Abnormality detection method and device, storage medium and computer equipment
By analyzing the executable file identification information of the dump file and automatically analyzing it using the exception information database, the problem of low efficiency in dump file analysis in the existing technology is solved, and the application crash problem is quickly identified and solved.
Patent Information
- Application Number
- CN202311776193.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-06-24
AI Technical Summary
In the prior art, developers need to analyze the dump files generated when software crashes one by one, which is inefficient and is not conducive to timely solving the crash problem.
By analyzing the executable file identification information of the dump file, determining the executable file and the corresponding symbol files, using these files to automatically analyze the dump file, and summarizing the program exception information of different dump files through the exception information database, and performing automatic comprehensive analysis.
Improves the efficiency of dump file analysis, reduces the workload of developers, and can identify and resolve application crash problems more quickly.
Smart Images

Figure CN120196592A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technologies, and particularly to an anomaly detection method and apparatus, a storage medium, and a computer device. Background Art
[0002] In today's society, with the development of computer technologies, application software has become an important tool for people's work and even life. With the continuous change of user requirements, application software is also constantly iterated and updated. During the operation of an application program, program crashes usually occur, and the reasons for program crashes in different versions of application programs are usually different. Therefore, it is usually necessary to collect and analyze the abnormal files of the application program, so that through the obtained anomaly analysis results, the application program can be optimized to reduce the crash rate of the application program.
[0003] In the prior art, it depends on developers to analyze the dump files generated when the software crashes one by one to discover the abnormal problems of the software, with low efficiency and being not conducive to the timely solution of crash problems. Summary of the Invention
[0004] In view of this, embodiments of the present application provide an anomaly detection method and apparatus, a storage medium, and a computer device. By parsing the executable file identification information of the dump file, the executable file and the corresponding symbol file are determined, and then the dump file is automatically analyzed by using the executable file and the symbol file. The program anomaly information corresponding to different dump files is summarized in an anomaly information database, so as to automatically and comprehensively analyze the anomaly situation of the program code corresponding to the target application program, and solve the problems of large workload and low efficiency for developers to analyze the dump files one by one.
[0005] According to one aspect of the present application, an anomaly detection method is provided, and the method includes:
[0006] Obtain a report file generated when the target application program crashes, where the report file includes a dump file;
[0007] Parse the executable file identification information corresponding to the dump file;
[0008] Determine the executable file corresponding to the executable file identification information and the symbol file corresponding to the executable file, and analyze the dump file by using the symbol file and the executable file to determine the program anomaly information corresponding to the dump file;
[0009] Associate the program anomaly information and the executable file identification information and add them to the anomaly information database, and based on the anomaly information database, count the program anomaly information corresponding to each executable file identification.
[0010] Optionally, the executable file identification information includes the version number and platform identification of the executable file; determining the executable file corresponding to the executable file identification information and the symbol file corresponding to the executable file, and analyzing the dump file by using the symbol file and the executable file to determine the program exception information corresponding to the dump file, including:
[0011] Based on the version number and the platform identification, determining the executable file path and symbol file path corresponding to the dump file;
[0012] Passing the executable file path, the symbol file path, and the dump file path corresponding to the dump file into a debugger, so as to call, through the debugger, the executable file under the executable file path, the symbol file under the symbol file path, and the dump file under the dump file path, and analyzing the dump file by using the symbol file and the executable file to determine the program exception information corresponding to the dump file, where the program exception information includes an exception stack, at least one stack frame included in the exception stack, an exception stack frame in the at least one stack frame, an exception program code line corresponding to the exception stack frame, and local variable information accessed by each stack frame.
[0013] Optionally, the report file further includes an error log; after obtaining the report file generated when the executable file runs and crashes, the method further includes:
[0014] Querying, in the error log, exception attention information corresponding to a preset keyword;
[0015] Correspondingly, adding the program exception information and the executable file identification information to the exception information database after association includes:
[0016] Adding the program exception information, the exception attention information, and the executable file identification information to the exception information database after association.
[0017] Optionally, after obtaining the report file generated when the executable file runs and crashes, the method further includes:
[0018] Creating a task object corresponding to the report file;
[0019] Writing the exception attention information, the executable file path, the symbol file path, and the dump file path into the task object, and adding the task object to a task queue, and allocating the task object to at least one analysis function based on the task queue;
[0020] Among them, the analysis function is used to call a debugger to analyze program exception information and write the analyzed program exception information into the task object, and the task object is used to transmit the program exception information, the exception concern information, and the executable file identification information to the exception information database.
[0021] Optionally, based on the exception information database, counting the program exception information corresponding to each executable file identification includes:
[0022] Grouping the program exception information based on the version number and the platform identification to obtain at least one program exception information group, where the version numbers and platform identifications corresponding to the program exception information included in each program exception information group are the same;
[0023] For each program exception information group, counting the first occurrence number of each exception stack frame in the group and the second occurrence number of at least one exception stack corresponding to each exception stack frame.
