Computer system risk monitoring method and system based on digital twinning
By constructing a computer system risk monitoring method using digital twin technology, the problems of insufficient real-time and dynamic capabilities in existing technologies are solved, enabling efficient and accurate monitoring and prediction of computer system risks, and optimizing the comprehensiveness and accuracy of risk assessment.
Patent Information
- Application Number
- CN202510134651.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2045-02-07
AI Technical Summary
Existing technologies for risk monitoring in computer systems lack real-time and dynamic processing capabilities, making it difficult to quickly capture the complex changing characteristics of multi-dimensional data. This results in insufficient accuracy in risk prediction and a lack of attention to the interrelationships and propagation mechanisms between key nodes, limiting the comprehensiveness of the overall risk path analysis of the system.
A computer system risk monitoring method based on digital twins is adopted. By collecting real-time operating data, a digital twin model is constructed, data change trends are analyzed, abnormal intervals are screened, abnormal parameters are identified, future state trends are predicted, the path weights of key nodes are evaluated, and risk propagation paths are constructed to achieve dynamic risk monitoring.
It improves the accuracy of data analysis, enhances the ability to predict future trends, optimizes the distribution of risk weights, significantly enhances the ability to track key risk paths, and ensures that risk assessment can dynamically reflect the propagation path and diffusion trend of potential problems.
Smart Images

Figure CN120150984B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a computer system risk monitoring method and system based on digital twinning. BACKGROUND
[0002] The technical field of network security includes related technical content for protecting, monitoring and managing computer networks and systems. The core of this technical field is to protect the confidentiality, integrity and availability of information and systems, which covers but is not limited to network attack detection, intrusion prevention, data encryption, access control and system vulnerability repair, etc.
[0003] Among them, the computer system risk monitoring method refers to the method of identifying, analyzing and monitoring the risks that the computer system may face in the running process. Specifically, the risk sources include abnormal network traffic, malicious attack behavior and system vulnerabilities, etc. A security monitoring mechanism based on specific rule matching is adopted, combined with historical data analysis method, a risk judgment model is constructed, and the potential threats in the system running process are monitored and classified. At the same time, by collecting system running logs and multi-dimensional data, the optimized risk assessment means is used to accurately locate the abnormal behavior, so as to realize the dynamic tracking and real-time monitoring of the risk.
[0004] The prior art has deficiencies in the processing capacity of real-time and dynamics in the data monitoring process. The traditional security monitoring mechanism based on rule matching is easy to be limited to the pre-set rule range, and cannot flexibly adapt to the dynamic changes of the running environment. The identification and analysis method of abnormal data is relatively dependent on the fixed mode, and it is difficult to quickly capture the complex change characteristics of multi-dimensional data, which may cause lag or missed judgment when dealing with malicious behavior or abnormal traffic. The historical data analysis focuses more on static characteristics, and lacks in-depth mining of the dynamic evolution law of data state, which may lead to insufficient accuracy of future risk prediction. In addition, the risk assessment method is mostly based on single weight or static distribution, and pays less attention to the mutual association and propagation mechanism between key nodes, which limits the comprehensiveness of the overall risk path analysis of the system. SUMMARY
[0005] The purpose of the present application is to solve the shortcomings in the prior art, and to provide a computer system risk monitoring method and system based on digital twinning.
[0006] In order to achieve the above purpose, the present application adopts the following technical scheme: a computer system risk monitoring method based on digital twinning, comprising the following steps:
[0007] S1: Collecting real-time running data of the computer system, constructing a digital twinning model according to the running data, calculating the difference value of each type of running data, analyzing the change trend of the running data according to the difference value, and generating a digital twinning state change trend sequence according to the change trend;
[0008] S2: divide the digital twin state change trend sequence into multiple interval segments according to fixed time, screen abnormal interval segments corresponding to running data from each interval segment, count hard disk read-write rate fluctuation amplitude, memory occupancy rate change rate and network traffic abnormal fluctuation parameters of abnormal interval segments, and generate a computer system abnormal parameter set;
[0009] S3: collect state transition records of running data, identify state transition modes corresponding to target abnormal parameters, extract transition nodes and associated running data features of abnormal parameters in records, calculate transition probabilities of target abnormal parameters in the computer system abnormal parameter set, predict future state trends of running data according to transition probabilities, and generate abnormal transition state prediction results;
[0010] S4: evaluate the probability of entering an abnormal state in a corresponding time period according to the abnormal transition state prediction results, distribute weights of corresponding running data according to the probability of abnormal states, extract abnormal state paths corresponding to key nodes, evaluate weight distribution of key nodes in each path, filter and sort key node paths according to weight distribution, and generate dynamic weight risk parameter paths according to the sorting list;
[0011] S5: analyze the interaction frequency of each key node path in the dynamic weight risk parameter path, analyze the relevance between key node paths according to the interaction frequency, construct propagation paths between key node paths with reference to the relevance information, and generate computer system risk monitoring results according to the propagation paths.
[0012] The application improves that the digital twin state change trend sequence is a difference value curve change mode and a timing characteristic of running data fluctuation, the computer system abnormal parameter set includes hard disk read-write rate fluctuation amplitude, memory occupancy rate change rate and network traffic abnormal fluctuation parameters, the abnormal transition state prediction result includes transition nodes, running data features and transition probability prediction results of target abnormal parameters, the dynamic weight risk parameter path includes weight distribution and sorting of key node paths, and the computer system risk monitoring result includes interaction frequency, relevance and propagation path of key node paths.
[0013] The application improves that real-time running data of a computer system is collected, a digital twin model is constructed according to the running data, a difference value of each type of running data is calculated, a change trend of the running data is analyzed with reference to the difference value, and the specific steps of generating a digital twin state change trend sequence according to the change trend are as follows:
[0014] S101: Collect computer system real-time running data, construct a digital twin model according to the real-time running data, classify and group the running data in the digital twin model, record the real-time value of each type of data in time sequence, and form a classified real-time running data table according to the real-time value of each type of data;
[0015] S102: Obtain the data difference value of adjacent time points in the classified real-time running data table, convert the data difference value of adjacent time points into a corresponding change sequence and record the change sequence, and generate a running data difference value set;
[0016] S103: According to the change trend between each type of difference value in the running data difference value set, evaluate the time sequence characteristics of the running data fluctuation based on the change trend, and generate a digital twin state change trend sequence according to the time sequence characteristics of the running data fluctuation.
