System application access relationship graph generation method, device, equipment and readable medium
By obtaining and filtering the application module configuration information and process information of the business system, abstract process information at the operating system level is generated, which solves the problems of sensitive information leakage and waste of computing resources in the existing technology, and realizes more efficient and secure system application access relationship diagram generation.
Patent Information
- Application Number
- CN202510819791.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-19
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-06-19
AI Technical Summary
When existing technologies collect business access traffic in a bypass manner to generate system application access relationship graphs, it is easy to cause sensitive information leakage and waste of computer computing resources, especially due to the parsing of original network packets and the processing of non-business requests.
By obtaining application module configuration information and process information sets, screening and matching, and communication relationship modeling are performed to generate abstract process information at the operating system level, avoiding parsing sensitive data. Through validity detection and grouping processing, invalid information interference is reduced, and an accurate system application access relationship diagram is generated.
It reduces the risk of sensitive information leakage, reduces the waste of computer computing resources, and improves the accuracy and efficiency of generating system application access relationship diagrams.
Smart Images

Figure CN120315969B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of computer technology, and in particular to a method, apparatus, device, and readable medium for generating a system application access relationship graph. Background Art
[0002] The system application access relationship graph generation method is a technology that generates access relationship graphs for both inter-business system access and application access within a business system. Currently, generating these graphs typically involves collecting business access traffic through a bypass method and then parsing it to generate the system application access relationship graph.
[0003] However, when using the above method to generate a system application access relationship graph, the following technical problems often occur:
[0004] Business access traffic is collected through a bypass method and parsed to generate a system application access relationship diagram. Traffic parsing requires parsing the captured raw network packets (such as HTTP / HTTPS requests and database protocols). Raw network packets may contain sensitive information (such as user passwords, ID numbers, and transaction amounts). Parsing raw network data packets can easily lead to the leakage of user sensitive information. Traffic may also contain a large number of non-business requests (such as health checks and heartbeat packets). Parsing all traffic data would result in a waste of computer computing resources.
[0005] The above information disclosed in this Background section is only for enhancement of understanding of the background of the inventive concept and therefore it may contain information that does not form the prior art that is already known to a person of ordinary skill in the art. Summary of the Invention
[0006] The content of this disclosure is used to briefly introduce concepts that will be described in detail in the detailed description section below. The content of this disclosure is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0007] Some embodiments of the present disclosure propose a method, apparatus, electronic device, and computer-readable medium for generating a system application access relationship graph to solve one or more of the technical problems mentioned in the above background technology section.
[0008] In the first aspect, some embodiments of the present disclosure provide a method for generating a system application access relationship diagram, the method comprising: in response to detecting that the startup state of a preset business system in each preset business system is the initial startup state or that a configuration change occurs in the preset business system, obtaining configuration information of each application module corresponding to the above-mentioned each preset business system; collecting each process information set of each preset business system where each application module corresponding to the above-mentioned each application module configuration information is located, wherein each process information set in the above-mentioned each process information set corresponds to an application module configuration information in each application module configuration information; screening and matching the above-mentioned each process information set to obtain at least one communication process information; generating a communication process diagram based on the above-mentioned each application module configuration information. Into at least one application business affiliation information corresponding to the above-mentioned at least one communication process information; perform communication relationship modeling processing on the above-mentioned at least one communication process information to obtain at least one business system communication association information corresponding to the above-mentioned at least one communication process information; based on the above-mentioned at least one application business affiliation information, perform grouping processing on the above-mentioned at least one communication process information to obtain a communication process information group set; perform matching processing on the above-mentioned communication process information group set to obtain access relationship information between various business systems; based on the above-mentioned at least one business system communication association information and the access relationship information between the above-mentioned various business systems, generate a system application access relationship diagram corresponding to the above-mentioned each preset business system; and display the above-mentioned system application access relationship diagram on the preset page.
