A method and apparatus for traffic analysis of a service

By building a multi-level time window and dynamically adjusting according to the system load and fluctuation characteristics, real-time abnormality detection of business traffic is achieved, solving the problem that it is difficult to detect burst traffic in a fixed time window, and improving the adaptability and accuracy of analysis.

CN120090957BActive Publication Date: 2025-07-22SHENZHEN HUOLI TIAN HUI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510541155.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-07-22
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

In the prior art, the traffic analysis method with a fixed time window is difficult to detect bursty service traffic abnormalities in real time, resulting in increased system pressure and alarm delay.

Method used

By building a multi-level time window, dynamically adjusting the time window level according to the system load indicators and traffic fluctuations characteristics, abnormal detection is performed in combination with business foundations and compound indicators, and alarms are output.

Benefits of technology

Improve the adaptability and accuracy of traffic analysis, respond to network traffic changes in real time, reduce resource consumption, and avoid missing out on unexpected traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090957B_ABST
    Figure CN120090957B_ABST
Patent Text Reader

Abstract

This application belongs to the field of traffic technology, and discloses a method and device for traffic analysis of services. The method includes: obtaining service logs of multiple services, and constructing multiple levels of time windows corresponding to the multiple services; for any service, and according to the system load index, adjusting the window levels of the multiple levels of time windows; for any service, determining the fluctuation characteristics of the traffic of the service according to the service logs, and adjusting the window levels of the multiple levels of time windows according to the fluctuation characteristics; for any level of time window, determining the service basic index and service composite index within the time range of the previous time window according to the service logs; for any service, determining whether the service is abnormal according to the service basic index and service composite index of each level of time window, and if it is abnormal, outputting an abnormal alarm. Using this application, the real-time performance of service detection can be improved by dynamically adjusting the size of the analysis time window.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of traffic, and particularly to a method and device for traffic analysis of services. Background Art

[0002] In Internet applications, traffic analysis of services is a basic and crucial task. In the prior art, the method of traffic analysis is to use fixed time windows to perform statistics and analysis on services. For example, the traffic of services within 1 minute, 5 minutes, or 1 hour is statistically analyzed. However, at a certain moment, the traffic of a service suddenly becomes extremely high. The sudden increase in traffic may cause pressure on the system and result in anomalies. Moreover, when sudden traffic is detected, an alarm needs to be issued as soon as possible. If the sudden traffic of the service is missed and no alarm is issued, greater problems will arise. Therefore, there is an urgent need for a method for traffic analysis of services to improve the real-time detection of sudden traffic. Summary of the Invention

[0003] Based on this, in view of the above technical problems, it is necessary to provide a method and device for traffic analysis of services.

[0004] In a first aspect, a method for traffic analysis of services is provided. The method includes:

[0005] Obtain service logs of multiple services, and construct multiple levels of time windows corresponding to each of the multiple services;

[0006] For any service, obtain the system load metrics of the service, and adjust the window levels of the multiple levels of time windows according to the system load metrics;

[0007] For any service, determine the traffic fluctuation characteristics of the service according to the service log, and adjust the window levels of the multiple levels of time windows according to the fluctuation characteristics;

[0008] For any level of time window, within the time range of the time window, determine the service basic metrics and service composite metrics within the time range of the previous time window according to the request data in the service log;

[0009] For any service, determine whether the service is abnormal according to the service basic metrics and service composite metrics of each level of time window. If the service is abnormal, output an abnormal alarm.

[0010] As an optional implementation, the system load metrics include CPU usage rate, memory usage rate, and number of requests. The obtaining the system load metrics of the service and adjusting the window levels of the multiple levels of time windows according to the system load metrics includes:

[0011] Obtain the CPU usage rate and the memory usage rate of the service through the system interface, and determine the number of requests of the service according to the service log;

[0012] When the CPU usage rate is greater than the preset CPU usage rate threshold, the memory usage rate is greater than the preset memory usage rate threshold, or the number of requests is greater than the preset number of requests threshold, reduce the window level of the time windows at multiple levels;

[0013] When the CPU usage rate is less than or equal to the preset CPU usage rate threshold, the memory usage rate is less than or equal to the preset memory usage rate threshold, and the number of requests is less than or equal to the preset number of requests threshold, increase the window level of the time windows at multiple levels.

[0014] As an alternative implementation, the system load metrics include CPU usage rate, memory usage rate, and number of requests. Adjusting the window level of the time windows at multiple levels according to the system load metrics includes:

[0015] Determine the sum of the product of the CPU usage rate and the preset CPU usage rate weight coefficient, the product of the memory usage rate and the preset memory usage rate weight coefficient, and the product of the number of requests and the preset number of requests weight coefficient as the target system load metric;

[0016] If the target system load metric is greater than the preset system load metric threshold, reduce the window level of the time windows at multiple levels;

[0017] If the target system load metric is less than or equal to the preset system load metric threshold, increase the window level of the time windows at multiple levels.

