Network video recorder abnormal behavior detection method and system, and storage medium
By building rules engine features, statistical model features and deep learning features in the abnormal behavior detection system of network hard disk recorders, and performing fusion analysis, the problem that existing systems cannot identify burst exceptions is solved, and the reliability of the core functions of the monitoring system is improved.
Patent Information
- Application Number
- CN202510200536.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-05-27
AI Technical Summary
The existing network hard disk recorder abnormal behavior detection system relies on static rules and thresholds, and cannot effectively identify burst abnormalities in application situations, affecting the reliability of the core functions of the monitoring system.
Through the analysis node obtains video feature data, network status data and device status data based on the time window, builds rules engine features, statistical model features and deep learning features, and fuses them and inputs them into the intelligent analysis model to perform abnormal behavior detection.
It realizes the identification and identification of undefined abnormal behaviors, improves the reliability of the core functional functions of the monitoring system, and can comprehensively judge abnormal behaviors from multiple dimensions.
Smart Images

Figure CN120050416A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communications, and in particular to a method for detecting abnormal behavior of a network hard disk video recorder, a system for detecting abnormal behavior of a network hard disk video recorder, and a storage medium. Background Art
[0002] The Network Video Recorder (NVR) is the core device of the security monitoring system, which is mainly used to receive, store, manage and play back the video data transmitted by the IP Camera. Therefore, to ensure the reliability of the core functions of the monitoring system, it is necessary to be able to promptly detect whether the NVR has any abnormal behavior in storage, network connection, equipment operation, security and configuration.
[0003] At present, abnormal behavior detection systems generally rely on static rules and thresholds to detect abnormal behavior of NVRs by setting fixed rules. For example, thresholds corresponding to storage space thresholds, CPU occupancy alarms and other indicators are set to detect abnormal behavior. In the abnormal behavior detection system based on the above method, since each abnormality must first define the corresponding rules for identification, and due to the knowledge limitations of the rule setting personnel, some sudden abnormalities based on application situations cannot be identified. This affects the reliability of the core functions of the monitoring system. Summary of the invention
[0004] The main purpose of the present application is to provide a method for detecting abnormal behavior of a network hard disk recorder, a system for detecting abnormal behavior of a network hard disk recorder and a storage medium, aiming to solve the technical problem that the relevant technical solutions affect the reliability of the core functions of the monitoring system.
[0005] To achieve the above purpose, the present application provides a method for detecting abnormal behavior of a network hard disk video recorder, the method comprising:
[0006] An analysis node of the abnormal behavior detection system acquires raw data based on a time window, wherein the raw data includes video feature data, network status data, and device status data;
[0007] Determine rule engine features, statistical model features, and deep learning features based on the raw data;
[0008] Fusion of the rule engine feature, the statistical model feature and the deep learning feature to obtain a fusion feature;
[0009] The fusion features are input into the intelligent analysis model to obtain abnormal behavior detection results.
[0010] In the embodiment of the present application, before the step of acquiring raw data based on the time window at the analysis node of the abnormal behavior detection system, the method further includes:
[0011] The camera pushes the video stream to the edge network hard disk video recorder, and the built-in streaming media server of the edge network hard disk video recorder receives and forwards the video stream to the edge computing box;
[0012] After the edge computing box pulls the video stream in real time, determining the video feature data based on the video stream;
[0013] The video feature data corresponding to each edge network hard disk video recorder is sequentially sent to the analysis node.
[0014] In the embodiment of the present application, the step of determining the video feature data based on the video stream includes:
[0015] Determine a key frame hash calculation result corresponding to the video stream;
[0016] The key frame hash calculation results are based on the time sequence corresponding to the key frame to construct a hash sequence of continuous key frames as the video feature stream.
[0017] In the embodiment of the present application, the step of determining the rule engine features, the statistical model features and the deep learning features according to the original data includes:
[0018] Inputting the video feature data, the network status data and the device status data into a rule engine to determine a corresponding rule triggering status; and
[0019] Inputting the video feature data, the network status data and the device status data into a statistical model to determine a statistical result;
[0020] Constructing the rule engine feature according to the rule triggering state and the timestamp, device topology relationship and service tag corresponding to the original data; and
[0021] The rule engine feature is constructed according to the statistical result and the timestamp, the device topology relationship and the service label.
