Method and device for detecting business index abnormity

By obtaining and analyzing business indicator values, slopes and quantiles in real time, and combining month-on-month, year-on-year and extreme-value early warning strategies, the problem of inability to effectively balance the fault recall rate and false alarm frequency in the existing technology is solved, and efficient and flexible business indicator abnormal detection is achieved, and false alarm rate is reduced.

CN120123919APending Publication Date: 2025-06-10YUANBAO TECH (BEIJING) TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510034473.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-09
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

When detecting abnormal business indicators, the prior art cannot effectively balance the fault recall rate and false alarm frequency, especially when dealing with complex business scenarios.

Method used

By obtaining the current business indicator value, indicator slope and indicator quantile in real time, and detecting it based on the preset month-on-month, year-on-year and extreme-value warning strategies to determine business indicator abnormalities.

Benefits of technology

It realizes an efficient and flexible solution for abnormal detection of business indicators, and can detect abnormal fluctuations in a timely manner, especially sudden changes, improves recall, and effectively filters false alarms through dual detection of quantiles and slopes, reducing false alarm rates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120123919A_ABST
    Figure CN120123919A_ABST
Patent Text Reader

Abstract

The invention provides a service index abnormity detection method and device, and the method comprises the steps: obtaining a current service index value, a current index slope and a current index quantile in real time, and enabling the current index slope and the current index quantile to be determined based on a historical service index value in a first time period; detecting the current business index value, the current index slope and the current index quantile according to at least one preset early warning strategy to obtain a detection result; and determining that the business index corresponding to the current business index value is abnormal under the condition that the detection result represents that the business index is abnormal. According to the invention, through at least one early warning strategy, an efficient and flexible solution for business index anomaly detection is realized, business index anomaly fluctuation can be ensured to be detected in time, and the recall rate is improved; by combining double detection of quantiles and slopes, false alarms caused by normal fluctuation are effectively filtered out, meanwhile, accurate early warning is carried out on extreme conditions, unnecessary alarm interference is reduced, and the false alarm rate is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular, to a method and device for detecting abnormal business indicators. Background Art

[0002] In business activities such as commerce and production, it is crucial to monitor whether business activities are abnormal. Generally, by designing key business indicators and continuously observing the values of these business indicators at different time periods (such as time series indicators) to determine whether there are abnormalities.

[0003] However, existing methods for detecting whether business indicators are abnormal, such as expert experience method, time series decomposition method, and standard distribution detection method, etc., rely on fixed thresholds or idealized time series models, and cannot adapt to the diversity and non-linear characteristics in business data. When dealing with complex business scenarios, there is a problem that the fault recall rate and false alarm frequency cannot be effectively balanced. Therefore, an effective solution is urgently needed to solve the above problems. Summary of the Invention

[0004] The present invention provides a method and device for detecting abnormal business indicators to solve the defect in the prior art that the fault recall rate and false alarm frequency cannot be effectively balanced.

[0005] The present invention provides a method for detecting abnormal business indicators, including: Real-time obtaining the current business indicator value, the current indicator slope, and the current indicator quantile, where the current indicator slope and the current indicator quantile are determined based on historical business indicator values within a first time period; Detecting the current business indicator value, the current indicator slope, and the current indicator quantile according to at least one preset warning strategy to obtain a detection result; When the detection result indicates an abnormality, determining that the business indicator corresponding to the current business indicator value is abnormal.

[0006] According to the method for detecting abnormal business indicators provided by the present invention, the at least one warning strategy includes a month-on-month warning strategy, a year-on-year warning strategy, and an extreme value warning strategy; The step of detecting the current business indicator value, the current indicator slope, and the current indicator quantile according to at least one preset warning strategy to obtain a detection result includes: Detecting the current business indicator value according to the extreme value warning strategy to obtain an extreme value detection result; Detecting the current indicator slope according to the month-on-month warning strategy to obtain a month-on-month detection result; Detecting the current indicator quantile according to the year-on-year warning strategy to obtain a year-on-year detection result.

[0007] According to a method for detecting abnormal service indicators provided by the present invention, the step of detecting the current service indicator value according to the extreme value warning strategy to obtain an extreme value detection result includes: Comparing the current service indicator value with a first threshold interval of the extreme value warning strategy; If the current service indicator value is within the first threshold interval, it is determined that the extreme value detection result indicates normal; If the current service indicator value is outside the first threshold interval, it is determined that the extreme value detection result indicates abnormal.

[0008] According to a method for detecting abnormal service indicators provided by the present invention, the step of detecting the current indicator slope according to the month-on-month warning strategy to obtain a month-on-month detection result includes: Comparing the current indicator slope with a second threshold interval of the month-on-month warning strategy; If the current indicator slope is within the second threshold interval, it is determined that the month-on-month detection result indicates normal; If the current indicator slope is outside the second threshold interval, it is determined that the month-on-month detection result indicates abnormal.

[0009] According to a method for detecting abnormal service indicators provided by the present invention, the step of detecting the current indicator quantile according to the year-on-year warning strategy to obtain a year-on-year detection result includes: Obtaining a set indicator quantile, where the set indicator quantile is the indicator quantile at the same time point within the previous interval period and belonging to the same time point as the current indicator quantile; Calculating the change ratio between the current indicator quantile and the set indicator quantile; Comparing the change ratio with a third threshold interval of the year-on-year warning strategy; If the change ratio is within the third threshold interval, it is determined that the year-on-year detection result indicates normal; If the change ratio is outside the third threshold interval, it is determined that the year-on-year detection result indicates abnormal.

[0010] Before comparing the current service indicator value with the first threshold interval of the extreme value warning strategy according to a method for detecting abnormal service indicators provided by the present invention, it further includes: Obtaining historical service indicator values within a second time period; Taking the Y 1 quantile of the historical service indicator values within the second time period as the first downward threshold, and taking the Y 2 quantile of the historical service indicator values within the second time period as the first upward threshold, where Y1 Less than Y 2 ; Based on the first descending threshold and the first ascending threshold, the first threshold interval is formed.

