Computer system risk monitoring method and system based on digital twinning
Through the computer system risk monitoring method based on digital twins, the problem of insufficient real-time and dynamic processing capabilities in the existing technology is solved, more refined data monitoring and more accurate risk assessment are achieved, and dynamic tracking and real-time monitoring capabilities of computer system risks are improved.
Patent Information
- Application Number
- CN202510134651.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-02-07
AI Technical Summary
The prior art has insufficient real-time and dynamic processing capabilities in computer system risk monitoring, and cannot flexibly adapt to dynamic changes in the operating environment, resulting in lag or missed judgments when handling malicious behaviors or abnormal traffic.
The computer system risk monitoring method based on digital twins is adopted to build a digital twin model by collecting real-time running data, calculating the difference values and analyzing the change trends, and generating a sequence of digital twin state changes trends, thereby identifying abnormal interval segments and counting multi-dimensional parameters, predicting future state trends, evaluating risks and generating dynamic weight risk parameter paths.
It improves the dynamicity and accuracy of data monitoring, can capture the complex changing characteristics of multi-dimensional data more quickly, improves the real-time monitoring capabilities of malicious behavior and abnormal traffic, and ensures the accuracy and comprehensiveness of risk assessment.
Smart Images

Figure CN120150984A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a method and system for monitoring computer system risks based on digital twins. Background Art
[0002] The field of network security technology includes related technical contents for protecting, monitoring, and managing computer networks and systems. The core of this technical field lies in ensuring the confidentiality, integrity, and availability of information and systems, and its coverage includes, but is not limited to, network attack detection, intrusion prevention, data encryption, access control, and system vulnerability repair, etc.
[0003] Among them, the computer system risk monitoring method refers to a method for identifying, analyzing, and monitoring the risks that a computer system may face during operation. Specifically, for risk sources including abnormal network traffic, malicious attack behaviors, and system vulnerabilities, a security monitoring mechanism based on specific rule matching is adopted, combined with historical data analysis methods, to construct a risk determination model to monitor and classify potential threats during the operation of the system. At the same time, by collecting system operation logs and multi-dimensional data, optimized risk assessment means are used to accurately locate abnormal behaviors to achieve dynamic tracking and real-time monitoring of risks.
[0004] The existing technologies have deficiencies in the processing capabilities of real-time and dynamics during data monitoring. The traditional security monitoring mechanism based on rule matching is easily limited to the preset rule scope and cannot flexibly adapt to the dynamic changes of the operating environment. The methods for identifying and analyzing abnormal data relatively rely on fixed patterns and are difficult to quickly capture the complex change characteristics of multi-dimensional data, resulting in possible lags or missed judgments when dealing with malicious behaviors or abnormal traffic. Historical data analysis mostly focuses on static characteristics and lacks in-depth exploration of the dynamic evolution law of data states, which easily leads to insufficient accuracy in future risk prediction. In addition, risk assessment methods are mostly based on single weights or static distributions, paying less attention to the mutual associations and propagation mechanisms between key nodes, which limits the comprehensiveness of the overall risk path analysis of the system. Summary of the Invention
[0005] The purpose of the present invention is to solve the deficiencies existing in the prior art, and to propose a method and system for monitoring computer system risks based on digital twins.
[0006] To achieve the above purpose, the present invention adopts the following technical solutions: A method for monitoring computer system risks based on digital twins, including the following steps:
[0007] S1: Collect real-time operation data of the computer system, construct a digital twin model according to the operation data, calculate the difference value of each type of operation data, analyze the change trend of the operation data with reference to the difference value, and generate a digital twin state change trend sequence according to the change trend;
[0008] S2: Divide the digital twin state change trend sequence into multiple interval segments according to a fixed time, screen out the abnormal interval segments of the corresponding operation data from each interval segment, and count the fluctuation amplitude of the hard disk read / write rate, the change rate of the memory occupancy rate, and the abnormal fluctuation parameters of the network traffic in the abnormal interval segments to generate a computer system abnormal parameter set;
[0009] S3: Collect the state transition records of the operation data, identify the state transition patterns corresponding to the target abnormal parameters, extract the transition nodes of the abnormal parameters in the records and the associated operation data characteristics, calculate the transition probability of the target abnormal parameters in the computer system abnormal parameter set, and predict the future state trend of the operation data according to the transition probability to generate an abnormal transition state prediction result;
[0010] S4: Evaluate the probability of entering the abnormal state within the corresponding time period according to the abnormal transition state prediction result, assign weights to the corresponding operation data according to the probability of the abnormal state, extract the abnormal state paths corresponding to the key nodes, evaluate the weight distribution of the key nodes in each path, screen and sort the key node paths according to the weight distribution, and generate a dynamic weight risk parameter path according to the sorted list;
[0011] S5: Analyze the interaction frequency of each key node path in the dynamic weight risk parameter path, analyze the correlation between the key node paths according to the interaction frequency, construct the propagation path between the key node paths with reference to the correlation information, and generate a computer system risk monitoring result according to the propagation path.
[0012] The improvements of the present invention are that the digital twin state change trend sequence is a change mode of a difference value curve and the time series characteristics of the operation data fluctuation, the computer system abnormal parameter set includes the fluctuation amplitude of the hard disk read / write rate, the change rate of the memory occupancy rate, and the abnormal fluctuation parameters of the network traffic, the abnormal transition state prediction result includes the transition nodes of the target abnormal parameters, the operation data characteristics, and the transition probability prediction result, the dynamic weight risk parameter path includes the weight distribution of the key node paths and the sorting of the key node paths, and the computer system risk monitoring result includes the interaction frequency of the key node paths, the correlation between the key node paths, and the propagation path of the key node paths.
[0013] The improvements of the present invention are that the specific steps of collecting the real-time operation data of the computer system, constructing a digital twin model according to the operation data, calculating the difference value of each type of operation data, analyzing the change trend of the operation data with reference to the difference value, and generating a digital twin state change trend sequence according to the change trend are as follows:
[0014] S101: Collect the real-time operation data of the computer system, construct a digital twin model based on the real-time operation data, classify and group the operation data in the digital twin model, record the real-time values of each type of data according to the time series, and form a classified real-time operation data table with reference to the real-time values of each type of data;
[0015] S102: Obtain the data differences between adjacent time points in the classified real-time operation data table, convert the data differences between adjacent time points into corresponding change sequences and record the change sequences to generate a set of operation data difference values;
[0016] S103: Based on the change trends between each type of difference value in the set of operation data difference values, evaluate the timing characteristics of the operation data fluctuations based on the change trends, and generate a digital twin state change trend sequence with reference to the timing characteristics of the operation data fluctuations.