[0009] In a second aspect, some embodiments of the present disclosure provide a system application access relationship diagram generation device, the device comprising: an acquisition unit, configured to, in response to detecting that the startup state of a preset business system in each preset business system is the initial startup state or a configuration change occurs in the preset business system, acquire the configuration information of each application module corresponding to the above-mentioned each preset business system; a collection unit, configured to collect each process information set of each preset business system where each application module corresponding to the above-mentioned each application module configuration information is located, wherein each process information set in the above-mentioned each process information set corresponds to one application module configuration information in each application module configuration information; a screening and matching processing unit, configured to perform screening and matching processing on the above-mentioned each process information set to obtain at least one communication process information; a first generation unit, configured to generate, based on the above-mentioned each application module configuration information, at least one communication process information. at least one application business affiliation information corresponding to each communication process information; a communication relationship modeling processing unit, configured to perform communication relationship modeling processing on the above-mentioned at least one communication process information, and obtain at least one business system communication association information corresponding to the above-mentioned at least one communication process information; a grouping unit, configured to perform grouping processing on the above-mentioned at least one communication process information based on the above-mentioned at least one application business affiliation information, and obtain a communication process information group set; a matching processing unit, configured to perform matching processing on the above-mentioned communication process information group set, and obtain access relationship information between each business system; a second generating unit, configured to generate a system application access relationship diagram corresponding to the above-mentioned each preset business system based on the above-mentioned at least one business system communication association information and the above-mentioned access relationship information between each business system; a display unit, configured to display the above-mentioned system application access relationship diagram on a preset page.
[0010] In a third aspect, some embodiments of the present disclosure provide an electronic device comprising: one or more processors; a storage device on which one or more programs are stored, and when the one or more programs are executed by one or more processors, the one or more processors implement the method described in any implementation of the first aspect above.
[0011] In a fourth aspect, some embodiments of the present disclosure provide a computer-readable medium having a computer program stored thereon, wherein when the program is executed by a processor, the method described in any implementation of the first aspect is implemented.
[0012] The aforementioned embodiments of the present disclosure have the following beneficial effects: The system application access graph generation method of some embodiments of the present disclosure reduces the risk of sensitive information leakage and reduces the waste of computer computing resources. Specifically, the vulnerability to sensitive user information leakage and the waste of computer computing resources arises from the fact that business access traffic is collected in a bypass manner and parsed to generate the system application access graph. Traffic parsing requires parsing captured raw network packets (such as HTTP / HTTPS requests, database protocols, etc.), which may contain sensitive information (such as user passwords, ID numbers, transaction amounts, etc.). Parsing raw network packets can easily lead to the leakage of user sensitive information. Furthermore, traffic may contain a large number of non-business requests (such as health checks and heartbeat packets). Parsing all traffic data would result in a waste of computer computing resources. Based on this, the system application access graph generation method of some embodiments of the present disclosure first obtains configuration information for each application module corresponding to each preset business system in response to detecting that the startup state of a preset business system is in the initial startup state or that a configuration change has occurred in the preset business system. This allows the acquisition of configuration information for each application module used to collect process information sets for each preset business system. Next, each process information set is collected for each preset business system where each application module corresponding to each application module configuration information resides. Each process information set corresponds to one piece of application module configuration information in each application module configuration information. This allows the collection of each process information set corresponding to each preset business system. Next, each process information set is screened and matched to obtain at least one piece of communication process information. This allows the screening of each process information set to obtain at least one piece of communication process information related to communication (i.e., access). Next, based on each application module configuration information, at least one piece of application service attribution information corresponding to the at least one piece of communication process information is generated. This allows the at least one piece of application service attribution information to be grouped. Next, communication relationship modeling is performed on the at least one piece of communication process information to obtain at least one piece of intra-business system communication association information corresponding to the at least one piece of communication process information. This allows the generation of at least one piece of intra-business system communication association information for use in generating a system application access relationship graph. Next, based on the at least one piece of application service attribution information, the at least one piece of communication process information is grouped to obtain a communication process information group set. This allows the generation of access relationship information between each business system to obtain a communication process information group set. Then, the communication process information set is matched to obtain access relationship information between each business system, thereby obtaining access relationship information between each business system for generating a system application access relationship graph.Next, based on the communication association information within the at least one business system and the access relationship information between the business systems, a system application access relationship graph corresponding to each of the preset business systems is generated. This generates a system application access relationship graph corresponding to each of the preset business systems. Finally, the system application access relationship graph is displayed on a preset page. Furthermore, in the process of generating the system application access relationship graph corresponding to each of the preset business systems, the system application access relationship graph is generated by collecting process information sets from each of the preset business systems. Process information is an abstraction at the operating system level and typically does not contain sensitive user data (such as passwords, ID numbers, transaction amounts, etc.), thereby reducing the risk of sensitive information leakage. Furthermore, each process information set is filtered to obtain at least one communication process information related to communication (i.e., access). Based on this at least one communication process information, the system application access relationship graph is generated, avoiding the need to analyze non-communication data and reducing the waste of computer computing resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that components and elements are not necessarily drawn to scale.
