Log auditing method and device

By constructing a knowledge graph for multi-dimensional comparison, automatic audit of network equipment operation logs has been solved, and the problem of lack of operation log audit automation capabilities in the existing technology has been solved, achieving the effect of quickly detecting illegal operations and improving risk management capabilities.

CN120017496AInactive Publication Date: 2025-05-16CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411886442.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-19
Publication Date
2025-05-16
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Currently, there is a lack of operation log audit automation capabilities, and it is impossible to quickly detect operators' violations, resulting in insufficient network failure and risk management capabilities.

Method used

By obtaining the changed operation plan and equipment operation log of network equipment, building the operation plan instruction knowledge graph and equipment operation log knowledge graph, and performing multi-dimensional comparisons to automatically audit the equipment operation log to quickly discover illegal operations.

Benefits of technology

It realizes automated audit of operation logs, improves audit efficiency, can quickly detect operator violations, and enhances the security and risk management capabilities of network equipment change operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017496A_ABST
    Figure CN120017496A_ABST
Patent Text Reader

Abstract

Embodiments of the invention provide a log auditing method and apparatus. The method comprises the steps of obtaining a change operation scheme and an equipment operation log for network equipment; the change operation scheme is a preset scheme before the change operation is carried out on the network equipment, and the equipment operation log is a log recorded after the change operation is carried out on the network equipment; constructing an operation scheme instruction knowledge graph according to the change operation scheme; constructing an equipment operation log knowledge graph according to the equipment operation log; and auditing the equipment operation log according to the operation scheme instruction knowledge graph and the equipment operation log knowledge graph. According to the embodiment of the invention, the quick retrieval and comparison capability of the knowledge graph is utilized, so that the difference between the equipment operation log and the change operation scheme can be quickly found, the auditing efficiency of the equipment operation log is further improved, the automatic auditing of the operation log is realized, and the illegal operation of an operator can be quickly found.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of computer technology, and in particular to a log audit method, a log audit device, an electronic device, and a computer-readable storage medium. Background Art

[0002] Currently, network infrastructure is IP-based, core equipment is deployed in the cloud, and business platforms are fully cloud-based. Business changes bring about frequent network change operations, which can easily cause cross-level network failures. Currently, the compliance of change operations is mainly audited manually, and there is a lack of automatic audit capabilities for operation logs.

[0003] For the change operation scenarios of network devices such as metropolitan area network CR (Core Router), log audits are mainly conducted by relevant personnel. However, there is a lack of automated operation log auditing capabilities, and it is impossible to quickly discover illegal operations by operators. Summary of the invention

[0004] The purpose of the embodiment of the present invention is to provide a log audit method to solve the problem that there is currently a lack of automated operation log auditing capabilities and an inability to quickly discover illegal operations by operators. The specific technical solution is as follows:

[0005] In a first aspect of the present invention, a log audit method is provided, the method comprising:

[0006] Obtaining a change operation plan and a device operation log for a network device; wherein the change operation plan is a preset plan before the change operation is performed on the network device, and the device operation log is a log recorded after the change operation is performed on the network device;

[0007] Constructing an operation plan instruction knowledge graph according to the changed operation plan;

[0008] Constructing a device operation log knowledge graph according to the device operation log;

[0009] The device operation log is audited according to the operation plan instruction knowledge graph and the device operation log knowledge graph.

[0010] Optionally, constructing an operation plan instruction knowledge graph according to the change operation plan includes:

[0011] Performing entity extraction on the change operation plan to obtain a first entity;

[0012] Extracting relationships from the change operation scheme to obtain a first association relationship between the first entities;

[0013] Construct an operation plan instruction knowledge graph based on the first entity and the first association relationship.

[0014] Optionally, constructing a device operation log knowledge graph according to the device operation log includes:

[0015] Perform entity extraction on the device operation log to obtain a second entity;

[0016] Extracting relationships from the device operation logs to obtain second association relationships between the second entities;

[0017] Construct a device operation log knowledge graph based on the second entity and the second association relationship.

[0018] Optionally, the first entity and the second entity include at least: an operation time period, an operator, an operation device and an operation instruction; the first association relationship and the second association relationship include at least: the operator and the operation time period, the operator and the operation instruction, the operation time period and the operation instruction, the operation device and the operation time period, the operation device and the operation instruction, the operation device and the operator; the network device includes at least a router, a broadband access server and a router.

