Novel server operation abnormity monitoring method

By analyzing the detection effect of the initial isolated forest and adjusting the number of isolated trees, the detection accuracy problem caused by improper setting of the number of isolated trees in the isolated forest algorithm is solved, and higher detection accuracy and stability are achieved.

CN120123202AActive Publication Date: 2025-06-10ZHONGNAN INFORMATION TECH (SHENZHEN) CO LTD +1

Patent Information

Application Number
CN202510615696.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2025-06-10
Estimated Expiration
2045-05-14

AI Technical Summary

Technical Problem

In the server running abnormal detection, the setting of the number of isolated trees is likely to cause underfitting or overfitting, affecting the detection accuracy.

Method used

By analyzing the detection effect of the initial isolated forest, the local detection stability of each operation log data point is obtained, and the weight is set based on the difficulty of distinguishing, the overall detection stability is obtained through weighting summing, and the number of isolated trees is adjusted to achieve operational abnormality monitoring.

Benefits of technology

It improves the accuracy of isolated forest detection, prevents noise interference, evaluates the difficulty of distinction more accurately, and enhances the stability and precision of abnormal detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120123202A_ABST
    Figure CN120123202A_ABST
Patent Text Reader

Abstract

The invention relates to the field of data processing, in particular to an abnormal operation monitoring method for a novel server, and the method comprises the steps: obtaining operation log data points of the novel server; obtaining distinguishing difficulty; constructing an initial isolated forest for all the operation log data points by using an isolated forest algorithm; and obtaining local detection stability of each operation log data point, setting a weight based on the distinguishing difficulty, carrying out weighted summation on the local detection stability to obtain overall detection stability, and adjusting the number of isolated trees of the initial isolated forest according to the overall detection stability to realize operation anomaly monitoring. According to the method, the accuracy of anomaly detection is improved by setting the accurate number of isolated trees.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing. More specifically, the present invention relates to a method for monitoring the abnormal operation of a new type of server. Background Art

[0002] With the rapid development of information technology, servers are widely used in modern enterprises, cloud computing platforms, and various data centers. The stable operation of servers is crucial for ensuring business continuity, data security, and user experience. However, during operation, servers are affected by various factors and occasionally exhibit abnormal operation phenomena. To maintain the stable operation of servers, it is necessary to monitor the servers for abnormalities.

[0003] As a commonly used anomaly detection algorithm, the Isolation Forest algorithm has good anomaly detection effects. However, the detection accuracy of this algorithm is easily affected by relevant parameters. For example, if the number of isolation trees is set too small, underfitting will occur, and some patterns in the detection model will not be fitted out; if the number of isolation trees is set too large, overfitting will occur, and some interference factors in the detection model will be fitted out, such as noise. Therefore, how to set the appropriate number of isolation trees has become the research focus of the present invention.

[0004] The patent application document with the publication number CN117806912A discloses a method and system for monitoring server anomalies. The method in this patent application document realizes the anomaly detection of the server by comparing the predicted temperature with a preset threshold. Since the method in this patent application document does not involve the Isolation Forest algorithm, the technical problems of this solution cannot be solved using this method. Summary of the Invention

[0005] To solve the problem of how to set the appropriate number of isolation trees, the present invention proposes a method for monitoring the abnormal operation of a new type of server, which includes the following steps: Obtain the operation log data points of the new type of server; Obtain the discrimination difficulty , , obtain the isolation degree of each operation log data point in each dimension, cluster the isolation degrees of all operation log data points in any dimension into two categories, and obtain the membership degrees of each isolation degree to each category. Respectively represent the membership degrees of the th operation log data point in the th dimension to one category and another category. Represents the th operation log data point in the th dimension. Denote the mean of the isolation degree of the j-th running log data point in all dimensions. Denote the number of dimensions; Use the isolation forest algorithm to construct an initial isolation forest for all running log data points; Obtain the local detection stability of each running log data point. The local detection stability characterizes the stability of the detection results of each running log data point under different numbers of isolation trees. Based on the discrimination difficulty, set weights, perform weighted summation on the local detection stability to obtain the overall detection stability, and adjust the number of isolation trees in the initial isolation forest according to the overall detection stability to achieve running anomaly monitoring.