[0014] Figure 1 is a flowchart of some embodiments of the method for generating a system application access relationship graph according to the present disclosure;
[0015] Figure 2 It is a structural diagram of some embodiments of the system application access relationship graph generation device according to the present disclosure;
[0016] Figure 3 is a schematic structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure;
[0017] Figure 4 It is a schematic internal test system application access relationship diagram generated according to some embodiments of the system application access relationship diagram generation method disclosed in the present invention. DETAILED DESCRIPTION
[0018] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments described herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.
[0019] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of the present disclosure may be combined with each other.
[0020] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0021] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".
[0022] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0023] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.
[0024] Figure 1 The process 100 of some embodiments of the method for generating a system application access relationship graph according to the present disclosure is shown. The method for generating a system application access relationship graph includes the following steps:
[0025] Step 101 : in response to detecting that the startup state of a preset business system in each preset business system is the initial startup state or the configuration of the preset business system has been changed, obtaining configuration information of each application module corresponding to each preset business system.
[0026] In some embodiments, the execution entity (e.g., a computing device) of the system application access relationship graph generation method may, in response to detecting that a preset business system in each preset business system is in its initial startup state or has undergone a configuration change, obtain configuration information for each application module corresponding to the preset business system. In practice, the execution entity may monitor each preset business system using a preset monitoring tool (e.g., Prometheus, Zabbix, etc.) to determine whether any of the preset business systems is in its initial startup state or has undergone a configuration change. The initial startup state may represent the first startup. In practice, the execution entity may obtain configuration information for each application module by parsing predefined configuration files (e.g., XML, JSON, YAML, etc.) corresponding to each preset business system. Each of the application module configuration information includes application module address information and application name information. The application module address information may represent the access address of the application module on the network. The application name information may represent the identifier or name of the application module (e.g., application name information: user management module). The application module is a module that implements preset business logic or functionality. For example, the above-mentioned application module may be a user management module responsible for functions such as user registration, login, and authority verification under a preset item circulation system (such as an e-commerce system).
[0027] Step 102 : collecting each process information set of each preset business system where each application module is located and corresponding to each application module configuration information.
[0028] In some embodiments, the execution entity may collect each process information set of each preset business system where each application module corresponding to each application module configuration information is located, wherein each process information set in each process information set corresponds to one application module configuration information in each application module configuration information.
[0029] In some optional implementations of some embodiments, the execution entity may collect each process information set of each preset business system where each application module corresponding to each application module configuration information is located through the following steps:
[0030] In the first step, for each of the above application module configuration information, perform the following collection steps:
[0031] The first sub-step is to obtain preset script information corresponding to the application module configuration information, wherein the preset script information may be a code or instruction set for collecting information about each process in the business system to which the application module corresponding to the application module configuration information belongs based on the module configuration information.
[0032] The second sub-step involves deploying the script corresponding to the preset script information to the preset business system corresponding to the application module configuration information, and using the deployed script to collect process information corresponding to each process within the preset business system. Each piece of process information may represent a process within the preset business system. The process information may include, but is not limited to, at least one of the following: port information, address information, and keyword information. The port information may represent the port number of the process. The address information may represent the host IP address of the host where the process resides. The keyword information may represent the process keyword (i.e., process identifier (PID)).
[0033] The third sub-step is to determine the collected process information as a process information set.
[0034] Step 103: Screen and match each process information set to obtain at least one communication process information.