[0022] In the embodiment of the present application, the step of inputting the video feature data, the network status data and the device status data into a statistical model to determine the statistical result includes:
[0023] After the statistical model receives the video feature data, the network status data, and the device status data, obtaining a baseline calculated based on an n-day rolling window;
[0024] The baseline is used to calculate the Z score of the current value of each indicator of the original data as the statistical result.
[0025] In the embodiment of the present application, the step of determining the rule engine features, statistical model features and deep learning features according to the original data includes:
[0026] The original data is input into an encoder based on time sequence, and the deep learning features are generated by the encoder.
[0027] In the embodiment of the present application, the step of inputting the fusion feature into the intelligent analysis model to obtain the abnormal behavior detection result includes:
[0028] Sending the fusion feature to the Deepseek platform based on a preset interface;
[0029] Receive the abnormal behavior detection result responded by the Deepseek platform.
[0030] In the embodiment of the present application, after the step of determining the rule engine features, the statistical model features and the deep learning features according to the original data, the method further includes:
[0031] If the original data update based on the time window sliding is detected, the difference between the original data before and after the update is determined;
[0032] The rule engine feature, the statistical model feature and the deep learning feature are updated according to the difference portion.
[0033] The embodiment of the present application also provides a network hard disk video recorder abnormal behavior detection system, the network hard disk video recorder abnormal behavior detection system comprising:
[0034] Analysis component: an analysis node of the abnormal behavior detection system, which obtains raw data based on a time window, wherein the raw data includes video feature data, network status data, and device status data;
[0035] A computing component determines a rule engine feature, a statistical model feature, and a deep learning feature according to the original data; and fuses the rule engine feature, the statistical model feature, and the deep learning feature to obtain a fused feature;
[0036] Sending and receiving component: inputting the fusion features into the intelligent analysis model to obtain abnormal behavior detection results.
[0037] The embodiment of the present application further provides a storage medium, which is a computer-readable storage medium. A computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the method for detecting abnormal behavior of a network hard disk video recorder as described above are implemented.
[0038] The embodiments of the present application disclose a method for detecting abnormal behavior of a network hard disk video recorder and a system for detecting abnormal behavior of a network hard disk video recorder. The fusion features used for analysis are obtained by fusing the original data twice. The first time is to fuse the expressiveness of multi-source data in the process of generating deep learning features. Since the deep learning features alone will ignore the basic rule recognition results and statistical information, the present application further constructs rule engine features and statistical model features based on the original data, so that after being fused with the deep learning features, the statistical expressiveness and rule expressiveness are increased in the fusion features. When abnormal behavior identification is performed based on such fusion features, it is possible to comprehensively judge from multiple dimensions whether abnormal behavior is currently occurring, and even undefined abnormal behavior can be identified, thereby achieving the effect of improving the reliability of the core functions of the monitoring system. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 It is an optional deployment architecture of the abnormal behavior detection system of the network hard disk video recorder involved in the embodiment of the present application;
[0040] Figure 2 It is a flow chart of an embodiment of a method for detecting abnormal behavior of a network hard disk video recorder involved in an embodiment of the present application;
[0041] Figure 3 This is a schematic diagram of data differences involved in the embodiments of the present application;
[0042] Figure 4 A schematic diagram of data flow in an analysis node involved in an embodiment of the present application;
[0043] Figure 5 This is a schematic diagram of the structure of the abnormal behavior detection device of the network hard disk video recorder in this application;
[0044] Figure 6 This is a schematic diagram of the modular structure of the abnormal behavior detection system of the network hard disk video recorder in this application.
[0045] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0046] It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0047] The Network Video Recorder (NVR) is the core device of the security monitoring system, which is mainly used to receive, store, manage and play back the video data transmitted by the IP Camera. Therefore, to ensure the reliability of the core functions of the monitoring system, it is necessary to be able to promptly detect whether the NVR has any abnormal behavior in storage, network connection, equipment operation, security and configuration.