[0011] According to a method for detecting abnormal service indicators provided by the present invention, before comparing the current indicator slope with the second threshold interval of the month-on-month warning strategy, the method further includes: Obtain the historical indicator slope within a third time period; Take the Y 3 quantile of the historical indicator slope within the third time period as the second descending threshold, and take the Y 4 quantile of the historical indicator slope within the third time period as the second ascending threshold, where Y 3 is less than Y 4 ; Based on the second descending threshold and the second ascending threshold, the second threshold interval is formed.

[0012] According to a method for detecting abnormal service indicators provided by the present invention, before comparing the change ratio with the third threshold interval of the year-on-year warning strategy, the method further includes: Obtain the historical indicator quantiles within a fourth time period; According to the set interval period, determine at least one pair of the historical indicator quantiles from the historical indicator quantiles within the fourth time period, where the two historical indicator quantiles in the pair of historical indicator quantiles are adjacent in period and have the same time points within the corresponding periods; For each pair of the historical indicator quantiles, calculate the change ratio between the two historical indicator quantiles in the pair of historical indicator quantiles; Take the Y 5 quantile of the change ratio corresponding to each pair of the historical indicator quantiles as the third descending threshold, and take the Y 6 quantile of the change ratio corresponding to each pair of the historical indicator quantiles as the third ascending threshold, where Y 5 is less than Y 6 ; Based on the third descending threshold and the third ascending threshold, the third threshold interval is formed.

[0013] According to a method for detecting abnormal service indicators provided by the present invention, the process of obtaining the current indicator slope and the current indicator quantiles includes: Fit the historical service indicator values within the first time period, and calculate the current indicator slope based on the method of taking the derivative; Statistically analyze the historical business metric values within the first time period, and determine the current metric quantile based on the quantile method.

[0014] According to a method for detecting abnormal business metrics provided by the present invention, when the detection result indicates an abnormality, determining that the business metric corresponding to the current business metric value is abnormal includes: When the detection result indicates an abnormality, statistically analyze the duration for which the detection result indicates an abnormality; When the duration reaches the duration corresponding to at least one warning strategy, determine that the business metric corresponding to the current business metric value is abnormal.

[0015] The present invention further provides a device for detecting abnormal business metrics, including: An acquisition module configured to acquire in real time the current business metric value, the current metric slope, and the current metric quantile, where the current metric slope and the current metric quantile are determined based on the historical business metric values within the first time period; A detection module configured to detect the current business metric value, the current metric slope, and the current metric quantile according to at least one preset warning strategy to obtain a detection result; A determination module configured to determine that the business metric corresponding to the current business metric value is abnormal when the detection result indicates an abnormality.

[0016] The present invention further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the program, it implements the method for detecting abnormal business metrics as described in any one of the above.

[0017] The present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the method for detecting abnormal business metrics as described in any one of the above.

[0018] The present invention further provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the method for detecting abnormal business metrics as described in any one of the above.

[0019] The method and device for detecting abnormal business metrics provided by the present invention, through at least one warning strategy, achieve an efficient and flexible solution for detecting abnormal business metrics, ensuring that abnormal fluctuations in business metrics can be detected in a timely manner, especially for sudden changes, a warning can be issued faster, and the recall rate is improved. By combining the dual detection of quantiles and slopes, false alarms caused by normal fluctuations are effectively filtered out, and accurate warnings are issued for extreme situations, reducing unnecessary alarm interference, that is, the false alarm rate is reduced. Brief Description of the Drawings

[0020] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0021] Figure 1 It is one of the schematic flowcharts of the method for detecting abnormal service indicators provided by the present invention.

[0022] Figure 2 It is the second schematic flowchart of the method for detecting abnormal service indicators provided by the present invention.

[0023] Figure 3 It is the schematic structural diagram of the device for detecting abnormal service indicators provided by the present invention.

[0024] Figure 4 It is the schematic structural diagram of the electronic device provided by the present invention. Detailed Embodiments

[0025] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention in conjunction with the drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments in the present invention belong to the scope of protection of the present invention.

[0026] The following will describe Figures 1 - 4 the method and device for detecting abnormal service indicators of the present invention.

[0027] To facilitate a clearer understanding of the technical solutions of the embodiments of the present invention, some technical contents related to the embodiments of the present invention will be introduced first.

[0028] Time series indicators often have obvious periodic characteristics. The existing anomaly detection methods mainly include the expert experience method, the time series decomposition method, and the standard distribution detection method.

[0029] Expert experience method: Determine whether it is abnormal by comparing the current indicator with a preset threshold.

[0030] Time series decomposition method: usually use additive model or multiplicative model to decompose the time series into long-term trend, seasonal fluctuation, cyclical fluctuation and irregular fluctuation factors. For indicators generated by normal business, their irregular fluctuations usually conform to normal distribution. If the indicator value at a certain moment deviates from the normal distribution, the indicator is considered abnormal.

[0031] Standard distribution detection method: such as the detection method based on "standard distribution conversion", which uniformly converts business indicators with time periodicity into data that conforms to the standard distribution, thereby providing a general method for anomaly judgment based on probability distribution. It can accurately calculate the probability of occurrence of specific business indicator values ​​in a specific time period, and judge whether an abnormality has occurred in the business indicator based on the probability.

[0032] However, the above three methods all have certain defects in practical application.

[0033] Expert experience method: It relies heavily on experienced experts’ understanding of specific business scenarios. Specific rules need to be formulated for each indicator separately, which is labor-intensive and difficult to batch process anomaly detection of a large number of business indicators, and cannot be promoted in batches.