[0035] In some embodiments, the execution entity may perform screening and matching processing on each of the process information sets to obtain at least one communication process information.
[0036] In some optional implementations of some embodiments, the execution entity may perform screening and matching processing on each of the process information sets to obtain at least one communication process information through the following steps:
[0037] The first step is to query the process status information of the process corresponding to each process information in the above-mentioned process information sets, and obtain the process status information of each process corresponding to the above-mentioned process information sets. In practice, the above-mentioned execution subject can execute the preset query task information to query the process status information of each process information in the above-mentioned process information sets, and obtain the process status information of each process corresponding to the above-mentioned process information sets. Among them, the above-mentioned query task information can represent the command used to query the status of the process corresponding to the process information (for example, ss or netstat command). Each process status information in the above-mentioned process status information can represent the status of the process (for example, listening port, communicating, connection closed, etc.)
[0038] In the second step, at least one process status information representing ongoing communication among the above-mentioned process status information is determined as at least one target process status information.
[0039] In a third step, at least one process information corresponding to the at least one target process status information in the process information set is determined as at least one communication process information. Each communication process information in the at least one communication process information corresponds to a corresponding piece of application module configuration information in the application module configuration information, and the application module configuration information includes application module address information and application name information.
[0040] Step 104: Generate at least one application service attribution information corresponding to at least one communication process information based on the configuration information of each application module.
[0041] In some embodiments, the execution entity may generate at least one application service attribution information corresponding to the at least one communication process information based on the configuration information of each application module.
[0042] In some optional implementations of some embodiments, the execution entity may generate at least one application service attribution information corresponding to the at least one communication process information based on the configuration information of each application module through the following steps:
[0043] In the first step, for each piece of communication process information in the at least one communication process information, the following generation steps are performed:
[0044] In the first sub-step, the application module configuration information corresponding to the communication process information among the various application module configuration information is determined as the target application module configuration information.
[0045] The second sub-step is to determine the application name information included in the target application module configuration information as the target application name information.
[0046] The third sub-step involves querying a preset process knowledge base for the business system name information of the preset business system where the application module corresponding to the target application module configuration information resides. The preset process knowledge base may be a preset database that stores process-related information. The preset process knowledge base stores the correspondence between application module configuration information and business system name information. The business system name information may represent the name of the preset business system. For example, the business system name information may be "Goods Circulation System."
[0047] The fourth sub-step is to determine the target application name information and the service system name information as the application service attribution information corresponding to the communication process information.
[0048] Step 105 : performing communication relationship modeling processing on at least one communication process information to obtain at least one business system communication association information corresponding to the at least one communication process information.
[0049] In some embodiments, the execution entity may perform communication relationship modeling on the at least one communication process information to obtain at least one intra-business system communication association information corresponding to the at least one communication process information.
[0050] In the process of adopting technical solutions to solve the problems mentioned in the background technology, the following problems often arise:
[0051] Typically, the inter-process communication record information corresponding to at least one communication process information collected often contains a large amount of invalid information (for example, inter-process communication record information containing invalid IP addresses and invalid ports indicates communication with a non-existent IP address). Generating at least one piece of intra-business system communication-related information directly based on at least one inter-process communication record information containing a large amount of invalid information not only wastes computer computing resources due to the processing of invalid information, but also may interfere with the generation of intra-business system communication-related information, resulting in low accuracy or high redundancy in the generated intra-business system communication-related information. This in turn leads to poor accuracy in the generated and displayed system application access relationship graph, necessitating the regeneration and display of the system application access relationship graph, and further resulting in a waste of computer computing resources.
[0052] Faced with the above technical problems, the inventors decided to adopt the following solutions:
[0053] In some optional implementations of some embodiments, the execution entity may perform communication relationship modeling on the at least one communication process information through the following steps to obtain at least one intra-business system communication association information corresponding to the at least one communication process information:
[0054] In the first step, for each communication process information in the at least one communication process information, the following steps are performed:
[0055] The first sub-step is to determine the keyword information included in the communication process information as target keyword information.