[0048] At present, abnormal behavior detection systems generally rely on static rules and thresholds to detect abnormal behavior of NVRs by setting fixed rules. For example, thresholds corresponding to storage space thresholds, CPU occupancy alarms and other indicators are set to detect abnormal behavior. In the abnormal behavior detection system based on the above method, since each abnormality must first define the corresponding rules for identification, and due to the knowledge limitations of the rule setting personnel, some sudden abnormalities based on application situations cannot be identified. This affects the reliability of the core functions of the monitoring system.
[0049] Based on the above background, the present application provides a method for detecting abnormal behavior of a network hard disk recorder. After collecting raw data such as video feature data, network status data and device status data, the method first constructs rule engine features, statistical model features and deep learning features based on the raw data for subsequent analysis. Basic features. This enhances the ability of raw data to express abnormal behavior. Further, based on the enhanced raw data, fusion is performed and input into deepseek or other similar intelligent analysis models, so that the intelligent model can rely on the difference between the fusion feature and the fusion feature corresponding to the normal behavior stage to determine whether there is an abnormality at present, and identify the specific type of the current abnormality based on the difference between the fusion feature and the feature corresponding to the known type of abnormal behavior. In this way, when abnormal behavior occurs, the detection system can discover abnormal behavior of unknown types and give timely warnings. Thereby effectively improving the reliability of the core functions of the monitoring system.
[0050] To facilitate understanding, the technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0051] Please refer to Figure 1 The present application provides a network video recorder abnormal behavior detection system, which includes an edge layer data processing node (hereinafter described as an NVR node), a data transmission layer and an analysis node.
[0052] The components of the NVR node include cameras, edge network video recorders (i.e. edge NVRs), and edge computing boxes connected in sequence. As an optional implementation, each camera pushes the video stream to the edge NVR via the RTSP protocol, and the edge NVR's built-in streaming media server (such as Nginx-RTMP) receives and forwards the above video stream to the edge computing box. This allows the edge computing box to pull the video stream in real time, then extract video feature data based on the video stream, and forward it to the analysis node through the data transmission layer.
[0053] It should be noted that the NVR node can also deploy a lightweight agent program in the NVR based on an embedded probe or other collection methods to collect the device operation status parameters of the network hard disk recorder as device status data. Among them, the device status parameters may include but are not limited to hardware indicators, such as CPU usage, memory occupancy, disk IO rate, and hard disk temperature. Storage health indicators, such as hard disk SMART status (number of bad sectors, number of remapped sectors), remaining storage space. System process status, such as the status of key processes such as video decoding service process and storage service process.
[0054] The network parameter collection unit of the abnormal behavior detection system of the network hard disk recorder can send the collected network status data to the analysis node through the transport layer. The network status data can include traffic characteristics, such as upstream / downstream bandwidth occupancy, TCP retransmission rate, network jitter. Connection status, such as the number of online cameras and the number of abnormal IP connection attempts. Protocol analysis results, such as RTSP / ONVIF protocol traffic proportion and private protocol characteristics.
[0055] Optionally, in this embodiment, the data transmission layer may include an edge computing box, a message queue, and an analysis platform. For example, the message queue may be a Kafka message, and the analysis platform may be a deepseek analysis platform.
[0056] The analysis node includes a message queue and an analysis module, and the analysis module includes an analysis component, a calculation component, and a sending and receiving component.
[0057] Please refer to Figure 2 The present application also provides a method for detecting abnormal behavior of a network video recorder. In an optional implementation, the method includes the following steps:
[0058] Step S10: The analysis node of the abnormal behavior detection system obtains raw data based on the time window, wherein the raw data includes video feature data, network status data and device status data;
[0059] In the process of acquiring raw data, the analysis node can acquire the raw data in the time window based on the time window, so as to perform subsequent analysis through the raw data in the window. The time window step can be selectively set according to the specific needs of the system. For example, it can be set to 5 minutes to 10 minutes. Or the step can be set to 30 minutes to 60 minutes according to the needs. In addition, during the sliding of the time window, the sliding interval can also be set according to the needs.