[0024] Optionally, after counting the first occurrence number of each exception stack frame in the group and the second occurrence number of at least one exception stack corresponding to each exception stack frame for each program exception information group, the method further includes at least one of the following:
[0025] In response to an exception program query instruction, based on the first version number and the first platform identification indicated by the exception program query instruction, determining a first program exception information group, and based on the first letters of each exception stack frame corresponding to the first program exception information group, displaying an exception stack frame list in alphabetical order; or based on the first occurrence numbers of each exception stack frame corresponding to the first program exception information group, displaying the exception stack frame list in descending order, where the exception stack frame list includes each exception stack frame of the first program exception information group and its corresponding first occurrence number;
[0026] In response to a selection operation on any exception stack frame in the exception stack frame list, based on the second occurrence numbers of each exception stack corresponding to the any exception stack frame, displaying an exception stack list in descending order, or based on the first letters of each exception stack corresponding to the any exception stack frame, displaying the exception stack list in alphabetical order, where the exception stack list includes each exception stack of the first program exception information group and its corresponding second occurrence number, and when any exception stack in the exception stack list is triggered, at least one stack frame, exception stack frame, and exception program code line corresponding to the triggered exception stack are displayed, and local variable information corresponding to any stack frame is displayed when the stack frame is triggered;
[0027] In response to a query instruction for attention information, based on the second version number and the second platform identifier indicated by the query instruction for attention information, determine a second set of program exception information, and display a list of exception attention information based on the exception attention information corresponding to each program exception information in the second set of program exception information.
[0028] Optionally, before grouping the program exception information based on the version number and the platform identifier to obtain at least one set of program exception information, the method further includes:
[0029] In the case where there is a preset masked stack, query whether the preset masked stack is included in the program exception information;
[0030] If any program exception information includes the preset masked stack, mask the preset masked stack in the any program exception information, as well as at least one stack frame, exception stack frame, and local variable information of each stack frame corresponding to the preset masked stack;
[0031] Correspondingly, grouping the program exception information based on the version number and the platform identifier to obtain at least one set of program exception information includes:
[0032] Group the masked program exception information based on the version number and the platform identifier to obtain at least one set of program exception information.
[0033] Optionally, the method further includes:
[0034] In response to an exception stack trace instruction, determine the stack to be traced and the trace start time corresponding to the exception stack trace instruction;
[0035] Count the program exception information that is added after the trace start time and includes the stack to be traced in the exception information database, and determine the trace information of the stack to be traced based on the statistical result.
[0036] Optionally, the exception information database includes an index database, a main database, and a masked stack database; wherein, the index database is used to store the version number, platform identifier, the first occurrence number of each exception stack frame in the group, and the second occurrence number of at least one exception stack corresponding to each exception stack frame in the group corresponding to each set of program exception information; the main database is used to store the program exception information, the exception attention information, and the executable file identifier information; the masked stack database is used to store the preset masked stack information.
[0037] According to another aspect of the present application, there is provided an exception detection device, the device includes:
[0038] A file acquisition module, configured to acquire a report file generated when a target application crashes during operation, where the report file includes a dump file;
[0039] A parsing module, configured to parse the executable file identification information corresponding to the dump file;
[0040] An exception analysis module, configured to determine the executable file corresponding to the executable file identification information and the symbol file corresponding to the executable file, and analyze the dump file by using the symbol file and the executable file to determine the program exception information corresponding to the dump file;
[0041] A statistics module, configured to associate the program exception information and the executable file identification information and add them to an exception information database, and based on the exception information database, count the program exception information corresponding to each executable file identification.
[0042] Optionally, the executable file identification information includes the version number and platform identification of the executable file; the exception analysis module is further configured to:
[0043] Based on the version number and the platform identification, determine the executable file path and symbol file path corresponding to the dump file;
[0044] Pass the executable file path, the symbol file path, and the dump file path corresponding to the dump file into a debugger, so as to call, through the debugger, the executable file under the executable file path, the symbol file under the symbol file path, and the dump file under the dump file path, and analyze the dump file by using the symbol file and the executable file to determine the program exception information corresponding to the dump file, where the program exception information includes an exception stack, at least one stack frame included in the exception stack, an exception stack frame in the at least one stack frame, an exception program code line corresponding to the exception stack frame, and local variable information accessed by each stack frame.
[0045] Optionally, the report file further includes an error log; the parsing module is further configured to:
[0046] Query exception attention information corresponding to a preset keyword in the error log;
[0047] Correspondingly, the statistics module is further configured to:
[0048] Associate the program exception information, the exception attention information, and the executable file identification information and add them to the exception information database.
[0049] Optionally, the exception analysis module is further configured to:
[0050] Create a task object corresponding to the report file;
[0051] Write the exception attention information, the executable file path, the symbol file path, and the dump file path into the task object, add the task object to a task queue, and allocate the task object to at least one analysis function based on the task queue;
[0052] Wherein, the analysis function is used to call a debugger to analyze program exception information, and write the analyzed program exception information into the task object, and the task object is used to pass the program exception information, the exception attention information, and the executable file identification information to the exception information database.
[0053] Optionally, the statistics module is further configured to:
[0054] Group the program exception information based on the version number and the platform identifier to obtain at least one program exception information group, wherein the version number and the platform identifier corresponding to the program exception information included in each program exception information group are the same;
[0055] For each program exception information group, count the first occurrence times of each exception stack frame in the group and the second occurrence times of at least one exception stack corresponding to each exception stack frame.