[0056] The second sub-step involves verifying, based on the target keyword information, whether the process corresponding to the communication process information exists in the system, thereby obtaining process existence verification information. In practice, the execution entity may check whether a folder with the target keyword information as its file name exists in a preset process directory (e.g., the / proc directory). If a folder with the target keyword information as its file name is found in the preset process directory, the execution entity may determine information indicating the existence of the process corresponding to the communication process information as the process existence verification information. If no folder with the target keyword information as its file name is found in the preset process directory, the execution entity may determine information indicating the non-existence of the process corresponding to the communication process information as the process existence verification information.
[0057] In the third sub-step, in response to determining that the process existence check indicates the existence of the process corresponding to the communication process information, inter-process communication record information corresponding to the target keyword information is collected from a preset log file. The inter-process communication record information includes service address information and a communication role information sequence. Each communication role information in the communication role information sequence includes a communication role name and port information. The service address information may be an address identifying the location of the service (i.e., process), such as an IP address or host name. The communication role information may describe the various roles involved in the communication and their related information. For example, the communication role information sequence may be "The client accesses the web process of service A (listening on port 443). The web process calls NGNIX (listening on port 12866) for load, and then retrieves data from the database (listening on port 15400)." "The client accesses the web process of service A (listening on port 443)" is one piece of communication role information. The communication role name may represent the name of the communication role, such as client or web process. The port information may represent the port number on which the process listens, such as the listening port 15400.
[0058] The fourth sub-step is to perform validity detection processing on the address information and port information included in the above-mentioned inter-process communication record information to obtain validity detection information. In practice, for each address information and each port information included in the above-mentioned inter-process communication record information, the above-mentioned execution entity can query a preset valid address and port number list. In response to determining that each address information and each port information included in the inter-process communication record information are all present in the above-mentioned valid address and port number list, the above-mentioned execution entity can determine the information indicating that the address information and port information included in the above-mentioned inter-process communication record information are all valid information as the validity detection information. In response to determining that at least one address information or port information among the each address information and each port information included in the inter-process communication record information is not present in the above-mentioned valid address and port number list, the above-mentioned execution entity can determine the information indicating that the address information and port information included in the inter-process communication record information contain invalid address information or invalid port information as the validity detection information.
[0059] The fifth sub-step is to delete the communication process information from the at least one communication process information in response to determining that the validity detection information indicates that the address information and port information included in the inter-process communication record information contain invalid address information or invalid port information.
[0060] The sixth sub-step is, in response to determining that the validity detection information indicates that the address information and port information included in the inter-process communication record information are valid information, determining the communication role name included in each communication role information in the communication role information sequence as the communication role name to be arranged.
[0061] In the seventh sub-step, each of the determined communication role names to be arranged is arranged according to the order of its corresponding communication role information in the communication role information sequence to obtain a communication role name sequence. For example, the communication role name sequence may be "client->WEB->NGNIX->DB".
[0062] The eighth sub-step is to determine the above-mentioned communication role name sequence as the communication association information within the business system under the above-mentioned business address information.
