Abnormality detection device and method thereof
By using abnormal detection devices and methods in satellite systems and network communication systems, monitoring the data processing rate and operating time of the application, the problem of difficulty in detecting short-term mild and long-term severe abnormalities is solved in the prior art, and effective monitoring and management of the usage status of computing resources is realized to ensure the stability and transmission quality of the communication system.
Patent Information
- Application Number
- CN202410174787.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-13
- Filing Date
- 2024-02-07
- Publication Date
- 2025-06-13
AI Technical Summary
Existing satellite systems and network communication systems are difficult to effectively detect short-term mild abnormalities and long-term severe abnormalities, resulting in large-scale use of computing resources by specific applications, resulting in communication interruptions or reduced transmission quality.
An abnormality detection device and method are provided, through a data amount accumulation unit, an operating time counter and an abnormal state counter, to monitor the data processing rate and operating time of the application, and to determine whether the application is in a first abnormal state (short-term mild abnormality) or a second abnormal state (long-term severe abnormality).
It can effectively detect abnormalities in the application's usage status of computing resources, avoid exclusion of computing resources, and ensure the stability and transmission quality of the communication system.
Smart Images

Figure CN120144393A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a data processing apparatus and method, and more particularly to an anomaly detection apparatus and method for detecting an abnormal state of an application program. Background Art
[0002] In satellite systems and network communication systems, numerous application programs are typically installed and executed to perform system operations. The computing resources of satellite systems and network communication systems (such as the utilization rate of the processor, the usage amount of the memory, and the bandwidth, etc.) are allocated to these application programs.
[0003] When the allocation of computing resources fails to adapt to the actual operation of the system, it is possible that certain specific application programs may occupy a large amount of computing resources, resulting in the application programs dedicated to the communication function in the system being unable to be allocated sufficient computing resources (this is called computing resource crowding). In this situation, the application programs dedicated to the communication function are unable to process the current data volume within a predetermined time (that is, unable to achieve a predetermined data throughput), causing the communication interruption of the satellite system or the degradation of the transmission quality of the network communication system.
[0004] Existing satellite systems and network communication systems often use a watchdog timer to monitor the operation time of application programs, and based on this, determine whether the application programs can process a predetermined data volume within a predetermined time. However, both hardware-form and software-form watchdog timers have their drawbacks and limitations and cannot effectively detect short-term mild anomalies of the system and application programs.
[0005] In view of the above problems, an improved anomaly detection mechanism is needed that can effectively detect short-term mild anomalies and long-term severe anomalies. Summary of the Invention
[0006] According to one aspect of the present invention, there is provided an anomaly detection device for detecting anomalies in the usage status of computing resources by an application program. The anomalies in the usage status include a first anomaly state and a second anomaly state. The anomaly detection device includes the following components. A data volume accumulation unit for accumulating a first data volume processed by the application program. An operation time counter having a first count value and incrementing the first count value according to a first counting frequency. An anomaly state counter having a second count value and selectively incrementing the second count value according to the first anomaly state. A monitoring unit for performing the following operations. Monitoring whether the first data volume reaches a predetermined data volume, where the predetermined data volume is related to the maximum processing rate of the application program. When the first data volume reaches the predetermined data volume, reading the first count value and determining whether the application program is in the first anomaly state according to the first count value. When it is determined that the application program is in the first anomaly state, incrementing and reading the second count value and determining whether the application program is in the second anomaly state according to the second count value.
[0007] According to another aspect of the present invention, there is provided an anomaly detection method for detecting anomalies in the usage status of computing resources by an application program. The anomalies in the usage status include a first anomaly state and a second anomaly state. The anomaly detection method includes the following steps. Accumulating a first data volume processed by the application program through a data volume accumulation unit. Incrementing a first count value according to a first counting frequency through an operation time counter. Selectively incrementing a second count value according to the first anomaly state through an anomaly state counter. Performing the following operations through a monitoring unit. Monitoring whether the first data volume reaches a predetermined data volume, where the predetermined data volume is related to the maximum processing rate of the application program. When the first data volume reaches the predetermined data volume, reading the first count value and determining whether the application program is in the first anomaly state according to the first count value. When it is determined that the application program is in the first anomaly state, incrementing and reading the second count value and determining whether the application program is in the second anomaly state according to the second count value.
