Abnormal transaction link identification method and device
By acquiring and grouping transaction details, performing string line calculations and node judgments, the problem of the existing technology being unable to identify abnormal transaction links is solved, and rapid and accurate identification and investigation are achieved, and emergency response efficiency is improved.
Patent Information
- Application Number
- CN202510187776.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-06-13
AI Technical Summary
The prior art cannot identify exception links through the call relationship between transactions, and lacks a clear exception link definition, resulting in the inability to exclude interfering information such as unrelated service failures.
By obtaining transaction details, grouping to form transaction lines, performing string calculations to obtain transaction links, traversing nodes to judge response time and trading system status, marking long trading nodes and trading system failure nodes, and determining abnormal trading links.
It realizes the rapid and accurate identification of abnormal transaction links, thereby narrowing the scope of investigation and improving the efficiency of production emergency response.
Smart Images

Figure CN120144418A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of big data, and in particular, to a method and device for identifying an abnormal transaction link. Background Art
[0002] This section aims to provide background or context for the embodiments of the present invention described in the claims. The description herein is not admitted to be prior art merely because it is included in this section.
[0003] A business, that is, a transaction, is actually composed of a series of transactions. For example: Business 1: A->B->C->D; Business 2: E->F->C->G->H; Currently, it is already possible to calculate the path information of a transaction through transaction logs, but there are still two drawbacks in the prior art. One is that it is impossible to identify abnormal links through the call relationship between transactions; the other is that there is no clear definition of abnormal links to exclude interference information such as unrelated business failures.
[0004] Therefore, there is an urgent need for a method to quickly and accurately identify abnormal transaction links. Summary of the Invention
[0005] Embodiments of the present invention provide a method for identifying an abnormal transaction link to quickly and accurately identify an abnormal transaction link; the method for identifying an abnormal transaction link includes:
[0006] Obtain transaction detail data; group the transaction detail data according to the attributes of the transaction detail data, and determine each group of transaction detail data as a transaction line;
[0007] According to the transaction detail data, perform stringing calculation on the transaction detail data in the transaction line to obtain the transaction link of each transaction line; the transaction link includes multiple nodes, and each node is a piece of transaction detail data;
[0008] Traverse the nodes in the transaction link, judge the response duration of each node according to a preset response duration threshold, and mark the nodes with a response duration exceeding the preset response duration threshold as long transaction nodes;
[0009] Traverse the nodes in the transaction link, judge the transaction system status of each node, and mark the nodes with a transaction system status of transaction failure as transaction system failure nodes;
[0010] Determine the transaction link where the long transaction node or the transaction system failure node is located as an abnormal transaction link.
[0011] Embodiments of the present invention also provide a device for identifying an abnormal transaction link to quickly and accurately identify an abnormal transaction link; the device for identifying an abnormal transaction link includes:
[0012] A grouping module, configured to obtain transaction detail data; group the transaction detail data according to the attributes of the transaction detail data, and determine each group of transaction detail data as a transaction line;
[0013] A transaction link determination module, configured to perform stringing calculation on the transaction detail data in the transaction line according to the transaction detail data, and obtain the transaction link of each transaction line; the transaction link includes multiple nodes, and each node is a piece of transaction detail data;
[0014] A long transaction judgment module, configured to traverse the nodes in the transaction link, judge the response duration of each node according to a preset response duration threshold, and mark the node whose response duration exceeds the preset response duration threshold as a long transaction node;
[0015] A system failure judgment module, configured to traverse the nodes in the transaction link, judge the transaction system status of each node, and mark the node whose transaction system status is transaction failure as a transaction system failure node;
[0016] An abnormal link determination module, configured to determine the transaction link where the long transaction node or the transaction system failure node is located as an abnormal transaction link.
[0017] An embodiment of the present invention further provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the above-mentioned method for identifying an abnormal transaction link is implemented.
[0018] An embodiment of the present invention further provides a computer-readable storage medium, where the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned method for identifying an abnormal transaction link is implemented.
[0019] An embodiment of the present invention further provides a computer program product, where the computer program product includes a computer program, and when the computer program is executed by a processor, the above-mentioned method for identifying an abnormal transaction link is implemented.