[0019] Optionally, auditing the device operation log according to the operation scheme instruction knowledge graph and the device operation log knowledge graph includes:

[0020] Performing a multi-dimensional comparison between a first entity in the operation scheme instruction knowledge graph and a second entity in the device operation log knowledge graph according to the first association relationship and the second association relationship;

[0021] The audit result of the device operation log is determined according to the comparison result, so as to determine whether the operator has violated the regulations based on the audit result.

[0022] Optionally, before auditing the device operation log according to the operation scheme instruction knowledge graph and the device operation log knowledge graph, the method further includes:

[0023] The operation scheme instruction knowledge graph and the device operation log knowledge graph are displayed.

[0024] Optionally, after auditing the device operation log according to the operation scheme instruction knowledge graph and the device operation log knowledge graph, the method further includes:

[0025] The entities and association relationships in the operation plan instruction knowledge graph and the equipment operation log knowledge graph are marked according to the audit results of the equipment operation log.

[0026] The embodiment of the present invention further provides a log auditing device, the device comprising:

[0027] A data acquisition module, used to acquire a change operation plan and a device operation log for a network device; wherein the change operation plan is a preset plan before the change operation is performed on the network device, and the device operation log is a log recorded after the change operation is performed on the network device;

[0028] A first construction module is used to construct an operation scheme instruction knowledge graph according to the change operation scheme;

[0029] A second construction module is used to construct a device operation log knowledge graph according to the device operation log;

[0030] An audit module is used to audit the device operation log according to the operation plan instruction knowledge graph and the device operation log knowledge graph.

[0031] In another aspect of the present invention, a computer-readable storage medium is provided, wherein instructions are stored in the computer-readable storage medium, and when the computer-readable storage medium is run on a computer, the computer executes any of the above-mentioned log auditing methods.

[0032] In another aspect of the present invention, a computer program product including instructions is provided, which, when executed on a computer, enables the computer to execute any of the above-mentioned log auditing methods.

[0033] Compared with the related art, the embodiments of the present invention have at least the following advantages:

[0034] In an embodiment of the present invention, a change operation plan and a device operation log for a network device are obtained, wherein the change operation plan is a preset plan before the change operation is performed on the network device, and the device operation log is a log recorded after the change operation is performed on the network device. An operation plan instruction knowledge graph is constructed according to the change operation plan, and a device operation log knowledge graph is constructed according to the device operation log. The device operation log is audited according to the operation plan instruction knowledge graph and the device operation log knowledge graph. The embodiment of the present invention utilizes the rapid retrieval and comparison capabilities of the knowledge graph, so that the difference between the device operation log and the change operation plan can be quickly discovered, thereby improving the efficiency of the audit of the device operation log, and realizing the automated audit of the operation log, so that the illegal operations of the operator can be quickly discovered. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art.

[0036] Figure 1 A flow chart of the steps of a log audit method provided in an embodiment of the present invention;

[0037] Figure 2 is a schematic diagram of entity extraction of a change operation scheme provided in an embodiment of the present invention;

[0038] Figure 3 A schematic diagram of a relationship extraction for a change operation scheme provided in an embodiment of the present invention;

[0039] Figure 4 A schematic diagram of an operation scheme instruction knowledge graph provided in an embodiment of the present invention;

[0040] Figure 5 It is a schematic diagram of entity extraction of a device operation log provided in an embodiment of the present invention;

[0041] Figure 6 A schematic diagram of a relationship extraction of a device operation log provided in an embodiment of the present invention;

[0042] Figure 7 A schematic diagram of a device operation log knowledge graph provided in an embodiment of the present invention;

[0043] Figure 8 A schematic diagram of operator dimension comparison provided in an embodiment of the present invention;

[0044] Fig. 9 A schematic diagram of a dimension comparison of an operating device provided in an embodiment of the present invention;

[0045] Fig.10 A schematic diagram of an operation instruction dimension comparison provided in an embodiment of the present invention;

[0046] Fig.11 A schematic diagram of a device operation log audit provided in an embodiment of the present invention;

[0047] Fig.12 A structural block diagram of a log auditing device provided in an embodiment of the present invention;

[0048] Fig.13 The present invention is a block diagram of an electronic device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0049] The technical solutions in the embodiments of the present invention will be described below in conjunction with the accompanying drawings in the embodiments of the present invention.

[0050] Reference Figure 1 , is a flow chart of the steps of a log audit method provided in an embodiment of the present invention, such as Figure 1As shown, the method may specifically include the following steps:

[0051] Step 101, obtaining a change operation plan and a device operation log for a network device; wherein the change operation plan is a preset plan before the change operation is performed on the network device, and the device operation log is a log recorded after the change operation is performed on the network device.

