data transmission information needs to be input into the target model, which can identify anomalies in the data. Once the model identifies anomalies in the data transmission information, it determines the types of these anomalies and calculates the original anomaly probability corresponding to each anomaly type. Next, the target anomaly probability corresponding to the original anomaly probability is calculated based on the weight value corresponding to the anomaly type. The weight value here may be determined based on historical data, expert experience, or business rules, which reflect the importance of different anomaly types in the overall risk assessment. Finally, the calculated target anomaly probability is used as the anomaly probability value of the data transmission information. This probability value can be used for further risk assessment and decision making, such as deciding whether additional monitoring or intervention is needed for data transmission.

[0058] The abnormal data alarm method provided by the present application obtains historical transmission information of business data of the target business scenario, and builds a target model according to the historical data carried in the historical transmission information, wherein the target model is obtained by machine learning multiple groups of sample data, and each group of data in the multiple groups of sample data includes: historical data, data status of historical data, and probability of change of data status; real-time monitoring of data transmission information corresponding to the target business scenario, inputting the data transmission information into the target model, and obtaining an abnormal probability value of the data transmission information; when the abnormal probability value is greater than a preset value, determining that the data transmission information is abnormal data, initiating an abnormal data alarm, and achieving the effect of timely detecting network data anomalies and issuing an alarm.

[0059] Figure 3 The structural diagram of the abnormal data alarm device provided by this application is as follows: Figure 3 As shown, the abnormal data alarm device 30 provided in this embodiment includes:

[0060] The acquisition module 301 is used to acquire historical transmission information of business data of the target business scenario, and build a target model according to the historical data carried in the historical transmission information, wherein the target model is obtained by machine learning multiple groups of sample data, and each group of data in the multiple groups of sample data includes: historical data, data status of the historical data, and probability of change of the data status;

[0061] A monitoring module 302 is used to monitor the data transmission information corresponding to the target business scenario in real time, input the data transmission information into the target model, and obtain an abnormal probability value of the data transmission information;

[0062] The alarm module 303 is used to determine that the data transmission information is abnormal data and initiate an abnormal data alarm when the abnormal probability value is greater than a first preset value.

[0063] In an optional embodiment, the acquisition module 301 is used to determine the data tag carried by the historical data, and determine the transition probability of the transmission state of the historical data based on the number of changes in the data tag of the historical data in the historical transmission information within a preset time period, wherein the data tag includes at least one of the following: normal transmission data, abnormal transmission data, wherein the data tag is used to indicate the data transmission state of the historical data; construct a state transfer matrix based on the transition probabilities corresponding to all historical data, and determine the state transfer matrix as the target model.

[0064] In an optional embodiment, the acquisition module 301 is used to determine the data response time carried by the historical data; when the data response time is greater than a threshold, the data label of the historical data is determined to be abnormal transmission data; when the data response time is less than or equal to a threshold, the data label of the historical data is determined to be normal transmission data.

[0065] In an optional embodiment, the device also includes: an alarm module (not shown in the figure), which is used to determine a first timestamp when the abnormal data alarm is triggered for the first time within a first time period and a second timestamp when the abnormal data alarm is triggered for the second time within the first time period; determine the difference between the first timestamp and the second timestamp; and determine not to initiate the abnormal data alarm when the difference is less than a second preset value.

[0066] In an optional embodiment, the device also includes: a noise module (not shown in the figure), which is used to input the data transmission information into a preset filter model to obtain the target data transmission information after noise is removed; and determine whether to allow the target data transmission information to be input into the target model.

[0067] In an optional embodiment, the device also includes: a forwarding module (not shown in the figure), which is used to determine the abnormal transmission node currently corresponding to the abnormal data and monitor the network status of the abnormal transmission node; when the network status is abnormal, determine the previous normal transmission node corresponding to the abnormal data; and send a reminder instruction to the normal transmission node to prompt the normal transmission node to forward subsequent data to the backup node corresponding to the abnormal transmission node.

[0068] In an optional embodiment, the monitoring module 302 is used to determine the abnormality type corresponding to the data transmission information and the original abnormality probability corresponding to the abnormality type after inputting the data transmission information into the target model; determine the target abnormality probability corresponding to the original abnormality probability according to the weight value corresponding to the abnormality type; and determine the target abnormality probability as the abnormality probability value of the data transmission information.