[0006] The present invention adjusts the number of isolation trees by analyzing the detection effect of the initial isolation forest, so as to improve the accuracy of the isolation forest detection by setting a more accurate number of isolation trees; further, when analyzing the detection effect of the initial isolation forest, analyze each running log data point separately to improve the fineness of the detection effect analysis, and then improve the accuracy of the detection effect analysis; further, when analyzing the detection effect of the initial isolation forest, introduce the discrimination difficulty to set the evaluation weight of the detection effect of each running log data point, so as to effectively prevent the interference of factors such as noise on the detection effect evaluation and improve the accuracy of the evaluation; further, when analyzing the discrimination difficulty, introduce the variance of the isolation degree of different dimensions to accurately reflect the interference of the abnormal differences of different dimensions on anomaly recognition, and more accurately evaluate the discrimination difficulty of the isolation forest algorithm for each running log data point; further, when analyzing the discrimination difficulty, introduce the membership degree difference of each running log data point to different categories to reflect the degree to which each running log data point belongs to abnormal and normal, and then provide a data basis for accurately evaluating the discrimination difficulty.

[0007] Preferably, the step of using the isolation forest algorithm to construct an initial isolation forest for all running log data points includes: Obtain the pre-obtained initial number of isolation trees; Based on the initial number of isolation trees, use the isolation forest algorithm to process all running log data points to obtain an initial isolation forest.

[0008] Preferably, the step of obtaining the pre-obtained initial number of isolation trees includes: Multiply the normalized value of the cumulative sum of the discrimination difficulties of all running log data points by a preset number of isolation trees to obtain the initial number of isolation trees.

[0009] The present invention sets the initial number of isolation trees by combining the discrimination difficulty, so as to consider the discrimination difficulty of the analyzed data when setting the isolation trees, so as to set more appropriate isolation trees and improve the accuracy of anomaly detection.

[0010] Preferably, obtaining the isolation degree of each operation log data point in each dimension includes: For any dimension, obtain the distance between every two adjacent operation log data points in this dimension, and record the cumulative sum of the distances between all two adjacent operation log data points in this dimension as the overall isolation distance; obtain the cumulative sum of the distances between any operation log data point and its two adjacent operation log data points in this dimension as the local isolation distance of this operation log data point in this dimension; divide the local isolation distance of this operation log data point in this dimension by the overall isolation distance to obtain the isolation degree of this operation log data point in this dimension.

[0011] Preferably, obtaining the membership degree of each isolation degree to each category includes: Take the normalized value of the reciprocal of the distance between any isolation degree and the cluster center of any category as the center binding degree; Take the normalized value of the reciprocal of the product of the distance between this isolation degree and the category boundary of this category and the attribute relationship flag value as the boundary binding degree; Take the product of the center binding degree and the boundary binding degree as the membership degree of this isolation degree to this category.

[0012] When analyzing the membership degree in the present invention, not only the distance from the cluster center is considered, but also the distance from the boundary is considered, so as to more comprehensively and comprehensively evaluate the degree to which the isolation degree belongs to each category.

[0013] Preferably, obtaining the local detection stability of each operation log data point includes: Set a preset variable , randomly combine every T isolation trees in the initial isolation forest to obtain several isolation tree combinations, perform anomaly detection on any operation log data point based on each isolation tree combination to obtain the anomaly score under this isolation tree combination, and take the mean value of the anomaly scores of this operation log data point under all isolation tree combinations as the comprehensive anomaly score; take each integer in the interval [K - A, K] for T, where K represents the number of isolation trees included in the initial isolation forest, and A represents a preset parameter; take the difference between the comprehensive anomaly score under any value and the comprehensive anomaly score under the previous value as the anomaly detection change amount under this value, and take the reciprocal of the mean value of the anomaly detection change amounts of this operation log data point under all values as the local detection stability of this operation log data point.