[0034] Time series decomposition method: Since the time series generated by the business often do not conform to the ideal time series model, it is difficult to accurately decompose trends, cycles and irregular fluctuations. There may not even be a stable trend or cycle at all, which leads to calculation deviations of irregular fluctuations and affects the accuracy of anomaly detection. The actual application cost of the time series decomposition algorithm is relatively high, including understanding cost, implementation complexity and consumption of computing resources.

[0035] Standard distribution detection method: It assumes that the standard distribution may not be accurate. Although this method normalizes business indicators to the standard distribution through conversion, the data in actual business is often complex and may not fully conform to the standard distribution. The conversion process may lose key information or cause deviations, which in turn affects the accuracy of abnormal judgment; it is sensitive to extreme values ​​of the distribution. Methods based on probability distribution may be too sensitive to extreme values ​​and misjudge very few normal but extreme situations as abnormalities. Conversely, if the abnormal event manifests itself relatively smoothly and does not deviate significantly from the standard distribution, it may not be detected in time; the model has limited generalization capabilities. Since this method does not rely on a specific time series model, in some specific scenarios, complex business rules cannot be effectively captured, resulting in insufficient generalization capabilities of the model and difficulty in coping with all business scenarios.

[0036] Figure 1 This is one of the flow charts of the method for detecting abnormal business indicators provided by the present invention, such as Figure 1 As shown, the method includes steps 101 to 103.

[0037] Step 101: Obtain the current business metric value, the current metric slope, and the current metric quantile in real time. The current metric slope and the current metric quantile are determined based on the historical business metric values within the first time period.

[0038] Specifically, the business metric value refers to the numerical value corresponding to the business metric. The current business metric value refers to the business metric value at the current moment. The metric slope refers to the slope of the line formed by arranging the business metric values over a period of time in chronological order. The current metric slope refers to the metric slope determined based on the business metric values within the first time period. The first time period refers to a period of time before the current moment, such as the past X minutes, where X can be adjusted according to actual needs. The metric quantile refers to the Y-th quantile calculated by statistically analyzing the business metric values over a period of time using the quantile method, and Y can be adjusted according to actual needs. The current metric quantile refers to the metric slope determined based on the business metric values within the first time period. The historical business metric values refer to the business metric values generated before the current moment.

[0039] In practical applications, the business metrics can be monitored in real time to obtain the current business metric value. It is also possible to obtain the historical business metric values within the first time period, and then calculate the current metric slope and the current metric quantile based on the historical business metric values within the first time period.

[0040] Step 102: Detect the current business metric value, the current metric slope, and the current metric quantile according to at least one preset warning strategy to obtain a detection result.

[0041] The warning strategy refers to the general term for methods, schemes, and ways used for warning. There can be one warning strategy, corresponding to one detection result; there can be at least two warning strategies, such as warning strategies set from different dimensions. Correspondingly, there are also multiple detection results, and each warning strategy corresponds to one detection result.

[0042] In practical applications, according to at least one warning strategy, the current business metric value, the current metric slope, and the current metric quantile can be processed, that is, detected, to obtain the detection results corresponding to each warning strategy.

[0043] Step 103: When the detection result indicates an anomaly, determine that the business metric corresponding to the current business metric value is abnormal.

[0044] In practical applications, after obtaining the detection results corresponding to each warning strategy, check each detection result. If all detection results indicate normal, the business metric corresponding to the current business metric value is normal. If there is a detection result indicating an anomaly, determine that the business metric corresponding to the current business metric value is abnormal.

[0045] The detection method and device for abnormal business indicators provided by the present invention achieve an efficient and flexible solution for detecting abnormal business indicators through at least one early warning strategy, ensuring that abnormal fluctuations in business indicators can be detected in a timely manner, especially for sudden changes, an early warning can be issued faster, and the recall rate is improved. By combining the dual detection of quantiles and slopes, false alarms caused by normal fluctuations are effectively filtered out, and at the same time, accurate early warnings are issued for extreme situations, reducing unnecessary alarm interference, that is, the false alarm rate is reduced.

[0046] In one or more alternative embodiments of the present invention, the at least one early warning strategy includes a month-on-month early warning strategy, a year-on-year early warning strategy, and an extreme value early warning strategy; correspondingly, the detecting the current business indicator value, the current indicator slope, and the current indicator quantile according to the preset at least one early warning strategy to obtain a detection result includes: Detecting the current business indicator value according to the extreme value early warning strategy to obtain an extreme value detection result; Detecting the current indicator slope according to the month-on-month early warning strategy to obtain a month-on-month detection result; Detecting the current indicator quantile according to the year-on-year early warning strategy to obtain a year-on-year detection result.

[0047] Specifically, the month-on-month early warning strategy is based on the fluctuation of business indicators in adjacent time periods. By comparing the trend slope at the current moment with that in the previous time period, abnormal fluctuations are identified; the month-on-month early warning strategy is more sensitive to short-term sudden abnormal changes. The year-on-year early warning strategy: Based on the quantiles of historical data in the same time period or interval period (such as daily, weekly, monthly), the year-on-year change rate of the indicator is calculated; by analyzing the fluctuation trends of the same type of time points, the periodic changes of the data are monitored, and abnormal deviations in the long-term trend are identified. The extreme value early warning strategy uses a static threshold to detect extreme situations of business indicators, mainly used to capture abnormal peaks or valleys in the data; the extreme value early warning strategy is suitable for scenarios with extremely large changes in business load, such as a sharp increase or decrease in traffic.

[0048] In practical applications, the month-on-month early warning strategy, the year-on-year early warning strategy, and the extreme value early warning strategy can be used for detection: The extreme value early warning strategy is used to detect the current business indicator value to obtain an extreme value detection result; the month-on-month early warning strategy is used to detect the current indicator slope to obtain a month-on-month detection result; the year-on-year early warning strategy is used to detect the current indicator quantile to obtain a year-on-year detection result. In this way, by detecting indicators from three dimensions of month-on-month, year-on-year, and extreme values, not only can the detection be more comprehensive, improving the reliability of the detection, but also sudden abnormal changes, trend deviation anomalies, and extremely large change scenarios can be detected, further ensuring a high recall rate and a low false alarm rate for fault detection.