[0008] By reading the following drawings, detailed description, and claims, other aspects and advantages of the present invention can be seen. Description of the Drawings
[0009] Figure 1 A schematic diagram showing an anomaly detection device according to an embodiment of the present invention applied to a computer system platform.
[0010] Figure 2 A block diagram showing the anomaly detection device and showing the operation of the anomaly detection device.
[0011] Figure 3 A flowchart showing an anomaly detection method according to an embodiment of the present invention.
[0012] Figure 4Flowchart of the anomaly detection method according to another embodiment of the present invention.
[0013] Description of reference numerals:
[0014] 100: Data volume accumulation unit
[0015] 200: Counting unit
[0016] 210: Operating time counter
[0017] 220: Anomaly status counter
[0018] 300: Monitoring unit
[0019] 400: Warning unit
[0020] 1000: Anomaly detection device
[0021] 2000: Computer system platform
[0022] 2100: Processor
[0023] 2200: Memory
[0024] 3000: User
[0025] APP_1 to APP_N: Application programs
[0026] D1: First data volume
[0027] CNT1: First count value
[0028] CNT2: Second count value
[0029] RD1, RD2, AB2_W: Control signals
[0030] WR: Warning signal
[0031] S300 to S318: Steps
[0032] S400 to S408: Steps Detailed implementation manners
[0033] The technical terms in this specification refer to the customary terms in the technical field. If this specification explains or defines some terms, the explanations of these terms shall prevail according to the explanations or definitions in this specification. Each embodiment of the present invention has one or more technical features. On the premise of possible implementation, those skilled in the art can selectively implement some or all of the technical features in any embodiment, or selectively combine some or all of the technical features in these embodiments.
[0034] Please refer to Figure 1, which shows a schematic diagram of an anomaly detection device 1000 according to an embodiment of the present invention applied to a computer system platform 2000. The computer system platform 2000 includes a processor 2100 and a memory 2200. A plurality of application programs (e.g., N application programs APP_1 to APP_N) operate on the computer system platform 2000. During operation, the application programs APP_1 to APP_N can be temporarily stored in the memory 2200, and the processor 2100 and the memory 2200 provide computing resources for the application programs APP_1 to APP_N. According to the actual operation conditions, the computing resources are allocated to the application programs APP_1 to APP_N. The computing resources include, for example: the usage and utilization rate of the processor 2100, and the usage, bandwidth and access efficiency of the memory 2200, and the bandwidth of the bus, and so on. Taking the application program APP_1 as an example, it uses the above computing resources for data processing. The definition of the data processing rate R1 of the application program APP_1 is the amount of data generated per unit time, which can also be referred to as the data throughput, data throughput (throughput) or network throughput in unit time. For example, the network throughput is the average amount of data successfully transmitted per unit time in a channel (including a physical link or a logical link), or the average amount of data passing through a certain network node. The unit of the above data throughput, data throughput or network throughput can be expressed as bits per second (bit / s or bps). The data processing rate R1 of the application program APP_1 is positively correlated with the proportion of the computing resources allocated to the application program APP_1 (or the utilization rate of the application program APP_1 for the computing resources). When the allocation proportion or utilization rate of the application program APP_1 for the computing resources is higher, the data processing rate R1 of the application program APP_1 is larger.
[0035] The anomaly detection device 1000 is used to detect anomalies in the usage status of each of the application programs APP_1 to APP_N for the computing resources. The anomaly status includes: one of the application programs APP_1 to APP_N fails to process and generate a predetermined amount of data within a predetermined time, or its data throughput, data throughput or network throughput is abnormal. In one example, the anomaly detection device 1000 can be a set of software programs installed on and executed on the computer system platform 2000. In another example, the anomaly detection device 1000 can be an independent hardware component in the computer system platform 2000, such as a microcontroller or an application specific integrated circuit (ASIC).
[0036] The following still takes the application APP_1 as an example for illustration. The anomalies in the usage status of the application APP_1 for computing resources may include a first anomaly status S_AB1 and a second anomaly status S_AB2. The first anomaly status S_AB1 indicates that the usage status of the application APP_1 for computing resources is a short-term or mild anomaly. For example, the utilization rate of the application APP_1 for computing resources does not reach the predetermined utilization rate in the short term. The second anomaly status S_AB2 indicates that the usage status of the application APP_1 for computing resources is a long-term or severe anomaly. For example, the utilization rate of the application APP_1 for computing resources is continuously lower than the predetermined utilization rate for a long time.