[0017] The present application improves the digital twin state change trend sequence according to the fixed time division interval, filters the corresponding running data abnormal interval from each interval, and calculates the hard disk read-write rate fluctuation amplitude, memory occupancy rate change rate and network traffic abnormal fluctuation parameters of the abnormal interval, and the specific steps of generating the computer system abnormal parameter set are as follows:
[0018] S201: Based on the digital twin state change trend sequence, filter the interval segment where the CPU utilization rate continuously increases beyond the preset increase range and the thread scheduling frequency exceeds the preset fluctuation threshold, extract the running data in the target interval segment, and generate a target running data interval segment set;
[0019] S202: Based on the target running data interval segment set, calculate the hard disk read-write rate fluctuation amplitude, memory occupancy rate change rate and network traffic abnormal fluctuation, and combine the parameter set of normal running data for difference calculation, and generate a running data statistical difference set;
[0020] S203: Based on the running data statistical difference set, calculate the membership degree of the running data abnormality and normal state, classify the risk conditions of the running data according to the membership degree, extract the abnormal parameters from the divided classified risk conditions, and generate a computer system abnormal parameter set;
[0021] The normal running data is specifically data lower than the preset change range of the difference value of the running data in each period.
[0022] The specific steps of the abnormal transition state prediction result generated by the application are as follows:
[0023] S301: Based on the state transition record of the operation data, all state changes of the target abnormal parameter in the computer system abnormal parameter set are obtained, the transition probability of the target abnormal parameter keeping an abnormal state or changing to a normal state in the future is calculated by referring to all state changes, and a target abnormal parameter transition probability set is generated;
[0024] S302: Based on the target abnormal parameter transition probability set, the future state change trend of the operation data corresponding to the target abnormal parameter is predicted, key nodes in the future state change trend are extracted and marked, and a target abnormal parameter key node set is generated;
[0025] S303: Based on the target abnormal parameter key node set, the key node information and the state transition information of the target parameter are integrated to generate an abnormal transition state prediction result.
[0026] The specific steps of the application are as follows: according to the abnormal transition state prediction result, the probability of entering an abnormal state in the corresponding time period is evaluated, the weight of the corresponding operation data is allocated according to the probability of the abnormal state, the abnormal state path corresponding to the key node is extracted, the weight distribution of the key node in each path is evaluated, the key node path is filtered and sorted according to the weight distribution, and the dynamic weight risk parameter path is generated according to the sorting list:
[0027] S401: Based on the key nodes in the abnormal transition state prediction result, the importance of each key node is referred to, the weight of the target key node is allocated, and the abnormal state path corresponding to the target key node is extracted according to the weight information, and a key node abnormal path set is generated;
[0028] S402: Based on the key node abnormal path set, the weight distribution of the key node in each path is evaluated, the key node path with a weight distribution exceeding a preset risk threshold is filtered, and a key node path weight distribution set is generated;
[0029] S403: Based on the key node path weight distribution set, the key node abnormal state path is sorted, the sorted key nodes are integrated, and a dynamic weight risk parameter path is generated.
[0030] The application improves that the interaction frequency of each key node path in the dynamic weight risk parameter path is analyzed, the correlation between the key node paths is analyzed according to the interaction frequency, the propagation path between the key node paths is constructed by referring to the correlation information, and the specific steps of generating the computer system risk monitoring result according to the propagation path are as follows:
[0031] S501: Based on the dynamic weight risk parameter path, the occurrence frequency of the key node in each path is counted, the interaction of the key node in multiple paths is analyzed according to the occurrence frequency of the key node, and a key node interaction frequency table is generated;
[0032] S502: Based on the key node interaction frequency table, the correlation strength between the paths is analyzed in combination with the interaction data between the key nodes, the path relationship between the corresponding key nodes is extracted according to the correlation strength, and a key node path correlation analysis result is generated;
[0033] S503: Based on the key node path correlation analysis result, the paths with correlation exceeding a preset key node threshold are connected, and the propagation path between the key nodes is constructed, the potential risk transmission chain is identified through the propagation path, and the computer system risk monitoring result is generated according to the potential risk transmission chain.
[0034] The computer system risk monitoring system based on digital twinning includes:
[0035] The running data processing module collects computer system running data, constructs a digital twin model according to the running data, calculates the difference value of each type of running data, analyzes the change trend of the data according to the difference value, and generates a digital twin state change trend sequence;
[0036] The abnormal parameter analysis module divides multiple interval segments according to a fixed time based on the digital twin state change trend sequence, selects an abnormal interval segment of the running data from each interval segment, and generates a computer system abnormal parameter set;
[0037] The state transition prediction module calculates the transition probability of the target abnormal parameter remaining in an abnormal state or turning to a normal state based on the computer system abnormal parameter set and the state transition record of the running data, predicts the future state trend of the target parameter and extracts key nodes, and generates an abnormal transition state prediction result;
[0038] The weight path evaluation module assigns weights to the key nodes and extracts abnormal state paths based on the key nodes in the abnormal transition state prediction result, evaluates the weight distribution of the key nodes in the paths, filters the paths with weights exceeding a risk threshold, and generates a dynamic weight risk parameter path;
[0039] The risk propagation visualization module analyzes the interaction frequency of the key node path based on the dynamic weight risk parameter path, analyzes the correlation between paths according to the interaction frequency, constructs the path propagation relationship according to the correlation information, and displays the propagation path in a visual manner, and generates a computer system risk monitoring result.
[0040] Compared with the prior art, the application has the advantages and positive effects that:
[0041] In the application, by collecting real-time operation data and constructing a digital twin model, the difference value of the operation data is combined with the change trend, and the dynamic monitoring capability of the data is effectively refined. Dividing the trend sequence by a fixed time, screening the abnormal data interval and counting the multi-dimensional parameters, helps to identify the key features of abnormal data from a more fine dimension, and improves the accuracy of data analysis. Based on the state transition record, the correlation features of the abnormal parameters are extracted, and the transition probability is calculated, which can make a higher accuracy prediction on the future trend, and provide a scientific basis for dynamic threat assessment. Through the dynamic weight distribution mechanism, the key node path is generated and sorted, and the distribution structure of the risk weight is reasonably optimized, which significantly enhances the tracking ability of the key risk path. Combined with the interaction frequency between the key node paths and the construction of the propagation path, the correlation and integrity of the risk monitoring result are effectively strengthened, and it is ensured that the risk assessment can dynamically reflect the propagation path and diffusion trend of potential problems. BRIEF DESCRIPTION OF DRAWINGS
[0042] Figure 1 The method flowchart of the application is shown in Figure 1.