[0018] As an alternative implementation, the fluctuation characteristics include stable, fluctuating, and sudden. Adjusting the window level of the time windows at multiple levels according to the fluctuation characteristics includes:

[0019] When the fluctuation characteristic is stable, increase the window level of the time windows at multiple levels;

[0020] When the fluctuation characteristic is fluctuating or sudden, reduce the window level of the time windows at multiple levels.

[0021] As an alternative implementation, determining whether the service is abnormal according to the business basic metrics and business composite metrics of the time windows at each level includes:

[0022] Compare the business basic metrics and preset business basic metric thresholds, and the business composite metrics and preset business composite metric thresholds of the time windows at each level to determine whether the business is abnormal.

[0023] As an alternative implementation, determining whether the business is abnormal according to the business basic metrics and business composite metrics of the time windows at each level includes:

[0024] Set corresponding level weights for time windows at different levels, and determine the sum of the products of the business basic metrics of the time windows at all levels and the corresponding level weights as the target basic metric;

[0025] Determine the sum of the products of the business composite metrics of the time windows at all levels and the corresponding level weights as the target composite metric;

[0026] Compare the target basic metric and the preset target basic metric threshold, and the target composite metric and the preset target composite metric threshold to determine whether the business is abnormal.

[0027] In a second aspect, an apparatus for traffic analysis of a service is provided. The apparatus includes:

[0028] An acquisition module, configured to acquire service logs of multiple services and construct multiple levels of time windows corresponding to each of the multiple services;

[0029] An obtaining module, configured to obtain, for any one service, the system load metrics of the service and adjust the window levels of the multiple levels of time windows according to the system load metrics;

[0030] A first determination module, configured to determine, for any one service, the fluctuation characteristics of the traffic of the service according to the service log and adjust the window levels of the multiple levels of time windows according to the fluctuation characteristics;

[0031] A second determination module, configured to determine, for any level of time window, within the time range of the time window, the business basic metrics and business composite metrics within the time range of the previous time window according to the request data in the service log;

[0032] A third determination module, configured to determine, for any one service, whether the service is abnormal according to the business basic metrics and business composite metrics of the time windows at each level, and if the service is abnormal, output an abnormal alarm.

[0033] As an alternative implementation, the system load metrics include CPU usage rate, memory usage rate, and number of requests. The obtaining module is specifically configured to:

[0034] Obtain the CPU usage rate and the memory usage rate of the service through the system interface, and determine the number of requests of the service according to the service log;

[0035] When the CPU usage rate is greater than the preset CPU usage rate threshold, the memory usage rate is greater than the preset memory usage rate threshold, or the number of requests is greater than the preset number of requests threshold, reduce the window level of the time windows at multiple levels;

[0036] When the CPU usage rate is less than or equal to the preset CPU usage rate threshold, the memory usage rate is less than or equal to the preset memory usage rate threshold, and the number of requests is less than or equal to the preset number of requests threshold, increase the window level of the time windows at multiple levels.

[0037] As an optional implementation manner, the system load metrics include CPU usage rate, memory usage rate, and number of requests. The obtaining module is specifically configured to:

[0038] Determine the sum of the product of the CPU usage rate and the preset CPU usage rate weight coefficient, the product of the memory usage rate and the preset memory usage rate weight coefficient, and the product of the number of requests and the preset number of requests weight coefficient as the target system load metric;

[0039] If the target system load metric is greater than the preset system load metric threshold, reduce the window level of the time windows at multiple levels;

[0040] If the target system load metric is less than or equal to the preset system load metric threshold, increase the window level of the time windows at multiple levels.

[0041] As an optional implementation manner, the fluctuation characteristics include stable, fluctuating, and sudden. The first determining module is specifically configured to:

[0042] When the fluctuation characteristic is stable, increase the window level of the time windows at multiple levels;

[0043] When the fluctuation characteristic is fluctuating or sudden, reduce the window level of the time windows at multiple levels.

[0044] As an optional implementation manner, the third determining module is specifically configured to:

[0045] Compare the service basic metrics and the preset service basic metric thresholds, and the service composite metrics and the preset service composite metric thresholds of the time windows at each level to determine whether the service is abnormal.

[0046] As an optional implementation manner, the third determining module is specifically configured to:

[0047] Set corresponding hierarchical weights for time windows at different levels, and determine the target basic metric as the sum of the products of the business basic metrics of time windows at all levels and the corresponding hierarchical weights;

[0048] Determine the target composite metric as the sum of the products of the business composite metrics of time windows at all levels and the corresponding hierarchical weights;

[0049] Compare the target basic metric with a preset target basic metric threshold, and compare the target composite metric with a preset target composite metric threshold to determine whether the business is abnormal.

[0050] In a third aspect, a system for traffic analysis of a service is provided. The system for traffic analysis of the service includes: the method for traffic analysis of the service as described in the first aspect and the device for traffic analysis of the service as described in the second aspect.