[0017] The improvement of the present invention is that the digital twin state change trend sequence is divided into multiple interval segments according to a fixed time, the abnormal interval segments of the corresponding operation data are screened from each interval segment, and the hard disk read / write rate fluctuation amplitude, memory occupancy change rate and network traffic abnormal fluctuation parameters of the abnormal interval segments are statistically calculated to generate a computer system abnormal parameter set. The specific steps are as follows:
[0018] S201: Based on the digital twin state change trend sequence, screen the interval segments where the CPU utilization rate continuously increases by more than a preset increase range and the thread scheduling frequency exceeds a preset fluctuation threshold, extract the operation data within the target interval segments, and generate a set of target operation data interval segments;
[0019] S202: Based on the set of target operation data interval segments, statistically calculate the abnormal fluctuations of the hard disk read / write rate fluctuation amplitude, memory occupancy change rate and network traffic, and perform difference calculations in combination with the parameter set of the normal operation data to generate a set of operation data statistical differences;
[0020] S203: Based on the set of operation data statistical differences, calculate the membership degree of the operation data abnormality and the normal state, classify the risk conditions of the operation data according to the membership degree, and extract abnormal parameters from the classified risk conditions to generate a computer system abnormal parameter set;
[0021] The normal operation data is specifically the data lower than the preset change range of the difference value of the operation data within each period.
[0022] The improvements of the present invention are as follows: collect the state transition records of the operation data, identify the state transition patterns corresponding to the target abnormal parameters, extract the transition nodes of the abnormal parameters in the records and the associated operation data characteristics, calculate the transition probability of the target abnormal parameter in the abnormal parameter set of the computer system, predict the future state trend of the operation data according to the transition probability, and generate the specific steps of the abnormal transition state prediction result as follows:
[0023] S301: Based on the state transition records of the operation data, obtain all the state changes of the target abnormal parameter in the abnormal parameter set of the computer system, calculate the transition probability of the target abnormal parameter to remain in the abnormal state or transition to the normal state in the future with reference to all the state changes, and generate a set of transition probabilities of the target abnormal parameter;
[0024] S302: Based on the set of transition probabilities of the target abnormal parameter, predict the future state change trend of the operation data corresponding to the target abnormal parameter, extract and mark the key nodes in the future state change trend, and generate a set of key nodes of the target abnormal parameter;
[0025] S303: Based on the set of key nodes of the target abnormal parameter, integrate the key node information and the state transition information of the target parameter to generate an abnormal transition state prediction result.
[0026] The improvements of the present invention are as follows: evaluate the probability of entering the abnormal state within the corresponding time period according to the abnormal transition state prediction result, assign weights to the corresponding operation data according to the probability of the abnormal state, extract the abnormal state paths corresponding to the key nodes, evaluate the weight distribution of the key nodes in each path, screen and sort the key node paths according to the weight distribution, and generate the specific steps of the dynamic weight risk parameter path according to the sorted list as follows:
[0027] S401: Based on the key nodes in the abnormal transition state prediction result, assign weights to the target key nodes with reference to the importance of each key node and extract the abnormal state paths corresponding to the target key nodes according to the weight information to generate a set of abnormal paths of key nodes;
[0028] S402: Based on the set of abnormal paths of key nodes, evaluate the weight distribution of the key nodes in each path, screen the key node paths with the weight distribution exceeding the preset risk threshold, and generate a set of weight distributions of key node paths;
[0029] S403: Based on the set of weight distributions of key node paths, sort the abnormal state paths of key nodes, integrate the sorted key nodes, and generate a dynamic weight risk parameter path.
[0030] The improvement of the present invention is as follows. The interaction frequency of each key node path in the dynamic weight risk parameter path is analyzed, the correlation between key node paths is analyzed according to the interaction frequency, the propagation path between key node paths is constructed with reference to the correlation information, and the specific steps for generating the risk monitoring result of the computer system according to the propagation path are as follows:
[0031] S501: Based on the dynamic weight risk parameter path, count the occurrence times of key nodes in each path, analyze the interaction of key nodes in multiple paths according to the occurrence times of key nodes, and generate a key node interaction frequency table;
[0032] S502: Based on the key node interaction frequency table, combine the interaction data between key nodes to analyze the correlation strength between paths, extract the path relationship associated with corresponding key nodes according to the correlation strength, and generate a key node path correlation analysis result;
[0033] S503: Based on the key node path correlation analysis result, connect the paths whose correlation exceeds the preset key node threshold, construct the propagation path between key nodes, identify potential risk transmission chains through the propagation path, and generate the risk monitoring result of the computer system according to the potential risk transmission chains.
[0034] A computer system risk monitoring system based on digital twin, the system includes:
[0035] The operation data processing module collects the operation data of the computer system, constructs a digital twin model according to the operation data, calculates the difference value of each type of operation data, analyzes the change trend of the data according to the difference value, and generates a digital twin state change trend sequence;
[0036] The abnormal parameter analysis module, based on the digital twin state change trend sequence, divides multiple interval segments according to a fixed time, screens the abnormal interval segments of the operation data from each interval segment, and generates a computer system abnormal parameter set;
[0037] The state transition prediction module, based on the computer system abnormal parameter set and the state transition record of the operation data, calculates the transition probability that the target abnormal parameter remains in the abnormal state or turns into the normal state in the future, predicts the future state trend of the target parameter and extracts key nodes, and generates an abnormal transition state prediction result;
[0038] The weight path evaluation module, based on the key nodes in the abnormal transition state prediction result, assigns weights to the key nodes and extracts the abnormal state paths, evaluates the weight distribution of the key nodes in the paths, screens the paths whose weights exceed the risk threshold, and generates a dynamic weight risk parameter path;
[0039] The risk propagation visualization module analyzes the interaction frequency of the key node paths based on the dynamic weight risk parameter paths, analyzes the correlation between the paths according to the interaction frequency, constructs the path propagation relationship based on the correlation information, and displays the propagation path in a visual manner to generate the risk monitoring results of the computer system.
