Emergency scheme generation method, device, equipment and medium
By clustering and weighting the monitoring indicators and monitoring values of the to-detection system, target emergency plans are generated, and the problems of low accuracy and efficiency of emergency response in the existing technology are solved, and more efficient emergency response is achieved.
Patent Information
- Application Number
- CN202510184301.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-05-27
AI Technical Summary
In the prior art, in emergency treatment, emergency treatment steps are performed according to the order of fault information, resulting in low accuracy and efficiency of emergency treatment.
By obtaining the monitoring indicators and monitoring values of the system to be detected, clustering processing is carried out to determine the fault category, determining the fault weight based on the monitoring indicators and monitoring values of the fault category, querying the initial emergency steps, and generating the target emergency plan according to the fault weight sorting.
The accuracy and efficiency of emergency treatment are improved, and the optimal order of emergency treatment steps is determined through multi-dimensional data analysis, and the target emergency plan with the best emergency treatment effect is obtained.
Smart Images

Figure CN120047292A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing and the field of fintech, and particularly relates to a method, device, equipment and medium for generating an emergency plan. Background Art
[0002] With the rapid development of technology, the types and quantities of data processing systems are gradually increasing. To ensure the safe operation of the systems, it is necessary to monitor the data processing systems. According to the monitored fault information, the data processing systems perform emergency processing to ensure the security of the system operation.
[0003] Currently, for the system to be detected, according to the order of the monitored fault information, emergency processing steps are executed.
[0004] However, only executing the emergency processing steps in the order of obtaining the fault information, the accuracy and efficiency of the emergency processing are relatively low. Summary of the Invention
[0005] The present invention provides a method, device, equipment and medium for generating an emergency plan to improve the accuracy of generating the emergency plan.
[0006] In a first aspect, an embodiment of the present invention provides a method for generating an emergency plan, the method comprising:
[0007] Obtaining at least one monitoring index corresponding to the system to be detected and the monitoring value corresponding to each monitoring index;
[0008] Performing clustering processing on each monitoring index and the monitoring value corresponding to each monitoring index to obtain at least one fault class;
[0009] For each fault class, determining the fault weight of the fault class according to each monitoring index included in the fault class and the monitoring value corresponding to each monitoring index;
[0010] For each fault class, querying the initial emergency steps of the fault class according to each monitoring index corresponding to the fault class and the monitoring value corresponding to each monitoring index;
[0011] Sorting the execution order of each initial emergency step according to the fault weight of each fault class to generate a target emergency plan.
[0012] In a second aspect, an embodiment of the present invention further provides an emergency plan generating device, the device comprising:
[0013] A data acquisition module, configured to obtain at least one monitoring index corresponding to the system to be detected and the monitoring value corresponding to each monitoring index;
[0014] A data clustering module, configured to perform clustering processing on each monitoring index and the monitoring value corresponding to each monitoring index to obtain at least one fault class;
[0015] A weight determination module, configured to determine the fault weight of each fault class according to each monitoring index included in the fault class and the monitoring value corresponding to each monitoring index.
[0016] A data query module, configured to query the initial emergency steps of each fault class according to each monitoring index corresponding to the fault class and the monitoring value corresponding to each monitoring index.
[0017] A solution generation module, configured to sort the execution order of each initial emergency step according to the fault weight of each fault class, and generate a target emergency solution.
[0018] In a third aspect, an embodiment of the present invention further provides an emergency solution generation device, which includes:
[0019] At least one processor; and
[0020] A memory communicatively connected to the at least one processor; wherein,
[0021] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the emergency solution generation method of any embodiment of the present invention.
[0022] According to another aspect of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to implement the emergency solution generation method of any embodiment of the present invention when executed.
[0023] The technical solution of the embodiment of the present invention obtains at least one monitoring index corresponding to the system to be detected and the monitoring value corresponding to each monitoring index; performs clustering processing on each monitoring index and the monitoring value corresponding to each monitoring index to obtain at least one fault class; for each fault class, determines the fault weight of the fault class according to each monitoring index included in the fault class and the monitoring value corresponding to each monitoring index; for each fault class, queries the initial emergency steps of the fault class according to each monitoring index corresponding to the fault class and the monitoring value corresponding to each monitoring index; sorts the execution order of each initial emergency step according to the fault weight of each fault class to generate a target emergency solution. Different emergency treatment effects correspond to different emergency step processing orders. By performing multi-dimensional data analysis on the execution order of the initial emergency steps of each fault class and executing each initial emergency treatment step in the order of the fault weight of each fault class, a target emergency solution with the optimal emergency treatment effect is obtained, improving the accuracy and efficiency of emergency treatment.