[0060] Before being acquired, the above raw data may be cached in the analysis node in the form of a message queue. The message queue is set to first-in-first-out, and the length of the message queue may be set based on the cache capacity requirement.
[0061] In an example solution, the message queue can be a Kafka message queue. Independent consumer groups are created for the three types of data: video feature data, network status data, and device status data, or logical isolation is performed when a consumer group is shared to ensure that the consumption progress of each data type is managed independently. In addition, the data of each NVR can be fixedly written into the corresponding partition, so that consumers can also distinguish which NVR the data belongs to when reading the data.
[0062] Then, based on the time window, the original data in the current window is read from the Kafka message queue as the basic data for subsequent analysis.
[0063] Step S20: determining rule engine features, statistical model features and deep learning features according to the original data;
[0064] After reading the raw data, the analysis node first performs preprocessing operations on the acquired element data to convert the raw data into rule engine features, statistical model features and deep learning features. Among them, the preprocessing module of the analysis node also includes a rule engine, a statistical model and an encoder. After the raw data is input into the rule engine, the statistical model and the encoder respectively, the above rule engine features, statistical model features and deep learning features are obtained.
[0065] It should be noted that the rule engine is provided with preset encoding rules for the original data, so that the rule engine feature can be constructed according to the rule triggering state and the timestamp, device topology relationship and service tag corresponding to the original data.
[0066] Optionally, the data encoding rules of the rule engine have different settings for different indicators. It can be customized according to the specific content of the original data in the system design. It at least includes encoding rules for numerical type indicators and encoding rules for text type indicators. For numerical type indicators, multiple numerical intervals can be set according to the possible amplitude range of the numerical indicator. When the current numerical indicator is in different intervals, different encoding results are obtained. In order to achieve a unified description of the numerical indicator.
[0067] Exemplarily, hard disk temperature and packet loss rate are used as examples for explanation. The hard disk temperature and packet loss rate collected at the four time nodes a, b, c, and d are (T1, M1), (T2, M2), (T3, M3), and (T3, M3), respectively. Among them, T1 to T4 are temperature values, and M1 to M4 are packet loss rates. After entering them into the rule model, the trigger states corresponding to T1 to T4, that is, the temperature intervals to which they belong, can be determined respectively. Different temperature intervals can correspond to different encoding values. For example, T1 and T2 belong to temperature interval 1, and T3 and T4 belong to temperature interval 2. The encoding value corresponding to temperature interval 1 is 001, and the encoding value corresponding to temperature interval 2 is 011; M1 to M4 are in packet loss rate interval 1, and the encoding value corresponding to packet loss rate interval 1 is 100. After encoding the collected original data, the encoding result can be obtained as [001, 100, 001, 100, 011, 100, 011, 100]. Then, the encoding results of the device topology relationship and the business label are obtained, and after the data encoding results, the device topology relationship and the business label are combined, the rule engine features corresponding to the current time window are obtained.
[0068] It should be noted that the device topology relationship and service label are fixed contents after the device is deployed, so their fixed coding values can be preset. Or they can also be coded in real time according to the rules. This embodiment does not limit this. In addition, the timestamp is reflected in the coding process, that is, in the final coding result, and its coding order is sorted according to the corresponding timestamp. It can be understood that if the collected original data is continuous data, it can be sampled based on the preset frequency to obtain discrete values. In addition, the network hard disk recorder abnormal behavior detection system has done clock synchronization in the initialization stage, so that each data collection environment can collect data synchronously. For text data, when encoding, encoding rules adapted to its specific content can also be set. For example, based on the text of the standard template, the encoding of the text content can be directly realized by using the coding table according to the text content. For video feature data, since it is a hash sequence itself, it can be directly used as the encoding result and spliced. In this way, based on the rule engine, the purpose of encoding and fusing three different types of original data is achieved. The rule engine feature obtained has a more integrated expressiveness.