[0014] The present invention accurately reflects the convergence situation of the detection results of the initial isolation forest by introducing the difference in the detection effects of each operation log data point under different numbers of isolation tree combinations, and further accurately reflects the appropriate number of isolation trees in the initial isolation forest, providing a basis for setting an appropriate number of isolation trees.

[0015] Preferably, adjusting the number of isolation trees in the initial isolation forest according to the overall detection stability includes: Taking the ratio of the preset reference value to the overall detection stability as the adjustment coefficient; Taking the integer value of the product of the number of isolation trees in the initial isolation forest and the adjustment coefficient as the adjusted number of isolation trees.

[0016] The present invention adjusts the number of isolation trees according to the overall detection stability, so as to obtain a more accurate number of isolation trees, and further improve the accuracy of anomaly detection.

[0017] Preferably, achieving operation anomaly monitoring includes: Inputting the operation log data points of the newly collected new type of server into the isolation forest with the adjusted number of isolation trees to obtain the anomaly detection result.

[0018] Preferably, after obtaining the anomaly detection result, it further includes: If the anomaly detection result is that there is an anomaly, a warning reminder is issued; If the anomaly detection result is that there is no anomaly, no warning reminder is issued.

[0019] Preferably, obtaining the operation log data points of the new type of server includes: Obtaining each log of the new type of server and converting the data of each log; Denoting the data points composed of the converted data of all dimensions in each log as the operation log data points.

[0020] The present invention has the following beneficial effects: The present invention adjusts the number of isolation trees by analyzing the detection effect of the initial isolation forest, so as to improve the accuracy of the isolation forest detection by setting a more accurate number of isolation trees; Furthermore, when analyzing the detection effect of the initial isolation forest, by analyzing each operation log data point separately, the fineness of the detection effect analysis is improved, and further the accuracy of the detection effect analysis is improved; Furthermore, when analyzing the detection effect of the initial isolation forest, by introducing the discrimination difficulty to set the evaluation weight of the detection effect of each operation log data point, the interference of factors such as noise to the detection effect evaluation can be effectively prevented, and the accuracy of the evaluation is improved; Furthermore, when analyzing the discrimination difficulty, by introducing the variance of the isolation degree of different dimensions to accurately reflect the interference of the anomaly differences of different dimensions to anomaly recognition, the discrimination difficulty situation of the isolation forest algorithm for each operation log data point can be evaluated more accurately; Further, when analyzing the discrimination difficulty, the degree of membership difference of each operation log data point to each category is introduced to reflect the degree of belonging of each operation log data point to abnormal and normal, so as to provide a data basis for accurately evaluating the discrimination difficulty. Brief Description of the Drawings

[0021] Figure 1 is a flowchart of the steps of a method for monitoring operation anomalies of a new type of server according to an embodiment of the present invention. Detailed Embodiment

[0022] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0023] Next, the detailed embodiments of the present invention will be described in conjunction with the accompanying drawings.

[0024] Please refer to Figure 1 , which shows a flowchart of the steps of a method for monitoring operation anomalies of a new type of server provided by an embodiment of the present invention. The method includes the following steps: S1: Obtain operation log data points of the new type of server.

[0025] Specifically, obtain the operation logs of the new type of server, and convert the words, texts, and characters in each operation log into data. In this embodiment, the Word2vec algorithm is used for data conversion, and other embodiments can adopt other methods, which are not specifically limited in this embodiment.

[0026] The data points formed by the converted data of all dimensions in each operation log are recorded as operation log data points.

[0027] S2: Obtain the discrimination difficulty.

[0028] It should be noted that some operation log data points are noise data points, and the discrimination degree of these data points from normal data points is small. If the number of isolation trees in the isolation forest algorithm is set too large, these data points will be misjudged as abnormal data points. And some operation log data points are abnormal data points, but the discrimination degree of these data points from normal data points is also relatively small. If the number of isolation trees in the isolation forest algorithm is set too small, these data points will be misjudged as normal data points, thus unable to detect these abnormal data points. Therefore, in order to set an appropriate number of isolation trees, it is necessary to analyze the detection effects of operation log data points with different discrimination difficulties. First, analyze the discrimination difficulty of each operation log data.