[0024] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. Brief Description of the Drawings
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0026] Figure 1 is a flowchart of a method for generating an emergency plan provided in Embodiment 1 of the present invention;
[0027] Figure 2 is a flowchart of a method for generating an emergency plan provided in Embodiment 2 of the present invention;
[0028] Figure 3 is a structural diagram of a device for generating an emergency plan provided in an embodiment of the present invention;
[0029] Figure 4 is a schematic structural diagram of a device for implementing an emergency plan generation method provided in an embodiment of the present invention. Detailed Embodiments
[0030] In order to enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0031] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0032] In the technical solution of the embodiment of the present invention, the acquisition, storage, and application of monitoring values, etc. all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0033] Embodiment 1
[0034] Figure 1 It is a flowchart of an emergency plan generation method provided by Embodiment 1 of the present invention. The embodiment of the present invention is applicable to the situation of emergency plan generation. This method can be executed by an emergency plan generation device, and the emergency plan generation device can be implemented in the form of hardware and / or software.
[0035] See Figure 1 The emergency plan generation method shown, includes:
[0036] S101. Obtain at least one monitoring index corresponding to the system to be detected and the monitoring values corresponding to the monitoring indexes.
[0037] Among them, the system to be detected can be the system to be detected. Special monitoring tools and methods can be used to monitor the devices in the system to be detected and the related software systems, and monitor data such as the hardware performance, software running status, and network connection of the system to be detected. The monitoring index can be used to describe the index for monitoring the system to be detected. The monitoring value can be the data detected for the system to be detected according to the monitoring index.
[0038] Specifically, a system to be detected corresponds to at least one device to be detected and the software to be detected corresponding to each device to be detected. Each device to be detected corresponds to at least one monitoring index. The monitoring indexes corresponding to different devices to be detected are different. The software to be detected corresponds to at least one monitoring index. The monitoring indexes corresponding to different software to be detected are different. The monitoring index and the monitoring value are in one-to-one correspondence. The monitoring indexes corresponding to the device to be detected can be: CPU usage rate, memory usage rate, disk read / write efficiency, network bandwidth, disk space, number of processes, system load, service availability, etc. The monitoring indexes corresponding to the software to be detected can be: response time, number of concurrent users, resource utilization rate, failure frequency, number of security vulnerabilities, throughput, availability percentage, application error rate, etc.
[0039] S102. Perform clustering processing on each monitoring index and the monitoring value corresponding to each monitoring index to obtain at least one failure class.
[0040] Among them, the failure class can be used to describe the set of data of the same type of failure.
[0041] Specifically, historical fault information can be obtained, analyzed, and a mapping relationship can be established between the monitoring indicators corresponding to each fault type to obtain historical classification data. According to the historical classification data, the monitoring indicators corresponding to each fault type and the characteristics of the monitoring values corresponding to the monitoring indicators are obtained, and clustering processing is performed on each monitoring indicator and the monitoring values corresponding to each monitoring indicator. Features that have an important impact on the clustering results are selected from each monitoring indicator and the monitoring values corresponding to each monitoring indicator, and irrelevant or redundant features are removed to reduce the data dimension and computational complexity, and improve the clustering efficiency and accuracy. Methods such as correlation analysis, chi-square test, or information gain are used for feature selection. When the feature dimensions of each monitoring indicator and the monitoring values corresponding to each monitoring indicator are relatively high, methods such as principal component analysis (PCA), linear discriminant analysis (LDA), and singular value decomposition (SVD) can be used to convert the high-dimensional data into low-dimensional data, reducing the computational amount while retaining the main information of the data. Potential patterns and rules in each monitoring indicator and the monitoring values corresponding to each monitoring indicator can be discovered. According to the clustering results and evaluation indicators, the characteristics and distribution of each fault class are analyzed, the internal structure and rules of the data are understood, and each monitoring indicator and the monitoring values corresponding to each monitoring indicator belonging to the same fault type are determined as a fault class. The clustering methods include but are not limited to: K-Means algorithm, K-Means algorithm, divisive hierarchical clustering, and K-Medoids algorithm, and the embodiments of the present invention do not limit this.
[0042] S103. For each fault class, determine the fault weight of the fault class according to each monitoring indicator included in the fault class and the monitoring values corresponding to each monitoring indicator.
[0043] Among them, the fault weight can be used to describe the level of urgency of the fault that needs to be processed corresponding to the fault class.
[0044] Specifically, for each fault class, according to each monitoring indicator included in each fault class and the monitoring values corresponding to each monitoring indicator, determine the fault type corresponding to the fault class and the severity level of the fault, and determine the fault weight of the fault class according to the fault type corresponding to the fault class and the severity level of the fault. Each fault class corresponds to a fault weight one by one. The larger the fault weight, the higher the level of urgency of the fault corresponding to the fault class that needs to be processed, and the fault corresponding to the fault class needs to be processed as soon as possible; the smaller the fault weight, the lower the level of urgency of the fault corresponding to the fault class that needs to be processed, and the fault corresponding to the fault class with a higher level of urgency that needs to be processed can be processed first, and then the fault corresponding to the fault class with a smaller fault weight can be processed.
[0045] S104. For each fault class, query the initial emergency steps of the fault class according to each monitoring indicator corresponding to the fault class and the monitoring values corresponding to each monitoring indicator.