[0051] In a fourth aspect, a computer device is provided, including a memory and a processor. A computer program that can run on the processor is stored on the memory. When the processor executes the computer program, the method steps as described in the first aspect are implemented.

[0052] In a fifth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the method steps as described in the first aspect are implemented.

[0053] The present application provides a method for traffic analysis of services. The technical solutions provided by the embodiments of the present application at least bring the following beneficial effects: obtaining service logs of multiple services, and constructing multiple levels of time windows corresponding to each of the multiple services; for any service, obtaining the system load index of the service, and adjusting the window levels of the multiple levels of time windows according to the system load index; for any service, determining the fluctuation characteristics of the traffic of the service according to the service log, and adjusting the window levels of the multiple levels of time windows according to the fluctuation characteristics; for any level of time window, within the time range of the time window, determining the service basic index and service composite index within the time range of the previous time window according to the request data in the service log; for any service, determining whether the service is abnormal according to the service basic index and service composite index of each level of time window, and if the service is abnormal, outputting an abnormal alarm. In this way, an adaptive time window traffic analysis method according to the system load index and the fluctuation characteristics of the traffic dynamically adjusts the time window size, realizes multi-level traffic monitoring, significantly improves the adaptability and accuracy of traffic analysis, can respond in real time to the dynamic changes of network traffic, and improves the real-time detection of sudden traffic. By dynamically adjusting the time window size, it is possible to adapt to the time granularity requirements of different service scenarios and not miss sudden abnormal traffic.

[0054] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0056] Figure 1 Structural schematic diagram of a traffic analysis system for a service provided by an embodiment of the present application;

[0057] Figure 2 Flowchart of a traffic analysis method for a service provided by an embodiment of the present application;

[0058] Figure 3 Structural schematic diagram of a traffic analysis device for a service provided by an embodiment of the present application;

[0059] Figure 4 Structural schematic diagram of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0060] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0061] The method for traffic analysis of services provided by the embodiments of the present application can be applied to a traffic analysis system for services. As Figure 1 shown, the traffic analysis system for services includes a server 101 and a client 102. The server 101 is connected to the client 102.

[0062] The server 101 is configured to execute a program corresponding to a service after receiving a service request sent by the client 102. Obtain service logs of multiple services, and construct multiple levels of time windows corresponding to each service among the multiple services. For any service, obtain the system load index of the service, and adjust the window levels of the multiple levels of time windows according to the system load index. For any service, determine the fluctuation characteristics of the traffic of the service according to the service log, and adjust the window levels of the multiple levels of time windows according to the fluctuation characteristics. For any level of time window, within the time range of the time window, determine the service basic index and service composite index within the time range of the previous time window according to the request data in the service log. For any service, determine whether the service is abnormal according to the service basic index and service composite index of each level of time window. If the service is abnormal, output an abnormal alarm.

[0063] The client 102 is configured to send a service request to the server 101.

[0064] Next, a method for traffic analysis of a service provided by the embodiments of the present application will be described in detail in conjunction with specific embodiments. Figure 2 It is a flowchart of a method for traffic analysis of a service provided by the embodiments of the present application. As Figure 2 shown, the specific steps are as follows:

[0065] Step 201: Obtain service logs of multiple services, and construct multiple levels of time windows corresponding to each service among the multiple services.

[0066] In implementation, in the prior art, the traffic of services is statistically analyzed through fixed time windows. However, the fixed time windows may miss the sudden abnormal traffic of services. Traffic analysis is to analyze the data collected during the operation of services through periodic time windows. Then, multiple levels of time windows corresponding to each service among multiple services can be constructed. Through the multiple levels of time windows, the traffic with different time spans can be detected and analyzed. At the beginning, the smallest statistical time unit needs to be set, and the time unit can be 1 second or 1 minute. Different levels of time windows contain different numbers of time units. The higher the level, the more time units are included, that is, the larger the time span. The size of the time range of each level of time window can be a multiple of the size of the time range of the time window of the next lower level. In this way, the traffic monitoring of multi-level time windows can be realized. The subsequent steps can also dynamically adjust the size of the time range of the time window according to the service data, realize multi-level traffic monitoring, and improve the accuracy and real-time performance of anomaly detection. Then, it is necessary to obtain the service logs of multiple services, and the service logs contain service data. For example, the time unit is set to 1 minute, and 3 levels of time windows are set: level 1, 1 time unit, corresponding time window is 1 minute; level 2, 5 time units, corresponding time window is 5 minutes; level 3, 30 time units, corresponding time window is 30 minutes.

[0067] Step 202, for any service, obtain the system load index of the service, and adjust the window levels of multiple levels of time windows according to the system load index.