[0020] In an embodiment of the present invention, transaction detail data is obtained; the transaction detail data is grouped according to the attributes of the transaction detail data, and each group of transaction detail data is determined as a transaction line; according to the transaction detail data, stringing calculation is performed on the transaction detail data in the transaction line to obtain the transaction link of each transaction line; the nodes in the transaction link are traversed, and according to a preset response duration threshold, the response duration of each node is judged, and the node whose response duration exceeds the preset response duration threshold is marked as a long transaction node; the nodes in the transaction link are traversed, and the transaction system status of each node is judged, and the node whose transaction system status is transaction failure is marked as a transaction system failure node; the transaction link where the long transaction node or the transaction system failure node is located is determined as an abnormal transaction link; the embodiment of the present invention can quickly and accurately identify abnormal transaction links from a large amount of data, and provide help for production operation and maintenance; during the emergency process, abnormal transaction links can be identified from numerous real-time transaction links to narrow the investigation scope and improve the efficiency of production emergency handling. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to these drawings. In the drawings:
[0022] Figure 1 It is a schematic diagram of an example method for identifying an abnormal transaction link in an embodiment of the present invention;
[0023] Figure 2 It is a specific example diagram for obtaining transaction detail data in an embodiment of the present invention;
[0024] Figure 3 It is a specific example diagram for performing stringing calculation on the transaction detail data in a transaction line in an embodiment of the present invention;
[0025] Figure 4 It is a specific example diagram of a stringing calculation process in an embodiment of the present invention;
[0026] Figure 5 It is a schematic diagram of the structure of an apparatus for identifying an abnormal transaction link in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0027] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0028] The inventor's research found that in the prior art, it is impossible to identify abnormal links through the call relationships between transactions. For example, when identifying many abnormal nodes, it is impossible to know the call relationships between these abnormal nodes; nor is there a clear definition of abnormal links to exclude interference information such as unrelated business failures. As a result, technicians are unable to narrow down the scope of investigation of abnormal transaction links, reducing the efficiency of production emergency handling.
[0029] In view of the defects existing in the prior art, the inventor proposed the above-mentioned abnormal transaction link identification method, aiming to solve the problem of how to quickly identify the abnormal upstream and downstream of a certain transaction system from numerous alarms, that is, the abnormal upstream and downstream transaction links of a certain node.
[0030] Figure 1 It is an example diagram of the method for identifying abnormal transaction links in the embodiments of the present invention; as Figure 1 shown, the method includes:
[0031] Step 101: Obtain transaction detail data; group the transaction detail data according to the attributes of the transaction detail data, and determine each group of transaction detail data as a transaction line;
[0032] Step 102: According to the transaction detail data, perform stringing calculation on the transaction detail data in the transaction line to obtain the transaction link of each transaction line; the transaction link includes multiple nodes, and each node is a piece of transaction detail data;
[0033] Step 103: Traverse the nodes in the transaction link, judge the response duration of each node according to the preset response duration threshold, and mark the nodes with a response duration exceeding the preset response duration threshold as long transaction nodes;
[0034] Step 104: Traverse the nodes in the transaction link, judge the transaction system status of each node, and mark the nodes with the transaction system status of transaction failure as transaction system failure nodes;
[0035] Step 105: Determine the transaction link where the long transaction node or the transaction system failure node is located as an abnormal transaction link.
[0036] In the embodiment, obtaining the transaction detail data may include: obtaining the transaction detail data through a data collection engine; the transaction detail data is stored in a distributed data stream processing platform in real time.
[0037] For example, Figure 2 FIG. is a specific example diagram for obtaining transaction detail data in an embodiment of the present invention. As Figure 2 shown, in the process of obtaining transaction detail data: the upstream transaction system first writes the transaction detail data into the distributed data stream processing platform; when it is necessary to obtain the transaction detail data, the downstream transaction system can obtain the transaction detail data through the data collection engine.
[0038] In the embodiment, the attributes of the transaction detail data include a global tracking number;
[0039] Grouping the transaction detail data according to the attributes of the transaction detail data, and determining each group of transaction detail data as a transaction line may include: grouping the transaction detail data according to the global tracking number of the transaction detail data, and determining each group of transaction detail data as a transaction line.