[0069] Optionally, see Figure 3 In order to save encoding time, after the time window slides, that is, after the analysis node obtains the original data based on the time window again to update the original data, there is an overlapping part before and after the window slides. Therefore, the overlapping part is not repeatedly encoded, but only the difference part is encoded to achieve the update of the features. This can effectively save the computing power requirements in the encoding process. The determination of the difference part can be directly determined according to the sliding step size of the sliding window.
[0070] Exemplarily, after the raw data is obtained, the video feature data, the network status data, and the device status data can also be input into a statistical model to determine the statistical results. After the statistical model receives the video feature data, the network status data, and the device status data, a baseline calculated based on an n-day rolling window is obtained, and the Z score of the current value of each indicator of the raw data is calculated using the baseline as the statistical result, and then the rule engine feature is constructed based on the statistical result and the timestamp, the device topology relationship, and the service tag.
[0071] It is understandable that different statistical results have different expressiveness, and different statistical methods can be adopted for different data contents in the original data. The setting of the specific statistical method is not repeated in this embodiment. As for the statistical model, its main function is to encode the original data based on the preset statistical rules, and then splice the statistical results and timestamps, the device topology relationship and the service label to obtain statistical information.
[0072] Optionally, the analysis node further includes an encoder, wherein the original data can be input into the encoder based on time sequence, and the deep learning features are generated by the encoder.
[0073] For example, if the video feature data only includes the hash sequence, the video feature encoder of the encoder can encode it directly. If it also includes structural features such as video frame rate, bit rate, key frame interval and motion vector strength, a temporal convolutional network can be used to capture the temporal dependency and output a time-aware compressed feature vector.
[0074] The network state encoder corresponding to the network state data can take network state data such as bandwidth fluctuation, transmission delay, packet loss rate, TCP retransmission times, etc. as input, and use the bidirectional LSTM network to model the short-term fluctuation and long-term trend of the network state to obtain the corresponding features to be fused. Then, the device state encoder takes device state data such as CPU / memory occupancy, disk input / output, temperature sensor data, etc. as input, and extracts multi-dimensional correlation features of the device state through the self-attention mechanism.
[0075] Furthermore, a multimodal dynamic gating network is used to fuse the outputs of the sub-encoders. The weight values in the fusion process can be preset data, or the fusion weights can be dynamically adjusted according to the confidence of each modality data in the current window. This embodiment is not limited to this. After the multimodal dynamic gating network determines the fusion weights, weighted fusion can be performed based on the weights to obtain deep learning features.
[0076] Step S30: fusing the rule engine feature, the statistical model feature and the deep learning feature to obtain a fusion feature;
[0077] Step S40: input the fusion features into the intelligent analysis model to obtain abnormal behavior detection results.
[0078] Reference Figure 4 After the raw data is obtained based on the time window, the raw data is input into the rule engine, the statistical model and the encoder respectively. The encoder includes a video feature encoder, a network status encoder and a device status encoder. Therefore, when the raw data is input into the encoder, the video feature data, the network status data and the device status data can be used as the input of the three sub-encoders of the video feature encoder, the network status encoder and the device status encoder respectively, and the inputs of the three sub-encoders are weighted and fused through the fusion module to obtain the deep learning features.
[0079] Furthermore, the rule engine features, the statistical model features and the deep learning features may be fused to obtain fused features, and the fused features may be input into an intelligent analysis model to obtain abnormal behavior detection results.
[0080] The intelligent analysis model may be a model pre-trained based on sample data. After receiving the fusion vector, it may determine whether there is abnormal behavior at the current moment based on clustering or vector difference, and identify specific abnormal behavior, depending on the design of the intelligent analysis model.
[0081] For example, when performing abnormality identification based on clustering, each known abnormal behavior and normal state can be used as a cluster core for limited distance clustering. When the clustering result of the fused sample is obtained, if it belongs to the same category as a known abnormal behavior, it is determined that the corresponding known abnormal behavior is currently occurring. Similarly, if it belongs to the same category as the normal state, it is determined that no abnormal behavior is currently occurring. If it cannot be classified into any cluster core, it means that an unknown abnormality has occurred.
[0082] It should be noted that during the model training process, the normal state can correspond to one or more cluster cores. For example, the normal state during the busy period, the normal state during the idle period, and other cluster cores. This allows for further state segmentation in each state, rather than just expressing that the current state is normal, which is conducive to subsequent management actions based on the results.