[0046] Among them, the initial emergency steps can be used to describe the emergency handling steps for dealing with the faults corresponding to the fault classes.
[0047] Specifically, at least one fault type and the corresponding emergency handling steps for each fault type are obtained and stored in the emergency handling library. A fault class includes at least one monitoring index and the corresponding monitoring values for each monitoring index. According to the monitoring indexes corresponding to the fault class and the monitoring values corresponding to each monitoring index, the fault type corresponding to the fault class is determined, and according to the fault type corresponding to the fault class, a query is made in the emergency handling library to obtain the initial emergency steps of the fault class. The query methods include but are not limited to: sequential search algorithm, block search algorithm, tree table search algorithm, and hash search algorithm, etc. The embodiments of the present invention do not limit this.
[0048] S105. Sort the execution order of the initial emergency steps according to the fault weights of each fault class to generate a target emergency plan.
[0049] Among them, the target emergency plan can be a plan for emergency handling of the faults of the system to be detected.
[0050] Specifically, one fault class corresponds to at least one emergency handling step, and the emergency handling steps corresponding to one fault class are determined as the initial emergency handling steps of the fault class. One system to be detected corresponds to at least one fault class. The fault weights of each fault class are obtained. The fault weights of each fault class are sorted in descending order to obtain a fault class sequence. The initial emergency handling steps of each fault class in the fault class sequence are sorted according to the order of each fault class in the fault class sequence, and the sorted initial emergency steps are determined as the target emergency plan of the system to be detected.
[0051] The technical solution of the embodiments of the present invention, by obtaining at least one monitoring index corresponding to the system to be detected and the monitoring values corresponding to each monitoring index; performing clustering processing on each monitoring index and the monitoring values corresponding to each monitoring index to obtain at least one fault class; for each fault class, determining the fault weight of the fault class according to the monitoring indexes included in the fault class and the monitoring values corresponding to each monitoring index; for each fault class, querying the initial emergency steps of the fault class according to the monitoring indexes corresponding to the fault class and the monitoring values corresponding to each monitoring index; sorting the execution order of the initial emergency steps according to the fault weights of each fault class to generate a target emergency plan, different execution orders of emergency steps correspond to different emergency handling effects, by performing multi-dimensional data analysis on the execution order of the initial emergency steps of each fault class, and executing each initial emergency handling step in the order of the fault weights of each fault class, the target emergency plan with the optimal emergency handling effect is obtained, improving the accuracy and efficiency of emergency handling.
[0052] Embodiment 2
[0053] Figure 2 This is a flowchart of an emergency plan generation method provided in the second embodiment of the present invention. On the basis of the above embodiments, the present invention embodiment optimizes and improves the emergency plan generation operation.
[0054] Further, "determining the fault weight of the fault class according to each monitoring index included in the fault class and the monitoring value corresponding to each monitoring index" is refined to "obtaining the preset value corresponding to each monitoring index; for each monitoring index, identifying the monitoring value corresponding to the monitoring index to obtain the numerical type corresponding to the monitoring value; determining the target value corresponding to each monitoring index according to the numerical type of the monitoring value corresponding to each monitoring index and the preset value corresponding to each monitoring index; determining the fault weight of the fault class according to the target value corresponding to each monitoring index" to improve the operation of generating the emergency plan.
[0055] It should be noted that for the parts not detailed in the embodiments of the present invention, reference can be made to the descriptions of other embodiments.
[0056] See Figure 2 The emergency plan generation method shown includes:
[0057] S201. Obtain at least one monitoring index corresponding to the system to be detected and the monitoring value corresponding to each monitoring index.
[0058] S202. Perform clustering processing on each monitoring index and the monitoring value corresponding to each monitoring index to obtain at least one fault class.
[0059] S203. For each fault class, obtain the preset value corresponding to each monitoring index
[0060] Among them, the preset value can be the value corresponding to the preset monitoring index.
[0061] Specifically, different fault classes correspond to different monitoring indexes, and the preset values corresponding to different monitoring indexes are different. When the monitoring index corresponding to the device to be detected in the system to be detected or the monitoring index corresponding to the software to be detected does not monitor data or the monitoring value corresponding to the monitoring index is incorrect, in order to ensure the successful and accurate generation of the target emergency plan, the incorrect monitoring value or the empty monitoring value corresponding to each monitoring index can be replaced with the preset value corresponding to the monitoring index. The preset value corresponding to each monitoring index can be selected from the monitoring values corresponding to each monitoring index in the historical time period.
[0062] S204. For each monitoring index, identify the monitoring value corresponding to the monitoring index to obtain the numerical type corresponding to the monitoring value.
[0063] Among them, the numerical type can be used to describe the type of the monitoring value corresponding to the monitoring index.