[0068] In implementation, for any one of multiple services, obtain the system load index of the service. Since the system load indexes of services are different, the required time ranges of the time windows are different. The size of the time range of the analysis time window can be dynamically adjusted according to the system load index. Since different levels of time windows contain different numbers of time units, the window levels of multiple levels of time windows can be adjusted according to the system load index. Among them, the system load index includes CPU usage rate, memory usage rate, number of requests, etc. Among them, adjusting the window levels of multiple levels of time windows can be an increase or decrease in the number of window levels or a change in the total number of windows. For a certain time window, a change in the level means a change in the number of time units it contains.

[0069] Further, the system load index includes CPU usage rate, memory usage rate, and number of requests. Specifically, the specific steps for executing step 202 are as follows:

[0070] Step 1, obtain the CPU usage rate and memory usage rate of the service through the system interface, and determine the number of requests of the service according to the service log.

[0071] In implementation, since the system load metrics of services are different, the time ranges of the required time windows are also different. Before adjusting the window levels of time windows at multiple levels according to the system load metrics, it is necessary to first obtain the system load metrics of the service. The CPU usage rate and memory usage rate of the service can be obtained through the system interface, and the number of requests for the service can be determined based on the service logs.

[0072] Step 2: When the CPU usage rate is greater than the preset CPU usage rate threshold, the memory usage rate is greater than the preset memory usage rate threshold, or the number of requests is greater than the preset number of requests threshold, lower the window levels of time windows at multiple levels.

[0073] In implementation, the higher the window level of the time window, the longer the time span, and the greater the resources consumed for traffic analysis. When the system load of the service is too high, it is necessary to reduce the system load. Therefore, when the system load is high, in order to reduce resource consumption and maintain the stability of the system, it is necessary to lower the window level and reduce the time span of the time window. Therefore, when the CPU usage rate, memory usage rate, and number of requests are obtained, compare the CPU usage rate with the preset CPU usage rate threshold, the memory usage rate with the preset memory usage rate threshold, and the number of requests with the preset number of requests threshold. When the CPU usage rate is greater than the preset CPU usage rate threshold, the memory usage rate is greater than the preset memory usage rate threshold, or the number of requests is greater than the preset number of requests threshold, that is, when one of the system load metrics is too high, it indicates that the system load is high. At this time, the window levels of time windows at multiple levels can be lowered.

[0074] Step 3: When the CPU usage rate is less than or equal to the preset CPU usage rate threshold, the memory usage rate is less than or equal to the preset memory usage rate threshold, and the number of requests is less than or equal to the preset number of requests threshold, raise the window levels of time windows at multiple levels.

[0075] In implementation, when the system load of the service is too low, the system load can be appropriately increased. The lower the window level of the time window, the shorter the time span, and the fewer resources consumed for traffic analysis. Therefore, when the system load is low, the resource consumption can be appropriately increased, and it is necessary to raise the window level and increase the time span of the time window. Therefore, when the CPU usage rate, memory usage rate, and number of requests are obtained, compare the CPU usage rate with the preset CPU usage rate threshold, the memory usage rate with the preset memory usage rate threshold, and the number of requests with the preset number of requests threshold. When the CPU usage rate is less than or equal to the preset CPU usage rate threshold, the memory usage rate is less than or equal to the preset memory usage rate threshold, and the number of requests is less than or equal to the preset number of requests threshold, that is, when all system load metrics are low, it indicates that the system load is low. At this time, the window levels of time windows at multiple levels can be raised.

[0076] Further, according to the system load metrics, another adjustment step for adjusting the window levels of multiple levels of time windows is as follows:

[0077] Step 4: Determine the target system load metric as the sum of the product of the CPU usage rate and the preset CPU usage rate weight coefficient, the product of the memory usage rate and the preset memory usage rate weight coefficient, and the product of the number of requests and the preset number of requests weight coefficient.

[0078] In implementation, during the execution of multiple services in the server, the CPU usage rate, memory usage rate, and number of requests corresponding to different services are different. The corresponding weight coefficients can be set for the CPU usage rate, memory usage rate, and number of requests according to different services. When adjusting the window levels of multiple levels of time windows according to the system load metrics, the sum of the product of the CPU usage rate and the preset CPU usage rate weight coefficient, the product of the memory usage rate and the preset memory usage rate weight coefficient, and the product of the number of requests and the preset number of requests weight coefficient can be determined as the target system load metric, and then the window size of the time window can be adapted according to the target system load metric.

[0079] Step 5: If the target system load metric is greater than the preset system load metric threshold, reduce the window levels of multiple levels of time windows.

[0080] In implementation, compare the target system load metric with the preset system load metric threshold. If the target system load metric is greater than the preset system load metric threshold and the system load needs to be reduced, then reduce the window levels of multiple levels of time windows.

[0081] Step 6: If the target system load metric is less than or equal to the preset system load metric threshold, increase the window levels of multiple levels of time windows.

[0082] In implementation, compare the target system load metric with the preset system load metric threshold. If the target system load metric is less than or equal to the preset system load metric threshold and the system load can be appropriately increased, then increase the window levels of multiple levels of time windows.