[0063] The above technical solution and its related contents, combined with steps 108 to 109, serve as an inventive point of an embodiment of the present disclosure, and solve the technical problem of "waste of computer computing resources." Factors that lead to waste of computer computing resources are often as follows: the inter-process communication record information corresponding to at least one communication process information collected often contains a large amount of invalid information (for example, inter-process communication record information containing invalid IP addresses and invalid ports indicates communication with a non-existent IP address). Generating at least one business system communication association information directly based on at least one inter-process communication record information containing a large amount of invalid information not only leads to waste of computer computing resources due to the processing of invalid information, but also invalid information may interfere with the generation of business system communication association information, resulting in low accuracy or high redundancy of the generated business system communication association information, which in turn leads to poor accuracy of the generated and displayed system application access relationship diagram, requiring the system application access relationship diagram to be regenerated and displayed, which also results in waste of computer computing resources. If the above factors are resolved, the effect of reducing the waste of computer computing resources can be achieved. To achieve this effect, first, for each communication process information in the at least one communication process information, the following steps are performed: First, keyword information included in the communication process information is determined as target keyword information. This results in target keyword information being obtained for verifying whether the process corresponding to the communication process information exists in the system. Second, based on the target keyword information, the process corresponding to the communication process information is verified to exist in the system, thereby obtaining process existence verification information. Third, in response to determining that the process existence verification indicates that the process corresponding to the communication process information exists, inter-process communication record information corresponding to the target keyword information is collected from a preset log file. The inter-process communication record information includes service address information and a sequence of communication role information, and each communication role information in the sequence of communication role information includes a communication role name and port information. This allows filtering out non-existent or terminated processes, avoiding the collection and processing of inter-process communication record information corresponding to invalid processes and reducing waste of computer computing resources. Fourth, a validity check is performed on the address information and port information included in the inter-process communication record information, thereby obtaining validity check information. This allows detection of invalid or erroneous address / port information. In a fifth sub-step, in response to determining that the validity check information indicates that the address information and port information included in the inter-process communication record information contain invalid address information or invalid port information, the communication process information is deleted from the at least one communication process information. In a sixth sub-step, in response to determining that the validity check information indicates that the address information and port information included in the inter-process communication record information are all valid information, the communication role name included in each communication role information in the communication role information sequence is determined as the communication role name to be arranged.Thus, if the validity check information indicates that the address information and port information included in the inter-process communication record information are both valid, the communication role name included in each communication role information is determined as the communication role name to be arranged. In a seventh sub-step, each of the determined communication role names to be arranged is arranged according to the order of its corresponding communication role information in the communication role information sequence, thereby obtaining a communication role name sequence. In an eighth sub-step, the communication role name sequence is determined as the intra-service system communication-related information associated with the service address information. Thus, intra-service system communication-related information can be obtained. By filtering out non-existent or terminated processes, processing of communication records for invalid processes is avoided, thereby reducing waste of computer computing resources. Furthermore, if the process corresponding to the communication process information exists, the address information and port information included in the inter-process communication record information corresponding to the communication process information is validated. Communication-related information is generated only based on inter-process communication record information for which both address information and port information are valid. This avoids interference from invalid data, thereby improving the accuracy of the generated intra-service system communication-related information and reducing redundancy in the intra-service system communication-related information. In conjunction with step 108, a system application access relationship graph corresponding to each of the preset business systems is generated based on the communication association information within the at least one business system and the access relationship information between the business systems. This allows a system application access relationship graph corresponding to each of the preset business systems to be generated based on the more accurate communication association information within the at least one business system. In conjunction with step 109, the system application access relationship graph is displayed on a preset page. This allows a more accurate system application access relationship graph to be displayed, thereby reducing the need for multiple generation and display of the generated and displayed system application access relationship graph due to poor accuracy, and thus reducing the waste of computer computing resources.
[0064] Step 106: Based on at least one application service attribution information, group at least one communication process information to obtain a communication process information group set.
[0065] In some embodiments, the execution entity may group the at least one communication process information based on the at least one application service attribution information to obtain a communication process information group set.
[0066] In some optional implementations of some embodiments, the execution entity may group the at least one communication process information based on the at least one application service attribution information to obtain a communication process information group set through the following steps:
[0067] In the first step, for each communication process information in the at least one communication process information, the following steps are performed:
[0068] In a first sub-step, the application service attribution information corresponding to the communication process information in the at least one application service attribution information is determined as target application service attribution information.
[0069] The second sub-step is to determine the service system name information included in the target application service attribution information as the target service system name corresponding to the communication process information.
[0070] In the second step, duplicate removal is performed on the determined at least one target business system name to obtain various filtered business system names.
[0071] In the third step, for each of the aforementioned screening service system names, each communication process information corresponding to the aforementioned screening service system name in at least one communication process information is determined as a communication process information group.
[0072] The fourth step is to determine the determined communication process information groups as a communication process information group set.