[0040] In specific implementation, each transaction detail data will have an attribute: global tracking number. Different transaction detail data are grouped according to the global tracking number "glb", so that each group of transaction details can be determined as a transaction line.
[0041] In the embodiment, according to the transaction detail data, threading calculation is performed on the transaction detail data in the transaction line to obtain the transaction link of each transaction line, which may include: obtaining the recipient node number, recipient service code, and sender node number of the transaction detail data from the transaction log corresponding to the transaction detail data; performing threading calculation on the transaction detail data in the transaction line according to the recipient node number, recipient service code, and sender node number of the transaction detail data to obtain the transaction link of each transaction line.
[0042] In the embodiment, performing threading calculation on the transaction detail data in the transaction line according to the recipient node number, recipient service code, and sender node number of the transaction detail data to obtain the transaction link of each transaction line may include:
[0043] Performing threading calculation in the following manner: the recipient node number of the upstream transaction system is the same as the node number of the downstream transaction system, and the recipient service code of the upstream transaction system is the same as the service code of the downstream transaction system; the sender node number of the downstream transaction system is the same as the node number of the upstream transaction system.
[0044] For example, string calculation is performed according to the node numbers of each node on the global tracking number of transaction detail data. The application system will output the receiving node number (rcvnd), receiving service code (rcvtc), and sending node number (sndnd) of the transaction detail data in the transaction log. The architecture view implements transaction line calculation based on this information, that is, the receiving node number of the upstream transaction system is the same as the node number of the downstream transaction system, the receiving service code of the upstream transaction system is the same as the service code of the downstream transaction system, and the sending node number of the downstream transaction system is the same as the node number of the upstream transaction system.
[0045] During specific implementation, Figure 3 This is a specific example diagram for string calculation of transaction detail data in the transaction line in the embodiment of the present invention. As Figure 3 shown, the node number 101001 of the upstream transaction system A is the same as the sending node number 101001 of the downstream transaction system B; the receiving node number 108046 of the upstream transaction system A is the same as the node number 108046 of the downstream transaction system B; the receiving service code 100800010 of the upstream transaction system A is the same as the service code 100800010 of the downstream transaction system B; after confirming that the matching results are the same, one string calculation is completed.
[0046] Next, an example is given to illustrate the complete string calculation process; Figure 4 This is a specific example diagram for the string calculation process in the embodiment of the present invention. As Figure 4 shown, the complete string calculation process is as follows:
[0047] a. Obtain the transaction detail data in the distributed data stream processing platform;
[0048] b. Group the transaction detail data according to the global tracking number to obtain the transaction line;
[0049] c. Traverse the transaction detail data in the transaction line to determine the initiator node list and other node lists;
[0050] d. Sort the initiator node list according to the start time;
[0051] e. Traverse the initiator node list to determine the first node A for string calculation;
[0052] f. Query the other node lists according to the receiving node information of A. If no node is found, supplement the node;
[0053] g. Continue to determine the next receiving node according to the node information of the child node of A, and connect the string calculation result to the string path;
[0054] h. Determine whether the list of other nodes is empty. If it is not empty, take the node with the smallest start time in the list of other nodes as the head node and execute step f. If it is empty, output the final cross-connection result.
[0055] In specific implementation, for long transaction judgment: traverse the transaction detail nodes to check if there are long transactions. The specific process is as follows:
[0056] First, determine whether the first node is a long transaction node. If it is, mark the transaction link where this node is located as an abnormal transaction link. If not, determine whether the parent node of this node is a long transaction node. If it is, mark the transaction link where this node is located as an abnormal transaction link. Taking the A-B segment of the link as an example, there are three abnormal states of the transaction link:
[0057] A is normal, B is a long transaction;
[0058] A is a long transaction, B is a long transaction;
[0059] A is a long transaction, B is normal;
[0060] In specific implementation, for system failure judgment: traverse the detail nodes to check if there are system failure transactions. The specific process is as follows:
[0061] First, determine whether the system status of the first node is a system failure. If it is, mark the transaction link where this node is located as an abnormal transaction link. If not, determine whether the system status of the parent node of this node is a system failure. If it is, mark the transaction link where this node is located as an abnormal transaction link. Taking the A-B segment of the link as an example, there are three abnormal states of the transaction link:
[0062] A is normal, B is a failed transaction;
[0063] A is a failed transaction, B is a failed transaction;
[0064] A is a failed transaction, B is normal;
[0065] In the embodiments of the present invention, an identification device for abnormal transaction links is also provided, as described in the following embodiments. Since the principle of the device for solving problems is similar to that of the identification method for abnormal transaction links, the implementation of the device can refer to the implementation of the identification method for abnormal transaction links, and the repeated parts will not be elaborated.