[0040] Compared with the prior art, the advantages and positive effects of the present invention are as follows:
[0041] In the present invention, by collecting real-time operation data and constructing a digital twin model, combining the difference value and the change trend of the operation data effectively refines the dynamic monitoring ability of the data. Dividing the trend sequence by a fixed time, screening the abnormal data interval and statistically analyzing multi-dimensional parameters helps to identify the key features of abnormal data from a finer dimension and improves the accuracy of data analysis. Extracting the correlation features of abnormal parameters based on the state transition records and calculating the transition probability can make a more accurate prediction of future trends and provide a scientific basis for dynamic threat assessment. Through the dynamic weight allocation mechanism, generating key node paths and performing sorting analysis reasonably optimizes the distribution structure of risk weights and significantly enhances the tracking ability of key risk paths. Combining the interaction frequency between key node paths and the construction of propagation paths effectively strengthens the correlation and integrity of risk monitoring results and ensures that the risk assessment can dynamically reflect the propagation path and diffusion trend of potential problems. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 is the flowchart of the method of the present invention;
[0043] Figure 2 is the schematic diagram of the refinement process of step S1 of the present invention;
[0044] Figure 3 is the schematic diagram of the refinement process of step S2 of the present invention;
[0045] Figure 4 is the schematic diagram of the refinement process of step S3 of the present invention;
[0046] Figure 5 is the schematic diagram of the refinement process of step S4 of the present invention;
[0047] Figure 6 is the schematic diagram of the refinement process of step S5 of the present invention;
[0048] Figure 7 is the system module diagram of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0049] To make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0050] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the accompanying drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the present invention. In addition, in the description of the present invention, the meaning of "a plurality of" is two or more, unless otherwise specifically defined.
[0051] Please refer to Figure 1 , the present invention provides a technical solution: a method for monitoring the risks of a computer system based on digital twin, including the following steps:
[0052] S1: Collect the real-time operation data of the computer system, construct a digital twin model according to the operation data, calculate the difference value of each type of operation data, analyze the change trend of the operation data with reference to the difference value, and generate a digital twin state change trend sequence according to the change trend;
[0053] S2: Divide the digital twin state change trend sequence into multiple interval segments according to a fixed time, screen the abnormal interval segments of the corresponding operation data from each interval segment, and count the hard disk read / write rate fluctuation amplitude, memory occupancy rate change rate, and network traffic abnormal fluctuation parameters of the abnormal interval segments to generate a computer system abnormal parameter set;
[0054] S3: Collect the state transition records of the operation data, identify the state transition mode corresponding to the target abnormal parameter, extract the transition nodes and associated operation data characteristics of the abnormal parameter in the records, calculate the transition probability of the target abnormal parameter in the computer system abnormal parameter set, and predict the future state trend of the operation data according to the transition probability to generate an abnormal transition state prediction result;
[0055] S4: Evaluate the probability of entering the abnormal state within the corresponding time period according to the abnormal transition state prediction result, assign weights to the corresponding operation data according to the probability of the abnormal state, extract the abnormal state paths corresponding to the key nodes, evaluate the weight distribution of the key nodes in each path, screen and sort the key node paths according to the weight distribution, and generate a dynamic weight risk parameter path according to the sorted list;
[0056] S5: Analyze the interaction frequency of each key node path in the dynamic weight risk parameter path, analyze the correlation between the key node paths according to the interaction frequency, construct the propagation path between the key node paths with reference to the correlation information, and generate the computer system risk monitoring results according to the propagation path;
[0057] The digital twin state change trend sequence is the difference value curve change pattern and the timing characteristics of the operating data fluctuation. The computer system abnormal parameter set includes the fluctuation amplitude of the hard disk read and write rate, the memory occupancy rate change rate, and the network traffic abnormal fluctuation parameters. The abnormal transfer state prediction results include the transfer nodes of the target abnormal parameters, the operating data characteristics, and the transfer probability prediction results. The dynamic weight risk parameter path includes the weight distribution of the key node path and the key node path sorting. The computer system risk monitoring results include the interaction frequency of the key node path, the correlation of the key node path, and the propagation path of the key node path.
[0058] See also Figure 2 , collect the real-time operation data of the computer system, build a digital twin model based on the operation data, calculate the difference value of each type of operation data, analyze the change trend of the operation data with reference to the difference value, and generate the digital twin state change trend sequence according to the change trend. The specific steps are as follows:
[0059] S101: Collecting real-time operation data of the computer system, building a digital twin model based on the real-time operation data, classifying and grouping the operation data in the digital twin model, recording the real-time value of each type of data in time series, and forming a classified real-time operation data table with reference to the real-time value of each type of data;
[0060] Collect real-time operation data of computer systems, including but not limited to key indicators such as CPU utilization (such as fluctuations in the range of 5% to 90%), memory utilization (such as fluctuations in the range of 20% to 95%), and network bandwidth utilization (such as the range of 0.5Gbps to 10Gbps). Use data filters to remove abnormal values that exceed the set range in a short period of time, such as removing data points with CPU utilization below 1% or above 99%. Use timestamps to serialize and store various parameters, and use a hierarchical grouping mechanism to classify data, such as dividing CPU and memory parameters into resource utilization groups, and dividing network parameters into transmission status groups. Real-time storage and dynamic update of classified data are realized through a database to ensure that the latest status of each type of data can timely reflect the operating status of the system, and finally generate a classified real-time operation data table based on time series.
[0061] S102: obtaining data differences between adjacent time points in the classified real-time operation data table, converting the data differences between adjacent time points into corresponding change sequences and recording the change sequences to generate an operation data difference value set;
[0062] Obtain the data difference between adjacent time points in the classification real-time operation data table, set the adjacent time point interval to 1 minute, and calculate the time difference value sequence. Extract the absolute difference and relative difference from the data of adjacent time points. For example, if the CPU utilization rate increases from 50% to 60% within one minute, the absolute difference is 10% and the relative difference is 20%. Arrange these differences according to time points to form a change sequence. Classify the change sequence into a high-frequency fluctuation area (such as the fluctuation amplitude is greater than 15%) and a low-frequency fluctuation area (such as the fluctuation amplitude is less than 5%), and use the classification rules to screen out the significantly fluctuating points, and record the results in the operation data difference value set. The operation data difference value set is used to evaluate the dynamic performance change of the system.
[0063] S103: According to the change trend between each type of difference value in the operation data difference value set, evaluate the timing characteristics of the operation data fluctuation based on the change trend. Refer to the timing characteristics of the operation data fluctuation and generate a digital twin state change trend sequence;
[0064] According to the change trend between each type of difference value in the operation data difference value set, conduct a segmented evaluation of the time series characteristics of the data fluctuation. Use the sliding window method to segment the data in the difference value set, set the sliding window size to 10 minutes, analyze the change rate and fluctuation amplitude within each window. If the average change rate of the difference value within a certain window is greater than 10% / minute or the fluctuation amplitude exceeds 50%, it is marked as a high-risk window; Fit the trend of each segment of data through the autoregressive integrated moving average model (ARIMA) to generate a trend change curve, and conduct outlier analysis on the high-risk windows based on the fitting results. The outliers are screened by setting a threshold (such as the fluctuation amplitude exceeds twice the historical average value). Finally, output the digital twin state change trend sequence. The trend sequence is used to identify high-risk time periods and potential fault areas.