[0083] Step 203: For any service, determine the fluctuation characteristics of the traffic of the service according to the service log, and adjust the window levels of multiple levels of time windows according to the fluctuation characteristics.

[0084] In implementation, for any service, a technical algorithm is used to determine the fluctuation characteristics of the traffic of the service based on service logs. Among them, the technical algorithm can be the coefficient of variation or the interquartile range, etc. Different traffic fluctuation characteristics of services correspond to different sizes of the time ranges of the required time windows. The fluctuation characteristics include stable, fluctuating, and sudden. When the data of the traffic fluctuation characteristics changes from fluctuating or sudden to relatively stable, a coarser-grained analysis can be performed, that is, the number of time units of the time window increases and the level becomes higher. When the data of the traffic fluctuation characteristics changes from stable to relatively fluctuating or sudden, a finer-grained analysis can be performed. Therefore, the window levels of time windows at multiple levels can be adjusted according to the fluctuation characteristics. Among them, adjusting the window levels of time windows at multiple levels can be an increase or decrease in the number of window levels or a change in the total number of windows. For a certain time window, a change in level means a change in the number of time units it contains.

[0085] Further, the specific process of executing step 203 is as follows:

[0086] Step A, when the fluctuation characteristic is stable, increase the window levels of time windows at multiple levels.

[0087] In implementation, different traffic fluctuation characteristics of services correspond to different sizes of time windows. When the fluctuation characteristic is stable, a coarser-grained analysis of the service can be performed, and the window levels of time windows at multiple levels are increased.

[0088] Step B, when the fluctuation characteristic is fluctuating or sudden, decrease the window levels of time windows at multiple levels.

[0089] In implementation, different traffic fluctuation characteristics of services correspond to different sizes of time windows. When the fluctuation characteristic is fluctuating or sudden, a finer-grained analysis of the service can be performed, and the window levels of time windows at multiple levels are decreased.

[0090] Step 204, for the time window at any level, within the time range of this time window, based on the request data in the service logs, determine the service basic metrics and service composite metrics within the time range of the previous time window.

[0091] In implementation, for the time window at any level, within the time range of the time window, based on the request data in the business logs, the business basic metrics and business composite metrics within the time range of the previous time window are determined. The traffic analysis of the business is to determine the business basic metrics and business composite metrics of the business and analyze the business basic metrics and business composite metrics. Among them, the business basic metrics include the request volume, error rate, response time, and business metrics, etc. The composite metrics are the year-on-year, month-on-month, and change rate of the request volume, error rate, response time, and business metrics. The business basic metrics can also be obtained from the server through an interface.

[0092] Step 205, for any business, based on the business basic metrics and business composite metrics of the time windows at each level, determine whether the business is abnormal. If the business is abnormal, an abnormal alarm is output.

[0093] In implementation, after determining the business basic metrics and business composite metrics of the time windows at each level, for any business, based on the business basic metrics and business composite metrics of the time windows at each level, an abnormal determination of the business traffic can be made. For example, through the request volume, error rate, response time, and business metrics, as well as the year-on-year, month-on-month, and change rate of the request volume, error rate, response time, and business metrics, an abnormal analysis of the business traffic is carried out to determine whether the business is abnormal. If the business is abnormal, an abnormal alarm is output.

[0094] Further, the process of executing step 205 is: compare the business basic metrics of the time windows at each level with the preset business basic metric thresholds, and compare the business composite metrics with the preset business composite metric thresholds to determine whether the business is abnormal.

[0095] In implementation, compare the business basic metrics of the time windows at each level with the preset business basic metric thresholds, and compare the business composite metrics with the preset business composite metric thresholds. If the business basic metric is greater than the preset business basic metric threshold, or the business composite metric is greater than the preset business composite metric threshold, then determine that the business is abnormal. Or if the business basic metric is less than or equal to the preset business basic metric threshold, or the business composite metric is less than the preset business composite metric threshold, then determine that the business is abnormal. Specifically, whether it is greater than or equal to or less than needs to be determined according to the specific metrics. For example, when the error rate is greater than the error rate threshold, it is determined that the business is abnormal; when the year-on-year of the error rate indicates that the error rate becomes smaller and the year-on-year of the error rate is less than the preset year-on-year error rate threshold, it is determined that the business is abnormal. Among them, the thresholds corresponding to different levels are different. Because the time span corresponding to the time window at the lower level is smaller than the time span corresponding to the time window at the higher level, generally speaking, its quantity is less. At this time, the error rate threshold is different from that of other levels.

[0096] Furthermore, the specific process of determining whether the business is abnormal based on the business basic indicators and business composite indicators of the time windows at each level can also be as follows:

[0097] Step a: Set corresponding level weights for time windows at different levels, and determine the target basic indicator as the sum of the products of the business basic indicators of the time windows at all levels and the corresponding level weights.