[0037] In one example, the anomaly detection device 1000 can determine whether the application APP_1 is in an abnormal state according to the current data processing rate R1 of the application APP_1. When the data processing rate R1 reaches the maximum processing rate R_max, it indicates that the application APP_1 is allocated sufficient computing resources (i.e., the utilization rate for computing resources reaches the predetermined utilization rate), and the anomaly detection device 1000 determines that the application APP_1 is in a normal state. On the contrary, when the data processing rate R1 does not reach the maximum processing rate R_max, it indicates that the application APP_1 does not obtain sufficient computing resources, and it is determined that the application APP_1 is in an abnormal state.
[0038] Please refer to Figure 2 , which shows the block diagram of the anomaly detection device 1000 and shows the operation of the anomaly detection device 1000. The anomaly detection device 1000 includes a data volume accumulation unit 100, a counting unit 200, a monitoring unit 300, and a warning unit 400, which are respectively software modules or hardware circuits inside the anomaly detection device 1000. For example, the data volume accumulation unit 100 is an embedded device, the counting unit 200 is a software counting program or a hardware digital counting circuit, and the counting unit 200 further includes an operation time counter 210 and an anomaly status counter 220. The monitoring unit 300 is a monitoring software or a hardware monitoring circuit. The warning unit 400 can be a hardware circuit that provides a sound signal or a light signal. The following describes the basic operation of the anomaly detection device 1000.
[0039] The data volume accumulation unit 100 is used to accumulate the first data volume D1 processed and generated by the application APP_1 using computing resources. If the application APP_1 takes the first operation time T1 to process and generate the first data volume D1, then the first data volume D1 is equal to the first operation time T1 multiplied by the data processing rate R1 of the application APP_1.
[0040] The monitoring unit 300 monitors the first data volume D1 of the application APP_1. When the first data volume D1 reaches a predetermined data volume, the monitoring unit 300 transmits a control signal RD1 to the operation time counter 210 to read the first count value CNT1 of the operation time counter 210. The first count value CNT1 is accumulated according to the first counting frequency F1 of the operation time counter 210, and the read first count value CNT1 is positively correlated with the first operation time T1. That is, the operation time counter 210 can be used to estimate the first operation time T1 of the application APP_I.
[0041] When the first data volume D1 reaches the predetermined data volume, the monitoring unit 300 determines whether the application APP_1 is in the first abnormal state S_AB1 according to the read first count value CNT1. When the application APP_1 is determined to be in the first abnormal state S_AB1, the monitoring unit 300 transmits a control signal RD2 to the abnormal state counter 220.
[0042] The second count value CNT2 of the abnormal state counter 220 is selectively accumulated according to the first abnormal state S_AB1. When the abnormal state counter 220 receives the control signal RD2, the second count value CNT2 is accumulated and the second count value CNT2 is read. In other words, the second count value CNT2 is equal to the occurrence times of the first abnormal state S_AB1 (that is, the number of times the application APP_1 is determined to be in the first abnormal state S_AB1). That is, the abnormal state counter 220 can be used to estimate the occurrence times of the first abnormal state S_AB1 of the application APP_1. And, the monitoring unit 300 determines whether the application APP_1 is in the second abnormal state S_AB2 according to the read second count value CNT2.
[0043] The warning unit 400 is used to selectively issue a warning signal WR. For example, when the monitoring unit 300 determines that the application APP_1 is in the second abnormal state S_AB2, the monitoring unit 300 transmits a control signal AB2_W to the warning unit 400, and the warning unit 400 issues a warning signal WR in response to the control signal AB2_W. The warning signal WR can be transmitted to the processor 2100 to prompt the processor 2100 to re-adjust the allocation of computing resources. The warning signal WR can also be a sound signal or a light signal to prompt the user 3000.
[0044] Figure 3 The flowchart showing an embodiment of the abnormal detection method of the present invention implements the abnormal detection method through the abnormal detection device 1000. Please also refer to Figure 2 and Figure 3, to illustrate the detailed operation of the anomaly detection device 1000. First, step S300 is executed: analyze the system state of the computer system platform 2000 through the anomaly detection device 1000, and determine whether the system state is the busy state S_BUSY. If it is not the busy state S_BUSY, return to step S300. If the anomaly detection device 1000 analyzes that the application APP_1 continuously receives / transmits a predetermined number (e.g., 30) of packets without interruption, it is determined that the system state is the busy state S_BUSY, and then step S302 is executed: accumulate the first data volume D1 that the application APP_1 has processed through the data volume accumulation unit 100. The first data volume D1 is related to the data processing rate R1 of the application APP_1 when the data processing rate R1 is relatively large, the first data volume D1 is relatively large.