[0043] Figure 2 The detailed flowchart of step S1 of the application is shown in Figure 2.
[0044] Figure 3 The detailed flowchart of step S2 of the application is shown in Figure 3.
[0045] Figure 4 The detailed flowchart of step S3 of the application is shown in Figure 4.
[0046] Figure 5 The detailed flowchart of step S4 of the application is shown in Figure 5.
[0047] Figure 6 The detailed flowchart of step S5 of the application is shown in Figure 6.
[0048] Figure 7 The system module diagram of the application is shown in Figure 7. DETAILED DESCRIPTION
[0049] In order to make the objects, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and not to limit the present application.
[0050] In the description of the present application, it should be understood that the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation of the present application. In addition, in the description of the present application, the meaning of "a plurality of" is two or more, unless otherwise explicitly and specifically limited.
[0051] Please refer to Figure 1 The present application provides a technical solution: a computer system risk monitoring method based on digital twinning, comprising the following steps:
[0052] S1: collecting real-time running data of the computer system, constructing a digital twinning model according to the running data, calculating the difference value of each type of running data, analyzing the change trend of the running data with reference to the difference value, and generating a digital twinning state change trend sequence according to the change trend;
[0053] S2: dividing the digital twinning state change trend sequence into multiple interval segments according to a fixed time, selecting an abnormal interval segment corresponding to the running data from each interval segment, and calculating the hard disk read-write rate fluctuation amplitude, memory occupancy rate change rate and network traffic abnormal fluctuation parameters of the abnormal interval segment to generate a computer system abnormal parameter set;
[0054] S3: collecting state transition records of the running data, identifying a state transition mode corresponding to a target abnormal parameter, extracting a transition node of the abnormal parameter in the record and associated running data features, calculating a transition probability of the target abnormal parameter in the computer system abnormal parameter set, predicting a future state trend of the running data according to the transition probability, and generating an abnormal transition state prediction result;
[0055] S4: evaluating the probability of entering an abnormal state in the corresponding time period according to the abnormal transition state prediction result, assigning a weight to the corresponding running data according to the probability of the abnormal state, extracting an abnormal state path corresponding to a key node, evaluating the weight distribution of the key node in each path, screening the key node path according to the weight distribution and sorting, and generating a dynamic weight risk parameter path according to the sorting list;
[0056] S5: analyze the interaction frequency of each key node path in the dynamic weight risk parameter path, analyze the correlation between the key node paths according to the interaction frequency, construct the propagation path between the key node paths according to the correlation information, and generate the computer system risk monitoring result according to the propagation path;
[0057] The digital twin state change trend sequence is a difference value curve change pattern and a timing characteristic of an operation data fluctuation. The computer system abnormal parameter set includes a hard disk read-write rate fluctuation amplitude, a memory occupancy rate change rate, and a network traffic abnormal fluctuation parameter. The abnormal transition state prediction result includes a target abnormal parameter transition node, an operation data feature, and a transition probability prediction result. The dynamic weight risk parameter path includes a key node path weight distribution and a key node path sorting. The computer system risk monitoring result includes a key node path interaction frequency, a key node path correlation, and a key node path propagation path.
[0058] Please refer to Figure 2 , collect computer system real-time operation data, construct a digital twin model according to the operation data, calculate the difference value of each type of operation data, analyze the change trend of the operation data according to the difference value, and generate the specific steps of the digital twin state change trend sequence as follows:
[0059] S101: Collect computer system real-time operation data, construct a digital twin model according to the real-time operation data, classify and group the operation data in the digital twin model, record the real-time value of each type of data in time sequence, and form a classified real-time operation data table according to the real-time value of each type of data;
[0060] Collect computer system real-time operation data, parameters including but not limited to CPU utilization rate (such as 5% to 90% range fluctuation), memory usage rate (such as 20% to 95% range fluctuation), network bandwidth usage rate (such as 0.5Gbps to 10Gbps range) and other key indicators, use a data filter to remove abnormal values exceeding the set range in a short time, for example, remove data points with CPU utilization rate below 1% or above 99%, use timestamps to serialize each parameter, use a hierarchical grouping mechanism to classify data, for example, group CPU and memory parameters into a resource utilization group, and group network parameters into a transmission state group, realize real-time storage and dynamic update of classified data through a database, ensure that the latest state of each type of data can timely reflect the operation state of the system, and finally generate a classified real-time operation data table based on time sequence.
[0061] S102: Obtain the data difference value of adjacent time points in the classified real-time operation data table, convert the data difference value of adjacent time points into a corresponding change sequence and record the change sequence, and generate a running data difference value set;
[0062] The data difference value of adjacent time points in the classification real-time running data table is obtained, the interval between adjacent time points is set to 1 minute, and the time difference value sequence is calculated. The absolute difference value and the relative difference value are extracted from the data of adjacent time points. For example, if the CPU utilization rate increases from 50% to 60% in one minute, the absolute difference value is 10%, and the relative difference value is 20%. These difference values are arranged according to the time points to form a change sequence. The change sequence is classified into a high-frequency fluctuation area (such as a fluctuation amplitude greater than 15%) and a low-frequency fluctuation area (such as a fluctuation amplitude less than 5%). The fluctuation points with significant characteristics are screened out using the classification rule, and the results are recorded in the running data difference value set. The data difference value set is used to evaluate the dynamic performance change of the system.
[0063] S103: According to the change trend between each type of difference value in the running data difference value set, the time sequence characteristics of the running data fluctuation are evaluated based on the change trend, and the digital twin state change trend sequence is generated according to the time sequence characteristics of the running data fluctuation.
[0064] According to the change trend between each type of difference value in the running data difference value set, the time sequence characteristics of the data fluctuation are segmented and evaluated. The data in the difference value set is processed in segments using a sliding window method. The size of the sliding window is set to 10 minutes. The change rate and fluctuation amplitude in each window are analyzed. For example, if the average change rate of the difference value in a certain window is greater than 10% / minute or the fluctuation amplitude exceeds 50%, the window is marked as a high-risk window. An autoregressive integrated moving average model (ARIMA) is used to fit the trend of each segment of data, generate a trend change curve, and perform anomaly point analysis on the high-risk window based on the fitting result. The anomaly points are screened out by setting a threshold (such as a fluctuation amplitude exceeding twice the historical average value). Finally, the digital twin state change trend sequence is output. The trend sequence is used to identify high-risk periods and potential fault areas.