[0056] Optionally, the statistics module is further configured to perform at least one of the following:
[0057] In response to an exception program query instruction, based on the first version number and the first platform identifier indicated by the exception program query instruction, determine a first program exception information group, and display an exception stack frame list in alphabetical order based on the first letters of each exception stack frame corresponding to the first program exception information group; or display an exception stack frame list in descending order based on the first occurrence times of each exception stack frame corresponding to the first program exception information group, wherein the exception stack frame list includes each exception stack frame of the first program exception information group and its corresponding first occurrence times;
[0058] In response to a selection operation on any abnormal stack frame in the list of abnormal stack frames, an abnormal stack list is displayed in descending order based on the second occurrence numbers of the respective abnormal stacks corresponding to the any abnormal stack frame, or the abnormal stack list is displayed in alphabetical order based on the first letters of the respective abnormal stacks corresponding to the any abnormal stack frame, where the abnormal stack list includes each abnormal stack of the first program abnormal information group and its corresponding second occurrence number, and when any abnormal stack in the abnormal stack list is triggered, at least one stack frame, an abnormal stack frame, and an abnormal program code line corresponding to the triggered abnormal stack are displayed, and when any stack frame is triggered, the corresponding local variable information is displayed;
[0059] In response to a concern information query instruction, based on the second version number and the second platform identifier indicated by the concern information query instruction, a second program abnormal information group is determined, and an abnormal concern information list is displayed based on the abnormal concern information corresponding to each program abnormal information within the second program abnormal information group.
[0060] Optionally, the statistics module is further configured to:
[0061] In the presence of a preset masked stack, query whether the preset masked stack is included in the program abnormal information; if the preset masked stack is included in any program abnormal information, then mask the preset masked stack in the any program abnormal information, as well as at least one stack frame, an abnormal stack frame, and the local variable information of each stack frame corresponding to the preset masked stack;
[0062] Based on the version number and the platform identifier, group the masked program abnormal information to obtain at least one program abnormal information group.
[0063] Optionally, the statistics module is further configured to:
[0064] In response to an abnormal stack trace instruction, determine the stack to be traced and the trace start time corresponding to the abnormal stack trace instruction;
[0065] Count the program abnormal information that is added after the trace start time and includes the stack to be traced in the abnormal information database, and determine the trace information of the stack to be traced based on the statistical result.
[0066] Optionally, the abnormal information database includes an index database, a main database, and a masked stack database; where the index database is used to store the version number, platform identifier, the first occurrence number of each abnormal stack frame within the group, and the second occurrence number of at least one abnormal stack corresponding to each abnormal stack frame within the group corresponding to each program abnormal information group; the main database is used to store the program abnormal information, the abnormal concern information, and the executable file identification information; the masked stack database is used to store the preset masked stack information.
[0067] According to another aspect of the present application, a storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the above-mentioned anomaly detection method is implemented.
[0068] According to still another aspect of the present application, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor. When the processor executes the program, the above-mentioned anomaly detection method is implemented.
[0069] By means of the above technical solution, a report file generated when the target application crashes can be obtained, the dump file in the report file can be parsed to obtain the executable file identification information, and then the executable file and its corresponding symbol file can be determined by using the executable file identification information. The symbol file and the executable file are used to analyze the program anomaly information of the dump file, and then the program anomaly information and the executable file identification information are associated and stored in the anomaly information database. By statistically analyzing the summary data in the anomaly information database, the anomaly information of the program code corresponding to the target application is determined. In the embodiment of the present application, the executable file and the corresponding symbol file are determined by parsing the executable file identification information of the dump file, so that the dump file can be automatically analyzed by using the executable file and the symbol file, and the program anomaly information corresponding to different dump files is summarized through the anomaly information database, so as to automatically comprehensively analyze the anomaly situation of the program code corresponding to the target application, so as to solve the problem that developers have a large workload and low efficiency in analyzing each dump file one by one.
[0070] The above description is only an overview of the technical solution of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the following specifically gives the specific implementation manners of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0072] Figure 1 A flowchart showing a method for anomaly detection provided by an embodiment of the present application is shown;
[0073] Figure 2 A flowchart showing another method for anomaly detection provided by an embodiment of the present application is shown;
[0074] Figure 3 A structural diagram showing an anomaly detection device provided by an embodiment of the present application is shown. Detailed implementation manners
[0075] The present application will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other.
[0076] In this embodiment, an anomaly detection method is provided. As Figure 1 shown, the method includes:
[0077] Step 101: Obtain a report file generated when the target application crashes during operation, where the report file includes a dump file.
[0078] In the embodiment of the present application, for the target application that needs to perform anomaly analysis, pre-settings are made so that a.dmp format dump file will be generated when the target application crashes during operation, and the file contains the stack information when the program crashes. In the embodiment of the present application, the report file of the target application can be obtained in real time or periodically to analyze the anomaly problem of the target application based on the report file.
[0079] Step 102: Parse the executable file identification information corresponding to the dump file.
[0080] In the embodiment of the present application, there may be multiple versions of the executable file corresponding to the target application, and each version has its own executable file. In order to accurately locate the anomaly problem, the executable file identification information corresponding to the dump file can be parsed first to determine the executable file corresponding to the dump file through the executable text identification information, that is, to determine the version of the target application that crashed.
[0081] Step 103: Determine the executable file corresponding to the executable file identification information and the symbol file corresponding to the executable file, and analyze the dump file by using the symbol file and the executable file to determine the program anomaly information corresponding to the dump file.