[0083] When judging based on vector differences, the cosine similarity can be used to determine the difference amount, and then a threshold corresponding to the difference amount is set to determine the current abnormal behavior detection result based on the threshold and the difference.
[0084] Optionally, the intelligent analysis model can be a remotely deployed intelligent model, for example, it can be a deepseek platform, or other platforms with intelligent analysis capabilities, so that after the analysis node obtains the fusion vector, the fusion vector can be directly sent to the corresponding platform based on a preset interface, and the abnormal behavior detection result can be obtained through the platform. For example, the fusion feature can be sent to the Deepseek platform based on a preset interface, and then the abnormal behavior detection result responded by the Deepseek platform is received.
[0085] In the solution provided in this embodiment, the fusion features used for analysis are obtained by fusing the original data twice. The first time is to fuse the expressiveness of multi-source data in the process of generating deep learning features. Since the deep learning features alone will ignore the basic rule recognition results and statistical information, the present application further constructs rule engine features and statistical model features based on the original data, so that after being fused with the deep learning features, the statistical expressiveness and rule expressiveness are increased in the fusion features. When abnormal behavior identification is performed based on such fusion features, it is possible to comprehensively judge whether abnormal behavior is currently occurring from multiple dimensions, and even undefined abnormal behavior can be identified, thereby achieving the effect of improving the reliability of the core functions of the monitoring system.
[0086] In another embodiment of the present application, based on the above embodiment, before step S10, the method further includes:
[0087] The camera pushes the video stream to the edge network hard disk recorder, and the video stream is received and forwarded to the edge computing box through the built-in streaming media server of the edge network hard disk recorder. After the edge computing box pulls the video stream in real time, the video feature data is determined based on the video stream, and the video feature data corresponding to each edge NVR is sent to the analysis node in sequence.
[0088] Optionally, the edge computing box can determine the key frame hash calculation result corresponding to the video stream, and then construct a hash sequence of continuous key frames based on the key frame hash calculation result based on the time sequence corresponding to the key frame as the video feature stream. Alternatively, in some schemes, the edge computing box can also determine the video frame rate, bit rate, key frame interval, motion vector strength and other structural features based on the video stream as video feature data.
[0089] Optionally, after step S40, the process further includes inputting the fusion vector and the abnormal behavior detection result into a root cause analysis model if abnormal behavior is detected, determining a processing action to be executed according to the cause of the abnormal behavior output by the root cause analysis model, and executing the processing action.
[0090] The present application provides a network hard disk video recorder abnormal behavior detection device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the network hard disk video recorder abnormal behavior detection method in the above-mentioned embodiment one.
[0091] Reference below Figure 5, which shows a schematic diagram of the structure of a network hard disk video recorder abnormal behavior detection device suitable for implementing the embodiment of the present application. The network hard disk video recorder abnormal behavior detection device in the embodiment of the present application may include but is not limited to mobile phones, tablets, PCs, servers and smart wearable devices. Figure 4 The network hard disk video recorder abnormal behavior detection device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0092] like Figure 5 As shown, the abnormal behavior detection device of the network hard disk video recorder may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1002 or the program loaded from the storage device 1003 to the random access memory (RAM) 1004. In the random access memory 1004, various programs and data required for the operation of the abnormal behavior detection device of the network hard disk video recorder are also stored. The processing device 1001, the read-only memory 1002 and the random access memory 1004 are connected to each other through a bus 1005. The input / output interface 1006 is also connected to the bus. Generally, the following systems can be connected to the input / output interface 1006: an input device 1007 including, for example, a touch screen, a touch pad, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the network video recorder abnormal behavior detection device to communicate with other devices wirelessly or by wire to exchange data. Although the figure shows a network video recorder abnormal behavior detection device with various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems can be implemented or have alternatively.