[0045] Next, step S304 is executed: determine whether the first data volume D1 reaches the predetermined data volume D0 through the monitoring unit 300. The predetermined data volume D0 is related to the maximum processing rate R_max of the application APP_1. The monitoring unit 300 can set the predetermined data volume D0 according to the maximum processing rate R_max. For example, first calculate the quotient of the maximum processing rate R_max divided by the first counting frequency F1 of the operation time counter 210. This quotient is equal to the second data volume D2. And set the set normal proportion value N1 of the operation time counter 210. Furthermore, calculate the product of the second data volume D2 and the normal proportion value N1. This product is equal to the predetermined data volume D0, as shown in Equation (1).
[0046] D0 = D2 × N1 = (R_max / F1) × N1 (1)
[0047] In an example, taking the driver of the Ethernet communication device (Ethernet driver) as the application APP_1, the maximum processing rate R_max of the application APP_1 is, for example, 1000 Mbps. And the first counting frequency F1 of the operation time counter 210 is, for example, 100 Hz. When the normal proportion value N1 is set to "1", the predetermined data volume D0 is 10 Mb. The normal proportion value N1 can also be set to other positive integers, such as "2", "3",..., "10", etc. When the normal proportion value N1 is set to "5", the predetermined data volume D0 is 50 M.
[0048] If the judgment result of step S304 is that the first data volume D1 does not reach the predetermined data volume D0, return to step S302: continuously accumulate the first data volume D1 that the application APP_1 has processed. If the judgment result of step S304 is that the first data volume D1 has reached the predetermined data volume D0, execute step S306: read the first count value CNT1 of the operation time counter 210 through the monitoring unit 300.
[0049] Next, step S308 is executed: The monitoring unit 300 compares the read first count value CNT1 (the first count value CNT1 read when the first data volume D1 reaches the predetermined data volume D0) with the normal ratio value N1. If the first count value CNT1 is greater than the normal ratio value N1, it indicates that the first operation time T1 taken by the application APP_1 to process and generate the first data volume D1 exceeds the normal operation time T0 that should be in the normal state (that is, the first operation time T1 of the application APP_1 times out). The normal operation time T0 is the quotient obtained by dividing the normal ratio value N1 by the first counting frequency F1 of the operation time counter 210, as shown in Equation (2).
[0050] T0 = N1 / F1 (2)
[0051] In other words, by comparing whether the first count value CNT1 is greater than the normal ratio value N1, it is determined whether the first operation time T1 of the application APP_1 exceeds the normal operation time T0. When the first count value CNT1 is greater than the normal ratio value N1, it indicates that the application APP_1 fails to reach the maximum processing rate R_max, resulting in the timeout of the first operation time T1. The reason why the application APP_1 fails to reach the maximum processing rate R_max is that the utilization rate of the computing resources by the application APP_1 does not reach the predetermined utilization rate. Therefore, it is determined that the application APP_1 is in the first abnormal state S_AB1 (that is, it is determined that the usage state of the computing resources by the application APP_1 is a short-term abnormality or a mild abnormality).
[0052] If the first count value CNT1 is greater than the normal ratio value N1 in step S308, it is determined that the application APP_1 is in the first abnormal state S_AB1, and then step S314 is executed: increment the second count value CNT2 of the abnormal state counter 220. In other words, the second count value CNT2 is equal to the number of times the application APP_1 is determined to be in the first abnormal state S_AB1. Then, step S316 is executed: the monitoring unit 300 reads the second count value CNT2 of the abnormal state counter 220 and compares the second count value CNT2 with the threshold value AB1_TH. When the second count value CNT2 is greater than the threshold value AB1_TH, it indicates that the number of times the application APP_1 is determined to be in the first abnormal state S_AB1 is excessive, and the application APP_1 is no longer a short-term or mild abnormal, but a long-term or severe abnormal. Therefore, the monitoring unit 300 determines that the application APP_1 is in the second abnormal state S_AB2. Then, step S318 is executed: the warning unit 400 transmits a warning signal WR to the processor 2100 and / or the user 3000. After step S318, step S310 is executed: reset the second count value CNT2 of the abnormal state counter 220 to "0". And then, step S312 is executed: reset the first count value CNT1 of the operation time counter 210 to "0". Then, steps S300 to S316 are executed again, and the abnormal detection device 1000 re-detects whether the subsequent operation of the application APP_1 is abnormal.