[0052] Among them, the network equipment may at least include routers (such as CR equipment), servers (such as BAS equipment) and gateways (such as IPRAN equipment). Of course, the above network equipment is only used as an example. In actual applications, it may also include equipment in other networks, and the embodiments of the present invention do not need to limit this. Specifically, CR equipment: Core Router refers to the router that occupies a core position in the Internet architecture. It is mainly responsible for the routing and forwarding of data packets. It has attracted much attention due to its high throughput. This type of router is usually called a backbone router, which is in sharp contrast to the access router located at the edge of the network. The core router serves the connection and data transmission of multi-layer networks due to its powerful functions and high processing capabilities. BAS equipment: Broadband Access Server (BAS) is a user access service device set at the network aggregation layer. It can intelligently realize user aggregation, authentication, billing and other services, and can also conveniently provide a variety of IP value-added services according to user needs. IPRAN equipment: IP RAN (IP Radio Access Network) is an end-to-end service bearer network based on IP / MPLS (Multi-Protocol Label Switching) protocols and key technologies. It is mainly oriented to mobile service bearer and also provides second and third layer channel service bearer. It is based on provinces and relies on the CN2 (ChinaNetNext Carrying Network) backbone layer to form an end-to-end service bearer network. In the IPRAN network, it mainly includes the access layer, aggregation layer and core layer, and the core layer is divided into the metropolitan core layer and the provincial core layer.

[0053] In specific implementation, the change operation plan refers to a preset plan designed in advance before the change operation is performed on the network equipment. Specifically, the change operation plan may at least include the operation time period, operator, operation equipment, and operation instructions, etc. Of course, it may also include information such as the purpose of the operation and the risk of the operation. The operator may perform corresponding change operations on the network equipment according to the change operation plan, such as configuring the environment of the network equipment, configuring the link of the network equipment, and other change operations. The device operation log is a log generated after the operator performs the change operation on the network equipment according to the change operation plan. Specifically, the device operation log may at least include the operation time period, operator, operation equipment, and operation instructions, etc.

[0054] Step 102: construct an operation plan instruction knowledge graph based on the changed operation plan.

[0055] Step 103: construct a device operation log knowledge graph based on the device operation log.

[0056] Among them, Knowledge Graph refers to what is called knowledge domain visualization or knowledge domain mapping map in the library and information industry. It is a series of various graphs that show the development process and structural relationship of knowledge. It uses visualization technology to describe knowledge resources and their carriers, and to mine, analyze, construct, draw and display knowledge and their interrelationships.

[0057] In an embodiment of the present invention, after obtaining the change operation plan and the equipment operation log, an operation plan instruction knowledge graph can be generated based on the change operation plan, and an equipment operation log knowledge graph can be generated according to the equipment operation log, wherein the operation plan instruction knowledge graph and the equipment operation log knowledge graph include multiple entities (such as operation time period, operator, operation equipment and operation instructions), as well as association relationships between entities (for example, operator <--> operation time period, operator <--> operation instruction).

[0058] Step 104: Audit the device operation log according to the operation plan instruction knowledge graph and the device operation log knowledge graph.

[0059] In an embodiment of the present invention, for network devices such as CR devices in a metropolitan area network, after the change operation is completed, relevant information such as the change operation plan and the device operation log is obtained, and the operation plan instruction knowledge graph and the device operation log knowledge graph are constructed respectively. Then, after the operation plan instruction knowledge graph and the device operation log knowledge graph are constructed, the automatic audit of the device operation log can be realized by comparing the two knowledge graphs, so as to find out whether the operator has violated the regulations such as over-range operation at the first time, standardize the operation of the operator, improve the safety of the change operation, and strengthen the risk management ability of the enterprise. Among them, the metropolitan area network (Metropolitan Area Network): is a computer communication network established within a city, referred to as MAN. It is a broadband local area network. Due to the use of local area network technology with active switching elements, the transmission delay in the network is small, and its transmission medium mainly uses optical cable, with a transmission rate of more than 100 megabits per second.

[0060] In the above log auditing method, the change operation plan and the device operation log for the network device are obtained, wherein the change operation plan is a preset plan before the change operation is performed on the network device, and the device operation log is a log recorded after the change operation is performed on the network device. The operation plan instruction knowledge graph is constructed according to the change operation plan, and the device operation log knowledge graph is constructed according to the device operation log. The device operation log is audited according to the operation plan instruction knowledge graph and the device operation log knowledge graph. The embodiment of the present invention utilizes the rapid retrieval and comparison capabilities of the knowledge graph, so that the difference between the device operation log and the change operation plan can be quickly discovered, thereby improving the efficiency of the audit of the device operation log, and realizing the automated audit of the operation log, so that the illegal operations of the operator can be quickly discovered.