[0064] Specifically, a historical time period to be analyzed is preset, and at least one historical numerical type corresponding to each monitoring index within the historical time period to be analyzed is obtained. One monitoring index corresponds to at least one numerical type. The numerical type can also be an empty type. According to the type characteristics of at least one historical numerical type corresponding to each monitoring index, for each monitoring index, the monitoring value corresponding to the monitoring index is identified to obtain the numerical type corresponding to the monitoring value. The identification methods include, but are not limited to, feedforward neural network algorithms, feedback neural network algorithms, generative adversarial neural network algorithms, or convolutional neural network algorithms, etc. The embodiments of the present invention do not limit this.
[0065] S205. Determine the target value corresponding to each monitoring index according to the numerical type of the monitoring value corresponding to each monitoring index and the preset value corresponding to each monitoring index.
[0066] Specifically, for the monitoring value of each monitoring index, the numerical type of the monitoring value of each monitoring index is obtained. The numerical type of the monitoring index is compared with each historical numerical type and the empty type of the monitoring index. If the numerical type of the monitoring value of the monitoring index is different from each historical numerical type of the monitoring index, or the numerical type of the monitoring value of the monitoring index is an empty type, it indicates that the monitoring of the monitoring value corresponding to the monitoring index is not accurate enough or the monitoring value has mutated. Then, the monitoring value of the monitoring index is replaced with the preset value corresponding to the monitoring index, and the preset value corresponding to the monitoring index is determined as the target value of the monitoring index; if the numerical type of the monitoring value of the monitoring index is the same as any one of the historical numerical types of the monitoring index, it indicates that the monitoring of the monitoring value corresponding to the monitoring index is accurate, and then the monitoring value of the monitoring index is determined as the target value of the monitoring index.
[0067] S206. Determine the fault weight of the fault class according to the target value corresponding to each monitoring index.
[0068] Specifically, after the monitoring values corresponding to each monitoring index are subjected to data cleaning, the errors in the data are identified and corrected. The cleaned data is more standardized and unified, facilitating subsequent data processing and analysis, and the target value corresponding to each monitoring index is determined. The fault weight of the fault class is calculated according to the target value of each monitoring index. One fault class corresponds to one fault weight.
[0069] S207. For each fault class, query the initial emergency steps of the fault class according to the monitoring indexes corresponding to the fault class and the monitoring values corresponding to the monitoring indexes.
[0070] S208. Sort the execution order of each initial emergency step according to the fault weight of each fault class to generate a target emergency plan.
[0071] In an embodiment of the present invention, preset values corresponding to each monitoring index are obtained; for each monitoring index, the monitoring value corresponding to the monitoring index is identified to obtain the numerical type corresponding to the monitoring value; according to the numerical type of the monitoring value corresponding to each monitoring index and the preset value corresponding to each monitoring index, the target value corresponding to each monitoring index is determined; according to the target value corresponding to each monitoring index, the fault weight of the fault class is determined, and data processing is performed on the monitoring value corresponding to the monitoring index, which is convenient for processing the monitoring error value and null value of the monitoring value, and ensures the accuracy of the calculation of the fault weight.
[0072] Optionally, determining the fault weight of the fault class according to the target value corresponding to each monitoring index includes: calculating the fault entropy value of the fault class according to the target value corresponding to each monitoring index; determining the dispersion value of the fault class according to the fault entropy value of the fault class; and determining the fault weight of the fault class through normalization processing of the dispersion value of the fault class.
[0073] Specifically, for different monitoring indexes, at least one acquisition value is acquired for each monitoring index. For each acquisition value of the monitoring index, the ratio of the acquisition value to the values of the acquisition values of the monitoring index is calculated to obtain the acquisition ratio of each acquisition value corresponding to the monitoring index. The fault entropy value corresponding to the monitoring index is calculated according to the acquisition ratio of each acquisition value corresponding to the monitoring index. The calculation method may be: Shannon entropy algorithm, cross-entropy algorithm, relative entropy algorithm, etc. The embodiment of the present invention does not limit this. The dispersion value corresponding to the monitoring index is calculated through the difference between 1 and the fault entropy value of the monitoring index. The dispersion values corresponding to the monitoring indexes of the fault class are normalized to determine the fault weight corresponding to the fault class. The normalization method may be: min-max standardization, logarithmic transformation, decimal scaling standardization, etc. The embodiment of the present invention does not limit this.
[0074] By calculating the fault entropy value of the fault class according to the target value corresponding to each monitoring index, determining the dispersion value of the fault class according to the fault entropy value of the fault class, and determining the fault weight of the fault class through normalization processing of the dispersion value of the fault class, analyzing through multi-dimensional data to determine the fault weight of the fault class improves the accuracy of the calculation of the fault weight.
[0075] Optionally, after querying the initial emergency steps of the fault class according to each fault class, the corresponding monitoring indexes of the fault class, and the monitoring values corresponding to the monitoring indexes, it further includes: obtaining at least one information detection condition of the fault class; detecting the initial emergency steps of the fault class according to each information detection condition to determine the detection result of the fault class; determining the emergency optimization information corresponding to the initial emergency steps of the fault class according to the detection result; and optimizing the initial emergency steps of the fault class according to the emergency optimization information.