[0029] Preferably, as an example, obtaining the discrimination difficulty includes:

[0030] Among them, obtaining the isolation degree of each operation log data point in each dimension, clustering the isolation degrees of all operation log data points in any dimension into two categories, and obtaining the membership degrees of each isolation degree to each category. Denote the th operation log data point's membership degree of the isolation degree in the th dimension to a category. Denote the th operation log data point's membership degree of the isolation degree in the th dimension to another category. Denote the th operation log data point's isolation degree in the th dimension. Denote the mean value of the isolation degrees of the jth operation log data point in all dimensions. Denote the number of dimensions. Denote the discrimination difficulty of the jth operation log data point.

[0031] It can be understood that reflects the difference in the membership degrees of the isolation degrees of each operation log data point to different categories. The larger this value is, the more the operation log data point tends to a detection result, so the discrimination difficulty of this operation log data point is smaller. reflects the difference in the isolation degrees of each operation log data point in different dimensions. The larger this value is, the greater the difference in the isolation degrees of this operation log data point in different dimensions, so the possibility that the anomaly detection results obtained using different dimensions are different is greater, and thus the discrimination difficulty of this operation log data point is greater.

[0032] The above embodiments involve the isolation degree and the membership degrees of each isolation degree to each category. Next, the determination methods of the isolation degree and the membership degrees of the isolation degree to each category need to be described.

[0033] First, introduce the method for obtaining the isolation degree.

[0034] Preferably, as an example, obtaining the isolation degree of each operation log data point in each dimension includes: For any dimension, obtain the distance between every two adjacent running log data points in this dimension, and record the cumulative sum of the distances between all two adjacent running log data points in this dimension as the overall isolation distance; obtain the accumulated sum of the distances between any running log data point and its two adjacent running log data points in this dimension, and record it as the local isolation distance of this running log data point in this dimension; divide the local isolation distance of this running log data point in this dimension by the overall isolation distance to obtain the isolation degree of this running log data point in this dimension.

[0035] It should be noted that the implementation process of the isolation forest algorithm includes: obtaining the value range of the data of all data points in one dimension, randomly selecting a point within the value range as the splitting point, and using the splitting point to divide the data points into two sets until independent data points are split out. Since abnormal data points deviate from normal data points, abnormal data points are quickly split out. Through the above calculation process, it can be found that the isolation degree reflects the probability of being extracted for the intervals on both sides of each running log data point in one dimension. The larger this value is, the greater the probability that this running log data point is extracted, and thus the smaller the difficulty of splitting out this running log data point. Therefore, the isolation degree calculated through this can provide a data basis for accurately calculating the discrimination difficulty.

[0036] Then, introduce the method for obtaining the membership degree of the isolation degree to each category.

[0037] Preferably, as an example, obtaining the membership degree of each isolation degree to each category includes: Taking the normalized value of the reciprocal of the distance between any isolation degree and the clustering center of any category as the center binding degree; Taking the normalized value of the reciprocal of the product of the distance between this isolation degree and the category boundary of this category and the attribute relationship flag value as the boundary binding degree; Taking the product of the center binding degree and the boundary binding degree as the membership degree of this isolation degree to this category. This embodiment uses the maximum-minimum normalization method for normalization processing. Other embodiments can use other normalization methods, and this embodiment does not make specific restrictions.

[0038] It should be noted that when performing membership degree analysis, not only the distance between the data point and the center point is considered, but also the distance between the data point and the boundary is considered. Therefore, it can more comprehensively and accurately analyze the membership degree relationship between the data and the corresponding category.

[0039] It should be added that the method for setting the attribute relationship flag value includes: If the isolation degree belongs to a category, set the attribute relationship flag value between the isolation degree and this category to -1. If the isolation degree does not belong to a category, set the attribute relationship flag value between this isolation degree and this category to 1.

[0040] S3: Use the Isolation Forest algorithm to construct an initial isolation forest for all running log data points.