[0061] In one embodiment of the present invention, constructing an operation scheme instruction knowledge graph according to the change operation scheme includes:

[0062] Performing entity extraction on the change operation plan to obtain a first entity;

[0063] Extracting relationships from the change operation scheme to obtain a first association relationship between the first entities;

[0064] Construct an operation plan instruction knowledge graph based on the first entity and the first association relationship.

[0065] In an embodiment of the present invention, before performing a change operation on a network device based on a change operation plan, information related to the operation content in the change operation plan is obtained, and an operation plan instruction knowledge graph with operation time period, operator, operation equipment and operation instructions as entities is established.

[0066] After obtaining the change operation plan, it is necessary to extract information from the change operation plan. Specifically, information extraction is a technology that extracts structured information such as entities, relationships, and entity attributes from unstructured or semi-structured data, including entity extraction and relationship extraction. Among them, entity extraction is also called named entity recognition (NER), which automatically identifies named entities from text data sets. Figure 2 , is a schematic diagram of entity extraction of a change operation scheme provided in an embodiment of the present invention. By performing entity extraction on the change operation scheme, an operator, an operation device, an operation instruction, and an operation time period can be extracted as entities, namely, a first entity.

[0067] After the change operation plan is subjected to entity extraction, a series of discrete named entities are obtained. In order to obtain semantic information, it is also necessary to extract the association relationship between entities from the relevant corpus, and connect the entities through the association relationship to form a network knowledge structure. Among them, the corpus is the language material, the corpus is the content of linguistic research, and the corpus is the basic unit of the corpus. In this embodiment of the present invention, the change operation plan is used as the corpus for relationship extraction. Figure 3 , is a schematic diagram of a relationship extraction of a change operation scheme provided in an embodiment of the present invention. The relationship extraction of the change operation scheme obtains a first association relationship, and the result of the relationship extraction may be as follows: operator <--> operation time period; operator <--> operation instruction; operation time period <--> operation instruction; operation device --> operation time period; operation device --> operation instruction; operation device --> operator. In some optional embodiments, after all entities and association relationships are obtained, if there are many entities and association relationships, some entities and association relationships may be screened out for subsequent multi-dimensional comparison, so as to avoid excessive information or too much useless information affecting the audit efficiency of the device operation log. Of course, the audit efficiency of the device operation log may also be evaluated based on all entities and association relationships, and the embodiment of the present invention does not need to be limited to this.

[0068] In an embodiment of the present invention, the operation scheme is changed by extracting the first entity, the first relationship between the first entities and other knowledge elements from the original corpus through information extraction. According to the first entity and the first relationship, the operation scheme instruction knowledge graph is constructed using the graph database to ensure that the structure of the operation scheme instruction knowledge graph is clear, easy to understand, and supports query and visualization. Figure 4 , is a schematic diagram of an operation scheme instruction knowledge graph provided in an embodiment of the present invention,

[0069] In one embodiment of the present invention, constructing a device operation log knowledge graph according to the device operation log includes:

[0070] Perform entity extraction on the device operation log to obtain a second entity;

[0071] Extracting relationships from the device operation logs to obtain second association relationships between the second entities;

[0072] Construct a device operation log knowledge graph based on the second entity and the second association relationship.

[0073] In an embodiment of the present invention, after the change operation of the network device is completed based on the change operation plan, a corresponding device operation log will be generated. At this time, the device operation log can be obtained to establish a device operation log knowledge graph with operation time, operator, operation device, and operation instructions as entities.

[0074] After obtaining the device operation log, you need to extract information from the device operation log. Figure 5 , is a schematic diagram of entity extraction of a device operation log provided in an embodiment of the present invention. By performing entity extraction on the device operation log, an operator, an operating device, an operating instruction, and an operating time period can be extracted as entities, namely, a second entity.

[0075] After the device operation log is subjected to entity extraction, a series of discrete named entities are obtained. In order to obtain semantic information, it is also necessary to extract the association relationship between entities from the relevant corpus, and connect the entities through the association relationship to form a network knowledge structure. The embodiment of the present invention uses the device operation log as corpus for relationship extraction. Figure 6 , is a schematic diagram of a relationship extraction of a device operation log provided in an embodiment of the present invention. The relationship extraction of the device operation log is performed to obtain a second association relationship. The result of the relationship extraction can be as follows: operator <--> operation time period; operator <--> operation instruction; operation time period <--> operation instruction; operation device --> operation time period; operation device --> operation instruction; operation device --> operator.