[0082] In the embodiment of the present application, after parsing the executable file identification information, the corresponding executable file and the symbol file for debugging the dump file corresponding to the executable file can be determined. Then, based on the symbol file and the executable file, the dump file is debugged to determine the program anomaly information corresponding to the dump file.
[0083] In the embodiments of the present application, target application programs with the same version but applicable to different computer bit widths correspond to different executable files. Therefore, for target application programs that are developed in multiple versions and can be applicable to different computer bit widths, the executable file identification information includes the version number of the executable file and the platform identifier (i.e., the computer bit width, such as 32 bits, 64 bits, etc.); Optionally, step 103 may include: based on the version number and the platform identifier, determining the executable file path and the symbol file path corresponding to the dump file; passing the executable file path, the symbol file path, and the dump file path corresponding to the dump file into the debugger, so as to call the executable file under the executable file path, the symbol file under the symbol file path, and the dump file under the dump file path through the debugger, and using the symbol file and the executable file to analyze the dump file to determine the program exception information corresponding to the dump file, where the program exception information includes an exception stack, at least one stack frame included in the exception stack, an exception stack frame in at least one stack frame, the exception program code line corresponding to the exception stack frame, and the local variable information accessed by each stack frame.
[0084] In the above embodiments, based on the differences in the version number and the platform identifier, each executable file and the corresponding symbol file can be stored in different locations. After parsing out the version number and the platform identifier of the dump file, the storage location of the executable file corresponding to the dump file, that is, the executable file path, and the symbol file path can be determined according to the version number and the platform identifier. Further, the executable file path, the symbol file path, and the dump file path are transmitted to the debugger, so that the debugger reads the corresponding files based on each path for analysis, and obtains the exception stack in the dump file, each stack frame included in the exception stack, the exception stack frame in the stack frame, locates the exception program code line corresponding to the exception stack frame based on the program code in the executable file, and the local variable information accessed by each stack frame. Specifically, the debugger can read out the exception stack in the dump file through the cdb instruction, and the stack is composed of multiple stack frames. The stack information is obtained through the kc instruction, the function that has not completed running, that is, the crashed function, is determined in the stack information, the name of the stack frame corresponding to this function is determined as the exception stack frame, and the stack frame depth of each stack frame is determined based on the stack information. The code line corresponding to the function that has not completed running is found in the executable file through the kn instruction as the exception program code line. Then, all local variables that can be accessed by each stack frame depth are traversed and obtained through the.frame and dv instructions as the local variable information accessed by each stack frame.
[0085] Step 104: After associating the program exception information and the executable file identification information, add them to the exception information database, and based on the exception information database, count the program exception information corresponding to each executable file identification.
[0086] In the embodiment of the present application, after analyzing the program exception information corresponding to the dump file, the program exception information and the executable file identification information can be associated and stored in the exception information database. The program exception information of the executable file running crash corresponding to each version and each platform identification of the target application program is summarized through the exception information database, so as to automatically comprehensively analyze the exception situation of the target application program, and solve the problems of large workload and low efficiency for developers to analyze each dump file one by one.
[0087] By applying the technical solution of this embodiment, obtain the report file generated when the target application program runs and crashes, parse the dump file in the report file to obtain the executable file identification information, thereby use the executable file identification information to determine the executable file and its corresponding symbol file, analyze the program exception information of the dump file using the symbol file and the executable file, and then associate and store the program exception information and the executable file identification information in the exception information database. By counting the summary data in the exception information database, determine the exception information of the program code corresponding to the target application program. In the embodiment of the present application, the executable file and the corresponding symbol file are determined by parsing the executable file identification information of the dump file, so as to automatically analyze the dump file using the executable file and the symbol file, and summarize the program exception information corresponding to different dump files through the exception information database, so as to automatically comprehensively analyze the exception situation of the program code corresponding to the target application program, and solve the problems of large workload and low efficiency for developers to analyze each dump file one by one.
[0088] Further, as a refinement and extension of the specific implementation manner of the above embodiment, in order to fully illustrate the specific implementation process of this embodiment, another exception detection method is provided, as Figure 2 shown. This method includes:
[0089] Step 201: Obtain the report file generated when the target application program runs and crashes, where the report file includes a dump file and an error log.
[0090] In the embodiment of the present application, the report file generated when the target application program runs and crashes includes a dump file and an error log. Taking the target application program as a game program as an example, the error log may include information such as the player's role_id, server, and IP address. At the same time, it may also include the client running environment and the player's behavior when the client crashes. All these data may help developers find the problems that cause the crash.
[0091] Step 202: Create a task object corresponding to the report file.
[0092] In the embodiment of the present application, a task object task is created for each report file, so as to record the information required for analyzing the report file through the task object.
[0093] Step 203: Parse the executable file identification information corresponding to the dump file, where the executable file identification information includes the version number and platform identification of the executable file; query the error log for exception attention information corresponding to a preset keyword.
[0094] In the embodiment of the present application, parsing the executable file identification information in the dump file includes the version number and platform identification. Additionally, if the user has preset a keyword of interest, then it is also possible to query whether the preset keyword exists in the error log. If so, further obtain the exception attention information corresponding to the preset keyword. For example, if the preset keyword is "server", then server information can be obtained from the error log as the exception attention information.