[0065] Please refer to Figure 3 , divide the digital twin state change trend sequence into multiple interval segments according to a fixed time, screen out the abnormal interval segments of the corresponding operation data from each interval segment, and count the hard disk read and write rate fluctuation amplitude, memory occupancy rate change rate, and network traffic abnormal fluctuation parameters in the abnormal interval segments. The specific steps to generate the computer system abnormal parameter set are as follows:
[0066] S201: Based on the digital twin state change trend sequence, screen out the interval segments where the CPU utilization rate continuously increases beyond the preset growth range and the thread scheduling frequency exceeds the preset fluctuation threshold, extract the operation data within the target interval segments, and generate a target operation data interval segment set;
[0067] Screen the interval segments where the CPU utilization rate continuously increases beyond the preset growth range. Use the scheduling management module to monitor the CPU load in real time and record the growth data as a time series. Set the preset growth range to 5% to 50%. During the screening process, record the fluctuation data of the thread scheduling frequency, and extract the abnormal fluctuation segments according to the upper and lower limits of the fluctuation threshold (such as 0.1Hz to 1Hz). Mark the time intervals that meet the conditions as target interval segments. Extract the operation data including parameters such as CPU utilization rate, thread scheduling frequency, and hard disk read / write rate within the target interval segments, and finally integrate them to generate a set of target operation data interval segments.
[0068] S202: Based on the set of target operation data interval segments, statistically analyze the abnormal fluctuations in the hard disk read / write rate fluctuation range, memory occupancy rate change rate, and network traffic, and perform difference calculations in combination with the parameter set of normal operation data to generate a set of statistical differences in operation data;
[0069] Based on the set of target operation data interval segments, perform a fluctuation analysis on the operation data. First, statistically analyze the fluctuation range of the hard disk read / write rate, and obtain the fluctuation value by calculating the difference between the maximum and minimum rates within each minute. Set the hard disk read / write rate fluctuation range to 1MB / s to 100MB / s, and extract the abnormal segments where the fluctuation exceeds the threshold. Secondly, statistically analyze the change rate of the memory occupancy rate, obtain the rate value by comparing the memory occupancy values at consecutive time points, and classify the part where the change rate exceeds the range of 10% to 30% per second as abnormal. Finally, statistically analyze the abnormal fluctuations in network traffic. The network traffic data is classified according to the traffic change frequency. Set the frequency range to 1Hz to 10Hz, extract the abnormal segments where the frequency changes abnormally, and compare the above statistical data with the parameter set of normal operation data to generate a set of statistical differences in operation data through differential calculation.
[0070] S203: Based on the set of statistical differences in operation data, calculate the membership degree of the operation data abnormality to the normal state, classify the risk conditions of the operation data according to the membership degree, extract the abnormal parameters from the classified hierarchical risk conditions, and generate a set of abnormal parameters for the computer system;
[0071] The normal operation data is specifically the data below the preset change range of the difference value of the operation data within each period.
[0072] Based on the set of statistical differences in operation data, calculate the membership degree of the operation data abnormality to the normal state, according to the formula:
[0073]
[0074] Calculate the membership degree value μ A (x);
[0075] where, μ A(x) represents the membership value of the operating data in the normal state, which is used to measure the degree of belonging of the current difference value relative to the normal state. It is directly obtained through the calculation formula, and the result value is between 0 and 1. The closer it is to 1, the lower the degree of deviation of the data from the normal state. x represents the difference value of the current statistical data, which comes from a single point of data in the operating data statistical difference set and is directly obtained through the real-time system monitoring module. For example, it is extracted from the difference between the CPU utilization rate and the normal reference value. a is the mean value of the normal operating data, which is obtained by statistically analyzing the historical values of the normal operating data in the time series. The historical values can be extracted through the log system. The mean value calculation formula is: In the formula, x i′ is the i'-th data point in the normal operating data, n is the total number of data points, b is the standard deviation of the normal operating data, which is used to characterize the volatility of the normal operating data, and is obtained through the formula: c is the dynamic adjustment factor, which is used to adjust the sensitivity of the membership calculation according to the real-time system fluctuation characteristics, and is obtained through the formula σ x is the real-time standard deviation of the difference data, which is obtained by monitoring the fluctuation of the real-time difference data within a certain time window.
[0076] For example, the normal mean value a of the operating data is 50, the standard deviation b is 10, the real-time standard deviation σ x of the difference data is 5, and the current difference value x is 70.
[0077] Dynamic adjustment factor:
[0078] Membership value calculation:
[0079] The result shows that the membership value is 0.36.
[0080] The calculated membership value is 0.36. According to the risk condition grading standard, the risk grading is set as follows:
[0081] Low risk: The membership value is above 0.8, indicating that the data deviates less from the normal state, and the operating state can be considered normal. Medium risk: The membership value is between 0.5 and 0.8, indicating that the data shows a certain degree of deviation, and the operating state needs to be concerned. High risk: The membership value is below 0.5, indicating that the data significantly deviates from the normal state, and immediate inspection and measures should be taken. The membership value is 0.36, which belongs to the high-risk range. Therefore, it is determined that there are obvious abnormalities in the current system state. Further analyze the abnormal state, and extract abnormal parameters from the statistical differences in the operation data. For example: CPU utilization rate: The difference value exceeds the mean range of normal operation. For example, it continuously exceeds 85% in the past minute. Memory usage rate: The change rate exceeds the set threshold, such as the growth rate per second exceeds 20%. Network traffic: The fluctuation range far exceeds the preset range. For example, the difference between the maximum value and the minimum value within one minute exceeds 10 Gbps. Summarize the above-extracted abnormal parameters to form a set of abnormal parameters for the computer system. For example: Abnormal parameter set: CPU utilization rate: 90%, Memory usage rate change rate: 25% / s, Network traffic fluctuation range: 12 Gbps. By extracting these abnormal parameters, it can be used for further analysis of the source of abnormalities, such as resource contention of specific threads, memory surge caused by high-load applications, or traffic anomalies caused by network device failures, thereby providing a guiding basis for system optimization and troubleshooting.