[0076] In the embodiment of the present invention, the device operation log extracts the second entity, the second relationship between the second entities and other knowledge elements from the original corpus through information extraction, and constructs the device operation log knowledge graph based on the second entity and the second relationship using the graph database to ensure that the structure of the device operation log knowledge graph is clear, easy to understand, and supports query and visualization. Figure 7 , is a schematic diagram of a device operation log knowledge graph provided in an embodiment of the present invention.

[0077] In one embodiment of the present invention, before auditing the device operation log according to the operation scheme instruction knowledge graph and the device operation log knowledge graph, the method further includes:

[0078] The operation scheme instruction knowledge graph and the device operation log knowledge graph are displayed.

[0079] In an embodiment of the present invention, after constructing the operation plan instruction knowledge graph and the equipment operation log knowledge graph, they are displayed to relevant personnel on a display so that the relevant personnel can quickly and clearly understand the entities (first entity and second entity) in the changed operation plan and the equipment operation log, as well as the relationship between the entities.

[0080] In one embodiment of the present invention, auditing the device operation log according to the operation scheme instruction knowledge graph and the device operation log knowledge graph includes:

[0081] Performing a multi-dimensional comparison between a first entity in the operation scheme instruction knowledge graph and a second entity in the device operation log knowledge graph according to the first association relationship and the second association relationship;

[0082] The audit result of the device operation log is determined according to the comparison result, so as to determine whether the operator has violated the regulations based on the audit result.

[0083] In an embodiment of the present invention, through knowledge retrieval, a multi-dimensional comparison is performed on the entities of the equipment operation knowledge graph and the entities of the operation plan instruction knowledge graph, so as to realize multi-dimensional rapid comparison of logs, and output illegal operation contents such as inconsistent operators, inconsistent operation time, inconsistent operation instructions, etc. as audit results, and then it can be determined whether the operator has violated the regulations based on the audit results, and then a corresponding solution can be given.

[0084] For example, multi-dimensional comparison can be achieved based on operator dimension comparison, operating device dimension comparison, operating instruction dimension comparison, etc.

[0085] Reference Figure 8, is a schematic diagram of an operator dimension comparison provided in an embodiment of the present invention. Specifically, based on the equipment operation log knowledge graph, the operator entity is quickly searched to obtain relevant operation time, operation equipment and operation instruction information. Exemplarily, the equipment operation log knowledge graph and the operation plan instruction knowledge graph are traversed through a for-each loop, and the association relationship with the operator dimension obtained from the equipment operation log knowledge graph is compared, and the association relationship of the operators in the two graphs is compared. for-each repeats an embedded statement group for each element in an array or object collection. The for-each statement is used to iterate through a collection to obtain the required information.

[0086] Starting from the operator, the entities and relationships are compared as follows:

[0087] Operator entity comparison: If the operator comparison is consistent, the output is 'Operator Audit Compliance', and the following relationship comparison is performed:

[0088] Relationship between operator and operating equipment: If the data is inconsistent, the output is 'Audit non-compliant, operator and operating equipment are inconsistent'; if they are consistent, the output is 'Audit compliant'.

[0089] The relationship between operators and operating instructions and data: If the data is inconsistent, the output is 'Audit non-compliance, the operator and the operating instructions are inconsistent'; if they are consistent, the output is 'Audit compliance'.

[0090] The relationship between the operator and the operation time and the data: If the data is inconsistent, the output is 'Audit non-compliance, the operator and the operation time are inconsistent'; if they are consistent, the output is 'Audit compliance'.

[0091] Operator entity comparison: If the operator comparison is inconsistent, the direct output is 'Operator audit is not compliant, operator is inconsistent'.

[0092] Reference Fig. 9 , is a schematic diagram of an operation device dimension comparison provided in an embodiment of the present invention. Based on the device operation log knowledge graph, the operation device entity is quickly searched to obtain relevant operation time and operation instructions and other information. The device operation log knowledge graph and the operation plan instruction knowledge graph are traversed through a for-each loop, and the association relationship between the operation device dimensions obtained from the device operation log knowledge graph is compared, and the two parts of the operation device association relationship data are compared.

[0093] Based on the operating device, the entities and relationships are compared as follows:

[0094] Operation equipment entity comparison: If the operation equipment comparison is consistent, the output is 'Operation equipment audit compliance', and the following association relationship comparison is performed:

[0095] Relationship between operating equipment and operating time: If the data is inconsistent, the output is 'Audit non-compliance, the comparison between operating equipment and operating time is inconsistent'; if they are consistent, the output is 'Audit compliance'.