[0095] Step 204: Based on the version number and the platform identification, determine the executable file path and symbol file path corresponding to the dump file; write the exception attention information, the executable file path, the symbol file path, and the dump file path into the task object, and add the task object to the task queue. Allocate the task object to at least one analysis function based on the task queue; where the analysis function is used to call a debugger to analyze program exception information and write the analyzed program exception information into the task object, and the task object is used to pass the program exception information, the exception attention information, and the executable file identification information to the exception information database.
[0096] In the embodiments of the present application, after determining the version number and platform identifier corresponding to the dump file, the executable file path and symbol file path corresponding to the version number and platform identifier can be further determined. The executable file path, symbol file path, dump file path, and exception concern information (if any) are all written into the task object. Specifically, for each piece of information obtained, it can be written into the task object immediately, without waiting for all the information to be obtained before writing. After all the information is written into the task object, the task object is added to the task queue for queuing. The task queue distributes the task object to one or multiple parallel analysis functions in sequence. The analysis function is used to call the debugger to analyze the program exception information and write the analyzed program exception information back into the task object, so as to use the task object to associatively store the program exception information, exception concern information, and executable file identifier information in the exception information database. Among them, the analysis function calls the debugger to analyze the program exception information, including: passing the executable file path, the symbol file path, and the dump file path corresponding to the dump file into the debugger, so that the debugger calls the executable file under the executable file path, the symbol file under the symbol file path, and the dump file under the dump file path, and uses the symbol file and the executable file to analyze the dump file to determine the program exception information corresponding to the dump file. The program exception information includes an exception stack, at least one stack frame included in the exception stack, an exception stack frame in at least one stack frame, an exception program code line corresponding to the exception stack frame, and local variable information accessed by each stack frame.
[0097] Step 205: After associating the program exception information, the exception concern information, and the executable file identifier information, add them to the exception information database.
[0098] In the embodiments of the present application, the program exception information, exception concern information, and executable file identifier information can be associatively stored in the exception information database through the task object, so as to comprehensively analyze the exception problems in the database.
[0099] Step 206: Based on the version number and the platform identifier, group the program exception information to obtain at least one program exception information group, where the version number and platform identifier corresponding to the program exception information included in each program exception information group are the same.
[0100] In the embodiments of the present application, when analyzing the abnormal information database, the program abnormal information can be grouped first according to the version number and the platform identifier. The version number and the platform identifier corresponding to the program abnormal information in each group are the same, and each group corresponds to a unique executable file, so as to analyze the abnormal program information generated by different executable files.
[0101] Step 207: For each group of program abnormal information, count the first occurrence times of each abnormal stack frame in the group and the second occurrence times of at least one abnormal stack corresponding to each abnormal stack frame.
[0102] In the embodiments of the present application, for each group of program abnormal information, the occurrence times of each abnormal stack frame in the group, that is, the first occurrence times, can be counted. The abnormal stacks corresponding to the same abnormal stack frame may be different. For each abnormal stack frame, the occurrence times of the abnormal stacks corresponding to the abnormal stack frame, that is, the second occurrence times, can be further counted. Further, based on the statistical information of the abnormal stack frames and the abnormal stacks, the visualization viewing requirements of developers can be met, so that developers can perform abnormal analysis.
[0103] In the embodiments of the present application, some stacks may come from other libraries referenced or depended on by the engine or the target application and cannot be repaired. Analyzing this part of the stacks does not make much sense. Therefore, the relevant information of this part of the stacks can be masked by adding mask words. For example, some stacks can be masked using the regular method to reduce invalid information. Optionally, before step 206, it may further include: when there is a preset masked stack, query whether the program abnormal information contains the preset masked stack; if any program abnormal information contains the preset masked stack, mask the preset masked stack in the any program abnormal information, as well as at least one stack frame, abnormal stack frame and local variable information of each stack frame corresponding to the preset masked stack; correspondingly, step 206 includes: grouping the masked program abnormal information based on the version number and the platform identifier to obtain at least one group of program abnormal information.
[0104] In the embodiments of the present application, optionally, in response to an abnormal program query instruction, based on the first version number and the first platform identifier indicated by the abnormal program query instruction, determine the first group of program abnormal information, and display a list of abnormal stack frames in alphabetical order based on the first letters of each abnormal stack frame corresponding to the first group of program abnormal information; or display a list of abnormal stack frames in descending order based on the first occurrence times of each abnormal stack frame corresponding to the first group of program abnormal information, where the list of abnormal stack frames includes each abnormal stack frame of the first group of program abnormal information and its corresponding first occurrence times.
[0105] In this embodiment, developers can specify a version number and a platform identifier to view the exception program information corresponding to a specific executable file. Specifically, according to the first version number and the first platform identifier specified by the developer's exception program query instruction, the corresponding first program exception information group is determined. Further, an exception stack frame list is generated for the first occurrence numbers of each exception stack frame in the first program exception information group and displayed in a list. For example, by default, each exception stack frame is displayed in ascending order by the first letter, and it also supports arranging and displaying each exception stack frame in descending order of the first occurrence number based on the developer's trigger operation.