[0069] The device for determining the abnormal data processing solution provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and this embodiment will not be described in detail here.

[0070] Figure 4 This is a schematic diagram of the structure of the device for determining the abnormal data processing solution provided by this application. Figure 4 As shown, the electronic device 40 provided in this embodiment includes: at least one processor 401 and a memory 402. Optionally, the device 40 also includes a communication component 403. The processor 401, the memory 402 and the communication component 403 are connected via a bus 404.

[0071] In a specific implementation process, at least one processor 401 executes the computer-executable instructions stored in the memory 402, so that at least one processor 401 executes the above method.

[0072] The specific implementation process of the processor 401 can be found in the above method embodiment, and its implementation principle and technical effect are similar, so this embodiment will not be repeated here.

[0073] In the above embodiments, it should be understood that the processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the invention can be directly implemented as a hardware processor, or can be implemented by a combination of hardware and software modules in the processor.

[0074] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (NVM), such as at least one disk storage.

[0075] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of this application is not limited to only one bus or one type of bus.

[0076] The present application also provides a computer program product, including a computer program, which implements the above method when executed by a processor.

[0077] The present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the above method is implemented.

[0078] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general or special-purpose computer.

[0079] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (Application Specific Integrated Circuits, referred to as: ASIC). Of course, the processor and the readable storage medium can also exist in the device as discrete components.

[0080] The division of units is only a logical function division, and there may be other divisions in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.

[0081] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0082] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0083] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.

[0084] Those skilled in the art can understand that all or part of the steps of implementing the above-mentioned method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, the steps of the above-mentioned method embodiments are executed; and the aforementioned storage medium includes: ROM, RAM, disk or optical disk and other media that can store program codes.

[0085] Finally, it should be noted that those skilled in the art will readily conceive of other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses or adaptations of the present invention, which follow the general principles of the present invention and include common knowledge or customary technical means in the art not disclosed by the present invention, are not limited to the precise structure described above and shown in the drawings, and may be modified and changed in various ways without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.

[0086] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily required by the present application.

[0087] It should be further noted that, although the various steps in the flowchart are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps is not strictly limited in order, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowchart may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these sub-steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.

[0088] It should be understood that the above-mentioned device embodiments are only illustrative, and the device of the present application can also be implemented in other ways. For example, the division of units / modules in the above-mentioned embodiments is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units, modules or components can be combined, or can be integrated into another system, or some features can be ignored or not executed.

[0089] In addition, unless otherwise specified, each functional unit / module in each embodiment of the present application may be integrated into one unit / module, each unit / module may exist physically separately, or two or more units / modules may be integrated together. The above-mentioned integrated unit / module may be implemented in the form of hardware or in the form of a software program module.

[0090] If the integrated unit / module is implemented in the form of hardware, the hardware may be a digital circuit, an analog circuit, etc. The physical implementation of the hardware structure includes but is not limited to transistors, memristors, etc. Unless otherwise specified, the processor may be any appropriate hardware processor, such as a CPU, a GPU, an FPGA, a DSP, an ASIC, etc. Unless otherwise specified, the storage unit may be any appropriate magnetic storage medium or magneto-optical storage medium, such as a resistive random access memory (RRAM), a dynamic random access memory (DRAM), a static random access memory (SRAM), an enhanced dynamic random access memory (EDRAM), a high-bandwidth memory (HBM), a hybrid memory cube (HMC), etc.

[0091] If the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a memory, including a number of instructions to enable a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned memory includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, disk or optical disk and other media that can store program codes.

[0092] In the above embodiments, the description of each embodiment has its own emphasis. For the part not described in detail in a certain embodiment, please refer to the relevant description of other embodiments. The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, all possible combinations of the technical features in the above embodiments are not described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0093] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. The present application is intended to cover any modification, use or adaptation of the present application, which follows the general principles of the present application and includes common knowledge or customary techniques in the art that are not disclosed in the present application. The specification and examples are intended to be exemplary only, and the true scope and spirit of the present application are indicated by the following claims.