[0041] It should be noted that in order to judge the detection effect of running log data points with different levels of discrimination difficulty, an anomaly detection model needs to be constructed first. Since the specific number of isolation trees cannot be determined currently, a rough number of isolation trees needs to be determined first, and an anomaly detection model is constructed based on the roughly determined number of isolation trees.

[0042] Optionally, as an example, using the Isolation Forest algorithm to construct an initial isolation forest for all running log data points includes: A preset number of isolation trees, use the preset number of isolation trees as the initial number of isolation trees, and based on the initial number of isolation trees, use the Random Forest algorithm to analyze all running log data points to obtain the initial isolation forest.

[0043] It should be noted that the preset number of isolation trees is generally a value set according to experience. However, due to the different data types for anomaly analysis, using a fixed empirical value to process diverse data cannot achieve good results.

[0044] Preferably, as an example, using the Isolation Forest algorithm to construct an initial isolation forest for all running log data points includes: Multiply the normalized value of the cumulative sum of the discrimination difficulties of all running log data points by the preset number of isolation trees to obtain the initial number of isolation trees; Based on the initial number of isolation trees, use the Isolation Forest algorithm to process all running log data points to obtain the initial isolation forest.

[0045] It should be noted that the discrimination difficulty reflects the difficulty of anomaly detection for running log data points. The larger this value is, the more isolation trees need to be set for fitting. Therefore, the preset number of isolation trees can be adjusted according to the discrimination difficulty.

[0046] S4: Obtain the local detection stability of each running log data point. The local detection stability characterizes the stability of the detection results of each running log data point under different numbers of isolation trees. Set weights based on the discrimination difficulty, perform weighted summation on the local detection stability to obtain the overall detection stability, and adjust the number of isolation trees in the initial isolation forest according to the overall detection stability to achieve running anomaly monitoring.

[0047] S40: Obtain the local detection stability of each running log data point.

[0048] It should be noted that the above is only the number of isolated trees set roughly. In order to obtain a more accurate number of isolated trees, it needs to be adjusted according to the actual anomaly detection effect. First, obtain the detection effect of the initial isolation forest constructed based on the rough number of isolated trees on each running log data point. In this embodiment, the detection effect is reflected by the local detection stability.

[0049] Preferably, as an example, obtaining the local detection stability of each running log data point includes: Set a preset variable T, randomly combine every T isolated trees in the initial isolation forest to obtain several combinations of isolated trees, perform anomaly detection on any running log data point based on each combination of isolated trees to obtain the anomaly score of the running log data point under this combination of isolated trees, and take the mean of the anomaly scores of the running log data point under all combinations of isolated trees as the comprehensive anomaly score of the running log data point.

[0050] Let T take each integer in the interval [K - A, K], where K represents the number of isolated trees in the initial isolation forest, and A represents a preset parameter. In this embodiment, the preset parameter is taken as 3 for description, and other values can be taken in other embodiments, which are not specifically limited in this embodiment. Obtain the comprehensive anomaly score of the running log data point under each value, take the difference between the comprehensive anomaly score under any value and the comprehensive anomaly score under the previous value as the anomaly detection change amount of the running log data point under this value, and take the reciprocal of the mean of the anomaly detection change amounts of the running log data point under all values as the local detection stability of the running log data point; It should be noted that the smaller the local detection stability, the more it indicates that the initial isolation forest has not converged, so the possibility of underfitting of the initial isolation forest is greater; the larger this value, the more it indicates that stable detection results can be obtained only by using some isolated trees in the initial isolation forest, so the possibility of overfitting of the initial isolation forest is greater.

[0051] It should be noted that performing anomaly detection on each running log data point based on the combination of isolated trees is a prior art and will not be elaborated here.

[0052] S41: Set weights based on the discrimination difficulty, and perform weighted summation on the local detection stability to obtain the overall detection stability.

[0053] Preferably, as an example, setting weights based on the discrimination difficulty and performing weighted summation on the local detection stability to obtain the overall detection stability includes: Taking the natural constant as the base and the negative value of the product of the discrimination difficulty of each running log data point and a preset ratio as the exponent, calculate the weight of each running log data point. Then, taking the weight of each running log data point as the weight, perform weighted summation on the local detection stability of all running log data points and then perform normalization processing to obtain the overall detection stability. In this embodiment, an example is described with the preset ratio taken as 0.05. Other embodiments can take other values, and this embodiment does not make specific restrictions.