[0049] In one or more alternative embodiments of the present invention, the detecting the current service metric value according to the extreme value warning strategy to obtain an extreme value detection result includes: Comparing the current service metric value with a first threshold range of the extreme value warning strategy; If the current service metric value is within the first threshold range, it is determined that the extreme value detection result indicates normal; If the current service metric value is outside the first threshold range, it is determined that the extreme value detection result indicates abnormal.

[0050] Specifically, the first threshold range includes a maximum threshold and a minimum threshold.

[0051] In practical applications, the extreme value detection of the current service metric value can be performed based on the first threshold range of the extreme value warning strategy: comparing the current service metric value with the maximum threshold and the minimum threshold. If the current service metric value is greater than the maximum threshold or less than the minimum threshold, that is, exceeding the first threshold range, it is determined that the extreme value detection result indicates abnormal and a warning notification is triggered; if the current service metric value is less than or equal to the maximum threshold or greater than or equal to the minimum threshold, that is, not exceeding the first threshold range, it is determined that the extreme value detection result indicates normal and no warning notification needs to be triggered.

[0052] In one or more alternative embodiments of the present invention, the detecting the current metric slope according to the month-on-month warning strategy to obtain a month-on-month detection result includes: Comparing the current metric slope with a second threshold range of the month-on-month warning strategy; If the current metric slope is within the second threshold range, it is determined that the month-on-month detection result indicates normal; If the current metric slope is outside the second threshold range, it is determined that the month-on-month detection result indicates abnormal.

[0053] In practical applications, the month-on-month detection of the current metric slope can be performed based on the second threshold range of the month-on-month warning strategy: comparing the current curve slope with the second threshold range. If the current curve slope exceeds the second threshold range, the month-on-month detection result indicates abnormal and a warning notification is triggered; if the current metric slope does not exceed the second threshold range, the month-on-month extreme value detection result indicates normal and no warning notification needs to be triggered.

[0054] In addition, to avoid the impact of short-term spikes (rising first and then falling) on the month-on-month early warning detection (short-term spikes are generally considered normal), the slope of the indicator F minutes ago can be used to remove the spikes. Because if there are short-term spikes, the slopes of their rise and fall should be similar, rising fast and falling fast. In the decline detection strategy, the slope F minutes ago (such as 6 minutes) is compared with the positive threshold (the upper limit of the second threshold range). If it exceeds the positive threshold, it means that it has risen too fast first. At this time, if it also falls quickly, the early warning will not be triggered.

[0055] In one or more alternative embodiments of the present invention, the detecting the current indicator quantile according to the year-on-year early warning strategy to obtain a year-on-year detection result includes: Obtain a set indicator quantile; Calculate the change ratio between the current indicator quantile and the set indicator quantile; Compare the change ratio with the third threshold range of the year-on-year early warning strategy; If the change ratio is within the third threshold range, it is determined that the year-on-year detection result indicates normal; If the change ratio is outside the third threshold range, it is determined that the year-on-year detection result indicates abnormal.

[0056] Specifically, the set indicator quantile is the indicator quantile at the same time point in the previous interval period and belonging to the same time point as the current indicator quantile. For example, if the interval period is one day and the current time is 15:00 on January 7th, the set indicator quantile is the indicator quantile obtained at 15:00 on January 6th. The interval period is the interval period set in the year-on-year early warning strategy.

[0057] In practical applications, the year-on-year detection of the current indicator quantile can be performed based on the third threshold range of the year-on-year early warning strategy: obtain the set indicator quantile based on the interval period set in the year-on-year early warning strategy, calculate the difference between the current indicator quantile and the set indicator quantile, and determine the ratio of the difference to the set indicator quantile as the change ratio between the current indicator quantile and the set indicator quantile. Further, compare whether the change ratio exceeds the third threshold range set by the year-on-year early warning strategy. If it exceeds, the year-on-year detection result indicates abnormal and an early warning notification is triggered. If it does not exceed, the year-on-year detection result indicates normal.

[0058] In one or more alternative embodiments of the present invention, before comparing the current business indicator value with the first threshold range of the extreme value early warning strategy, it further includes: Obtain the historical business indicator values within the second time period; Take the Y of the historical business indicator values within the second time period 1The quantile is used as the first descending threshold, and Y of the historical business metric values within the second time period is taken. 2 The quantile is used as the first ascending threshold, where Y 1 is less than Y 2 ; Based on the first descending threshold and the first ascending threshold, the first threshold interval is formed.

[0059] In practical applications, collect the actual values of business data within the second time period, that is, the historical business metric values within the second time period. Obtain the low quantile (Y 1 quantile, adjustable parameter) and the high quantile (Y 2 quantile, adjustable parameter) of the historical business metric values within the second time period. The low quantile is used as the first descending threshold, and the high quantile is used as the first ascending threshold. Exemplarily, take the 2 quantile of the historical business metric values within the past 10 days as the first descending threshold, and take the 98 quantile of the historical business metric values within the past 10 days as the first ascending threshold.

[0060] In one or more alternative embodiments of the present invention, before comparing the current metric slope with the second threshold interval of the month-on-month warning strategy, it further includes: Obtain the historical metric slope within the third time period; Take the Y 3 quantile of the historical metric slope within the third time period as the second descending threshold, and take the Y 4 quantile of the historical metric slope within the third time period as the second ascending threshold, where Y 3 is less than Y 4 ; Based on the second descending threshold and the second ascending threshold, the second threshold interval is formed.

[0061] In practical applications, collect the historical metric slope within the third time period. Obtain the low quantile (Y 3 quantile, adjustable parameter) and the high quantile (Y 4 quantile, adjustable parameter) of the historical metric slope within the third time period. The low quantile is used as the second descending threshold, and the high quantile is used as the second ascending threshold.