[0066] Figure 5 It is a structural example diagram of the identification device for abnormal transaction links in the embodiments of the present invention, as Figure 5 shown. The device includes:
[0067] A grouping module 501, configured to obtain transaction detail data; group the transaction detail data according to the attributes of the transaction detail data, and determine each group of transaction detail data as a transaction line;
[0068] A transaction link determination module 502, configured to perform threading calculation on the transaction detail data in the transaction line according to the transaction detail data, so as to obtain the transaction link of each transaction line; the transaction link includes multiple nodes, and each node is a piece of transaction detail data;
[0069] A long transaction judgment module 503, configured to traverse the nodes in the transaction link, perform response duration judgment on each node according to a preset response duration threshold, and mark the nodes with a response duration exceeding the preset response duration threshold as long transaction nodes;
[0070] A system failure judgment module 504, configured to traverse the nodes in the transaction link, perform transaction system status judgment on each node, and mark the nodes with the transaction system status of transaction failure as transaction system failure nodes;
[0071] An abnormal link determination module 505, configured to determine the transaction link where the long transaction node or the transaction system failure node is located as an abnormal transaction link.
[0072] In one embodiment, a grouping module 501 is specifically configured to obtain transaction detail data through a data collection engine; the transaction detail data is stored in a distributed data stream processing platform in real time.
[0073] In one embodiment, the attributes of the transaction detail data include a global tracking number. The grouping module 501 is specifically configured to group the transaction detail data according to the global tracking number of the transaction detail data, and determine each group of transaction detail data as a transaction line.
[0074] In one embodiment, the transaction link determination module 502 is specifically configured to obtain the recipient node number, recipient service code, and sender node number of the transaction detail data from the transaction log corresponding to the transaction detail data; according to the recipient node number, recipient service code, and sender node number of the transaction detail data, perform threading calculation on the transaction detail data in the transaction line, so as to obtain the transaction link of each transaction line.
[0075] In one embodiment, the transaction link determination module 502 is specifically configured to perform threading calculation in the following manner: the recipient node number of the upstream transaction system is the same as the node number of the downstream transaction system, and the recipient service code of the upstream transaction system is the same as the service code of the downstream transaction system; the sender node number of the downstream transaction system is the same as the node number of the upstream transaction system.
[0076] An embodiment of the present invention further provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the above-mentioned method for identifying an abnormal transaction link is implemented.
[0077] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the above-mentioned method for identifying an abnormal transaction link is implemented.
[0078] An embodiment of the present invention further provides a computer program product including a computer program, and when the computer program is executed by a processor, the above-mentioned method for identifying an abnormal transaction link is implemented.
[0079] In an embodiment of the present invention, transaction detail data is obtained; the transaction detail data is grouped according to the attributes of the transaction detail data, and each group of transaction detail data is determined as a transaction line; according to the transaction detail data, stringing calculation is performed on the transaction detail data in the transaction line to obtain the transaction link of each transaction line; the nodes in the transaction link are traversed, and the response duration of each node is judged according to a preset response duration threshold, and the nodes with a response duration exceeding the preset response duration threshold are marked as long transaction nodes; the nodes in the transaction link are traversed, and the transaction system status of each node is judged, and the nodes with the transaction system status of transaction failure are marked as transaction system failure nodes; the transaction link where the long transaction node or the transaction system failure node is located is determined as an abnormal transaction link; the embodiment of the present invention can quickly and accurately identify abnormal transaction links from a large amount of data, providing help for production operation and maintenance; during the emergency process, it can identify abnormal transaction links from numerous real-time transaction links to narrow the troubleshooting scope and improve the efficiency of production emergency handling.
[0080] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0081] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the flows or multiple flows and / or blocks Figure 1 one or more of the blocks or multiple blocks.