[0054] It should be noted that when the discrimination difficulty is too large, it indicates that the running log data point is more likely to be interfered by noise, and the data interfered by noise is not suitable for evaluating the detection effect of the initial isolation forest. Therefore, it is necessary to reduce the weight of the data with large discrimination difficulty.

[0055] It should be further noted that the overall detection stability reflects the stability of the initial isolation forest anomaly detection. The larger this value is, the more stable the initial isolation forest is, and the greater the probability of overfitting of this initial isolation forest. The smaller this value is, the more unstable the initial isolation forest is, and the greater the probability of underfitting of this initial isolation forest. Therefore, the fitting situation of the initial isolation forest can be judged according to the overall detection stability.

[0056] S42: Adjust the number of isolation trees in the initial isolation forest according to the overall detection stability.

[0057] It should be noted that in order to obtain a more accurate number of isolation trees, it is necessary to adjust the number of isolation trees according to the detection effect.

[0058] Preferably, as an example, adjusting the number of isolation trees in the initial isolation forest according to the overall detection stability includes: Taking the ratio of the preset reference value to the overall detection stability as the adjustment coefficient; Taking the integer value of the product of the number of isolation trees in the initial isolation forest and the adjustment coefficient as the adjusted number of isolation trees.

[0059] If the adjusted number of isolation trees is less than the number of isolation trees in the initial isolation forest, randomly select C isolation trees in the initial isolation forest for removal, and use the remaining isolation trees to form an isolation forest as the isolation forest after the number of isolation trees is adjusted.

[0060] If the adjusted number of isolation trees is greater than the number of isolation trees in the initial isolation forest, then construct C more isolation trees, and supplement the newly constructed isolation trees into the initial isolation forest to obtain the isolation forest after the number of isolation trees is adjusted. C represents the absolute value of the difference between the adjusted number of isolation trees and the number of isolation trees in the initial isolation forest.

[0061] It should be noted that if the overall detection stability is too large, it indicates that the number of isolation trees in the initial isolation forest is too large, and there is a high possibility of overfitting. Therefore, the number of isolation trees can be reduced; if the overall detection stability is too small, it indicates that the number of isolation trees in the initial isolation forest is too small, and there is a high possibility of underfitting. Therefore, the number of isolation trees can be increased.

[0062] S43: To implement operation anomaly monitoring.

[0063] Preferably, as an example, to implement operation anomaly monitoring, it includes: Input the operation log data points of the newly collected new type of server into the isolation forest with the adjusted number of isolation trees to obtain the anomaly detection result.

[0064] If the anomaly detection result indicates the existence of an anomaly, a warning reminder is issued; If the anomaly detection result indicates the non-existence of an anomaly, no warning reminder is issued.

[0065] Thus, this embodiment is completed.

[0066] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A novel method for monitoring abnormal operation of a server, characterized in that: include: Get the operation log data points of the new server; Obtaining the difficulty of differentiation , , obtain the isolation degree of each running log data point in each dimension, cluster the isolation degree of all running log data points in any dimension into two categories, and obtain the membership degree of each isolation degree to each category, Respectively represent The run log data point is in The degree of isolation of a dimension to the degree of membership of one category to another category, Indicates The run log data point is in The degree of isolation in each dimension, represents the mean of the isolation degree of the jth running log data point in all dimensions, Indicates the number of dimensions; Use the isolation forest algorithm to construct an initial isolation forest for all running log data points; The local detection stability of each operation log data point is obtained, and the local detection stability characterizes the stability of the detection results under different numbers of isolated trees of each operation log data point. The weight is set based on the difficulty of distinction, and the weighted sum of the local detection stabilities is obtained to obtain the overall detection stability. According to the overall detection stability, the number of isolated trees in the initial isolated forest is adjusted to realize operation abnormality monitoring.