[0106] In an embodiment of the present application, optionally, in response to a selection operation on any exception stack frame in the exception stack frame list, an exception stack list is displayed in descending order based on the second occurrence numbers of each exception stack corresponding to the any exception stack frame, or an exception stack list is displayed in alphabetical order based on the first letters of each exception stack corresponding to the any exception stack frame, where the exception stack list includes each exception stack in the first program exception information group and its corresponding second occurrence numbers, and when any exception stack in the exception stack list is triggered, at least one stack frame, an exception stack frame, and an exception program code line corresponding to the triggered exception stack are displayed, and when any stack frame is triggered, the corresponding local variable information is displayed.
[0107] In this embodiment, the displayed exception stack frame list supports different viewing forms. Developers can click on the list or move the cursor to a certain exception stack frame to trigger the display of the second occurrence numbers of each exception stack corresponding to the exception stack frame. Specifically, an exception stack list can be generated in a descending order (or alphabetical order) according to the second occurrence numbers, and the list contains each exception stack corresponding to the selected exception stack frame and its corresponding second occurrence numbers. Further, the exception stack list also supports continued trigger viewing. Developers can click on any exception stack in the exception stack list to trigger the viewing of the stack frames included in the exception stack, the exception stack frames in the exception stack, and the exception program code lines corresponding to the exception stack frames. Additionally, when developers continue to trigger a certain stack frame, the corresponding local variable information of the stack frame can be further displayed.
[0108] In an embodiment of the present application, optionally, in response to a concern information query instruction, based on the second version number and the second platform identifier indicated by the concern information query instruction, a second program exception information group is determined, and an exception concern information list is displayed based on the exception concern information corresponding to each program exception information in the second program exception information group.
[0109] In this embodiment, the developer can also specify a version number and a platform identifier to view the exception attention information corresponding to a specific group. Specifically, according to the second version number and the second platform identifier specified by the developer's attention information query instruction, a second program exception information group is determined, and the exception attention information included in each program exception information in the group is displayed in a list. Among them, the displayed exception attention information list can be divided into multiple sub-tables according to different corresponding preset keywords, and the developer can switch and view arbitrarily between multiple sub-tables.
[0110] In an embodiment of the present application, optionally, in response to an exception stack trace instruction, determine the traced stack and the trace start time corresponding to the exception stack trace instruction; count the program exception information that is added after the trace start time and includes the traced stack in the exception information database, and determine the trace information of the traced stack based on the statistical result.
[0111] In this embodiment, for some exception stacks that developers are more concerned about, tracing can also be performed to accurately focus on the information related to the exception stack. The developer can specify the traced stack and the trace start time, so as to count the exception information data that is added after the trace start time and includes the traced stack in the exception information database, and determine the trace information of the traced stack, which can specifically include the total number of occurrences of the traced stack, the number of occurrences in different program exception information groups, and so on. In addition, the developer can also enable the function of real-time exception stack tracing. After enabling the function, when program exception information including the traced stack is added to the exception information database, the developer can be notified in the form of information push, SMS, email, etc.
[0112] In an embodiment of the present application, optionally, the exception information database includes an index database, a main database, and a shielded stack database; wherein, the index database is used to store the version number, platform identifier, the first number of each exception stack frame in the group, and the second number of at least one exception stack corresponding to each exception stack frame in the group corresponding to each program exception information group; the main database is used to store the program exception information, the exception attention information, and the executable file identification information; the shielded stack database is used to store preset shielded stack information.
[0113] In this embodiment, the exception information database can be specifically divided into three databases: an index database, a main database, and a shielding stack database. The main database contains data of the main functions, including the stack information of the dump, warnings during the analysis process, and key information extracted from the log files. This is also expected to be the largest database. When a problem occurs or the database becomes too large, this database can be simply deleted to clear the data. After all, only the latest version of the dump needs to be concerned. For old versions, they only have statistical significance, and the statistical data can be stored in the index database. In short, the design of dividing the database can reduce the code amount and maintenance cost. Most problems can be solved by clearing the main database and starting the analysis again, and the size of a single database file can be effectively controlled.
[0114] Further, as Figure 1 a specific implementation of the method, an embodiment of the present application provides an exception detection device, as Figure 3 shown, the device includes:
[0115] a file acquisition module, configured to acquire a report file generated when a target application crashes during operation, where the report file includes a dump file;
[0116] a parsing module, configured to parse the executable file identification information corresponding to the dump file;
[0117] an exception analysis module, configured to determine the executable file corresponding to the executable file identification information and the symbol file corresponding to the executable file, and analyze the dump file by using the symbol file and the executable file to determine the program exception information corresponding to the dump file;
[0118] a statistics module, configured to associate the program exception information and the executable file identification information and add them to the exception information database, and based on the exception information database, statistics the program exception information corresponding to each executable file identification.
[0119] Optionally, the executable file identification information includes the version number and platform identification of the executable file; the exception analysis module is further configured to:
[0120] determine the executable file path and symbol file path corresponding to the dump file based on the version number and the platform identification;
[0121] Pass the path of the executable file, the path of the symbol file, and the path of the dump file corresponding to the dump file into the debugger, so as to call the executable file under the path of the executable file, the symbol file under the path of the symbol file, and the dump file under the path of the dump file through the debugger, and use the symbol file and the executable file to analyze the dump file to determine the program exception information corresponding to the dump file. Among them, the program exception information includes an exception stack, at least one stack frame included in the exception stack, an exception stack frame in at least one stack frame, the exception program code line corresponding to the exception stack frame, and the local variable information accessed by each stack frame.