[0098] In implementation, corresponding level weights can be set for time windows at different levels, and the sum of the products of the business basic indicators of the time windows at each level and the corresponding level weights is determined as the target basic indicator of the business. Among them, the level weights can be determined according to the size of the time window and the granularity of analysis. For time windows at lower levels with fine-grained analysis, the corresponding level weights can be set larger; for time windows at higher levels with coarse-grained analysis, the corresponding level weights can be set smaller. However, some levels are regarded as core levels and have the largest weights, and these levels are neither the lowest nor the highest.

[0099] Step b: Determine the target composite indicator as the sum of the products of the business composite indicators of the time windows at all levels and the corresponding level weights.

[0100] In implementation, the sum of all products of the business composite indicators of the time windows at each level and the corresponding level weights is determined as the target composite indicator of the business. Subsequently, only based on the target basic indicator and the target composite indicator, it is determined whether the traffic of the business is abnormal.

[0101] Step c: Compare the target basic indicator with the preset target basic indicator threshold, and the target composite indicator with the preset target composite indicator threshold, and determine whether the business is abnormal.

[0102] In implementation, the target basic indicator is compared with the preset target basic indicator threshold, and the target composite indicator is compared with the preset target composite indicator threshold. If the target basic indicator is greater than the preset target basic indicator threshold and the target composite indicator is greater than the preset target composite indicator threshold, it is determined that the business is abnormal. Or if the target basic indicator is less than or equal to the preset target basic indicator threshold and the target composite indicator is less than or equal to the preset target composite indicator threshold, it is determined that the business is abnormal.

[0103] For example, a) Define the basic time unit as 1 second. b) Set 5 levels of time windows, and the corresponding time windows are: level 1 window, with a time window of 10 seconds; level 2 window, with a time window of 30 seconds; level 3 window, with a time window of 60 seconds; level 4 window, with a time window of 300 seconds; level 5 window, with a time window of 600 seconds. And so on. c) Set the system load metric thresholds: HIGH_THRESHOLD, LOW_THRESHOLD. d) Obtain the data of the current system load metric through an interface or other means, and calculate a target system load metric S. When S > HIGH_THRESHOLD, reduce the level of the time window; when S < LOW_THRESHOLD, increase the level of the time window. e) Set the window levels of the time windows under different traffic fluctuation characteristics: stable: level 5 window; fluctuating: level 3 window; abrupt change: level 1 window. f) Obtain the current traffic fluctuation characteristics through an interface or other means, and automatically adjust the window level. g) According to the time range corresponding to the current time window, count the basic service metrics and service composite metrics within the corresponding time range. h) Perform anomaly detection according to the set thresholds, such as issuing an anomaly warning when the response time exceeds the threshold. Or, perform multi-level data collaborative detection, additionally calculate the data of the upper and lower levels of the current level, and finally obtain the final data through weighted calculation, and compare this data with the threshold. When determining the traffic anomaly of the service, output an anomaly warning.

[0104] The embodiment of the present application provides a method for traffic analysis of services, which significantly improves the adaptability and accuracy of traffic analysis, can respond to the dynamic changes of network traffic in real time, reduces the consumption of computing resources, and efficiently utilizes resources. The traffic analysis method with an adaptive time window realizes multi-level traffic monitoring by dynamically adjusting the size of the analysis window, can adapt to the time granularity requirements of different service scenarios, will not miss sudden abnormal traffic, and can dynamically adjust storage and computing resources according to actual needs to balance the requirements of real-time and accuracy.

[0105] It should be understood that although Figure 2 the steps in the flowchart of Figure 2 are shown in sequence according to the indication of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover,

[0106] It can be understood that the same / similar parts among the various embodiments of the above methods in this specification can be referred to each other. Each embodiment focuses on the differences from other embodiments. For the relevant parts, refer to the descriptions of other method embodiments.

[0107] An embodiment of the present application also provides a device for traffic analysis of services, as Figure 3 shown. The device includes:

[0108] An acquisition module 301, configured to acquire service logs of multiple services and construct multiple levels of time windows corresponding to each of the multiple services;

[0109] An obtaining module 302, configured to, for any service, obtain the system load metrics of the service and adjust the window levels of the multiple levels of time windows according to the system load metrics;

[0110] A first determination module 303, configured to, for any service, determine the fluctuation characteristics of the traffic of the service according to the service logs and adjust the window levels of the multiple levels of time windows according to the fluctuation characteristics;

[0111] A second determination module 304, configured to, for any level of time window, within the time range of the time window, determine the service basic metrics and service composite metrics within the time range of the previous time window according to the request data in the service logs;

[0112] A third determination module 305, configured to, for any service, determine whether the service is abnormal according to the service basic metrics and service composite metrics of each level of time window. If the service is abnormal, an abnormal alarm is output.