[0076] Among them, the information detection condition can be the condition for detecting the initial emergency step corresponding to the fault type of the fault class. The emergency optimization information can be used to describe the initial emergency step after modifying the incorrect data in the initial emergency step corresponding to the fault type of the fault class.
[0077] Specifically, at least one information detection condition of the fault class is obtained. The information detection condition can be to determine whether the data is within the data range, whether there is an abnormal string in the emergency handling step, whether the emergency handling step conforms to the grammar rules, or whether the emergency handling step has the execution permission, etc. The initial emergency steps of the fault class are detected according to each information detection condition to determine the detection result of the fault class; according to the detection result, the emergency optimization information corresponding to the initial emergency step of the fault class is determined, and the initial emergency step of the fault class is replaced according to the emergency optimization information to obtain the updated initial emergency step of the fault class.
[0078] By obtaining at least one information detection condition of the fault class; detecting the initial emergency steps of the fault class according to each information detection condition to determine the detection result of the fault class; determining the emergency optimization information corresponding to the initial emergency step of the fault class according to the detection result; optimizing the initial emergency steps of the fault class according to the emergency optimization information, detecting the initial emergency steps through multi-dimensional data, timely obtaining the accurate state of the data of the initial emergency steps, updating the incorrect data, and improving the accuracy of the initial emergency steps.
[0079] Optionally, detecting the initial emergency steps of the fault class according to each information detection condition to determine the detection result of the fault class includes: detecting the initial emergency steps of the fault class according to each information detection condition to obtain the number of abnormal data; obtaining the abnormal threshold corresponding to the fault class; comparing the number of abnormal data corresponding to the fault class with the abnormal threshold corresponding to the fault class to obtain the detection result of the fault class.
[0080] Among them, the number of abnormal data can be used to describe the number of abnormalities detected in the initial emergency steps of the fault class by each information detection condition. The abnormal threshold can be a preset threshold for the number of abnormal data. The detection result can be the result of comparing the number of abnormal data corresponding to the fault class with the abnormal threshold corresponding to the fault class.
[0081] Specifically, the initial emergency steps for the fault class are detected according to each information detection condition. If the result detected for the initial emergency steps of the fault class meets the information detection condition, it indicates that there is no abnormality corresponding to the information detection condition in the initial emergency steps of the fault class. If the result detected for the initial emergency steps of the fault class does not meet the information detection condition, it indicates that there is an abnormality corresponding to the information detection condition in the initial emergency steps of the fault class, and the corresponding abnormal data quantity of the fault class is incremented by 1. The total number of quantities that do not meet the information detection condition is counted to obtain the abnormal data quantity. The abnormal threshold corresponding to the fault class is obtained, and the abnormal data quantity corresponding to the fault class is compared with the abnormal threshold corresponding to the fault class to obtain the detection result of the fault class.
[0082] By detecting the initial emergency steps for the fault class according to each information detection condition, the abnormal data quantity is obtained; the abnormal threshold corresponding to the fault class is obtained; the abnormal data quantity corresponding to the fault class is compared with the abnormal threshold corresponding to the fault class to obtain the detection result of the fault class, ensuring the accuracy of the initial emergency handling steps and guaranteeing the accuracy of the target emergency plan generation.
[0083] Optionally, according to the detection result, the emergency optimization information corresponding to the initial emergency steps of the fault class is determined, including: if the detection result is that the abnormal data volume does not exceed the standard, the initial emergency steps of the fault class are determined as the emergency optimization information of the fault class; if the detection result is that the abnormal data volume exceeds the standard, the initial emergency steps of the fault class are re-obtained, and the re-obtained initial emergency steps of the fault class are determined as the emergency optimization information of the fault class, and the detection result is sent to the operation and maintenance personnel for alarm.
[0084] Specifically, the abnormal data quantity corresponding to the fault class is compared with the abnormal threshold corresponding to the fault class to obtain the detection result of the fault class. If the detection result is that the abnormal data volume does not exceed the standard, it indicates that the initial emergency steps meet the abnormal data volume requirement and the initial emergency steps meet the safety standard, then the initial emergency steps of the fault class are determined as the emergency optimization information of the fault class; if the detection result is that the abnormal data volume exceeds the standard, it indicates that there are a large number of abnormalities in the initial emergency steps, the initial emergency steps are inaccurate and cannot be correctly executed, then the initial emergency steps of the fault class are re-obtained, and the re-obtained initial emergency steps of the fault class are determined as the emergency optimization information of the fault class, and the detection result is sent to the operation and maintenance personnel for alarm. The alarm methods include but are not limited to: information alarm, pop-up alarm, sound and light alarm or telephone alarm, etc. The embodiments of the present invention do not limit this.