[0062] In one or more alternative embodiments of the present invention, before comparing the change ratio with the third threshold interval of the year-on-year warning strategy, it further includes: Obtain the historical metric quantiles within the fourth time period; According to the set interval period, determine at least one pair of the historical metric quantiles from the historical metric quantiles within the fourth time period. The two historical metric quantiles in the pair of historical metric quantiles are adjacent in period and have the same time point within the corresponding period; For each of the historical quantile pairs, calculate the change ratio of the two historical quantiles in the historical quantile pair; Take the Y 5 quantile of the change ratio corresponding to each of the historical quantile pairs as the third downward threshold, and take the Y 6 quantile of the change ratio corresponding to each of the historical quantile pairs as the third upward threshold, where Y 5 is less than Y 6 ; Based on the third downward threshold and the third upward threshold, form the third threshold interval.

[0063] In practical applications, collect the historical quantiles within the fourth time period. Then, according to the interval period set by the year-on-year warning strategy, determine the historical quantile pairs from the historical quantiles within the fourth time period. For example, if the interval period is daily, the historical quantile (such as L1) at 00:00:01 on December 12 and the historical quantile (such as L2) at 00:00:01 on December 13 form a historical quantile pair. Then, calculate the change ratio corresponding to each historical quantile pair, that is, the change ratio = (L1 - L2) / L2.

[0064] Further, determine the lower quantile (Y 5 quantile, adjustable parameter) and the upper quantile (Y 6 quantile, adjustable parameter) of the change ratios corresponding to all historical quantile pairs. The lower quantile is used as the third downward threshold, and the upper quantile is used as the third upward threshold.

[0065] It should be noted that the second time period, the third time period, and the fourth time period can be the same, such as all being the past T days, where T is a positive integer.

[0066] In one or more alternative embodiments of the present invention, the process of obtaining the current index slope and the current index quantile includes: Fit the historical business index values within the first time period and calculate the current index slope based on the method of taking the derivative; Statistically analyze the historical business index values within the first time period and determine the current index slope based on the quantile method.

[0067] In practical applications, fit the historical business index values of the business index in the past X minutes (within the first time period), and calculate the curve slope through taking the derivative, that is, the current index slope, which reflects the trend of the index change. If the curve slope is positive, it indicates that the business index is on an upward trend; if the curve slope is negative, it indicates a downward trend.

[0068] Statistically analyze the historical business metric values of a business metric in the past X minutes (within the first time period), and calculate the Y-th quantile N2 of the metric using the quantile method. The introduction of quantiles can better eliminate the interference of extreme values and help identify relatively common fluctuation patterns.

[0069] In one or more alternative embodiments of the present invention, when the detection result indicates an anomaly, determining that the business metric corresponding to the current business metric value is abnormal includes: When the detection result indicates an anomaly, statistically analyze the duration for which the detection result indicates an anomaly; When the duration reaches the duration corresponding to at least one warning strategy, determine that the business metric corresponding to the current business metric value is abnormal.

[0070] In practical applications, in order to further reduce the false alarm rate, the detection of business metric anomalies can also be combined with the duration. For example, set the trigger threshold (threshold range) and duration of the warning strategy. For example, it can be set that if the metric slope rises or falls significantly compared to 5 minutes ago for 3 consecutive minutes, an anomaly is detected and an anomaly warning is triggered.

[0071] In one or more alternative embodiments of the present invention, a trend graph of at least one of the historical business metric values, historical metric slopes, and historical metric quantiles can also be displayed through a visualization interface, so that users can intuitively observe the fluctuation trend of the data and the abnormal moments.

[0072] In one or more alternative embodiments of the present invention, the threshold region and / or duration of the warning strategy can also be adjusted through a visualization interface, and the frequency and recall rate can also be optimized through the visualization interface. For example, based on the statistical information of the warning frequency, users can adjust the threshold region and / or duration of the warning strategy to check whether the past warnings are too frequent or the recall is insufficient, thereby optimizing the accuracy of the warning strategy.

[0073] The detection of business metric anomalies provided by the present invention is based on data trend fluctuations and adaptive threshold adjustment, combines trend slopes and quantile changes as core parameters, dynamically sets the threshold of the warning strategy, and flexibly adjusts the warning parameters through a visualization debugging interface to ensure a high fault recall rate, a low false alarm rate, and good adaptability and generality.

[0074] The following combines Figure 2 to further illustrate the method for detecting business metric anomalies provided by the present invention.

[0075] Refer to Figure 2 , Figure 2 which is the second flowchart of the method for detecting business metric anomalies provided by the present invention.

[0076] First, set up the early warning strategy, which mainly includes data preprocessing, early warning strategy template setting, threshold setting, visualization debugging and analysis.

[0077] Data preprocessing includes slope calculation and quantile calculation.

[0078] Slope calculation, that is, obtaining the trend slope (index slope). Fit the business index within the time window of the past X minutes, and calculate the curve slope N1 by derivation, which reflects the trend of index change. If the value of N1 is positive, it indicates that the business index is on the rise; if it is negative, it indicates a downward trend.

[0079] Quantile calculation, that is, obtaining the (index) quantile. Statistically analyze the business index within the time window of the past X minutes, and calculate the Y quantile N2 of the index using the quantile method. The introduction of quantiles can better eliminate the interference of extreme values and help identify more common fluctuation patterns.

[0080] Early warning strategy template setting: Input the calculated N1, N2 and the actual index value N into the following three early warning strategy templates: month-on-month early warning strategy, year-on-year early warning strategy and extreme value early warning strategy.

[0081] The month-on-month early warning strategy is based on the index fluctuations in adjacent time periods. By comparing the trend slope at the current moment with that in the previous time period, it identifies abnormal fluctuations. This strategy is sensitive to short-term sudden abnormal changes.