[0096] Relationship between operating equipment and operating instructions and data: If the data is inconsistent, the output is 'Audit non-compliance, operating equipment and operating instructions are inconsistent'; if they are consistent, the output is 'Audit compliance'.

[0097] Operation equipment entity comparison: If the operation equipment comparison is inconsistent, the direct output is "the operation equipment audit is not compliant and there are out-of-scope operations".

[0098] Reference Fig.10 , is a schematic diagram of an operation instruction dimension comparison provided in an embodiment of the present invention. Based on the device operation log knowledge graph, the operation instruction entity is quickly searched to obtain relevant operation time and operation device information. The device operation log knowledge graph and the operation plan instruction knowledge graph are traversed through a for-each loop, and the association relationship between the operation instruction dimension obtained from the device operation log knowledge graph is compared, and the two parts of the operation instruction association relationship data are compared.

[0099] Based on the operation instructions, the entity and relationship comparison is as follows:

[0100] Operation instruction entity comparison: If the operation instruction comparison is consistent, the output is 'Operation instruction audit compliance', and the association relationship comparison is performed:

[0101] Relationship between operation instructions and operation time: If the data is inconsistent, the output is 'Audit non-compliance, the comparison between the operation equipment and the operation time is inconsistent'; if they are consistent, the output is 'Audit compliance'.

[0102] Entity comparison of operation device instructions: If the operation instruction comparison is inconsistent, the output is 'the operation instruction audit is not compliant and there are out-of-range operations'.

[0103] Further, after auditing the device operation log according to the operation scheme instruction knowledge graph and the device operation log knowledge graph, the method may further include:

[0104] The entities and association relationships in the operation plan instruction knowledge graph and the equipment operation log knowledge graph are marked according to the audit results of the equipment operation log.

[0105] In an embodiment of the present invention, after obtaining the audit results of the device operation log, the entities and associations in the operation plan instruction knowledge graph and the device operation log knowledge graph can be marked accordingly to remind relevant personnel which entities have illegal operations. Exemplarily, the content with illegal operations, such as the operation instructions in the operation plan instruction knowledge graph and the device operation log knowledge graph, can be grayed out.

[0106] By applying the embodiments of the present invention, after changing the existing network devices such as CR equipment, BAS equipment, IPRAN B equipment, etc., a knowledge graph of operation plan instructions and a knowledge graph of equipment operation logs can be established. By comparing the graphs, a multi-dimensional rapid audit of the equipment operation logs can be implemented, thereby improving the efficiency of discovering illegal operations and strengthening the risk management capabilities of the enterprise.

[0107] By introducing the knowledge graph, the embodiment of the present invention can clearly show the relationship and attributes between things and support multi-dimensional rapid query of data. After the change operation of the network device, the multi-dimensional rapid audit of the log is realized by constructing the operation plan instruction knowledge graph (before the operation) and the equipment operation log knowledge graph (after the operation), and the illegal operation is discovered at the first time to improve the safety of the change operation. The main implementation scheme of the embodiment of the present invention is as follows: Establishing the operation instruction knowledge graph: obtaining the information related to the operation content in the change plan, and establishing the operation plan instruction knowledge graph with the change operation time period, operator, operation equipment and instruction as entities. Establishing the equipment operation log knowledge graph: obtaining the equipment operation log, and establishing the equipment operation knowledge graph with the operation time, operator, equipment and instruction as entities. Log comparison and audit result output: through knowledge retrieval, the entities of the equipment operation knowledge graph and the entities of the operation plan instruction knowledge graph are compared in multiple dimensions to realize the multi-dimensional rapid audit of the log, and output the illegal operation content such as inconsistent operators, inconsistent operation time, and inconsistent operation instructions.

[0108] In order to enable those skilled in the art to better understand the embodiments of the present invention, an example is used below for illustration. Fig.11, is a schematic diagram of a device operation log audit provided in an embodiment of the present invention. Specifically, based on the operation plan instruction information (change operation plan) and the device operation instruction information (device operation log), the operator, operation time, operation device and operation instruction entities and their associations are respectively established through information extraction, and the operation plan instruction knowledge graph / scheme operation instruction graph (before change operation) and the device operation log knowledge graph / device operation instruction graph (after change operation) are constructed. Based on these two graphs, the data relationship between the operator, operation time, operation device and operation instruction can be reflected in detail and in multiple dimensions. In addition, through the capability of the knowledge graph combined with the for-each loop traversal method, multi-dimensional rapid audit of the device operation log and the change operation plan can be realized.