2. A method for monitoring abnormal operation of a new server according to claim 1, characterized in that: The isolation forest algorithm is used to construct an initial isolation forest for all running log data points, including: Get the number of initial isolated trees obtained in advance; Based on the initial number of isolated trees, the isolation forest algorithm is used to process all running log data points to obtain the initial isolation forest.

3. The method for monitoring abnormal operation of a new server according to claim 2, characterized in that: The step of obtaining the number of initial isolated trees obtained in advance includes: The normalized value of the cumulative sum of the distinction difficulties of all running log data points is multiplied by the preset number of isolated trees to obtain the initial number of isolated trees.

4. The method for monitoring abnormal operation of a new server according to claim 1, characterized in that: The obtaining of the isolation degree of each running log data point in each dimension includes: For any dimension, obtain the distance between every two adjacent operation log data points on this dimension, and record the cumulative sum of the distances between all two adjacent operation log data points on this dimension as the overall isolation distance; obtain the cumulative sum of the distances between any operation log data point and two adjacent operation log data points on this dimension as the local isolation distance of the operation log data point in this dimension; divide the local isolation distance of the operation log data point in this dimension by the overall isolation distance to obtain the degree of isolation of the operation log data point in this dimension.

5. The method for monitoring abnormal operation of a new server according to claim 1, characterized in that: The obtaining of the degree of membership of each isolation degree to each category includes: The normalized value of the inverse of the distance between any isolation degree and the cluster center of any category is taken as the central binding degree; The normalized value of the reciprocal of the product of the distance between the isolation degree and the category boundary of the category and the attribute relationship mark value is used as the boundary constraint degree; The product of the center constraint degree and the boundary constraint degree is taken as the degree of membership of the isolation degree to the category.

6. The method for monitoring abnormal operation of a new server according to claim 1, characterized in that: The obtaining of the local detection stability of each operation log data point includes: Setting Preset Variables , randomly combine every T isolated trees in the initial isolation forest to obtain several isolated tree combinations, perform anomaly detection on any running log data point based on each isolated tree combination to obtain the anomaly score under the isolated tree combination, and take the average of the anomaly scores of the running log data point under all isolated tree combinations as the comprehensive anomaly score; Take integers between the interval [KA, K], where K represents the number of isolated trees in the initial isolation forest and A represents the preset parameter; take the difference between the comprehensive anomaly score under any value and the comprehensive anomaly score under the previous value as the anomaly detection change under the value, and take the inverse of the mean of the anomaly detection change of the running log data point under all values ​​as the local detection stability of the running log data point.

7. The method for monitoring abnormal operation of a new server according to claim 1, characterized in that: The number of isolated trees in the initial isolation forest is adjusted according to the overall detection stability, including: The ratio of the preset reference value to the overall detection stability is used as the adjustment coefficient; The rounded value of the product of the number of isolated trees in the initial isolation forest and the adjustment coefficient is taken as the number of isolated trees after adjustment.

8. The method for monitoring abnormal operation of a new server according to claim 1, characterized in that: The above-mentioned method for realizing abnormal operation monitoring includes: The newly collected operation log data points of the new server are input into the isolation forest with the adjusted number of isolated trees to obtain the anomaly detection results.

9. The method for monitoring abnormal operation of a new server according to claim 8, characterized in that: After obtaining the anomaly detection results, it also includes: If the abnormal detection result shows that there is an abnormality, an early warning reminder will be issued; If the abnormality detection result is that there is no abnormality, no warning reminder will be issued.

10. The method for monitoring abnormal operation of a new server according to claim 1, characterized in that: The obtaining of the operation log data points of the new server includes: Obtain each log of the new server and perform data conversion on each log; The data points consisting of the transformed data of all dimensions in each log are recorded as running log data points.

Citation Information

Patent Citations

  • Server abnormity monitoring method and system

    CN117806912A

  • Server log anomaly detection method and system based on isolated forest algorithm

    CN110958222A

Cited By

  • Server fault diagnosis method and system for server group

    CN120315930A

  • Server fault diagnosis method and system for server group

    CN120315930B