[0122] Optionally, the report file further includes an error log; the parsing module is further configured to:
[0123] Query the exception concern information corresponding to the preset keyword in the error log;
[0124] Correspondingly, the statistics module is further configured to:
[0125] After associating the program exception information, the exception concern information, and the executable file identification information, add them to the exception information database.
[0126] Optionally, the exception analysis module is further configured to:
[0127] Create a task object corresponding to the report file;
[0128] Write the exception concern information, the path of the executable file, the path of the symbol file, and the path of the dump file into the task object, and add the task object to the task queue, and allocate the task object to at least one analysis function based on the task queue;
[0129] Among them, the analysis function is used to call the debugger to analyze the program exception information, and write the analyzed program exception information into the task object, and the task object is used to pass the program exception information, the exception concern information, and the executable file identification information into the exception information database.
[0130] Optionally, the statistics module is further configured to:
[0131] Based on the version number and the platform identifier, group the program exception information to obtain at least one program exception information group, where the version numbers and platform identifiers corresponding to the program exception information included in each program exception information group are the same;
[0132] For each program exception information group, count the first occurrence times of each exception stack frame within the group and the second occurrence times of at least one exception stack corresponding to each exception stack frame.
[0133] Optionally, the statistics module is further configured to perform at least one of the following:
[0134] In response to an exception program query instruction, based on the first version number and the first platform identifier indicated by the exception program query instruction, determine a first program exception information group, and based on the first letters of each exception stack frame corresponding to the first program exception information group, display a list of exception stack frames in alphabetical order; or based on the first occurrence times of each exception stack frame corresponding to the first program exception information group, display a list of exception stack frames in descending order, where the list of exception stack frames includes each exception stack frame of the first program exception information group and its corresponding first occurrence times;
[0135] In response to a selection operation on any exception stack frame in the list of exception stack frames, based on the second occurrence times of each exception stack corresponding to the any exception stack frame, display a list of exception stacks in descending order, or based on the first letters of each exception stack corresponding to the any exception stack frame, display a list of exception stacks in alphabetical order, where the list of exception stacks includes each exception stack of the first program exception information group and its corresponding second occurrence times, and when any exception stack in the list of exception stacks is triggered, display at least one stack frame, exception stack frame, and exception program code line corresponding to the triggered exception stack, and when any stack frame is triggered, display the corresponding local variable information;
[0136] In response to a concern information query instruction, based on the second version number and the second platform identifier indicated by the concern information query instruction, determine a second program exception information group, and based on the exception concern information corresponding to each program exception information within the second program exception information group, display a list of exception concern information.
[0137] Optionally, the statistics module is further configured to:
[0138] In the presence of a preset masked stack, query whether the program exception information contains the preset masked stack; if any program exception information contains the preset masked stack, then mask the preset masked stack in the any program exception information, as well as at least one stack frame, exception stack frame, and local variable information of each stack frame corresponding to the preset masked stack;
[0139] Based on the version number and the platform identifier, group the masked program exception information to obtain at least one program exception information group.
[0140] Optionally, the statistics module is further configured to:
[0141] In response to an exception stack trace instruction, determine the traced stack corresponding to the exception stack trace instruction and the trace start time;
[0142] Count the program exception information that is added after the trace start time and contains the traced stack in the exception information database, and determine the trace information of the traced stack based on the statistical result.
[0143] Optionally, the exception information database includes an index database, a main database, and a masked stack database; wherein, the index database is used to store the version number, platform identifier, the first occurrence number of each exception stack frame in the group, and the second occurrence number of at least one exception stack corresponding to each exception stack frame in the group for each program exception information group; the main database is used to store the program exception information, the exception concern information, and the executable file identification information; the masked stack database is used to store preset masked stack information.
[0144] It should be noted that for other corresponding descriptions of each functional unit involved in an exception detection device provided in an embodiment of the present application, reference can be made to Figures 1 to 2 the corresponding description in the method, which will not be elaborated here.
[0145] An embodiment of the present application further provides a computer device, which may specifically be a personal computer, a server, a network device, etc. The computer device includes a bus, a processor, a memory, and a communication interface, and may further include an input / output interface and a display device. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store location information. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the steps in each method embodiment are implemented.
[0146] Those skilled in the art can understand that the structure of the above computer device is only a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. A specific computer device may include more or fewer components, or combine certain components, or have different component arrangements.
[0147] In one embodiment, a computer-readable storage medium is provided. The computer-readable storage medium may be non-volatile or volatile, and a computer program is stored thereon. When the computer program is executed by a processor, the steps in each method embodiment are implemented.
[0148] In one embodiment, a computer program product is provided, including a computer program which, when executed by a processor, implements the steps in the above method embodiments.
[0149] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties.
[0150] Those of ordinary skill in the art can understand that all or part of the processes of implementing the above method embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above method embodiments. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0151] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0152] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. An anomaly detection method, characterized in that, The method includes: Obtaining a report file generated when a target application crashes during operation, where the report file includes a dump file; Parsing the executable file identification information corresponding to the dump file; Determining the executable file corresponding to the executable file identification information and the symbol file corresponding to the executable file, and analyzing the dump file by using the symbol file and the executable file to determine the program exception information corresponding to the dump file; Associating the program exception information and the executable file identification information and adding them to an exception information database, and based on the exception information database, counting the program exception information corresponding to each executable file identification.