[0065] Please refer to Figure 3 The digital twin state change trend sequence is divided into multiple interval segments according to a fixed time. The abnormal interval segments corresponding to the running data are screened out from each interval segment. The hard disk read / write rate fluctuation amplitude, memory occupancy rate change rate, and network traffic abnormal fluctuation parameters of the abnormal interval segments are calculated. The specific steps for generating the computer system abnormal parameter set are as follows:
[0066] S201: Based on the digital twin state change trend sequence, the interval segment in which the CPU utilization rate continuously increases beyond a preset increase range and the thread scheduling frequency exceeds a preset fluctuation threshold is screened out. The running data in the target interval segment is extracted, and a target running data interval segment set is generated.
[0067] The interval section with continuously increasing CPU utilization rate exceeding the preset increasing range is screened, the CPU load condition is monitored in real time by using the scheduling management module, and the increasing data is recorded as a time sequence, the preset increasing range is set as 5% to 50%, the fluctuation data of thread scheduling frequency is recorded in the screening process, and the abnormal fluctuation section is extracted according to the upper and lower limits (such as 0.1 Hz to 1 Hz) of the fluctuation threshold, the time interval meeting the condition is marked as a target interval section, the running data including the CPU utilization rate, thread scheduling frequency, hard disk read-write rate and the like in the target interval section is extracted, and finally the target running data interval section set is generated.
[0068] S202: Based on the target running data interval section set, the abnormal fluctuation conditions of the hard disk read-write rate fluctuation amplitude, the memory occupancy rate change rate and the network traffic are counted, and the difference calculation is performed in combination with the parameter set of the normal running data to generate a running data statistical difference set;
[0069] Based on the target running data interval section set, the running data is analyzed for fluctuation, the fluctuation amplitude of the hard disk read-write rate is counted first, the fluctuation value is obtained by calculating the maximum and minimum rate difference within each minute, the hard disk read-write rate fluctuation range is set as 1 MB / s to 100 MB / s, and the abnormal section exceeding the threshold is extracted; secondly, the change rate of the memory occupancy rate is counted, the rate value is obtained by comparing the memory occupancy values at continuous time points, and the part with a change rate exceeding 10% to 30% per second is classified as abnormal; finally, the abnormal fluctuation condition of the network traffic is counted, the network traffic data is classified according to the traffic change frequency, the frequency range is set as 1 Hz to 10 Hz, the frequency change abnormal section is extracted, and the above statistical data is compared with the parameter set of the normal running data to generate a running data statistical difference set through difference calculation.
[0070] S203: Based on the running data statistical difference set, the membership degree of the running data abnormality and the normal state is calculated, the risk condition of the running data is classified according to the membership degree, the abnormal parameters are extracted from the classified risk conditions, and a computer system abnormal parameter set is generated;
[0071] The normal running data is specifically data lower than the preset change range of the difference value of the running data in each period.
[0072] Based on the running data statistical difference set, the membership degree of the running data abnormality and the normal state is calculated, according to the formula:
[0073]
[0074] The membership degree value μ of the running data in the normal state is calculated A (x);
[0075] Wherein, μ A(x) represents the membership value of the running data in the normal state, which is used to measure the degree of belonging of the current difference value to the normal state, and is directly obtained by calculation formula, the result value is between 0 and 1, the closer to 1 indicates the lower the degree of data deviating from the normal state, x represents the difference value of the current statistical data, which is derived from the single point data in the running data statistical difference set and directly obtained by the real-time system monitoring module, for example, extracted from the difference between CPU utilization and normal benchmark value, a is the mean value of normal running data, which is obtained by statistical history value of normal running data in time series, the history value can be extracted by log system, and the mean value calculation formula is: In the formula, x i′ is the i'th data point in the normal running data, n is the total number of data points, b is the standard deviation of normal running data, which is used to represent the volatility of normal running data, and is obtained by formula: c is a dynamic adjustment factor, which is used to adjust the sensitivity of membership calculation according to the volatility characteristics of real-time system, and is obtained by formula σ x is the real-time standard deviation of difference data, which is obtained by monitoring the volatility of real-time difference data in a certain time window.
[0076] For example, the normal mean value a of running data is 50, the standard deviation b is 10, the real-time standard deviation σ x of difference data is 5, and the current difference value x is 70.
[0077] Dynamic adjustment factor:
[0078] Membership value calculation:
[0079] The results show that the membership value is 0.36.
[0080] The membership value is calculated as 0.36, according to the risk condition classification standard, the risk classification is set as follows:
[0081] Low risk: membership value above 0.8, indicating that the data deviates from the normal state is small, can be considered normal operation state. Medium risk: membership value between 0.5 and 0.8, indicating that the data appears to some extent, need to pay attention to the running state. High risk: membership value is less than 0.5, indicating that the data deviates significantly from the normal state, should be checked immediately and take measures. The membership value is 0.36, which belongs to the high risk interval, so it is determined that the current system state has obvious abnormalities. Further analysis of the abnormal state, extract abnormal parameters from the running data statistical difference set. For example: CPU utilization: difference value exceeds the mean value range of normal operation, for example, continuously exceeds 85% in the past one minute. Memory usage: change rate exceeds the set threshold, such as growth rate per second exceeds 20%. Network traffic: fluctuation amplitude far exceeds the preset range, for example, the difference between the maximum and minimum values within one minute exceeds 10Gbps. The above extracted abnormal parameters are summarized to form a computer system abnormal parameter set, for example: abnormal parameter set: CPU utilization: 90%, memory usage rate of change: 25% / s, network traffic fluctuation amplitude: 12Gbps, by extracting these abnormal parameters, which can be used for further analysis of the source of the anomaly, such as resource contention of a specific thread, memory surge caused by high load application, or traffic anomaly caused by network device failure, thereby providing guidance basis for system optimization and troubleshooting.