[0085] If the detected result is that the abnormal data volume does not exceed the standard, the initial emergency steps of the fault class are determined as the emergency optimization information of the fault class; if the detected result is that the abnormal data volume exceeds the standard, the initial emergency steps of the fault class are re-obtained, and the re-obtained initial emergency steps of the fault class are determined as the emergency optimization information of the fault class, and the detected result is sent to the operation and maintenance personnel for alarming. Different data processing operations are performed for different detected results, which refines the steps of processing the detected results and improves the accuracy of processing the detected results.
[0086] Optionally, obtaining at least one monitoring index corresponding to the system to be detected and the monitoring values corresponding to the monitoring indexes includes: obtaining at least one monitoring index corresponding to the system to be detected and the true index values corresponding to the monitoring indexes; obtaining at least one index data range corresponding to each monitoring index and the index characteristic values corresponding to the index data ranges; for each monitoring index, comparing the true index value corresponding to the monitoring index with each index data range corresponding to the monitoring index to determine the target data range and the target characteristic value corresponding to the monitoring index; determining the target characteristic value corresponding to the monitoring index as the monitoring value corresponding to the monitoring index.
[0087] Among them, the true index value can be used to describe the true value of the system to be detected detected according to the monitoring index. The index characteristic value can be used to describe the data representing its data characteristics, types or meanings corresponding to the true index value. The index data range can be used to describe the data range of the true index value corresponding to the monitoring index. The target data range is used to describe the index data range in which the true index value is located. The target data range can be used to describe the index characteristic value corresponding to the index data range in which the true index value is located.
[0088] Specifically, obtain at least one monitoring index corresponding to the system to be detected and the true index values corresponding to the monitoring indexes. Obtain at least one index data range corresponding to each monitoring index and the index characteristic values corresponding to the index data ranges, where one index data range corresponds to one index characteristic value. For each monitoring index, compare the true index value corresponding to the monitoring index with each index data range corresponding to the monitoring index, determine the index data range in which the true index value is located as the target data range corresponding to the monitoring index, and determine the index characteristic value corresponding to the target data range as the target characteristic value. Determine the target characteristic value corresponding to the monitoring index as the monitoring value corresponding to the monitoring index.
[0089] By obtaining at least one monitoring index corresponding to the system to be detected and the true index values corresponding to the monitoring indexes; obtaining at least one index data range corresponding to each monitoring index and the index characteristic values corresponding to the index data ranges; for each monitoring index, comparing the true index value corresponding to the monitoring index with each index data range corresponding to the monitoring index to determine the target data range and the target characteristic value corresponding to the monitoring index; determining the target characteristic value corresponding to the monitoring index as the monitoring value corresponding to the monitoring index.
[0090] Embodiment III
[0091] Figure 3 FIG. is a schematic structural diagram of an emergency plan generation device provided in Embodiment III of the present invention. The embodiment of the present invention is applicable to the situation of generating an emergency plan. The device can execute the emergency plan generation method and can be implemented in the form of hardware and / or software.
[0092] Refer to Figure 3 the emergency plan generation device shown in FIG., including: a data acquisition module 301, a data clustering module 302, a weight determination module 303, a data query module 304, and a plan generation module 305, where
[0093] The data acquisition module 301 is configured to acquire at least one monitoring index corresponding to the system to be detected and the monitoring value corresponding to each monitoring index;
[0094] The data clustering module 302 is configured to perform clustering processing on each monitoring index and the monitoring value corresponding to each monitoring index to obtain at least one fault class;
[0095] The weight determination module 303 is configured to determine the fault weight of each fault class according to each monitoring index included in the fault class and the monitoring value corresponding to each monitoring index;
[0096] The data query module 304 is configured to query the initial emergency steps of each fault class according to each monitoring index corresponding to the fault class and the monitoring value corresponding to each monitoring index;
[0097] The plan generation module 305 is configured to sort the execution order of each initial emergency step according to the fault weight of each fault class to generate a target emergency plan.
[0098] The technical solution of the embodiment of the present invention obtains at least one monitoring index corresponding to the system to be detected and the monitoring value corresponding to each monitoring index; performs clustering processing on each monitoring index and the monitoring value corresponding to each monitoring index to obtain at least one fault class; for each fault class, determines the fault weight of the fault class according to each monitoring index included in the fault class and the monitoring value corresponding to each monitoring index; for each fault class, queries the initial emergency steps of the fault class according to each monitoring index corresponding to the fault class and the monitoring value corresponding to each monitoring index; sorts the execution order of each initial emergency step according to the fault weight of each fault class to generate a target emergency plan. Different execution orders of emergency steps correspond to different emergency treatment effects. By performing multi-dimensional data analysis on the execution order of the initial emergency steps of each fault class and executing each initial emergency treatment step in the order of the fault weight of each fault class, a target emergency plan with the best emergency treatment effect is obtained, improving the accuracy and efficiency of emergency treatment.