[0109] After the network equipment is changed, the construction of the knowledge graph is used to achieve an in-depth comparison of the change operation plan and the equipment operation log, which not only accelerates the audit process of the equipment operation log, but also gives the audit activity an unprecedented multi-dimensional perspective. Through the intelligent analysis of the knowledge graph, every operation detail in the equipment operation log can be quickly captured after the operation is completed, and accurately matched with the preset change operation plan instructions and related data, and the change operation is audited for compliance. It is particularly worth mentioning that the embodiment of the present invention significantly improves the efficiency of discovering illegal operations. After the change operation of the network equipment is completed, once an out-of-range operation or potential risk behavior occurs, a rapid audit is performed and audit results are generated, which greatly improves the efficiency of discovering illegal operations.

[0110] In summary, establishing a knowledge graph to compare change operation plans with equipment operation logs not only optimizes the audit process and improves audit efficiency, but also strengthens the company's risk management capabilities. It is an indispensable part of modern enterprise management.

[0111] It should be noted that, for the sake of simplicity, the method embodiments are described as a series of action combinations, but those skilled in the art should be aware that the embodiments of the present invention are not limited by the order of the actions described, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present invention.

[0112] Reference Fig.12 , is a structural block diagram of a log audit device provided in an embodiment of the present invention, such as Fig.12 As shown, the device may specifically include the following modules:

[0113] The data acquisition module 1201 is used to acquire a change operation plan and a device operation log for a network device; wherein the change operation plan is a preset plan before the change operation is performed on the network device, and the device operation log is a log recorded after the change operation is performed on the network device;

[0114] A first construction module 1202 is used to construct an operation scheme instruction knowledge graph according to the change operation scheme;

[0115] The second construction module 1203 is used to construct a device operation log knowledge graph according to the device operation log;

[0116] The audit module 1204 is used to audit the device operation log according to the operation plan instruction knowledge graph and the device operation log knowledge graph.

[0117] In one embodiment of the present invention, constructing an operation scheme instruction knowledge graph according to the change operation scheme includes:

[0118] Performing entity extraction on the change operation plan to obtain a first entity;

[0119] Extracting relationships from the change operation scheme to obtain a first association relationship between the first entities;

[0120] Construct an operation plan instruction knowledge graph based on the first entity and the first association relationship.

[0121] In one embodiment of the present invention, constructing a device operation log knowledge graph according to the device operation log includes:

[0122] Perform entity extraction on the device operation log to obtain a second entity;

[0123] Extracting relationships from the device operation logs to obtain second association relationships between the second entities;

[0124] Construct a device operation log knowledge graph based on the second entity and the second association relationship.

[0125] In one embodiment of the present invention, the first entity and the second entity include at least: an operation time period, an operator, an operation device and an operation instruction; the first association relationship and the second association relationship include at least: the operator and the operation time period, the operator and the operation instruction, the operation time period and the operation instruction, the operation device and the operation time period, the operation device and the operation instruction, the operation device and the operator; the network device includes at least a router, a broadband access server and a router.

[0126] In one embodiment of the present invention, auditing the device operation log according to the operation scheme instruction knowledge graph and the device operation log knowledge graph includes:

[0127] Performing a multi-dimensional comparison between a first entity in the operation scheme instruction knowledge graph and a second entity in the device operation log knowledge graph according to the first association relationship and the second association relationship;

[0128] The audit result of the device operation log is determined according to the comparison result, so as to determine whether the operator has violated the regulations based on the audit result.

[0129] In one embodiment of the present invention, before auditing the device operation log according to the operation scheme instruction knowledge graph and the device operation log knowledge graph, the method further includes:

[0130] The operation scheme instruction knowledge graph and the device operation log knowledge graph are displayed.

[0131] In one embodiment of the present invention, after auditing the device operation log according to the operation scheme instruction knowledge graph and the device operation log knowledge graph, the method further includes:

[0132] The entities and association relationships in the operation plan instruction knowledge graph and the equipment operation log knowledge graph are marked according to the audit results of the equipment operation log.

[0133] As for the above-mentioned device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0134] In an embodiment of the present invention, a change operation plan and a device operation log for a network device are obtained, wherein the change operation plan is a preset plan before the change operation is performed on the network device, and the device operation log is a log recorded after the change operation is performed on the network device. An operation plan instruction knowledge graph is constructed according to the change operation plan, and a device operation log knowledge graph is constructed according to the device operation log. The device operation log is audited according to the operation plan instruction knowledge graph and the device operation log knowledge graph. The embodiment of the present invention utilizes the rapid retrieval and comparison capabilities of the knowledge graph, so that the difference between the device operation log and the change operation plan can be quickly discovered, thereby improving the efficiency of the audit of the device operation log, and realizing the automated audit of the operation log, so that the illegal operations of the operator can be quickly discovered.