[0082] Please refer to Figure 4 , collect the state transition records of the operation data, identify the state transition patterns corresponding to the target abnormal parameters, extract the transition nodes of the abnormal parameters in the records and the associated operation data characteristics, calculate the transition probability of the target abnormal parameters in the set of abnormal parameters of the computer system, and predict the future state trend of the operation data according to the transition probability. The specific steps for generating the abnormal transition state prediction result are as follows:
[0083] S301: Based on the state transition records of the operation data, obtain all the state changes of the target abnormal parameters in the set of abnormal parameters of the computer system, and calculate the transition probability of the target abnormal parameters to remain in the abnormal state or transition to the normal state in the future with reference to all the state changes, and generate a set of transition probabilities of the target abnormal parameters;
[0084] With reference to all the state changes of the target abnormal parameters, according to the formula:
[0085]
[0086] Calculate the weighted state transition probability P of the target abnormal parameter ij ;
[0087] Among them, P ijis the weighted state transition probability of the target anomaly parameter, which is used to characterize the possibility of the target parameter transferring from the current state i to the target state j. It is obtained by comprehensively calculating the state transition count and the weight factor, reflecting the importance and priority relationship of the state transition. N ij is the number of times of transferring from state i to state j, which is obtained by counting the state transition records of the target anomaly parameter. For example, by analyzing the transfer events recorded in the operation log or the state change sequence, and the acquisition method is to directly count the frequency from historical data. w ij is the weight factor of the state transition, which is used to represent the importance degree of different transfer paths. It is set through expert experience analysis, experimental simulation or based on business rules. For example, the weight factor is given according to the time cost of the transfer occurrence or the degree of influence on the system. For example, if a certain state transition occurs frequently, it indicates that it occupies an important position in the system and should be given a larger weight (such as 0 - 1). If a certain state transition occurs rarely, usually it has little impact on the long-term behavior of the system, then its weight should be lower (such as 1 - 2). Among them, frequently is 30 times and rarely is 10 times. ∑ k (N ik ·w ik ) is the total weighted number of times of transferring from state i to all states, which represents the total influence of all transfer events starting from state i. It is obtained by summing the product of the count and the weight factor of all possible transfer paths, and is used as the denominator to ensure the normalization of the probability value. i and j respectively represent the starting state and the target state of the target anomaly parameter, such as the abnormal state and the normal state. k represents any state in the state set and is used as the traversal counter in the summation symbol, indicating the statistical range from state i to all possible target states. · represents the multiplication operation symbol, indicating the product of the state count and the weight factor. ∑ represents the summation symbol, covering the calculation range of transferring from state i to all possible states, such as transferring from state A to all target states.
[0088] For example, the states of the target anomaly parameter are divided into two types: abnormal state A and normal state N. The following transfer times and weight factors are obtained from the data statistics:
[0089] N AA =30, w AA =1.2: The number of times that the abnormal state remains in the abnormal state is 30 times, and the weight factor is 1.2.
[0090] N AN =10, w AN =0.8: The number of times that the abnormal state transfers to the normal state is 10 times, and the weight factor is 0.8.
[0091] Total weighted transfer times: ∑ k (N Ak ·w Ak) = (30 · 1.2) + (10 · 0.8) = 44。
[0092] Transition probability calculation:
[0093] Weighted probability of the abnormal state remaining in the abnormal state:
[0094]
[0095] Weighted probability of the abnormal state transitioning to the normal state:
[0096]
[0097] The results show that the weighted probability of the target abnormal parameter remaining in the abnormal state in the future is 0.818, and the weighted probability of transitioning to the normal state is 0.182.
[0098] S302: Based on the set of transition probabilities of the target abnormal parameter, predict the future state change trend of the operating data corresponding to the target abnormal parameter, extract and mark the key nodes in the future state change trend, and generate the key node set of the target abnormal parameter;
[0099] According to the calculation result of the transition probability, the weighted probability of the target abnormal parameter remaining in the abnormal state in the future is 0.818, and the weighted probability of transitioning to the normal state is 0.182. The future state change trend is expressed as: currently in the abnormal state, in the next time step, the probability of remaining in the abnormal state is 0.818, and the probability of transitioning to the normal state is 0.182. After multiple iterations, the state will tend to be stable, forming a stable state distribution. Determine the state ratio in multiple future time steps according to the state distribution. Extract and mark the key nodes in the future state change trend. Dominant abnormal state node: When the proportion of the abnormal state in multiple future time steps is always higher than a certain threshold (such as 70%), it is marked as a key node. State mutation node: When there is a significant change in the state transition probability (such as the probability of the abnormal state transitioning to the normal state increases to more than 50%), it is marked as a mutation node. Stable node: When the state change trend tends to be stable, that is, the fluctuation range of the state proportion is lower than the set value (such as 5%), it is marked as a stable node. Extract key nodes: Dominant abnormal state node: In the 3rd future time step, the proportion of the abnormal state is 85%, significantly higher than the set threshold, and it is marked as a dominant abnormal state node. State mutation node: In the 5th future time step, the transition probability from the abnormal state to the normal state increases to 60%, and it is marked as a mutation node. Stable node: After the 10th future time step, the state distribution remains stable, with the abnormal state and the normal state being 40% and 60% respectively, and it is marked as a stable node. By generating the key node set of the target abnormal parameter, the future state change trend of the target abnormal parameter can be intuitively reflected, providing a decision-making basis for system risk monitoring and optimization.
[0100] S303: Based on the key node set of target abnormal parameters, integrate the key node information and the state transition information of the target parameters to generate an abnormal transition state prediction result;
[0101] Combine the abnormal dominant nodes, state mutation nodes, and stable nodes in the key node set to clarify the key time points of future state changes. For example, an abnormal state dominance occurs at the 3rd time step, a state mutation appears at the 5th time step, and a stable state is reached at the 10th time step. Superimpose the dynamic changes of the transition probability on the time series to clarify the transition direction and probability distribution of the state at each time step. For example, at the 3rd time step, the transition probability of the abnormal state is 0.818, and the transition probability of the normal state is 0.182. After the state mutation at the 5th time step, the transition probability of the abnormal state drops to 0.4, and the normal state rises to 0.6. Combine the key nodes and state transition information to gradually predict the state distribution at each time step, record the duration and change trend of the abnormal state. For example, the abnormal state persists from the current time to the 4th time step, starts to transfer to the normal state at the 5th time step, and stabilizes in a state distribution mainly dominated by the normal state after the 10th time step. From time step 1 to 3, the abnormal state is dominant, and the transition probability remains at 0.818, with the state distribution mainly in the abnormal state. From time step 4 to 5, there is a state mutation, the transition probability of the abnormal state gradually decreases to 0.4, and the transition probability of the normal state rises to 0.6, resulting in a significant change in the state. From time step 6 to 10, the state gradually stabilizes, the proportion of the abnormal state drops to 40%, and the proportion of the normal state rises to 60%. The prediction results show that the target abnormal parameter may continue to be in an abnormal state in the short term in the future, but will gradually return to the normal state after the 5th time step. The integration of key nodes provides a clear time mark for state changes and a clear reference for system operation and maintenance decisions. For example, implement abnormal repair measures before the state mutation node and optimize resource allocation after the stable node to improve the system operation efficiency and stability.