[0053] On the other hand, in step S308, if the first count value CNT1 is less than or equal to the normal ratio value N1, it is determined that the application APP_1 is in a normal state, and then step S310 is executed: reset the second count value CNT2 of the abnormal state counter 220 to "0". Similarly, in step S316, if the second count value CNT2 is less than or equal to the threshold value AB1_TH, it indicates that the number of occurrences of the first abnormal state S_AB1 of the application APP_1 is still small and still belongs to a short-term or mild abnormal (or the application APP_1 is only in the first abnormal state S_AB1 for a short period but then returns to the normal state). Then, step S310 is executed: reset the second count value CNT2 of the abnormal state counter 220 to "0".
[0054] Figure 4 The flowchart of the abnormal detection method according to another embodiment of the present invention is shown. Please also refer to Figure 2 and Figure 4, first, step S400 is executed: The anomaly detection device 1000 sets the set normal ratio value N1 of the operation time counter 210, and sets the predetermined data volume D0 according to the maximum processing rate R_max of the application APP_1, the first counting frequency F1 of the operation time counter 210, and the normal ratio value N1 (see Equation (1)). For example, when the maximum processing rate R_max of the application APP_1 is 1000 Mbps, the first counting frequency F1 is 100 Hz, and the normal ratio value N1 is set to "1", the predetermined data volume D0 is set to 10 Mb.
[0055] Next, step S402 is executed: Determine whether the system state of the computer system platform 2000 is the busy state S_BUSY.
[0056] Next, step S404 is executed: Accumulate the first data volume D1 that the application APP_1 has processed, and determine whether the first data volume D1 has reached the predetermined data volume D0. If the predetermined data volume D0 has been reached, estimate the first operation time T1 taken by the application APP_1 to reach the predetermined data volume D0, and determine whether the first operation time T1 exceeds the normal operation time T0 (that is, whether the application APP_1 times out). If the first operation time T1 exceeds the normal operation time T0, it is determined that the application APP_1 is in the first abnormal state S_AB1.
[0057] Next, step S406 is executed: Estimate the number of times the first operation time T1 exceeds the normal operation time T0. For example, the second count value CNT2 of the anomaly state counter 220 represents the number of times the first operation time T1 exceeds the normal operation time T0. And determine whether the second count value CNT2 is greater than the threshold value AB1_TH. If the second count value CNT2 is greater than the threshold value AB1_TH, it is determined that the application APP_1 is in the second abnormal state S_AB2, and then step S408 is executed.
[0058] In step S408, the warning unit 400 issues a warning signal WR to the processor 2100 or the user 3000. In response to the warning signal WR, the processor 2100 executes a congestion control mechanism to adjust the allocation of computing resources so that the application APP_1 can obtain sufficient computing resources. For different types of applications APP_1, different congestion control mechanisms can be adopted, for example: a congestion control mechanism adapted to the communication transmission protocol.
[0059] In Figure 3 and Figure 4Among the anomaly detection methods, the value of the threshold AB1_TH can be adjusted according to different application scenarios or different operating conditions. For example, when the application APP_1 is operating in a large amount of data transmission (such as FTP transmission) or transmitting high-volume information for a long time, the threshold AB1_TH is adjusted to a larger value. When the application APP_1 is operating in a short-time transmission of low-volume information (such as a voice call), the threshold AB1_TH is adjusted to a smaller value.