[0099] Optionally, the weight determination module 303 includes:
[0100] A preset value acquisition unit for acquiring the preset value corresponding to each monitoring index;
[0101] A monitoring value identification unit for identifying the monitoring value corresponding to each monitoring index to obtain the numerical type corresponding to the monitoring value;
[0102] A target value determination unit for determining the target value corresponding to each monitoring index according to the numerical type of the monitoring value corresponding to each monitoring index and the preset value corresponding to each monitoring index;
[0103] A weight calculation unit for determining the fault weight of the fault class according to the target value corresponding to each monitoring index.
[0104] Optionally, the weight calculation unit is specifically used for:
[0105] Calculating the fault entropy value of the fault class according to the target value corresponding to each monitoring index;
[0106] Determining the dispersion value of the fault class according to the fault entropy value of the fault class;
[0107] Determining the fault weight of the fault class by normalizing the dispersion value of the fault class.
[0108] Optionally, the emergency plan generation device further includes:
[0109] A condition acquisition module for querying the initial emergency steps of the fault class according to each monitoring index corresponding to the fault class and the monitoring value corresponding to each monitoring index, and then acquiring at least one information detection condition of the fault class;
[0110] A detection result determination module for detecting the initial emergency steps of the fault class according to each information detection condition and determining the detection result of the fault class;
[0111] An optimized information determination module for determining the emergency optimization information corresponding to the initial emergency steps of the fault class according to the detection result;
[0112] A step optimization module for optimizing the initial emergency steps of the fault class according to the emergency optimization information.
[0113] Optionally, the detection result determination module is specifically used for:
[0114] Detecting the initial emergency steps of the fault class according to each information detection condition to obtain the number of abnormal data;
[0115] Obtaining the abnormal threshold corresponding to the fault class;
[0116] Compare the number of abnormal data corresponding to the fault class with the abnormal threshold corresponding to the fault class to obtain the detection result of the fault class.
[0117] Optionally, the optimization information determination module is specifically configured to:
[0118] If the detection result is that the amount of abnormal data does not exceed the standard, determine the initial emergency step of the fault class as the emergency optimization information of the fault class;
[0119] If the detection result is that the amount of abnormal data exceeds the standard, re-obtain the initial emergency step of the fault class, determine the re-obtained initial emergency step of the fault class as the emergency optimization information of the fault class, and send the detection result to the operation and maintenance personnel for warning.
[0120] Optionally, the data acquisition module 301 is specifically configured to:
[0121] Obtain at least one monitoring index corresponding to the system to be detected and the index true value corresponding to each monitoring index;
[0122] Obtain at least one index data range corresponding to each monitoring index and the index characteristic value corresponding to each index data range;
[0123] For each monitoring index, compare the index true value corresponding to the monitoring index with each index data range corresponding to the monitoring index to determine the target data range and target characteristic value corresponding to the monitoring index;
[0124] Determine the target characteristic value corresponding to the monitoring index as the monitoring value corresponding to the monitoring index.
[0125] The emergency plan generation device provided by the embodiments of the present invention can execute the emergency plan generation method provided by any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the emergency plan generation method.
[0126] Embodiment 4
[0127] Figure 4 The structural schematic diagram of the emergency plan generation device 400 that can be used to implement the embodiments of the present invention is shown.
[0128] As Figure 4As shown, the emergency plan generation device 400 includes at least one processor 401 and a memory communicatively connected to the at least one processor 401, such as a read-only memory (ROM) 402, a random access memory (RAM) 403, etc. Among them, the memory stores a computer program executable by the at least one processor. The processor 401 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 402 or the computer program loaded from the storage unit 408 into the random access memory (RAM) 403. In the RAM 403, various programs and data required for the operation of the emergency plan generation device 400 can also be stored. The processor 401, the ROM 402, and the RAM 403 are connected to each other through a bus 404. The input / output (I / O) interface 405 is also connected to the bus 404.
[0129] Multiple components in the emergency plan generation device 400 are connected to the I / O interface 405, including: an input unit 406, such as a keyboard, a mouse, etc.; an output unit 407, such as various types of displays, speakers, etc.; a storage unit 408, such as a disk, an optical disc, etc.; and a communication unit 409, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 409 allows the emergency plan generation device 400 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0130] The processor 401 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 401 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 401 executes the various methods and processes described above, such as the emergency plan generation method.
[0131] In some embodiments, the emergency plan generation method can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 408. In some embodiments, part or all of the computer program can be loaded and / or installed onto the emergency plan generation device 400 via the ROM 402 and / or the communication unit 409. When the computer program is loaded into the RAM 403 and executed by the processor 401, one or more steps of the emergency plan generation method described above can be executed. Alternatively, in other embodiments, the processor 401 can be configured to execute the emergency plan generation method by any other appropriate means (such as by means of firmware).
[0132] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems-on-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.
[0133] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0134] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0135] To provide interaction with a user, the systems and techniques described herein can be implemented on an emergency plan generation device that has: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the emergency plan generation device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0136] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0137] A computing system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The relationship between the client and the server is created by computer programs that run on the respective computers and have a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS (Virtual Private Server) services.
[0138] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is imposed herein.