[0094] It should be understood that the present application is not limited to the precise structures that have been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

Claims

1. An abnormal data alarm method, characterized in that: include: Obtaining historical transmission information of business data of a target business scenario, and building a target model according to the historical data carried in the historical transmission information, wherein the target model is obtained by machine learning multiple groups of sample data, and each group of data in the multiple groups of sample data includes: historical data, data status of the historical data, and probability of change of the data status; Monitoring data transmission information corresponding to a target business scenario in real time, inputting the data transmission information into the target model, and obtaining an abnormal probability value of the data transmission information; When the abnormal probability value is greater than a first preset value, the data transmission information is determined to be abnormal data, and an abnormal data alarm is initiated.

2. The method according to claim 1, characterized in that Building a target model according to the historical data carried in the historical transmission information includes: Determine the data tag carried by the historical data, and determine the transition probability of the transmission state of the historical data according to the number of changes of the data tag of the historical data in the historical transmission information within a preset time period, wherein the data tag includes at least one of the following: normal transmission data, abnormal transmission data, wherein the data tag is used to indicate the data transmission state of the historical data; A state transfer matrix is ​​constructed according to the transfer probabilities corresponding to all historical data, and the state transfer matrix is ​​determined as the target model.

3. The method according to claim 2, characterized in that Determining the data tags carried by the historical data, the method further includes: Determine the data response time carried by the historical data; When the data response time is longer than a threshold, determining that the data label of the historical data is abnormal transmission data; When the data response is less than or equal to a threshold, it is determined that the data tag of the historical data is normal transmission data.

4. The method according to claim 1, characterized in that: Before initiating an abnormal data alarm, the method further includes: Determine a first timestamp when the abnormal data alarm is triggered for the first time within the first time period and a second timestamp when the abnormal data alarm is triggered for the second time within the first time period; determining a difference between the first timestamp and the second timestamp; When the difference is less than a second preset value, it is determined not to initiate the abnormal data alarm.

5. The method according to claim 1, characterized in that Before building the target model according to the historical data carried in the historical transmission information, the method further includes: Inputting the historical data into a preset filter model to obtain noise information corresponding to the historical data; A noise model is established according to the noise information.

6. The method according to claim 1, characterized in that When the abnormal probability value is greater than a first preset value, the data transmission information is determined to be abnormal data, and after initiating an abnormal data alarm, the method further includes: Determine the abnormal transmission node currently corresponding to the abnormal data, and monitor the network status of the abnormal transmission node; In the case where the network state is abnormal, determining the last normal transmission node corresponding to the abnormal data; A reminder instruction is sent to the normal transmission node to prompt the normal transmission node to forward subsequent data to the standby node corresponding to the abnormal transmission node.

7. The method according to claim 1, characterized in that Real-time monitoring of data transmission information corresponding to the target business scenario, inputting the data transmission information into the target model, and obtaining an abnormal probability value of the data transmission information, including: After inputting the data transmission information into the target model, determining the abnormality type corresponding to the data transmission information and the original abnormality probability corresponding to the abnormality type; Determine, according to the weight value corresponding to the abnormal type, the target abnormal probability corresponding to the original abnormal probability; The target abnormality probability is determined as an abnormality probability value of the data transmission information.

8. An abnormal data alarm device, comprising: An acquisition module is used to acquire historical transmission information of business data of a target business scenario, and to build a target model according to the historical data carried in the historical transmission information, wherein the target model is obtained by machine learning multiple groups of sample data, and each group of data in the multiple groups of sample data includes: historical data, data status of the historical data, and probability of change of the data status; A monitoring module, used to monitor the data transmission information corresponding to the target business scenario in real time, input the data transmission information into the target model, and obtain an abnormal probability value of the data transmission information; The alarm module is used to determine that the data transmission information is abnormal data and initiate an abnormal data alarm when the abnormal probability value is greater than a first preset value.

9. An electronic device, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.

11. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 7 when being executed by a processor.

Citation Information

Patent Citations

  • Fault diagnosis and prediction method utilizing multistep time domain difference value learning

    CN103400040A

  • Physical network early warning method and device, electronic equipment and storage medium

    CN116016150A

  • Business data monitoring method and device

    CN116167836A

  • Method and system for monitoring and evaluating running state of electronic security door

    CN117953661A

  • Power system risk assessment method and system for multiple types of extreme weather

    CN119168365A