[0082] The year-on-year early warning strategy is based on the quantiles of historical data in the same time cycle (such as daily, weekly, monthly), calculates the year-on-year change rate of the index. By analyzing the fluctuation trends at the same type of time points, it monitors the periodic changes of data and identifies anomalies with long-term trend deviations.

[0083] The extreme value early warning strategy uses static thresholds to detect extreme situations of business indicators, mainly used to capture abnormal peaks or troughs in data. This strategy is suitable for scenarios with large changes in business load, such as sudden increases or significant decreases in traffic.

[0084] Threshold setting, that is, setting the early warning threshold, is mainly completed through statistical analysis of historical data, including the following: Analyze the data changes in the past T days: Collect the actual values N of business data, curve slopes N1, and quantiles N2 in the past T days, calculate the proportional value of the year-on-year change of the quantile N2; then take the quantiles of the data set to obtain the thresholds for upward and downward changes (dynamic confidence intervals); Month-on-month threshold setting: Obtain the lower quantile (adjustable parameter) and upper quantile (adjustable parameter) of the trend slope (N1). The lower quantile is used as the downward threshold of the trend slope, and the upper quantile is used as the upward threshold of the trend slope.

[0085] Extreme value threshold setting: Obtain the lower quantile (adjustable parameter) and the upper quantile (adjustable parameter) of the actual values of business data in the past T days. The lower quantile is used as the downward threshold, and the upper quantile is used as the upward threshold.

[0086] Year-on-year threshold setting: Select the interval period (day, week, month); calculate the change ratio between two adjacent same-period values of the quantile; count the lower quantile (adjustable parameter) and the upper quantile (adjustable parameter) of the change ratio of the same-period quantile. The lower quantile is used as the downward threshold, and the upper quantile is used as the upward threshold.

[0087] Visual debugging and analysis are mainly carried out through the visual debugging interface. Users can view the trend changes of business indicators in the past period of time and conduct analysis and debugging in combination with the hit situation of the early warning strategy, including the following: Interface display: Display the trend chart of historical business data on the interface, and users can intuitively observe the fluctuation trend of the data and abnormal moments. Parameter debugging: Users can set the trigger threshold and duration of the early warning strategy in the interface, and adjust the strategy threshold and adjustment duration. For example, it can be set that if the slope rises or falls significantly compared to 5 minutes ago for 3 consecutive minutes, an abnormal early warning will be triggered. Frequency and recall rate optimization: According to the statistical information of the early warning frequency, users can adjust the threshold and duration, and view whether the past early warnings are too frequent or the recall is insufficient (view the hit time period), so as to optimize the accuracy of the early warning strategy.

[0088] Then real-time detection is carried out, mainly including data preprocessing and data detection.

[0089] Data preprocessing: Perform data preprocessing every minute, repeat the above steps of data preprocessing to obtain the curve slope N1, the quantile N2, and the actual value N of the indicator.

[0090] Data detection: Start a scheduled task to perform detection every N minutes, mainly including month-on-month detection, year-on-year detection, and extreme value detection, that is, retrieve the corresponding early warning strategies (month-on-month, year-on-year, and extreme value) for detection and trigger early warnings.

[0091] Month-on-month detection: If the curve slope N1 at the current time exceeds the interval threshold set by the month-on-month early warning strategy, an early warning notice will be triggered.

[0092] Year-on-year detection: Calculate the change ratio between the quantile N2 at the current time and the data N2` of the same period selected in the year-on-year early warning strategy. If it exceeds the interval threshold set by the early warning strategy, an early warning notice will be triggered.

[0093] Extreme value detection: Compare the actual data N at the current time with the maximum and minimum thresholds of the extreme value early warning strategy. If it exceeds the threshold, an early warning notice will be triggered.

[0094] The present invention provides an embodiment, which calculates the trend slope and quantile changes of business indicators, inputs them into at least one early warning strategy, and dynamically sets thresholds in combination with historical data analysis to achieve accurate detection of business indicator anomalies. At the same time, a visual debugging interface is provided to allow users to tune according to historical data trends and early warning strategy hits. By calculating the trend slope and quantile of the indicator, the volatility and nonlinear changes of business data are captured. Month-on-month, year-on-year and extreme value early warning strategies are introduced to cover dynamic and static anomaly detection. Through historical data analysis, reasonable early warning thresholds are automatically generated to reduce manual intervention. The frequency of early warning hits is intuitively displayed through the interface, and flexible adjustment of thresholds and durations is supported to improve user experience.

[0095] The present invention provides a multi-dimensional early warning strategy and dynamic threshold setting of an embodiment, realizing an efficient and flexible solution for abnormal detection of business indicators. By dynamically adjusting the threshold, it is ensured that abnormal fluctuations of business indicators can be detected in time, especially for sudden changes (such as sudden increase or decrease in traffic), early warnings can be issued more quickly, so that the recall rate is improved. By combining the dual detection of quantiles and slopes, false alarms caused by normal fluctuations are effectively filtered out, and accurate early warnings are given for extreme situations at the same time, reducing unnecessary alarm interference, that is, the false alarm rate is reduced. By setting reasonable thresholds through historical data analysis, the system can automatically adapt to different business scenarios, reducing the complexity of manually setting thresholds, that is, the versatility and adaptability are wider. A flexible visual interface is provided, and users can flexibly adjust the early warning parameters according to business characteristics to meet the monitoring needs of different business systems. By adopting simplified calculation methods such as quantiles and slopes, complex time series decomposition is avoided, and the consumption of computing resources is greatly reduced, making it suitable for real-time monitoring in large-scale business scenarios, that is, low resource consumption.