2. The method according to claim 1, characterized in that, The executable file identification information includes the version number and platform identification of the executable file; the determining the executable file corresponding to the executable file identification information and the symbol file corresponding to the executable file, and analyzing the dump file by using the symbol file and the executable file to determine the program exception information corresponding to the dump file includes: Based on the version number and the platform identification, determining the executable file path and symbol file path corresponding to the dump file; Passing the executable file path, the symbol file path, and the dump file path corresponding to the dump file into a debugger, so as to call the executable file under the executable file path, the symbol file under the symbol file path, and the dump file under the dump file path through the debugger, and analyzing the dump file by using the symbol file and the executable file to determine the program exception information corresponding to the dump file, where the program exception information includes an exception stack, at least one stack frame included in the exception stack, an exception stack frame in at least one stack frame, an exception program code line corresponding to the exception stack frame, and local variable information accessed by each stack frame.
3. The method according to claim 2, characterized in that, The report file further includes an error log; after obtaining the report file generated when the executable file crashes during operation, the method further includes: Querying for exception attention information corresponding to a preset keyword in the error log; Correspondingly, the associating the program exception information and the executable file identification information and adding them to the exception information database includes: Associating the program exception information, the exception attention information, and the executable file identification information and adding them to the exception information database.
4. The method according to claim 3, wherein After obtaining the report file generated when the executable file crashes during operation, the method further includes: Creating a task object corresponding to the report file; Writing the exception attention information, the executable file path, the symbol file path, and the dump file path into the task object, adding the task object to a task queue, and allocating the task object to at least one analysis function based on the task queue; Among them, the analysis function is used to call a debugger to analyze program exception information and write the analyzed program exception information into the task object, and the task object is used to transmit the program exception information, the exception attention information, and the executable file identification information to the exception information database.
5. The method according to claim 3 or 4, characterized in that, Based on the exception information database, counting the program exception information corresponding to each executable file identification includes: Grouping the program exception information based on the version number and the platform identification to obtain at least one program exception information group, where the version number and the platform identification corresponding to the program exception information included in each program exception information group are the same; For each program exception information group, counting the first occurrence times of each exception stack frame in the group and the second occurrence times of at least one exception stack corresponding to each exception stack frame.
6. The method according to claim 5, characterized in that, After counting the first occurrence times of each exception stack frame in the group and the second occurrence times of at least one exception stack corresponding to each exception stack frame for each program exception information group, the method further includes at least one of the following: In response to an exception program query instruction, based on the first version number and the first platform identification indicated by the exception program query instruction, determining a first program exception information group, and displaying a list of exception stack frames in descending order based on the first occurrence times of each exception stack frame corresponding to the first program exception information group, where the list of exception stack frames includes each exception stack frame of the first program exception information group and its corresponding first occurrence times; In response to a selection operation on any exception stack frame in the list of exception stack frames, displaying a list of exception stacks in descending order based on the second occurrence times of each exception stack corresponding to the any exception stack frame, or displaying a list of exception stacks in alphabetical order based on the first letters of each exception stack corresponding to the any exception stack frame, where the list of exception stacks includes each exception stack of the first program exception information group and its corresponding second occurrence times, and when any exception stack in the list of exception stacks is triggered, at least one stack frame, exception stack frame, and exception program code line corresponding to the triggered exception stack are displayed, and when any stack frame is triggered, the corresponding local variable information is displayed; In response to a attention information query instruction, based on the second version number and the second platform identification indicated by the attention information query instruction, determining a second program exception information group, and displaying a list of exception attention information based on the exception attention information corresponding to each program exception information in the second program exception information group.
7. The method according to claim 5, characterized in that, Before grouping the program exception information based on the version number and the platform identification to obtain at least one program exception information group, the method further includes: When there is a preset masked stack, querying whether the preset masked stack is included in the program exception information; If any program exception information includes the preset masked stack, masking the preset masked stack in the any program exception information, as well as at least one stack frame, exception stack frame, and local variable information of each stack frame corresponding to the preset masked stack. Correspondingly, grouping the program exception information based on the version number and the platform identifier to obtain at least one program exception information group, including: Grouping the masked program exception information based on the version number and the platform identifier to obtain at least one program exception information group.
8. The method according to claim 5, characterized in that, The method further includes: Responding to an exception stack trace instruction, determining the traced stack corresponding to the exception stack trace instruction and the trace start time; Counting the program exception information that is added after the trace start time and contains the traced stack in the exception information database, and determining the trace information of the traced stack based on the counting result.
9. An anomaly detection device, characterized in that, The device includes: A file acquisition module, configured to acquire a report file generated when a target application crashes during operation, where the report file includes a dump file; A parsing module, configured to parse the executable file identification information corresponding to the dump file; An exception analysis module, configured to determine the executable file corresponding to the executable file identification information and the symbol file corresponding to the executable file, and analyze the dump file by using the symbol file and the executable file to determine the program exception information corresponding to the dump file; A statistics module, configured to associate the program exception information with the executable file identification information and add the result to the exception information database, and count the program exception information corresponding to each executable file identification based on the exception information database.
10. A storage medium, on which a computer program is stored, characterized in that, When the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.
11. A computer device, comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, characterized in that, When the processor executes the computer program, the method according to any one of claims 1 to 8 is implemented.