[0102] Please refer to Figure 5 , and according to the abnormal transition state prediction result, evaluate the probability of entering the abnormal state within the corresponding time period, assign weights to the corresponding operation data according to the probability of the abnormal state, extract the abnormal state paths corresponding to the key nodes, evaluate the weight distribution of the key nodes in each path, screen and sort the key node paths according to the weight distribution, and generate the specific steps of the dynamic weight risk parameter path according to the sorted list as follows:
[0103] S401: Based on the key nodes in the abnormal transition state prediction result, refer to the importance of each key node, assign weights to the target key nodes, and extract the abnormal state paths corresponding to the target key nodes according to the weight information to generate a key node abnormal path set;
[0104] Based on the key nodes in the prediction results of the abnormal transfer state, weights are assigned to the target key nodes. The assignment process is based on historical transfer records and the importance of key nodes. The importance is comprehensively evaluated according to three core parameters, including the abnormal occurrence frequency of key nodes, the duration of the transfer state, and the impact of the transfer on the system operation. The abnormal occurrence frequency is obtained by counting the number of times a key node is triggered in the past month, and the evaluation range is set from 10 to 100 times. The higher the frequency, the greater the weight of the node. The duration of the transfer state is obtained by calculating the time span of a single abnormal event. Nodes with a duration exceeding 5 minutes are given a higher weight. The impact on the system is evaluated based on the resource consumption associated with the key node. Resource consumption includes CPU utilization and memory occupancy. Nodes exceeding the set threshold are marked as high-priority. By normalizing the above parameters, the weight of each key node is adjusted to the range of 0 to 1. Finally, the abnormal state path corresponding to the target key node is extracted. The path is organized according to the time series to generate a set of key node abnormal paths.
[0105] S402: Based on the set of key node abnormal paths, evaluate the weight distribution of key nodes in each path, filter out the key node paths whose weight distribution exceeds the preset risk threshold, and generate a set of key node path weight distributions;
[0106] Based on the set of key node abnormal paths, evaluate the weight distribution of key nodes in each path. The evaluation of the weight distribution takes the time series of node weights in the path as the core. By extracting the weight values of key nodes and constructing a weight distribution curve to analyze the risk concentration of the path, the weight values of key nodes in the weight distribution curve need to exceed the preset risk threshold. The threshold is obtained by statistical analysis of historical data. For example, the threshold is set as the average weight plus one standard deviation. That is, when the weight of a key node exceeds this threshold, it is marked as a high-risk node. By filtering out the paths where the proportion of high-risk nodes in the path exceeds 50%, the qualified paths are recorded as the set of key node path weight distributions. At the same time, paths with scattered weight distributions or insufficient proportions of high-risk nodes are excluded. After the path screening is completed, the priority labels of the path set are regenerated.
[0107] S403: Based on the set of key node path weight distributions, sort the key node abnormal state paths, integrate the sorted key nodes, and generate a dynamic weight risk parameter path;
[0108] Based on the key node path weight distribution set, prioritize the paths. The prioritization is based on the total weight value of the key nodes and the time centrality. The total weight value is obtained by calculating the cumulative value of the weights of all key nodes in the path, and the total value range is set from 1 to 10. The higher the total weight value, the higher the path priority. The time centrality is evaluated by the standard deviation of the time series distribution of the key nodes in the path, and the time centrality range is set from 0 to 5. The lower the standard deviation, the more concentrated the distribution of the key nodes and the higher the priority. After prioritizing the paths, extract the path with the highest priority and integrate the corresponding key nodes to generate a dynamic weight risk parameter path. The weight values and key node markers in the dynamic path are used to guide the prioritized allocation of system resources. For example, prioritize the resource allocation adjustment or anomaly repair of high-weight nodes associated with abnormal paths.
[0109] Please refer to Figure 6 , analyze the interaction frequency of each key node path in the dynamic weight risk parameter path, analyze the correlation between key node paths based on the interaction frequency, and construct the propagation path between key node paths with reference to the correlation information. The specific steps for generating the computer system risk monitoring results based on the propagation path are as follows:
[0110] S501: Based on the dynamic weight risk parameter path, count the number of occurrences of key nodes in each path, analyze the interaction of key nodes in multiple paths according to the number of occurrences of key nodes, and generate a key node interaction frequency table;
[0111] Based on the dynamic weight risk parameter path, count the number of occurrences of key nodes in each path. During the counting, scan each path one by one, record the timestamp of each key node in the path as the occurrence time, and generate the statistical result by accumulating the number of occurrences of each node in all paths. Set the range of the number of occurrences of key nodes from 1 to 20 times. Mark the nodes with more than 15 occurrences as high-frequency key nodes, and classify the low-frequency nodes at the same time. Combine time series analysis to analyze the distribution pattern of nodes in the path during the statistical process. For example, when the proportion of occurrences in a continuous time period exceeds 50% of the total nodes in the path, mark it as a time-aggregated path. Finally, generate a key node interaction frequency table.
[0112] S502: Based on the key node interaction frequency table, combine the interaction data between key nodes to analyze the correlation strength between paths, extract the path relationship associated with the corresponding key nodes according to the correlation strength, and generate the key node path correlation analysis result;
[0113] Based on the critical node interaction frequency table, combined with the analysis of the interaction data between nodes to analyze the correlation strength between paths. The analysis process first extracts the critical node pairs in all paths, and counts the number of times each pair of nodes co-occurs in the paths. The correlation strength is calculated by the ratio of the occurrence of the node pair in all paths. The node pairs with a correlation strength exceeding 60% are marked as highly correlated nodes. At the same time, further distribution analysis of the interaction frequency of nodes is carried out to analyze whether the node pairs are concentrated in a certain time period. If the time distribution coincidence degree of the node pairs exceeds 70%, it is determined as a path pair with high time correlation. The path pairs with high correlation and high time correlation are screened out, and combined with the weight distribution of the nodes in the path pairs, the path pairs with a node correlation strength lower than 30% or scattered distribution are removed to generate the analysis result of the critical node path correlation.