[0060] In addition, the value of the threshold AB1_TH can also be adjusted according to the update frequency F_S of the system state of the computer system platform 2000. The threshold AB1_TH can be adjusted to be greater than the number of times corresponding to the update frequency F_S. For example, if the update frequency F_S is 10 Hz, the threshold AB1_TH is adjusted to "11". In one example, when the system state of the computer system platform 2000 switches to the low-data volume state (lightly state) S_LIGHT, the data throughput of the computer system platform 2000 naturally decreases as a whole due to the low-data volume state S_LIGHT, resulting in a natural decrease in the data volume generated by the application APP_1. That is, in the low-data volume state S_LIGHT, the decrease in the data volume of the application APP_1 is not an abnormal state. Therefore, the value of the threshold ABl_TH can be increased so that when transitioning to the low-data volume state S_LIGHT, the second count value CNT2 does not exceed the threshold AB1_TH, and the application APP_1 is not judged to be in the second abnormal state S_AB2. And when the computer system platform 2000 switches from the busy state S_BUSY to the low-data volume state S_LIGHT, the second count value CNT2 is reset to "0".
[0061] In summary, the anomaly detection device 1000 and the anomaly detection method of the present invention can be applied to a low-earth orbit satellite communication system (LEO) to effectively detect short-term and long-term anomalies of the software of the satellite device, and avoid the software being misjudged as abnormal, resulting in frequent resetting of the satellite device and interruption of communication. Alternatively, the anomaly detection device 1000 can be applied to an embedded communication network system, such as the core network server of 4G LTE or 5G NR, to detect anomalies in the software of the network server, and avoid the software being misjudged as abnormal, resulting in frequent resetting of the network server in the telecommunications computer room and affecting the communication efficiency.
[0062] In a comparative example, it is based on "Rule-base" to detect whether an application is abnormal through logical inference, established rules, and by incorporating environmental variables. The operation behavior of the application (including the computing resources and operation time required for operation) is detected and judged inferentially. If the operation behavior conforms to the inference rules, the application is judged to be normal. However, the abnormal detection mechanism of the above comparative example has the following disadvantages: it is difficult to handle the operation behaviors of applications with a large range, high complexity, high dimension, and non-structuredness.
[0063] Moreover, in another comparative example, a watchdog timer (WDT) is set to detect abnormalities. However, in a system platform, at most two hardware watchdog timers can be set in hardware form. The small number of hardware watchdog timers cannot detect multiple software drivers or applications simultaneously. Even if a software watchdog timer can be adopted, however, it can only set a single timing limit, cannot accumulate abnormal states multiple times, and is also difficult to detect short-term abnormalities between a predetermined period and a timing cycle.
[0064] Compared with the above two comparative examples, the abnormal detection device 1000 and the abnormal detection method of the present invention can simply and effectively detect the abnormal states of applications APP_1 to APP_N in the busy state S_BUSY of the computer system platform 2000. Moreover, it can detect the first abnormal state S_AB1 (i.e., short-term abnormality) of applications APP_1 to APP_N before the watchdog timer is triggered, and can avoid the operation interruption caused by the frequent reset of the computer system platform 2000.
[0065] Although the present invention has been disclosed in detail above with preferred embodiments and examples, it can be understood that these examples are illustrative rather than restrictive. It is expected that those skilled in the art can think of various modifications and combinations, and various modifications and combinations fall within the spirit of the present invention and the scope of the appended patent application.
Claims
1. An abnormality detection device, characterized in that: Used to detect an abnormality in the usage status of computing resources by an application program, wherein the abnormality in the usage status includes a first abnormal state and a second abnormal state, the abnormality detection device includes: A data volume accumulation unit, used for accumulating a first data volume processed by the application program; An operation time counter having a first count value and accumulating the first count value according to a first count frequency; an abnormal state counter having a second count value and selectively accumulating the second count value according to the first abnormal state; and Monitoring unit, used to perform the following operations: monitoring whether the first data volume reaches a predetermined data volume, wherein the predetermined data volume is related to a maximum processing rate of the application; When the first data amount reaches the predetermined data amount, reading the first count value, and determining whether the application is in the first abnormal state according to the first count value; and When it is determined that the application is in the first abnormal state, the second count value is accumulated and read, and whether the application is in the second abnormal state is determined according to the second count value.
2. The abnormality detection device according to claim 1, characterized in that: The first abnormal state indicates a short-term abnormality or a mild abnormality of the use state, and the second abnormal state indicates a long-term abnormality or a severe abnormality of the use state.
3. The abnormality detection device according to claim 1, wherein: The monitoring unit sets a normal ratio value of the operation time counter; When the first data amount reaches the predetermined data amount, the monitoring unit compares the first count value with the normal ratio value; as well as When the first count value is greater than the normal ratio value, the monitoring unit determines that the application is in the first abnormal state.