[0113] As an optional implementation manner, the system load metrics include CPU usage rate, memory usage rate, and number of requests. The obtaining module 302 is specifically configured to:

[0114] Obtain the CPU usage rate and the memory usage rate of the service through a system interface, and determine the number of requests of the service according to the service logs;

[0115] When the CPU usage rate is greater than a preset CPU usage rate threshold, the memory usage rate is greater than a preset memory usage rate threshold, or the number of requests is greater than a preset number of requests threshold, reduce the window levels of the multiple levels of time windows;

[0116] When the CPU usage rate is less than or equal to the preset CPU usage rate threshold, the memory usage rate is less than or equal to the preset memory usage rate threshold, and the number of requests is less than or equal to the preset number of requests threshold, increase the window levels of the multiple levels of time windows.

[0117] As an alternative implementation, the system load metrics include CPU usage rate, memory usage rate, and the number of requests. The obtaining module 302 is specifically configured to:

[0118] Determine the sum of the product of the CPU usage rate and the preset CPU usage rate weight coefficient, the product of the memory usage rate and the preset memory usage rate weight coefficient, and the product of the number of requests and the preset number of requests weight coefficient as the target system load metric;

[0119] If the target system load metric is greater than the preset system load metric threshold, lower the window levels of the time windows at multiple levels;

[0120] If the target system load metric is less than or equal to the preset system load metric threshold, raise the window levels of the time windows at multiple levels.

[0121] As an alternative implementation, the fluctuation characteristics include stable, fluctuating, and sudden. The first determination module 303 is specifically configured to:

[0122] When the fluctuation characteristic is stable, raise the window levels of the time windows at multiple levels;

[0123] When the fluctuation characteristic is fluctuating or sudden, lower the window levels of the time windows at multiple levels.

[0124] As an alternative implementation, the third determination module 305 is specifically configured to:

[0125] Compare the service basic metrics and the preset service basic metric threshold, and the service composite metrics and the preset service composite metric threshold of the time windows at each level to determine whether the service is abnormal.

[0126] As an alternative implementation, the third determination module 305 is specifically configured to:

[0127] Set corresponding level weights for the time windows at different levels, and determine the sum value of the products of the service basic metrics of the time windows at all levels and the corresponding level weights as the target basic metric;

[0128] Determine the sum value of the products of the service composite metrics of the time windows at all levels and the corresponding level weights as the target composite metric;

[0129] Compare the target basic metric and the preset target basic metric threshold, and the target composite metric and the preset target composite metric threshold to determine whether the service is abnormal.

[0130] The embodiments of the present application provide a device for traffic analysis of services, which significantly improves the adaptability and accuracy of traffic analysis, can respond to the dynamic changes of network traffic in real time, reduces the consumption of computing resources, and efficiently utilizes resources. The traffic analysis method with an adaptive time window can achieve multi-level traffic monitoring by dynamically adjusting the size of the analysis window, can adapt to the time granularity requirements of different service scenarios, will not miss sudden abnormal traffic, and can dynamically adjust storage and computing resources according to actual needs to balance the requirements of real-time and accuracy.

[0131] For the specific limitations of the device for traffic analysis of services, reference can be made to the limitations of the method for traffic analysis of services in the above text, which will not be elaborated here. Each module in the above device for traffic analysis of services can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the computer device in the form of hardware or independent of the processor, or stored in the memory in the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.

[0132] In one embodiment, a computer device is provided, as Figure 4 shown, including a memory and a processor. A computer program that can run on the processor is stored on the memory. When the processor executes the computer program, the method steps for traffic analysis of the above services are implemented.

[0133] In one embodiment, a computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method for traffic analysis of the above services are implemented.

[0134] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in this application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0135] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or device including the said element.

[0136] It should also be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties.

[0137] Each embodiment in this specification is described in a relevant manner. For the same or similar parts among the embodiments, reference can be made to each other, and the key point of each embodiment is to illustrate the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiment.

[0138] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as within the scope described in this specification.

[0139] The above-described embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several deformations and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.

Claims

1. A method for traffic analysis of a service, characterized in that, The method includes: Obtaining the business logs of multiple services and constructing multiple levels of time windows corresponding to each of the multiple services; For any service, obtaining the system load metrics of the service and adjusting the window levels of the multiple levels of time windows according to the system load metrics; the system load metrics include CPU usage rate, memory usage rate, and number of requests. The process of executing this step is: obtaining the CPU usage rate and the memory usage rate of the service through a system interface, and determining the number of requests of the service according to the business logs; when the CPU usage rate is greater than the preset CPU usage rate threshold, the memory usage rate is greater than the preset memory usage rate threshold, or the number of requests is greater than the preset number of requests threshold, reducing the window levels of the multiple levels of time windows; when the CPU usage rate is less than or equal to the preset CPU usage rate threshold, the memory usage rate is less than or equal to the preset memory usage rate threshold, and the number of requests is less than or equal to the preset number of requests threshold, increasing the window levels of the multiple levels of time windows; the higher the window level, the larger the time span, and the lower the window level, the smaller the time span; For any service, determining the fluctuation characteristics of the traffic of the service according to the business logs and adjusting the window levels of the multiple levels of time windows according to the fluctuation characteristics; For any level of time window, within the time range of the time window, determining the business basic metrics and business composite metrics within the time range of the previous time window according to the request data in the business logs; For any service, determining whether the service is abnormal according to the business basic metrics and business composite metrics of each level of time window, and if the service is abnormal, outputting an abnormal alarm.