[0114] S503: Based on the analysis result of the critical node path correlation, connect the paths with a correlation exceeding the preset critical node threshold, and construct the propagation path between the critical nodes. Identify the potential risk transmission chain through the propagation path, and generate the computer system risk monitoring result according to the potential risk transmission chain;
[0115] Based on the analysis result of the critical node path correlation, connect the paths with a correlation exceeding the preset critical node threshold. When connecting the paths, sort them according to the continuity of the critical node time distribution and the path correlation strength. First, select the path pairs with a correlation strength exceeding 70%. Ensure the continuity of the time period during the connection process. For example, when the end time of path A and the start time of path B have a difference of no more than 5 minutes, give priority to connecting path A and path B to form a new continuous path. Subsequently, expand the calculation of the propagation range of the critical nodes in the new path. For example, when the propagation range of the critical nodes after path connection expands to 1.5 times the original range, it is marked as a propagation effective path. Finally, construct the propagation path between the critical nodes and display the propagation path diagram in a visual way. Each path in the diagram is distinguished by color and thickness for the propagation range and node interaction frequency. Generate the computer system risk monitoring result according to the propagation path diagram.
[0116] Please refer to Figure 7 , a computer system risk monitoring system based on digital twin, the system includes:
[0117] The operation data processing module collects the operation data of the computer system, constructs a digital twin model according to the operation data, calculates the difference value of each type of operation data, analyzes the change trend of the data according to the difference value, and generates a digital twin state change trend sequence;
[0118] The abnormal parameter analysis module, based on the digital twin state change trend sequence, divides multiple interval segments according to a fixed time, screens the abnormal interval segments of the operation data from each interval segment, and generates a computer system abnormal parameter set;
[0119] The state transition prediction module calculates the transition probability of a target abnormal parameter to remain in an abnormal state or turn into a normal state in the future based on the state transition records of the computer system abnormal parameter set and operation data, predicts the future state trend of the target parameter, extracts key nodes, and generates an abnormal transition state prediction result;
[0120] The weight path evaluation module assigns weights to the key nodes based on the key nodes in the abnormal transition state prediction result, extracts the abnormal state paths, evaluates the weight distribution of the key nodes in the paths, filters the paths with weights exceeding the risk threshold, and generates a dynamic weight risk parameter path;
[0121] The risk propagation visualization module analyzes the interaction frequency of the key node paths based on the dynamic weight risk parameter path, analyzes the correlation between the paths according to the interaction frequency, constructs a path propagation relationship based on the correlation information, and displays the propagation path in a visual manner to generate a computer system risk monitoring result.
[0122] The above are only the preferred embodiments of the present invention, and are not intended to limit the present invention in other forms. Any person skilled in the art may use the technical content disclosed above to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, any simple modification, equivalent change, and modification made to the above embodiments based on the technical essence of the present invention without departing from the technical solution content of the present invention still fall within the protection scope of the technical solution of the present invention.
Claims
1. A computer system risk monitoring method based on digital twins, characterized in that: The following steps are involved: S1: Collect real-time operation data of the computer system, build a digital twin model based on the operation data, calculate the difference value of each type of operation data, analyze the change trend of the operation data with reference to the difference value, and generate a digital twin state change trend sequence based on the change trend; S2: Divide the state change trend sequence of the digital twin into multiple interval segments according to a fixed time, select the abnormal interval segment of the corresponding operation data from each interval segment, and count the fluctuation amplitude of the hard disk read and write rate, the memory occupancy rate change rate and the abnormal fluctuation parameters of the network traffic in the abnormal interval segment to generate an abnormal parameter set of the computer system; S3: Collecting operation data state transition records, identifying the transition mode corresponding to the target abnormal parameter, extracting the transition node and associated features, calculating the transition probability of the target abnormal parameter in the abnormal parameter set of the computer system, predicting the future state trend, and generating the abnormal state prediction result; S4: Evaluate the probability of entering an abnormal state within a corresponding time period according to the abnormal state prediction result, assign weights to corresponding operating data according to the probability of the abnormal state, extract key node paths, evaluate weight distribution, screen and sort paths, and generate dynamic weight risk parameter paths; S5: Analyze the interaction frequency of each key node path in the dynamic weight risk parameter path, analyze the correlation between the key node paths based on the interaction frequency, construct the propagation path between the key node paths with reference to the correlation information, and generate the computer system risk monitoring result based on the propagation path.
2. The computer system risk monitoring method based on digital twins according to claim 1 is characterized in that: The digital twin state change trend sequence is the difference value curve change pattern and the timing characteristics of the operating data fluctuation. The computer system abnormal parameter set includes the fluctuation amplitude of the hard disk read and write rate, the memory occupancy rate change rate, and the network traffic abnormal fluctuation parameter. The abnormal transfer state prediction result includes the transfer node of the target abnormal parameter, the operating data characteristics, and the transfer probability prediction result. The dynamic weight risk parameter path includes the weight distribution of the key node path and the key node path sorting. The computer system risk monitoring result includes the interaction frequency of the key node path, the correlation of the key node path, and the propagation path of the key node path.
3. The computer system risk monitoring method based on digital twins according to claim 1 is characterized in that: The specific steps of collecting real-time operation data of the computer system, building a digital twin model based on the operation data, calculating the difference value of each type of operation data, analyzing the change trend of the operation data with reference to the difference value, and generating a digital twin state change trend sequence based on the change trend are as follows: S101: Collecting real-time operation data of the computer system, building a digital twin model based on the real-time operation data, classifying and grouping the operation data in the digital twin model, recording the real-time value of each type of data in time series, and forming a classified real-time operation data table with reference to the real-time value of each type of data; S102: obtaining data differences between adjacent time points in the classified real-time operation data table, converting the data differences between adjacent time points into corresponding change sequences and recording the change sequences to generate an operation data difference value set; S103: According to the change trend between each type of difference value in the operation data difference value set, the timing characteristics of the operation data fluctuation are evaluated based on the change trend, and a digital twin state change trend sequence is generated with reference to the timing characteristics of the operation data fluctuation.
4. The computer system risk monitoring method based on digital twins according to claim 1 is characterized in that: The digital twin state change trend sequence is divided into multiple intervals according to a fixed time, and the abnormal interval corresponding to the running data is selected from each interval. The fluctuation amplitude of the hard disk read and write rate, the memory occupancy rate change rate and the abnormal fluctuation parameters of the network traffic in the abnormal interval are counted, and the specific steps of generating the abnormal parameter set of the computer system are as follows: S201: Based on the digital twin state change trend sequence, filter the interval segments where the CPU utilization rate continuously increases beyond a preset growth range and the thread scheduling frequency exceeds a preset fluctuation threshold, extract the operating data within the target interval segment, and generate a target operating data interval segment set; S202: Based on the target operation data interval segment set, statistics are collected on the fluctuation range of hard disk read / write rate, the change rate of memory occupancy rate and abnormal fluctuation of network traffic, and difference calculation is performed in combination with the parameter set of normal operation data to generate an operation data statistical difference set; S203: Based on the statistical difference set of the operating data, calculating the membership degree between the abnormal and normal states of the operating data, grading the risk conditions of the operating data according to the membership degree, extracting abnormal parameters from the graded risk conditions after grading, and generating a computer system abnormal parameter set; The normal operation data is specifically data that is lower than a preset variation range of the difference value of the operation data in each period.