[0082] Please refer to Figure 4 , collect the state transition records of the running data, identify the state transition mode corresponding to the target abnormal parameter, extract the transition node and associated running data characteristics of the abnormal parameter in the record, calculate the transition probability of the target abnormal parameter in the computer system abnormal parameter set, and predict the future state trend of the running data according to the transition probability, the specific steps of generating the abnormal transition state prediction result are as follows:
[0083] S301: Based on the state transition records of the running data, obtain all state changes of the target abnormal parameter in the computer system abnormal parameter set, refer to all state changes to calculate the transition probability of the target abnormal parameter to remain in an abnormal state or to a normal state, and generate a target abnormal parameter transition probability set;
[0084] Referring to all state changes of the target abnormal parameter, according to the formula:
[0085]
[0086] Calculate the weighted state transition probability P ij of the target abnormal parameter;
[0087] Where P ijis the weighted state transition probability of the target abnormal parameter, used to represent the possibility of the target parameter transitioning from the current state i to the target state j, calculated by combining the state transition count and the weight factor, reflecting the importance and priority relationship of state transition, N ij is the number of times of transitioning from state i to state j, obtained by statistical analysis of the state transition records of the target abnormal parameter, such as analyzing the transition events recorded in the running log or state change sequence, the method is to directly count the frequency from historical data, w ij is the weight factor of state transition, used to represent the importance of different transition paths, set by expert experience analysis, experimental simulation or based on business rules, such as assigning weight factors according to the time cost of transition occurrence or the degree of influence on the system, for example, if a certain state transition occurs frequently, it indicates that it occupies an important position in the system, and should be given a larger weight (for example, 0-1), if a certain state transition occurs rarely, it usually has less impact on the long-term behavior of the system, then its weight should be lower (for example, 1-2), where frequent is 30 times, and rarely is 10 times, ∑ k (N ik ·w ik ) is the weighted total number of times of state i transitioning to all states, representing the total influence of all transition events starting from state i, obtained by summing the product of the count and weight factor of all possible transition paths, as the denominator to ensure the normalization of probability value, i and j represent the starting state and target state of the target abnormal parameter respectively, such as abnormal state and normal state, k represents any state in the state set, used as a traversal counter in the summation symbol, representing the statistical range from state i to all possible target states, · represents the multiplication operator, indicating the product of state count and weight factor, ∑ represents the summation symbol, covering the calculation range of state i transitioning to all possible states, such as transitioning from state A to all target states.
[0088] For example, the states of the target abnormal parameter are divided into two types: abnormal state A and normal state N, the following transition times and weight factors are obtained from data statistics:
[0089] N AA = 30, w AA = 1.2: the number of times of abnormal state remaining abnormal state is 30, and the weight factor is 1.2.
[0090] N AN = 10, w AN = 0.8: the number of times of abnormal state transitioning to normal state is 10, and the weight factor is 0.8.
[0091] Total weighted transition times: ∑ k (N Ak ·w Ak) = (30 * 1.2) + (10 * 0.8) = 44.
[0092] Transition probability calculation:
[0093] Weighted probability of abnormal state remaining in abnormal state:
[0094]
[0095] Weighted probability of abnormal state transitioning to normal state:
[0096]
[0097] The results show that the weighted probability of the target abnormal parameter remaining in an abnormal state in the future is 0.818, and the weighted probability of transitioning to a normal state is 0.182.
[0098] S302: Based on the target abnormal parameter transition probability set, predict the future state change trend of the target abnormal parameter corresponding running data, extract and mark the key nodes in the future state change trend, and generate a target abnormal parameter key node set;
[0099] According to the transition probability calculation result, the weighted probability of the target abnormal parameter remaining in an abnormal state in the future is 0.818, and the weighted probability of transitioning to a normal state is 0.182, and the future state change trend is expressed as: the current state is abnormal, and the probability of continuing to remain in an abnormal state in the next time step is 0.818, and the probability of transitioning to a normal state is 0.182. After multiple iterations, the state will tend to be stable, forming a stable state distribution, and the state proportion in the future multiple time steps is determined according to the state distribution. Extract and mark the key nodes in the future state change trend, the abnormal state dominant node: when the abnormal state proportion of the future multiple time steps is always higher than a certain threshold (such as 70%), it is marked as a key node. State mutation node: when the state transition probability changes significantly (such as the probability of abnormal state transitioning to normal state increasing to more than 50%), it is marked as a mutation node. Stable node: when the state change trend tends to be stable, i.e. the state proportion fluctuation amplitude is lower than a set value (such as 5%), it is marked as a stable node. Extract the key nodes: abnormal state dominant node: in the future 3rd time step, the abnormal state proportion is 85%, which is significantly higher than the set threshold, and is marked as an abnormal dominant node. State mutation node: in the future 5th time step, the transition probability increases to 60% from abnormal state to normal state, and is marked as a mutation node. Stable node: after the future 10th time step, the state distribution remains stable, and the abnormal state and normal state are 40% and 60% respectively, and are marked as stable nodes. By generating the target abnormal parameter key node set, the future state change trend of the target abnormal parameter can be intuitively reflected, providing a decision basis for system risk monitoring and optimization.
[0100] S303: Based on the target abnormal parameter key node set, integrate the key node information and the state transition information of the target parameter to generate an abnormal transition state prediction result;
[0101] In combination with the abnormal dominant nodes, state mutation nodes and stable nodes in the key node set, the key time points of future state changes are determined, for example, the abnormal state is dominant at the 3rd time step, the state mutation occurs at the 5th time step, and the stable state is reached at the 10th time step. The dynamic changes of transition probabilities are superimposed on the time series to determine the transition direction and probability distribution of each time step state, for example, at the 3rd time step, the transition probability of the abnormal state is 0.818, and the transition probability of the normal state is 0.182. After the state mutation at the 5th time step, the transition probability of the abnormal state decreases to 0.4, and the transition probability of the normal state increases to 0.6. In combination with the key nodes and state transition information, the state distribution of each time step is gradually predicted, and the duration and trend of the abnormal state are recorded, for example, the abnormal state lasts from the current time step to the 4th time step, the normal state starts to transition at the 5th time step, and the normal state is stable at the 10th time step. Time steps 1 to 3 are dominated by abnormal states, and the transition probability remains at 0.818. The state distribution is dominated by abnormal states. Time steps 4 to 5 are state mutations, the transition probability of the abnormal state gradually decreases to 0.4, the transition probability of the normal state increases to 0.6, and the state changes significantly. Time steps 6 to 10 are state stabilization, the abnormal state proportion decreases to 40%, and the normal state proportion increases to 60%. The prediction result shows that the target abnormal parameter may continue to remain in the abnormal state in the near future, but will gradually recover to the normal state after the 5th time step. The integration of key nodes provides a clear time marker for state changes and provides a clear reference for system operation decisions, for example, implementing abnormal repair measures before the state mutation node and optimizing resource allocation after the stable node, thereby improving system operation efficiency and stability.