[0093] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a read-only memory 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0094] The network hard disk video recorder abnormal behavior detection device provided by the present application adopts the network hard disk video recorder abnormal behavior detection device method in the above embodiment to solve the technical problem that affects the reliability of the core function of the monitoring system. Compared with the related art, the beneficial effect of the network hard disk video recorder abnormal behavior detection device provided by the present application is the same as the beneficial effect of the network hard disk video recorder abnormal behavior detection method provided by the above embodiment, and the other technical features in the network hard disk video recorder abnormal behavior detection device are the same as the features disclosed in the method of the previous embodiment, which will not be repeated here.
[0095] It should be understood that the various parts disclosed in this application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0096] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0097] Please refer to Figure 6 The present application provides a network hard disk video recorder abnormal behavior detection system, and the network hard disk video recorder abnormal behavior detection system 100 includes:
[0098] Analysis module 110: an analysis node of the abnormal behavior detection system, which obtains raw data based on a time window, wherein the raw data includes video feature data, network status data, and device status data;
[0099] The calculation module 120 determines the rule engine feature, the statistical model feature and the deep learning feature according to the original data; and fuses the rule engine feature, the statistical model feature and the deep learning feature to obtain a fusion feature;
[0100] The sending and receiving module 130 inputs the fusion features into the intelligent analysis model to obtain abnormal behavior detection results.
[0101] The present application provides a computer-readable storage medium having computer-readable program instructions (ie, computer programs) stored thereon, and the computer-readable program instructions are used to execute the abnormal behavior detection method for a network hard disk video recorder in the above-mentioned embodiment.
[0102] The computer-readable storage medium provided in the present application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems or devices, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (Random Access Memory, RAM,), a read-only memory (Read Only Memory, ROM), an erasable programmable read-only memory (Erasable Programmable Read Only Memory, EPROM) or flash memory, an optical fiber, a portable compact disk read-only memory (CD-Read Only Memory, CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present embodiment, the computer-readable storage medium can be any tangible medium containing or storing a program, which can be used by an instruction execution system, system or device or used in combination with it. The program code contained on the computer-readable storage medium can be transmitted with any appropriate medium, including but not limited to: wires, optical cables, radio frequency (Radio Frequency, RF), etc., or any suitable combination of the above.
[0103] The computer-readable storage medium may be included in the abnormal behavior detection device for a network hard disk video recorder; or may exist independently without being assembled into the abnormal behavior detection device for a network hard disk video recorder.
[0104] The computer-readable storage medium carries one or more programs. When the one or more programs are executed by the network video recorder abnormal behavior detection device, the network video recorder abnormal behavior detection device can improve the storage efficiency of the warehouse based on the method.
[0105] The computer program code for performing the operation of the present application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as an independent software package, partially on the user's computer, partially on the remote computer, or completely on the remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., using an Internet service provider to connect through the Internet).
[0106] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0107] The modules involved in the embodiments described in the present application may be implemented by software or hardware, wherein the name of the module does not constitute a limitation on the unit itself in some cases.
[0108] The readable storage medium provided by the present application is a computer-readable storage medium, which stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned network hard disk video recorder abnormal behavior detection method, and can solve the technical problems affecting the reliability of the core functions of the monitoring system. Compared with the related art, the beneficial effects of the computer-readable storage medium provided by the present application are the same as the beneficial effects of the network hard disk video recorder abnormal behavior detection method provided by the above-mentioned embodiment, and will not be repeated here.
[0109] An embodiment of the present application provides a computer program product, including a computer program, which implements the steps of the above-mentioned method for detecting abnormal behavior of a network hard disk video recorder when executed by a processor.
[0110] The computer program product provided by this application can solve the technical problem of low storage efficiency caused by static layout. Compared with the related art, the beneficial effects of the computer program product provided by the embodiment of this application are the same as the beneficial effects of the abnormal behavior detection method of the network hard disk recorder provided by the above embodiment, which will not be repeated here.
[0111] The above are only preferred embodiments of the present application, and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made by using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent scope of the present application.
[0112] It should be noted that, in this article, the terms "include", "comprises" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or system including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or system. In the absence of further restrictions, an element defined by the sentence "including a ..." does not exclude the existence of other identical elements in the process, method, article or system including the element. In the intervals given in this application, the boundary values are all included unless explicitly defined.