5. The computer system risk monitoring method based on digital twins according to claim 4 is characterized in that: For the membership degree of abnormal and normal operating data, the formula is used: Calculate the membership value μ of the operating data under normal conditions A (x); Among them, x represents the difference value of the current statistical data, a is the mean of the normal operation data, b is the standard deviation of the normal operation data, and c is the dynamic adjustment factor.
6. The computer system risk monitoring method based on digital twins according to claim 1 is characterized in that: The specific steps of collecting state transition records of operating data, identifying the state transition mode corresponding to the target abnormal parameter, extracting the transition nodes of the abnormal parameter in the record and the associated operating data features, calculating the transition probability of the target abnormal parameter in the abnormal parameter set of the computer system, predicting the future state trend of the operating data according to the transition probability, and generating the abnormal transition state prediction result are as follows: S301: based on the state transition record of the operation data, obtaining all state changes of the target abnormal parameters in the abnormal parameter set of the computer system, calculating the probability of the target abnormal parameters remaining in the abnormal state or transitioning to the normal state in the future with reference to all state changes, and generating a target abnormal parameter transition probability set; S302: Based on the target abnormal parameter transition probability set, predict the future state change trend of the operation data corresponding to the target abnormal parameter, extract and mark the key nodes in the future state change trend, and generate a target abnormal parameter key node set; S303: Based on the target abnormal parameter key node set, integrate the key node information and the state transition information of the target parameter to generate an abnormal transition state prediction result.
7. The computer system risk monitoring method based on digital twins according to claim 6 is characterized in that: For the probability that the target abnormal parameter will remain in an abnormal state or transition to a normal state in the future, the formula is used: Calculate the weighted state transition probability P of the target abnormal parameter ij ; Among them, N ij is the number of transitions from state i to state j, w ij is the weight factor of state transition, ∑ k (N ik ·w ik ) is the weighted total number of times state i transfers to all states, i and j represent the starting state and target state of the target abnormal parameter, respectively, and k represents any state in the state set.
8. The computer system risk monitoring method based on digital twins according to claim 1 is characterized in that: According to the abnormal transfer state prediction result, the probability of entering the abnormal state in the corresponding time period is evaluated, the weight of the corresponding operation data is assigned according to the probability of the abnormal state, the abnormal state path corresponding to the key node is extracted, the weight distribution of the key node in each path is evaluated, the key node path is screened and sorted according to the weight distribution, and the specific steps of generating the dynamic weight risk parameter path according to the sorted list are as follows: S401: Based on the key nodes in the abnormal transfer state prediction result, referring to the importance of each key node, assigning weights to target key nodes and extracting abnormal state paths corresponding to the target key nodes according to the weight information, to generate a key node abnormal path set; S402: Based on the critical node abnormal path set, evaluate the weight distribution of the critical nodes in each path, screen the critical node paths whose weight distribution exceeds a preset risk threshold, and generate a critical node path weight distribution set; S403: Based on the key node path weight distribution set, the key node abnormal state paths are sorted, and the sorted key nodes are integrated to generate a dynamic weight risk parameter path.
9. The computer system risk monitoring method based on digital twins according to claim 1 is characterized in that: The specific steps of analyzing the interaction frequency of each key node path in the dynamic weight risk parameter path, analyzing the correlation between the key node paths according to the interaction frequency, constructing the propagation path between the key node paths with reference to the correlation information, and generating the computer system risk monitoring result according to the propagation path are as follows: S501: Based on the dynamic weight risk parameter path, count the number of occurrences of key nodes in each path, analyze the interaction of key nodes in multiple paths according to the number of occurrences of key nodes, and generate a key node interaction frequency table; S502: Based on the key node interaction frequency table, analyze the correlation strength between paths in combination with the interaction data between key nodes, extract the path relationship between the corresponding key nodes according to the correlation strength, and generate a key node path correlation analysis result; S503: Based on the key node path correlation analysis results, the paths whose correlation exceeds the preset key node threshold are connected, and the propagation paths between the key nodes are constructed, the potential risk transmission chain is identified through the propagation path, and the computer system risk monitoring results are generated according to the potential risk transmission chain.
10. Computer system risk monitoring system based on digital twins, characterized by: According to any one of claims 1 to 9, the computer system risk monitoring method based on digital twins is implemented, and the system comprises: The operation data processing module collects the operation data of the computer system, builds a digital twin model based on the operation data, calculates the difference value of each type of operation data, analyzes the change trend of the data based on the difference value, and generates a digital twin state change trend sequence; The abnormal parameter analysis module divides the digital twin state change trend sequence into multiple intervals according to fixed time, screens abnormal intervals of operation data from each interval, and generates an abnormal parameter set of the computer system; The state transition prediction module calculates the transition probability of the target abnormal parameter remaining in an abnormal state or turning into a normal state in the future based on the abnormal parameter set of the computer system and the state transition record of the operation data, predicts the future state trend of the target parameter and extracts key nodes, and generates an abnormal transition state prediction result; The weighted path evaluation module assigns key node weights and extracts abnormal state paths based on the key nodes in the abnormal transfer state prediction results, evaluates the weight distribution of key nodes in the paths, screens paths whose weights exceed the risk threshold, and generates dynamic weighted risk parameter paths; The risk propagation visualization module analyzes the interaction frequency of key node paths based on the dynamic weight risk parameter path, analyzes the correlation between paths according to the interaction frequency, constructs the path propagation relationship according to the correlation information and displays the propagation path in a visual manner to generate computer system risk monitoring results.
Citation Information
Patent Citations
After-sales equipment predictive maintenance cooperation system based on digital twinning
CN112418523A
Urban road online microscopic simulation method and system based on digital twinborn technology
CN113704956A
Heat supply system fault analysis method and device based on artificial intelligence
CN117743909A
Method for evaluating toughness of novel power system in extreme weather
CN119250362A
Dynamic defense system and method of new energy centralized control station network based on dynamic IP
US20240414183A1
Cited By
Industrial equipment life cycle management system based on digital twinning
CN120317539A
Machine room management method and management device based on digital twinning
CN120338770A
A computer room management method and management device based on digital twin
CN120338770B
Anti-accident simulation-based scheduling accident plan writing method and system
CN120470328A
Multi-device behavior interoperation verification system and method based on Internet of Things platform
CN120528763A