[0102] Please refer to Figure 5 According to the abnormal transition state prediction result, the probability of entering the abnormal state in the corresponding time period is evaluated, the weight of the corresponding running data is allocated according to the probability of the abnormal state, the abnormal state path corresponding to the key node is extracted, the weight distribution of the key node in each path is evaluated, the key node path is selected and sorted according to the weight distribution, and the specific steps of generating a dynamic weight risk parameter path according to the sorting list are as follows:
[0103] S401: Based on the key nodes in the abnormal transition state prediction result, refer to the importance of each key node, assign weights to the target key node, and extract the abnormal state path corresponding to the target key node according to the weight information to generate a key node abnormal path set;
[0104] Based on the key nodes in the abnormal state transition prediction result, weights are assigned to the target key nodes. The assignment process is based on historical transition records and the importance of key nodes. The importance is evaluated based on three core parameters, including the abnormal occurrence frequency of key nodes, the duration of transition state, and the impact of transition on system operation. The abnormal occurrence frequency is obtained by counting the number of triggers of key nodes in the past month. The evaluation range is set to 10 to 100 times. The higher the frequency, the greater the weight of the node. The duration of the transition state is obtained by calculating the time span of a single abnormal event. Nodes with a duration of more than 5 minutes are given a higher weight. The impact on the system is evaluated based on the resource consumption associated with the key nodes, including CPU utilization and memory occupancy. Nodes exceeding the set threshold are marked as high priority. Through the normalization processing of the above parameters, the weight of each key node is adjusted to the range of 0 to 1. Finally, the abnormal state path corresponding to the target key node is extracted. The path is organized according to the time sequence, and a set of key node abnormal path is generated.
[0105] S402: Based on the key node abnormal path set, evaluate the weight distribution of key nodes in each path, filter the key node path whose weight distribution exceeds the preset risk threshold, and generate a key node path weight distribution set;
[0106] Based on the key node abnormal path set, evaluate the weight distribution of key nodes in each path. The evaluation of weight distribution is based on the time sequence of node weights in the path. By extracting the weight value of key nodes and constructing the weight distribution curve, the risk concentration of the path is analyzed. The weight value of key nodes in the weight distribution curve needs to exceed the preset risk threshold. The threshold is obtained by statistical analysis of historical data. For example, if the threshold is set to the average weight plus one standard deviation, when the weight of a key node exceeds this threshold, it is marked as a high-risk node. By filtering the paths where the proportion of high-risk nodes exceeds 50%, the paths that meet the conditions are recorded as the key node path weight distribution set. At the same time, paths with scattered weight distribution or insufficient proportion of high-risk nodes are excluded. After the path filtering is completed, the priority label of the path set is regenerated.
[0107] S403: Based on the key node path weight distribution set, sort the key node abnormal state path, integrate the sorted key nodes, and generate a dynamic weight risk parameter path;
[0108] The paths are prioritized based on the set of key node path weight distributions, the prioritization is based on the total weight value of the key nodes and the time concentration, the total weight value is obtained by calculating the cumulative value of the weights of all key nodes in the path, and the total value range is set to 1 to 10, the higher the total weight value, the higher the path priority, and the time concentration is evaluated by the standard deviation of the time sequence distribution of the key nodes in the path, and the time concentration range is set to 0 to 5, the lower the standard deviation, the more concentrated the key node distribution, and the higher the priority, after prioritizing the paths, the highest priority path is extracted and the corresponding key nodes are integrated to generate a dynamic weight risk parameter path, the weight value and key node mark in the dynamic path are used to guide the priority allocation of system resources, for example, resource allocation adjustment or abnormal repair is performed on the high weight nodes associated with the abnormal path.
[0109] Referring to Figure 6 , the interaction frequency of each key node path in the dynamic weight risk parameter path is analyzed, the relevance between the key node paths is analyzed according to the interaction frequency, the propagation path between the key node paths is constructed according to the relevance information, and the specific steps of generating the computer system risk monitoring result according to the propagation path are as follows:
[0110] S501: Based on the dynamic weight risk parameter path, the number of occurrences of each key node in each path is counted, the interaction of the key nodes in multiple paths is analyzed according to the number of occurrences of the key nodes, and a key node interaction frequency table is generated;
[0111] Based on the dynamic weight risk parameter path, the number of occurrences of each key node in each path is counted, each key node in the path is recorded as an occurrence time by scanning each path one by one, the statistical result is generated by accumulating the number of occurrences of each node in all paths, the number of occurrences of the key nodes is set to 1 to 20 times, and the nodes with more than 15 occurrences are marked as high-frequency key nodes, and the low-frequency nodes are classified, the distribution mode of the nodes in the path is analyzed in combination with the time sequence during the statistical process, for example, when the number of occurrences in a continuous time period accounts for more than 50% of the total nodes in the path, it is marked as a time aggregation path, and finally a key node interaction frequency table is generated.
[0112] S502: Based on the key node interaction frequency table, the association strength between the paths is analyzed in combination with the interaction data between the key nodes, the path relationship associated between the corresponding key nodes is extracted according to the association strength, and a key node path relevance analysis result is generated;
[0113] Based on the key node interaction frequency table, the association strength between paths is analyzed by combining the interaction data between nodes. The analysis process first extracts the key node pairs in all paths and counts the number of common occurrences of each node pair in the path. The association strength is calculated by the ratio of the occurrence of the node pair in all paths. The node pairs with an association strength exceeding 60% are marked as high-association nodes. At the same time, the interaction frequency of the nodes is further analyzed for distribution. If the time distribution of the node pairs exceeds 70%, it is determined that the path pair has high time correlation. The high-association and high-time-correlation path pairs are screened out. Combined with the weight distribution of the nodes in the path pair, the path pairs with a node association strength lower than 30% or a scattered distribution are removed. The key node path association analysis result is generated.