[0113] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method.
[0114] The above are only preferred embodiments of the present application, and are not intended to limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.
Claims
1. A method for detecting abnormal behavior of a network video recorder, characterized in that: The abnormal behavior detection method of the network hard disk video recorder includes: An analysis node of the abnormal behavior detection system acquires raw data based on a time window, wherein the raw data includes video feature data, network status data, and device status data; Determine rule engine features, statistical model features, and deep learning features based on the raw data; Fusion of the rule engine feature, the statistical model feature and the deep learning feature to obtain a fusion feature; The fusion features are input into the intelligent analysis model to obtain abnormal behavior detection results.
2. The method for detecting abnormal behavior of a network video recorder according to claim 1, characterized in that: Before the step of acquiring raw data based on the time window by the analysis node of the abnormal behavior detection system, the method further includes: The camera pushes the video stream to the edge network hard disk video recorder, and the built-in streaming media server of the edge network hard disk video recorder receives and forwards the video stream to the edge computing box; After the edge computing box pulls the video stream in real time, determining the video feature data based on the video stream; The video feature data corresponding to each edge network hard disk video recorder is sequentially sent to the analysis node.
3. The method for detecting abnormal behavior of a network video recorder according to claim 2, characterized in that: The step of determining the video feature data based on the video stream comprises: Determine a key frame hash calculation result corresponding to the video stream; The key frame hash calculation results are based on the time sequence corresponding to the key frame to construct a hash sequence of continuous key frames as the video feature stream.
4. The method for detecting abnormal behavior of a network video recorder according to claim 1, characterized in that: The step of determining the rule engine features, statistical model features and deep learning features according to the original data comprises: Inputting the video feature data, the network status data and the device status data into a rule engine to determine a corresponding rule triggering status; and Inputting the video feature data, the network status data and the device status data into a statistical model to determine a statistical result; Constructing the rule engine feature according to the rule triggering state and the timestamp, device topology relationship and service tag corresponding to the original data; and The rule engine feature is constructed according to the statistical result and the timestamp, the device topology relationship and the service label.
5. The method for detecting abnormal behavior of a network video recorder according to claim 4, characterized in that: The step of inputting the video feature data, the network status data and the device status data into a statistical model to determine the statistical result comprises: After the statistical model receives the video feature data, the network status data, and the device status data, obtaining a baseline calculated based on an n-day rolling window; The baseline is used to calculate the Z score of the current value of each indicator of the original data as the statistical result.
6. The method for detecting abnormal behavior of a network video recorder according to claim 1, characterized in that: The step of determining the rule engine features, statistical model features and deep learning features according to the original data comprises: The original data is input into an encoder based on time sequence, and the deep learning features are generated by the encoder.
7. The method for detecting abnormal behavior of a network video recorder according to claim 1, characterized in that: The step of inputting the fusion feature into the intelligent analysis model to obtain the abnormal behavior detection result comprises: Sending the fusion feature to the Deepseek platform based on a preset interface; Receive the abnormal behavior detection result responded by the Deepseek platform.
8. The method for detecting abnormal behavior of a network video recorder according to claim 1, characterized in that: After the step of determining the rule engine features, the statistical model features and the deep learning features according to the original data, the method further comprises: If the original data update based on the time window sliding is detected, the difference between the original data before and after the update is determined; The rule engine feature, the statistical model feature and the deep learning feature are updated according to the difference portion.
9. A network hard disk video recorder abnormal behavior detection system, characterized in that: The network hard disk video recorder abnormal behavior detection system comprises: Analysis component: an analysis node of the abnormal behavior detection system, which obtains raw data based on a time window, wherein the raw data includes video feature data, network status data, and device status data; A computing component determines a rule engine feature, a statistical model feature, and a deep learning feature according to the original data; and fuses the rule engine feature, the statistical model feature, and the deep learning feature to obtain a fused feature; Sending and receiving component: inputting the fusion features into the intelligent analysis model to obtain abnormal behavior detection results.
10. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the abnormal behavior detection method of a network hard disk video recorder according to any one of claims 1 to 8 are implemented.