2. The method according to claim 1, wherein The system load metrics include CPU usage rate, memory usage rate, and number of requests. The adjusting the window levels of the multiple levels of time windows according to the system load metrics includes: Determining the sum of the product of the CPU usage rate and the preset CPU usage rate weight coefficient, the product of the memory usage rate and the preset memory usage rate weight coefficient, and the product of the number of requests and the preset number of requests weight coefficient as the target system load metric; If the target system load metric is greater than the preset system load metric threshold, reducing the window levels of the multiple levels of time windows; If the target system load metric is less than or equal to the preset system load metric threshold, increasing the window levels of the multiple levels of time windows.

3. The method according to claim 1, wherein The fluctuation characteristics include stable, fluctuating, and sudden. The adjusting the window levels of the multiple levels of time windows according to the fluctuation characteristics includes: When the fluctuation characteristic is stable, increasing the window levels of the multiple levels of time windows; When the fluctuation characteristic is fluctuating or sudden, reducing the window levels of the multiple levels of time windows.

4. The method according to claim 1, wherein The determining whether the service is abnormal according to the business basic metrics and business composite metrics of each level of time window includes: Compare the business basic metrics and the preset business basic metric thresholds, as well as the business composite metrics and the preset business composite metric thresholds of each level of time window to determine whether the business is abnormal.

5. The method according to claim 1, wherein Determining whether the business is abnormal according to the business basic metrics and business composite metrics of each level of time window includes: Set corresponding level weights for time windows of different levels, and determine the target basic metric as the sum of the products of the business basic metrics of the time windows of all levels and the corresponding level weights; Determine the target composite metric as the sum of the products of the business composite metrics of the time windows of all levels and the corresponding level weights; Compare the target basic metric and the preset target basic metric threshold, as well as the target composite metric and the preset target composite metric threshold to determine whether the business is abnormal.

6. An apparatus for traffic analysis of a service, characterized in that, The device includes: An acquisition module for acquiring business logs of multiple services and constructing multiple levels of time windows corresponding to each of the multiple services; An obtaining module for, for any one service, obtaining the system load metrics of the service and adjusting the window levels of the multiple levels of time windows according to the system load metrics; the system load metrics include CPU usage rate, memory usage rate, and number of requests, and the process of executing this step is: obtaining the CPU usage rate and the memory usage rate of the service through a system interface, and determining the number of requests of the service according to the business log; when the CPU usage rate is greater than the preset CPU usage rate threshold, the memory usage rate is greater than the preset memory usage rate threshold, or the number of requests is greater than the preset number of requests threshold, reduce the window levels of the multiple levels of time windows; when the CPU usage rate is less than or equal to the preset CPU usage rate threshold, the memory usage rate is less than or equal to the preset memory usage rate threshold, and the number of requests is less than or equal to the preset number of requests threshold, increase the window levels of the multiple levels of time windows; the higher the window level, the larger the time span, and the lower the window level, the shorter the time span; A first determination module for, for any one service, determining the fluctuation characteristics of the traffic of the service according to the business log and adjusting the window levels of the multiple levels of time windows according to the fluctuation characteristics; A second determination module for, for any level of time window, determining the business basic metrics and business composite metrics in the time range of the previous time window according to the request data in the business log within the time range of this time window; A third determination module for, for any one service, determining whether the service is abnormal according to the business basic metrics and business composite metrics of each level of time window, and if the service is abnormal, outputting an abnormal alarm.

7. The device according to claim 6, characterized in that, The system load metrics include CPU usage rate, memory usage rate, and number of requests, and the obtaining module is specifically used for: Determine the target system load metric as the sum of the product of the CPU usage rate and the preset CPU usage rate weight coefficient, the product of the memory usage rate and the preset memory usage rate weight coefficient, and the product of the number of requests and the preset number of requests weight coefficient; If the target system load indicator is greater than the preset system load indicator threshold, lower the window levels of the time windows at multiple levels; If the target system load indicator is less than or equal to the preset system load indicator threshold, raise the window levels of the time windows at multiple levels.

8. The device according to claim 6, characterized in that, The fluctuation characteristics include stable, fluctuating, and sudden. The first determination module is specifically configured to: When the fluctuation characteristic is stable, raise the window levels of the time windows at multiple levels; When the fluctuation characteristic is fluctuating or sudden, lower the window levels of the time windows at multiple levels.

Citation Information

Patent Citations

  • Service monitoring and early warning implementation method

    CN112200397A

  • Dynamic adjustment method, system and equipment for aggregation window of database

    CN119862204A