[0082] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to work in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction device that implements the functions specified in one or more of the processes Figure 1 or steps and / or Figure 1 boxes or a plurality of boxes.
[0083] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, such that a series of operational steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one or more of the processes Figure 1 or steps and / or Figure 1 boxes or a plurality of boxes.
[0084] The specific embodiments described above further elaborate on the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A method for identifying abnormal transaction links, characterized in that: include: Get transaction details data; The transaction detail data are grouped according to the attributes of the transaction detail data, and each group of transaction detail data is determined as a transaction line; According to the transaction detail data, the transaction detail data in the transaction line is subjected to a string calculation to obtain a transaction link of each transaction line; the transaction link includes a plurality of nodes, each node being a piece of transaction detail data; Traverse the nodes in the transaction link, judge the response time of each node according to the preset response time threshold, and mark the node whose response time exceeds the preset response time threshold as a long transaction node; Traverse the nodes in the transaction link, determine the transaction system status of each node, and mark the node with transaction failure status as a transaction system failure node; The transaction link where the long transaction node or the transaction system failure node is located is determined as an abnormal transaction link.
2. The method according to claim 1, characterized in that Get transaction details, including: Transaction detail data is acquired through a data collection engine; the transaction detail data is stored in a distributed data stream processing platform in real time.
3. The method according to claim 1, characterized in that The attributes of the transaction detail data include a global tracking number; The transaction detail data are grouped according to their attributes, and each group of transaction detail data is determined as a transaction line, including: The transaction detail data are grouped according to their global tracking numbers, and each group of transaction detail data is identified as a transaction line.
4. The method according to claim 1, characterized in that According to the transaction details data, the transaction details in the transaction line are calculated in series to obtain the transaction link of each transaction line, including: Obtain the receiver node number, receiver service code and sender node number of the transaction details data from the transaction log corresponding to the transaction details data; According to the receiver node number, receiver service code and sender node number of the transaction detail data, the transaction detail data in the transaction line is subjected to string calculation to obtain the transaction link of each transaction line.
5. The method according to claim 4, characterized in that According to the receiver node number, receiver service code and sender node number of the transaction detail data, the transaction detail data in the transaction line is subjected to string calculation to obtain the transaction link of each transaction line, including: The string calculation is performed as follows: The receiver node number of the upstream transaction system is consistent with the node number of the downstream transaction system, the receiver service code of the upstream transaction system is consistent with the service code of the downstream transaction system; the sender node number of the downstream transaction system is consistent with the node number of the upstream transaction system.
6. A device for identifying abnormal transaction links, characterized in that: include: Grouping module, used to obtain transaction details data; The transaction detail data are grouped according to the attributes of the transaction detail data, and each group of transaction detail data is determined as a transaction line; A transaction link determination module is used to perform a string calculation on the transaction detail data in the transaction line according to the transaction detail data to obtain a transaction link for each transaction line; the transaction link includes a plurality of nodes, each node being a piece of transaction detail data; A long transaction judgment module is used to traverse the nodes in the transaction link, judge the response time of each node according to a preset response time threshold, and mark the node whose response time exceeds the preset response time threshold as a long transaction node; The system failure judgment module is used to traverse the nodes in the transaction link, judge the transaction system status of each node, and mark the node whose transaction system status is transaction failure as a transaction system failure node; The abnormal link determination module is used to determine the transaction link where the long transaction node or the transaction system failure node is located as an abnormal transaction link.
7. The device according to claim 6, characterized in that The transaction link determination module is specifically used for: Obtain the receiver node number, receiver service code and sender node number of the transaction details data from the transaction log corresponding to the transaction details data; According to the receiver node number, receiver service code and sender node number of the transaction detail data, the transaction detail data in the transaction line is subjected to string calculation to obtain the transaction link of each transaction line.
8. The device according to claim 7, characterized in that The transaction link determination module is specifically used for: The string calculation is performed as follows: The receiver node number of the upstream trading system is consistent with the node number of the downstream trading system, and the receiver service code of the upstream trading system is consistent with the service code of the downstream trading system; The sender node number of the downstream transaction system is consistent with the node number of the upstream transaction system.
9. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 5 is implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.
11. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.