[0114] S503: Based on the key node path association analysis result, the paths with an association exceeding a preset key node threshold are connected, and the propagation path between the key nodes is constructed. The potential risk transmission chain is identified through the propagation path, and the computer system risk monitoring result is generated according to the potential risk transmission chain;
[0115] Based on the key node path association analysis result, the paths with an association exceeding a preset key node threshold are connected. The paths are sorted according to the continuity of the key node time distribution and the path association strength during the connection. First, the path pairs with an association strength exceeding 70% are selected. During the connection process, the continuity of the time period is ensured. For example, when the end time of path A and the start time of path B differ by no more than 5 minutes, path A and path B are preferentially connected to form a new continuous path. Then, the propagation range of the key nodes in the new path is expanded and calculated. For example, when the propagation range of the key nodes is expanded to 1.5 times the original range after the path connection, the path is marked as a propagation effective path. Finally, the propagation path between the key nodes is constructed, and the propagation path graph is displayed in a visual manner. Each path in the graph is distinguished by color and thickness to represent the propagation range and node interaction frequency. The computer system risk monitoring result is generated according to the propagation path graph.
[0116] Please refer to Figure 7 , a computer system risk monitoring system based on digital twinning, the system comprising:
[0117] The operation data processing module collects computer system operation data, constructs a digital twinning model based on the operation data, calculates the difference value of each type of operation data, analyzes the change trend of the data based on the difference value, and generates a digital twinning state change trend sequence;
[0118] The abnormal parameter analysis module divides multiple interval segments according to a fixed time based on the digital twinning state change trend sequence, selects an abnormal interval segment of the operation data from each interval segment, and generates a computer system abnormal parameter set;
[0119] The state transition prediction module calculates the transition probability of the target abnormal parameter to remain in an abnormal state or to turn into a normal state based on the state transition record of the computer system abnormal parameter set and the running data, predicts the future state trend of the target parameter, extracts key nodes, and generates an abnormal transition state prediction result;
[0120] The weight path evaluation module assigns a key node weight based on the key nodes in the abnormal transition state prediction result and extracts an abnormal state path, evaluates the weight distribution of the key nodes in the path, screens the path with a weight exceeding a risk threshold, and generates a dynamic weight risk parameter path.
[0121] The risk propagation visualization module analyzes the interaction frequency of the key node path based on the dynamic weight risk parameter path, analyzes the relevance between the paths according to the interaction frequency, constructs a path propagation relationship according to the relevant information, and displays the propagation path in a visual manner, and generates a computer system risk monitoring result.
[0122] The above is only a preferred embodiment of the present application, and does not limit the present application in other forms. Any person skilled in the art can use the disclosed technical content to make changes or modifications to equivalent embodiments applied to other fields, but any simple modification, equivalent change and modification made to the above embodiments without departing from the technical solution content of the present application, according to the technical essence of the present application, still belongs to the protection scope of the technical solution of the present application.
Claims
1. A computer system risk monitoring method based on digital twinning, characterized in that, The method comprises the following steps: S1: collecting computer system real-time running data, constructing a digital twin model according to the running data, calculating the difference value of each type of running data, analyzing the change trend of the running data by referring to the difference value, and generating a digital twin state change trend sequence according to the change trend; S2: dividing the digital twin state change trend sequence into multiple interval segments according to a fixed time, screening abnormal interval segments corresponding to the running data from each interval segment, counting the hard disk read-write rate fluctuation amplitude, memory occupancy rate change rate and network traffic abnormal fluctuation parameters of the abnormal interval segments, and generating a computer system abnormal parameter set; S3: collecting running data state transition records, identifying the transition mode corresponding to the target abnormal parameter, extracting the transition node and associated features, calculating the transition probability of the target abnormal parameter in the computer system abnormal parameter set, predicting the future state trend, and generating an abnormal transition state prediction result; S4: evaluating the probability of entering an abnormal state in the corresponding time period according to the abnormal transition state prediction result, assigning weights to the corresponding running data according to the probability of the abnormal state, extracting key node paths, evaluating weight distribution, screening and sorting paths, and generating a dynamic weight risk parameter path; S5: analyzing the interaction frequency of each key node path in the dynamic weight risk parameter path, analyzing the relevance between the key node paths according to the interaction frequency, constructing a propagation path between the key node paths according to the relevance information, and generating a computer system risk monitoring result according to the propagation path.
2. The digital-twin-based computer system risk monitoring method of claim 1, wherein: The digital twin state change trend sequence is the difference value curve change mode and the time sequence characteristics of the running data fluctuation, the computer system abnormal parameter set includes the hard disk read-write rate fluctuation amplitude, the memory occupancy rate change rate, and the network traffic abnormal fluctuation parameters, the abnormal transition state prediction result includes the transition node of the target abnormal parameter, the running data features, and the transition probability prediction result, the dynamic weight risk parameter path includes the weight distribution of the key node path and the key node path sorting, and the computer system risk monitoring result includes the interaction frequency of the key node path, the relevance of the key node path, and the propagation path of the key node path.
3. The digital-twin-based computer system risk monitoring method of claim 1, wherein: The specific steps of collecting computer system real-time running data, constructing a digital twin model according to the running data, calculating the difference value of each type of running data, referring to the difference value to analyze the change trend of the running data, and generating a digital twin state change trend sequence are as follows: S101: collecting computer system real-time running data, constructing a digital twin model according to the real-time running data, classifying and grouping the running data in the digital twin model, recording the real-time value of each type of data in time sequence, and forming a classified real-time running data table by referring to the real-time value of each type of data; S102: obtaining the data difference value of adjacent time points in the classified real-time running data table, converting the data difference value of adjacent time points into a corresponding change sequence and recording the change sequence, and generating a running data difference value set; S103: According to the change trend between each type of difference value in the set of operation data difference values, the timing characteristics of the operation data fluctuation are evaluated based on the change trend, and the timing characteristics of the operation data fluctuation are referred to, and a digital twin state change trend sequence is generated.