[0096] The following is a description of the device for detecting abnormal business indicators provided by the present invention. The device for detecting abnormal business indicators described below and the method for detecting abnormal business indicators described above can be referred to in correspondence with each other. Figure 3 As shown, including: An acquisition module 301 is configured to acquire a current business indicator value, a current indicator slope, and a current indicator quantile in real time, wherein the current indicator slope and the current indicator quantile are determined based on a historical business indicator value in a first time period; The detection module 302 is configured to detect the current business indicator value, the current indicator slope and the current indicator quantile according to at least one preset early warning strategy to obtain a detection result; The determination module 303 is configured to determine that the business indicator corresponding to the current business indicator value is abnormal when the detection result indicates an abnormality.

[0097] Optionally, the at least one warning strategy includes a month-on-month warning strategy, a year-on-year warning strategy, and an extreme value warning strategy; The detection module 302 is further configured to: Detect the current business metric value according to the extreme value warning strategy to obtain an extreme value detection result; Detect the current metric slope according to the month-on-month warning strategy to obtain a month-on-month detection result; Detect the current metric quantile according to the year-on-year warning strategy to obtain a year-on-year detection result.

[0098] Optionally, the detection module 302 is further configured to: Compare the current business metric value with a first threshold interval of the extreme value warning strategy; If the current business metric value is within the first threshold interval, it is determined that the extreme value detection result indicates normal; If the current business metric value is outside the first threshold interval, it is determined that the extreme value detection result indicates abnormal.

[0099] Optionally, the detection module 302 is further configured to: Compare the current metric slope with a second threshold interval of the month-on-month warning strategy; If the current metric slope is within the second threshold interval, it is determined that the month-on-month detection result indicates normal; If the current metric slope is outside the second threshold interval, it is determined that the month-on-month detection result indicates abnormal.

[0100] Optionally, the detection module 302 is further configured to: Obtain a set metric quantile, where the set metric quantile is the metric quantile within the previous interval period and at the same time point as the current metric quantile; Calculate the change ratio between the current metric quantile and the set metric quantile; Compare the change ratio with a third threshold interval of the year-on-year warning strategy; If the change ratio is within the third threshold interval, it is determined that the year-on-year detection result indicates normal; If the change ratio is outside the third threshold interval, it is determined that the year-on-year detection result indicates abnormal.

[0101] Optionally, the device further includes a first composition module configured to: Obtain historical business metric values within a second time period; Take the Y 1 quantile of the historical business metric values within the second time period as the first downward threshold, and take the Y 2 quantile of the historical business metric values within the second time period as the first upward threshold, where Y 1 is less than Y 2 ; Based on the first downward threshold and the first upward threshold, form the first threshold interval.

[0102] Optionally, the device further includes a second forming module configured to: Obtain the historical metric slope within the third time period; Take the Y 3 quantile of the historical metric slopes within the third time period as the second downward threshold, and take the Y 4 quantile of the historical metric slopes within the third time period as the second upward threshold, where Y 3 is less than Y 4 ; Based on the second downward threshold and the second upward threshold, form the second threshold interval.

[0103] Optionally, the device further includes a third forming module configured to: Obtain the historical metric quantiles within the fourth time period; According to the set interval period, determine at least one pair of the historical metric quantiles from the historical metric quantiles within the fourth time period, where the two historical metric quantiles in the pair of historical metric quantiles have adjacent periods and the same time points within the corresponding periods; For each pair of historical metric quantiles, calculate the change ratio between the two historical metric quantiles in the pair of historical metric quantiles; Take the Y 5 quantile of the change ratios corresponding to each pair of historical metric quantiles as the third downward threshold, and take the Y 6 quantile of the change ratios corresponding to each pair of historical metric quantiles as the third upward threshold, where Y 5 is less than Y 6 ; Based on the third downward threshold and the third upward threshold, form the third threshold interval.

[0104] Optionally, the obtaining module 301 is further configured to: Fit the historical business metric values within the first time period and calculate the current metric slope based on differentiation; Statistically analyze the historical business metric values within the first time period and determine the current metric quantile based on the quantile method.

[0105] Optionally, the determining module 303 is further configured to: When the detection result indicates an anomaly, count the duration for which the detection result indicates an anomaly; When the duration reaches the duration corresponding to at least one warning policy, determine that the service metric corresponding to the current service metric value is abnormal.

[0106] Figure 4 FIG. shows a schematic physical structure diagram of an electronic device, which may include: a processor 410, a communication interface 420, a memory 430, and a communication bus 440. Among them, the processor 410, the communication interface 420, and the memory 430 communicate with each other through the communication bus 440. The processor 410 can call the logical instructions in the memory 430 to execute the method for detecting service metric anomalies, and the method includes: obtaining the current service metric value, the current metric slope, and the current metric quantile in real time, where the current metric slope and the current metric quantile are determined based on the historical service metric values within the first time period; detecting the current service metric value, the current metric slope, and the current metric quantile according to at least one preset warning policy to obtain a detection result; when the detection result indicates an anomaly, determining that the service metric corresponding to the current service metric value is abnormal.

[0107] In addition, when the logical instructions in the above-mentioned memory 430 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk, or an optical disc that can store program codes.

[0108] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the detection method for abnormal service metrics provided by the above-mentioned various methods. The method includes: obtaining the current service metric value, the current metric slope, and the current metric quantile in real time, where the current metric slope and the current metric quantile are determined based on the historical service metric values within the first time period; detecting the current service metric value, the current metric slope, and the current metric quantile according to at least one preset warning strategy to obtain a detection result; and when the detection result indicates an abnormality, determining that the service metric corresponding to the current service metric value is abnormal.

[0109] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it realizes the detection method for abnormal service metrics provided by the above-mentioned various methods. The method includes: obtaining the current service metric value, the current metric slope, and the current metric quantile in real time, where the current metric slope and the current metric quantile are determined based on the historical service metric values within the first time period; detecting the current service metric value, the current metric slope, and the current metric quantile according to at least one preset warning strategy to obtain a detection result; and when the detection result indicates an abnormality, determining that the service metric corresponding to the current service metric value is abnormal.