4. The abnormality detection device according to claim 3, characterized in that: When the first count value is less than or equal to the normal ratio value, the application reaches the maximum processing rate, and the monitoring unit determines that the application is in a normal state.
5. The abnormality detection device according to claim 3, characterized in that: The predetermined data amount is equal to the maximum processing rate divided by the first counting frequency multiplied by the normal ratio value.
6. The abnormality detection device according to claim 5, characterized in that: The monitoring unit estimates the maximum processing rate according to statistical data of the application.
7. The abnormality detection device according to claim 3, characterized in that: The monitoring unit sets a threshold value of the abnormal state counter; When the first data amount reaches the predetermined data amount and the first count value is greater than the normal ratio value, the monitoring unit accumulates the second count value and compares the second count value with the threshold value; and When the second count value is greater than the threshold value, the monitoring unit determines that the application is in the second abnormal state.
8. The abnormality detection device according to claim 7, characterized in that: Also includes: The warning device is used to issue a warning when the second count value is greater than the threshold value.
9. The abnormality detection device according to claim 7, characterized in that: The application runs on a system platform having a system state. When the system state is a busy state, the monitoring unit determines whether the application is in the first abnormal state or the second abnormal state based on the first data volume, the first count value and the second count value.
10. The abnormality detection device according to claim 9, characterized in that: The system state has an update frequency, and the threshold is set to be greater than the number of times corresponding to the update frequency.
11. An abnormality detection method, characterized in that: The method is used to detect an abnormality in the usage status of computing resources by an application program, wherein the abnormality in the usage status includes a first abnormality status and a second abnormality status. The abnormality detection method includes the following steps: accumulating, by a data amount accumulating unit, a first data amount processed by the application program; Accumulating a first count value according to a first count frequency by operating a time counter; selectively accumulating a second count value according to the first abnormal state through the abnormal state counter; and The following operations are performed by the monitoring unit: monitoring whether the first data volume reaches a predetermined data volume, wherein the predetermined data volume is related to a maximum processing rate of the application; When the first data amount reaches the predetermined data amount, reading the first count value, and determining whether the application is in the first abnormal state according to the first count value; and When it is determined that the application is in the first abnormal state, the second count value is accumulated and read, and whether the application is in the second abnormal state is determined according to the second count value.
12. The abnormality detection method according to claim 11, characterized in that: The first abnormal state indicates a short-term abnormality or a mild abnormality of the use state, and the second abnormal state indicates a long-term abnormality or a severe abnormality of the use state.
13. The abnormality detection method according to claim 11, characterized in that: The step of determining whether the application is in the first abnormal state according to the first count value includes: Setting a normal ratio value of the operation time counter by the monitoring unit; When the first data amount reaches the predetermined data amount, comparing the first count value with the normal ratio value through the monitoring unit; and When the first count value is greater than the normal ratio value, the monitoring unit determines that the application is in the first abnormal state.
14. The abnormality detection method according to claim 13, characterized in that: When the first count value is less than or equal to the normal ratio value, the application reaches the maximum processing rate, and the monitoring unit determines that the application is in a normal state.
15. The abnormality detection method according to claim 13, characterized in that: The predetermined data amount is equal to the maximum processing rate divided by the first counting frequency multiplied by the normal ratio value.
16. The abnormality detection method according to claim 15, characterized in that: The monitoring unit estimates the maximum processing rate according to statistical data of the application.
17. The abnormality detection method according to claim 13, characterized in that: The step of determining whether the application is in the second abnormal state according to the second count value: Setting a threshold of the abnormal state counter by the monitoring unit; When the first data amount reaches the predetermined data amount and the first count value is greater than the normal ratio value, the monitoring unit accumulates the second count value and compares the second count value with the threshold value; and When the second count value is greater than the threshold value, the monitoring unit determines that the application is in the second abnormal state.
18. The abnormality detection method according to claim 17, characterized in that: Also includes: When the second count value is greater than the threshold value, a warning is issued through the warning device.
19. The abnormality detection method according to claim 17, wherein: The application runs on a system platform having a system state. When the system state is a busy state, the monitoring unit determines whether the application is in the first abnormal state or the second abnormal state according to the first data volume, the first count value and the second count value.
20. The abnormality detection method according to claim 19, characterized in that: The system state has an update frequency, and the threshold is set to be greater than the number of times corresponding to the update frequency.