4. The digital-twin-based computer system risk monitoring method of claim 1, wherein: The digital twin state change trend sequence is divided into multiple interval segments according to a fixed time, and abnormal interval segments corresponding to the operation data are screened from each interval segment, and the hard disk read-write rate fluctuation amplitude, memory occupancy rate change rate and network traffic abnormal fluctuation parameters of the abnormal interval segments are counted, and the specific steps of generating the computer system abnormal parameter set are as follows: S201: Based on the digital twin state change trend sequence, interval segments in which the CPU utilization rate continuously increases beyond a preset increase range and the thread scheduling frequency exceeds a preset fluctuation threshold are screened, operation data in the target interval segment is extracted, and a target operation data interval segment set is generated; S202: Based on the target operation data interval segment set, the hard disk read-write rate fluctuation amplitude, memory occupancy rate change rate and network traffic abnormal fluctuation are counted, and difference calculation is performed in combination with the parameter set of normal operation data, and a running data statistical difference set is generated; S203: Based on the running data statistical difference set, the membership degree of the running data abnormality and normal state is calculated, the risk condition of the running data is classified according to the membership degree, the abnormal parameters are extracted from the classified risk conditions, and a computer system abnormal parameter set is generated; The normal operation data is specifically data lower than the preset change range of the difference value of the operation data in each period.
5. The digital-twin-based computer system risk monitoring method of claim 4, wherein: For the membership degree of the running data abnormality and normal state, the formula is: The membership value μ of the calculation running data in the normal state A (x); Wherein, x represents the difference value of the current statistical data, a is the mean value of the normal operation data, b is the standard deviation of the normal operation data, and c is a dynamic adjustment factor.
6. The digital-twin-based computer system risk monitoring method of claim 1, wherein: Collect the state transition records of the running data, identify the state transition mode corresponding to the target abnormal parameter, extract the transfer nodes and associated running data characteristics of the abnormal parameters in the records, calculate the transfer probability of the target abnormal parameter in the computer system abnormal parameter set, predict the future state trend of the running data according to the transfer probability, and the specific steps of generating the abnormal transfer state prediction result are as follows: S301: Based on the state transition records of the running data, all state changes of the target abnormal parameter in the computer system abnormal parameter set are obtained, the transfer probability of the target abnormal parameter to remain abnormal state or to normal state in the future is calculated by referring to all state changes, and a target abnormal parameter transfer probability set is generated; S302: Based on the target abnormal parameter transfer probability set, the future state change trend of the running data corresponding to the target abnormal parameter is predicted, key nodes in the future state change trend are extracted and labeled, and a target abnormal parameter key node set is generated; S303: Based on the target abnormal parameter key node set, the key node information and the state transition information of the target parameter are integrated, and an abnormal transfer state prediction result is generated.
7. The digital-twin-based computer system risk monitoring method of claim 6, wherein: For the transfer probability of the target abnormal parameter to remain abnormal state or to normal state in the future, the formula is: calculating a weighted state transition probability P of the target anomaly parameter ij ; where N ij is the number of transitions from state i to state j, w ij is a weight factor for the state transition, ∑ k (N ik ·w ik ) is the weighted total number of transitions from state i to all states, i and j represent the starting state and target state of the target abnormal parameter, respectively, and k represents any state in the state set.
8. The digital-twin-based computer system risk monitoring method of claim 1, wherein: According to the abnormal state transition prediction result, the probability of entering the abnormal state in the corresponding time period is evaluated, the weight of the corresponding operation data is allocated according to the probability of the abnormal state, the abnormal state path corresponding to the key node is extracted, the weight distribution of the key node in each path is evaluated, the key node path is screened and sorted according to the weight distribution, and the specific steps of generating the dynamic weight risk parameter path according to the sorting list are as follows: S401: Based on the key nodes in the abnormal state transition prediction result, the importance of each key node is referred to, the weight of the target key node is allocated, and the abnormal state path corresponding to the target key node is extracted according to the weight information, and a key node abnormal path set is generated; S402: Based on the key node abnormal path set, the weight distribution of the key node in each path is evaluated, the key node path with a weight distribution exceeding a preset risk threshold is screened, and a key node path weight distribution set is generated; S403: Based on the key node path weight distribution set, the key node abnormal state path is sorted, the sorted key nodes are integrated, and a dynamic weight risk parameter path is generated.
9. The digital-twin-based computer system risk monitoring method of claim 1, wherein: The interaction frequency of each key node path in the dynamic weight risk parameter path is analyzed, the relevance between the key node paths is analyzed according to the interaction frequency, the propagation path between the key node paths is constructed according to the relevance information, and the specific steps of generating the computer system risk monitoring result according to the propagation path are as follows: S501: Based on the dynamic weight risk parameter path, the number of occurrences of the key node in each path is counted, the interaction of the key node in multiple paths is analyzed according to the number of occurrences of the key node, and a key node interaction frequency table is generated; S502: Based on the key node interaction frequency table, the association strength between the paths is analyzed in combination with the interaction data between the key nodes, the path relationship associated between the corresponding key nodes is extracted according to the association strength, and a key node path relevance analysis result is generated; S503: Based on the key node path relevance analysis result, the paths with relevance exceeding a preset key node threshold are connected, and the propagation path between the key nodes is constructed, the potential risk transmission chain is identified through the propagation path, and the computer system risk monitoring result is generated according to the potential risk transmission chain.
10. A computer system risk monitoring system based on digital twinning, characterized in that, The computer system risk monitoring method based on digital twinning according to any one of claims 1-9 is executed, and the system comprises: The operation data processing module collects computer system operation data, constructs a digital twin model according to the operation data, calculates the difference value of each type of operation data, analyzes the change trend of the data according to the difference value, and generates a digital twin state change trend sequence; The abnormal parameter analysis module divides multiple interval segments according to a fixed time based on the digital twin state change trend sequence, selects an abnormal interval segment of operation data from each interval segment, and generates a computer system abnormal parameter set; The state transition prediction module calculates a transition probability of the target abnormal parameter remaining in an abnormal state or transitioning to a normal state based on the state transition record of the computer system abnormal parameter set and the running data, predicts a future state trend of the target parameter, extracts a key node, and generates an abnormal transition state prediction result; The weight path evaluation module assigns a key node weight based on the key node in the abnormal transition state prediction result and extracts an abnormal state path, evaluates the weight distribution of the key node in the path, filters a path with a weight exceeding a risk threshold, and generates a dynamic weight risk parameter path; The risk propagation visualization module analyzes the interaction frequency of the key node path based on the dynamic weight risk parameter path, analyzes the relevance between the paths according to the interaction frequency, constructs a path propagation relationship according to the relevant information, and displays the propagation path in a visual manner, and generates a computer system risk monitoring result.
Citation Information
Patent Citations
After-sales equipment predictive maintenance cooperation system based on digital twinning
CN112418523A
Urban road online microscopic simulation method and system based on digital twinborn technology
CN113704956A