[0110] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0111] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disc, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0112] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for detecting abnormal business indicators, characterized in that: include: Acquire a current business indicator value, a current indicator slope, and a current indicator quantile in real time, wherein the current indicator slope and the current indicator quantile are determined based on historical business indicator values ​​within a first time period; The current business indicator value, the current indicator slope and the current indicator quantile are tested according to at least one preset early warning strategy to obtain a test result; In the case where the detection result indicates an abnormality, it is determined that the business indicator corresponding to the current business indicator value is abnormal.

2. The method for detecting abnormal business indicators according to claim 1, characterized in that: The at least one early warning strategy includes a month-on-month early warning strategy, a year-on-year early warning strategy, and an extreme value early warning strategy; The detecting the current business indicator value, the current indicator slope and the current indicator quantile according to at least one preset early warning strategy to obtain a detection result includes: Detecting the current business indicator value according to the extreme value warning strategy to obtain an extreme value detection result; The current indicator slope is tested according to the month-on-month early warning strategy to obtain a month-on-month test result; The current indicator quantile is tested according to the year-on-year warning strategy to obtain a year-on-year test result.

3. The method for detecting abnormal business indicators according to claim 2, characterized in that: The detecting the current business indicator value according to the extreme value warning strategy to obtain the extreme value detection result includes: Comparing the current business indicator value with the first threshold interval of the extreme value warning strategy; If the current service indicator value is within the first threshold interval, determining that the extreme value detection result indicates normality; If the current service indicator value is outside the first threshold interval, determining that the extreme value detection result represents an abnormality; The current indicator slope is detected according to the month-on-month early warning strategy to obtain a month-on-month detection result, including: Comparing the current indicator slope with the second threshold interval of the month-on-month warning strategy; If the current indicator slope is within the second threshold interval, it is determined that the month-on-month detection result is normal; If the current indicator slope is outside the second threshold interval, it is determined that the month-on-month detection result represents an abnormality.

4. The method for detecting abnormal business indicators according to claim 2, characterized in that: The current indicator quantile is tested according to the year-on-year warning strategy to obtain a year-on-year test result, including: Obtaining a set indicator quantile, where the set indicator quantile is an indicator quantile within the previous interval period and at the same time point as the current indicator quantile; Calculate the change ratio between the current indicator quantile and the set indicator quantile; comparing the change ratio with a third threshold interval of the year-on-year warning strategy; If the change ratio is within the third threshold range, it is determined that the year-on-year detection result is normal; If the change ratio is outside the third threshold range, it is determined that the year-on-year detection result represents an abnormality.

5. The method for detecting abnormal business indicators according to claim 3, characterized in that: Before comparing the current business indicator value with the first threshold interval of the extreme value warning strategy, the method further includes: Obtain historical business indicator values ​​within a second time period; Taking the Y1 quantile of the historical business indicator value in the second time period as the first descending threshold, taking the Y2 quantile of the historical business indicator value in the second time period as the first ascending threshold, wherein Y1 is less than Y2; The first threshold interval is constructed based on the first falling threshold and the first rising threshold.

6. The method for detecting abnormal business indicators according to claim 3, characterized in that: Before comparing the current indicator slope with the second threshold interval of the month-on-month warning strategy, the method further includes: Get the historical indicator slope in the third time period; The Y3 quantile of the historical indicator slope in the third time period is taken as the second descending threshold, and the Y4 quantile of the historical indicator slope in the third time period is taken as the second ascending threshold, wherein Y3 is less than Y4; The second threshold interval is constructed based on the second falling threshold and the second rising threshold.

7. The method for detecting abnormal business indicators according to claim 4, characterized in that: Before comparing the change ratio with the third threshold interval of the year-on-year warning strategy, the method further includes: Get the historical indicator quantiles in the fourth time period; According to the set interval period, determine at least one of the historical indicator quantile pairs from the historical indicator quantiles in the fourth time period, wherein the periods of two historical indicator quantiles in the historical indicator quantile pair are adjacent and the time points in the corresponding periods are the same; For each of the historical indicator quantile pairs, calculating the change ratio of the two historical indicator quantiles in the historical indicator quantile pair; The Y5 quantile of the change ratio corresponding to each pair of the historical indicator quantiles is taken as the third descending threshold, and the Y6 quantile of the change ratio corresponding to each pair of the historical indicator quantiles is taken as the third ascending threshold, wherein Y5 is less than Y6; The third threshold interval is constructed based on the third falling threshold and the third rising threshold.

8. The method for detecting abnormal business indicators according to any one of claims 1 to 7, characterized in that: The process of obtaining the current indicator slope and the current indicator quantile includes: Fitting the historical business indicator values ​​within the first time period, and calculating the current indicator slope based on a derivation method; Statistics are collected on historical business indicator values ​​within the first time period, and the current indicator quantile is determined based on a quantile method.

9. The method for detecting abnormal business indicators according to any one of claims 1 to 7, characterized in that: When the detection result indicates an abnormality, determining that the business indicator corresponding to the current business indicator value is abnormal includes: In the case where the detection result indicates an abnormality, counting the duration of the abnormality indicated by the detection result; When the duration reaches the duration corresponding to the at least one early warning strategy, it is determined that the business indicator corresponding to the current business indicator value is abnormal.

10. A device for detecting abnormal business indicators, characterized in that: include: An acquisition module is configured to acquire in real time a current business indicator value, a current indicator slope, and a current indicator quantile, wherein the current indicator slope and the current indicator quantile are determined based on a historical business indicator value within a first time period; A detection module is configured to detect the current business indicator value, the current indicator slope and the current indicator quantile according to at least one preset early warning strategy to obtain a detection result; The determination module is configured to determine that the business indicator corresponding to the current business indicator value is abnormal when the detection result indicates an abnormality.

Citation Information

Cited By

  • Automatic data verification method and device based on dynamic threshold value

    CN120804066A