[0139] The above specific embodiments do not constitute a limitation to the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for generating an emergency plan, characterized in that: The method comprises: Obtaining at least one monitoring indicator corresponding to the system to be detected and a monitoring value corresponding to each of the monitoring indicators; Performing clustering processing on each of the monitoring indicators and the monitoring values corresponding to each of the monitoring indicators to obtain at least one fault class; For each of the fault classes, determining a fault weight of the fault class according to each of the monitoring indicators included in the fault class and a monitoring value corresponding to each of the monitoring indicators; For each of the fault types, querying the initial emergency response steps for the fault type according to each of the monitoring indicators corresponding to the fault type and the monitoring values corresponding to each of the monitoring indicators; The execution order of each of the initial emergency steps is sorted according to the fault weight of each of the fault categories to generate a target emergency plan.
2. The method according to claim 1, characterized in that The determining the fault weight of the fault class according to the monitoring indicators included in the fault class and the monitoring values corresponding to the monitoring indicators includes: Obtaining preset values corresponding to the monitoring indicators; For each of the monitoring indicators, a monitoring value corresponding to the monitoring indicator is identified to obtain a numerical value type corresponding to the monitoring value; Determine the target value corresponding to each monitoring indicator according to the numerical type of the monitoring value corresponding to each monitoring indicator and the preset value corresponding to each monitoring indicator; The fault weight of the fault class is determined according to the target value corresponding to each of the monitoring indicators.
3. The method according to claim 2, characterized in that The determining the fault weight of the fault class according to the target value corresponding to each of the monitoring indicators includes: Calculate the fault entropy value of the fault class according to the target value corresponding to each monitoring indicator; Determining a discrete value of the fault class according to the fault entropy value of the fault class; The fault weight of the fault class is determined according to the normalization processing of the discrete value of the fault class.
4. The method according to claim 1, characterized in that After querying the initial emergency response step of each fault class according to each monitoring indicator corresponding to the fault class and the monitoring value corresponding to each monitoring indicator, the method further includes: Obtaining at least one information detection condition of the fault class; Detecting the initial emergency steps of the fault class according to each of the information detection conditions, and determining the detection result of the fault class; Determining, according to the detection result, emergency optimization information corresponding to the initial emergency step of the fault class; The initial emergency steps of the fault class are optimized according to the emergency optimization information.
5. The method according to claim 4, characterized in that The detecting the initial emergency steps of the fault class according to each of the information detection conditions to determine the detection result of the fault class includes: Detecting the initial emergency steps of the fault type according to each of the information detection conditions to obtain the number of abnormal data; Obtaining an abnormal threshold corresponding to the fault class; The number of abnormal data corresponding to the fault class is compared with the abnormal threshold corresponding to the fault class to obtain the detection result of the fault class.
6. The method according to claim 4, characterized in that Determining the emergency optimization information corresponding to the initial emergency step of the fault type according to the detection result includes: If the detection result is that the amount of abnormal data does not exceed the standard, the initial emergency step of the fault class is determined as the emergency optimization information of the fault class; If the detection result is that the amount of abnormal data exceeds the standard, the initial emergency steps of the fault class are re-obtained, and the re-obtained initial emergency steps of the fault class are determined as the emergency optimization information of the fault class, and the detection result is sent to the operation and maintenance personnel for an alarm.
7. The method according to claim 1, characterized in that The obtaining of at least one monitoring indicator corresponding to the system to be detected and a monitoring value corresponding to each monitoring indicator includes: Obtaining at least one monitoring indicator corresponding to the system to be detected and the indicator true value corresponding to each of the monitoring indicators; Obtain at least one indicator data range corresponding to each of the monitoring indicators and an indicator characteristic value corresponding to each of the indicator data ranges; For each of the monitoring indicators, the indicator true value corresponding to the monitoring indicator is compared with the indicator data range corresponding to the monitoring indicator to determine the target data range and target characteristic value corresponding to the monitoring indicator; The target characteristic value corresponding to the monitoring indicator is determined as the monitoring value corresponding to the monitoring indicator.
8. An emergency plan generating device, characterized in that: The device comprises: A data acquisition module, used to acquire at least one monitoring indicator corresponding to the system to be detected and a monitoring value corresponding to each of the monitoring indicators; A data clustering module, used for clustering the monitoring indicators and the monitoring values corresponding to the monitoring indicators to obtain at least one fault class; A weight determination module, for determining, for each of the fault classes, a fault weight of the fault class according to each of the monitoring indicators included in the fault class and a monitoring value corresponding to each of the monitoring indicators; A data query module, for querying the initial emergency steps of each fault class according to each monitoring indicator corresponding to the fault class and the monitoring value corresponding to each monitoring indicator; The plan generation module is used to sort the execution order of each of the initial emergency steps according to the fault weight of each of the fault categories to generate a target emergency plan.
9. An emergency plan generation device, characterized in that: The emergency plan generating device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the emergency plan generation method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the emergency plan generation method according to any one of claims 1 to 7 when executed.