[0135] The embodiment of the present invention further provides an electronic device, such as Fig.13As shown, it includes a processor 501, a communication interface 502, a memory 503 and a communication bus 504, wherein the processor 501, the communication interface 502, and the memory 503 communicate with each other through the communication bus 504.

[0136] Memory 503, used for storing computer programs;

[0137] The processor 501 is used to implement the log audit method described in any of the above embodiments when executing the program stored in the memory 503.

[0138] The communication bus mentioned in the above terminal can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.

[0139] The communication interface is used for communication between the above terminal and other devices.

[0140] The memory may include a random access memory (RAM) or a non-volatile memory, such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.

[0141] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0142] In another embodiment provided by the present invention, a computer-readable storage medium is provided, in which instructions are stored. When the computer-readable storage medium is run on a computer, the computer executes the log audit method described in any one of the above embodiments.

[0143] In another embodiment of the present invention, a computer program product including instructions is provided. When the computer program product is run on a computer, the computer executes the log audit method described in any one of the above embodiments.

[0144] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented by software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present invention is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk Solid State Disk (SSD)), etc.

[0145] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or still includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "including one..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0146] Each embodiment in this specification is described in a related manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0147] The above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention are included in the protection scope of the present invention.

Claims

1. A log audit method, characterized in that: The method comprises: Obtaining a change operation plan and a device operation log for a network device; wherein the change operation plan is a preset plan before the change operation is performed on the network device, and the device operation log is a log recorded after the change operation is performed on the network device; Constructing an operation plan instruction knowledge graph according to the changed operation plan; Constructing a device operation log knowledge graph according to the device operation log; The device operation log is audited according to the operation plan instruction knowledge graph and the device operation log knowledge graph.

2. The method according to claim 1, characterized in that Constructing an operation plan instruction knowledge graph according to the change operation plan includes: Performing entity extraction on the change operation plan to obtain a first entity; Extracting relationships from the change operation scheme to obtain a first association relationship between the first entities; Construct an operation plan instruction knowledge graph based on the first entity and the first association relationship.

3. The method according to claim 2, characterized in that Constructing a device operation log knowledge graph according to the device operation log includes: Perform entity extraction on the device operation log to obtain a second entity; Extracting relationships from the device operation logs to obtain second association relationships between the second entities; Construct a device operation log knowledge graph based on the second entity and the second association relationship.

4. The method according to claim 3, characterized in that The first entity and the second entity include at least: an operation time period, an operator, an operation device and an operation instruction; the first association relationship and the second association relationship include at least: the operator and the operation time period, the operator and the operation instruction, the operation time period and the operation instruction, the operation device and the operation time period, the operation device and the operation instruction, the operation device and the operator; the network device includes at least a router, a broadband access server and a router.

5. The method according to claim 4, characterized in that Auditing the device operation log according to the operation scheme instruction knowledge graph and the device operation log knowledge graph includes: Performing a multi-dimensional comparison between a first entity in the operation scheme instruction knowledge graph and a second entity in the device operation log knowledge graph according to the first association relationship and the second association relationship; The audit result of the device operation log is determined according to the comparison result, so as to determine whether the operator has violated the regulations based on the audit result.

6. The method according to claim 1, characterized in that Before auditing the device operation log according to the operation scheme instruction knowledge graph and the device operation log knowledge graph, the method further includes: The operation scheme instruction knowledge graph and the device operation log knowledge graph are displayed.

7. The method according to claim 6, characterized in that After auditing the device operation log according to the operation scheme instruction knowledge graph and the device operation log knowledge graph, the method further includes: The entities and association relationships in the operation plan instruction knowledge graph and the equipment operation log knowledge graph are marked according to the audit results of the equipment operation log.

8. A log auditing device, characterized in that: The device comprises: A data acquisition module, used to acquire a change operation plan and a device operation log for a network device; wherein the change operation plan is a preset plan before the change operation is performed on the network device, and the device operation log is a log recorded after the change operation is performed on the network device; A first construction module is used to construct an operation scheme instruction knowledge graph according to the change operation scheme; A second construction module is used to construct a device operation log knowledge graph according to the device operation log; An audit module is used to audit the device operation log according to the operation plan instruction knowledge graph and the device operation log knowledge graph.

9. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, for implementing the method steps described in any one of claims 1 to 7 when executing a program stored in a memory.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • A full-service data center data auditing method based on a knowledge graph

    CN109815230A

  • Work order closed-loop method and device, electronic equipment and storage medium

    CN117634862A