[0073] The above technical solution and its related contents, as an inventive feature of an embodiment of the present disclosure, address the technical problem of "high redundancy in the grouping results of communication process information." Factors that contribute to high redundancy in the grouping results of communication process information are often as follows: a communication process may belong to multiple service systems, resulting in duplicate service system names in the obtained at least one target service system name. Consequently, when grouping the communication process information based on the at least one target service system name, the redundancy in the grouping results of the communication process information can be reduced. To achieve this, the following steps are first performed for each communication process information in the at least one communication process information: First, the application service attribution information corresponding to the communication process information in the at least one application service attribution information is determined as the target application service attribution information. This results in target application service attribution information used to determine the target service system name. Second, the service system name information included in the target application service attribution information is determined as the target service system name corresponding to the communication process information. This results in the determination of the target service system name corresponding to the communication process information. Third, duplicate removal is performed on the determined at least one target service system name to obtain each filtered service system name. In this way, duplicate business system names in at least one target business system name can be removed, resulting in individual filtered business system names used to group at least one communication process information. For each filtered business system name in the filtered business system names, the individual pieces of communication process information corresponding to the filtered business system name in the at least one communication process information are identified as a communication process information group. Thus, a communication process information group corresponding to the filtered business system name can be obtained. Finally, the identified individual communication process information groups are identified as a communication process information group set. Thus, through the above steps, at least one communication process information can be grouped based on the individual filtered business system names without duplicate business system names, resulting in a grouping result with less redundancy, namely, a communication process information group set.
[0074] Step 107: performing matching processing on the communication process information set to obtain access relationship information between various business systems.
[0075] In some embodiments, the execution entity may perform matching processing on the communication process information set to obtain access relationship information between various business systems.
[0076] In some optional implementations of some embodiments, the execution entity may perform matching processing on the communication process information set to obtain access relationship information between various business systems through the following steps:
[0077] In the first step, for every two communication process information groups in the communication process information group set, perform the following steps:
[0078] In response to determining that there is an intersection between the two communication process information groups, the intersection is determined as a shared communication process information set.
[0079] The two communication process information groups are respectively identified as a first communication process information group and a second communication process information group. For example, the first communication process information group may be a process information group under a pre-set business system named "Membership System" (Membership Management System), for example, the first communication process information group may include "B process information, C process information, D process information." The second communication process information group may be a process information group under a pre-set business system named "Goods Circulation System," for example, the second communication process information group may include "D process information, E process information, F process information."
[0080] The screening service system name corresponding to the first communication process information group is determined as the first screening service system name. For example, the first screening service system name may be "membership system".
[0081] The name of the screening business system corresponding to the second communication process information group is determined as the second screening business system name. For example, the second screening business system name may be "article circulation system."
[0082] For each shared communication process information in the shared communication process information set, perform the following steps:
[0083] The first step is to search the preset process business attribution record table for the business system name corresponding to the shared communication process information as the query business system name. The preset process business attribution record table may be a pre-set record table that records the correspondence between the process corresponding to the process information and the business system name of the preset business system to which it belongs.
[0084] In the second step, in response to determining that the query business system name is the same as the first screening business system name, information representing that the preset business system corresponding to the second screening business system name accesses the preset business system corresponding to the first screening business system name is determined as access relationship information between business systems.
[0085] In the third step, in response to determining that the query business system name is the same as the second screening business system name, information representing that the preset business system corresponding to the first screening business system name accesses the preset business system corresponding to the second screening business system name is determined as access relationship information between business systems.
[0086] Step 108 : generating a system application access relationship graph corresponding to each preset business system based on the communication association information within at least one business system and the access relationship information between each business system.
[0087] In some embodiments, the execution subject may generate a system application access relationship diagram corresponding to each of the preset business systems based on the communication association information within the at least one business system and the access relationship information between the business systems. In practice, first, the execution subject may deduplicate the access relationship information between the business systems. Then, the execution subject may call the platform data analysis and drawing engine to generate a system application access relationship diagram corresponding to each of the preset business systems based on the communication association information within the at least one business system and the deduplicated access relationship information between the business systems. The platform data analysis and drawing engine may be an internally developed analysis, search, and drawing tool. The application access relationship diagram represents the access (i.e., communication) relationship between the preset business systems and between the application modules within the system.
[0088] Figure 4 This is a schematic internal test system application access relationship diagram generated according to some embodiments of the system application access relationship diagram generation method disclosed herein. Figure (a) shows the access (i.e., communication) relationship between application modules within the system. Nodes represent applications or services (i.e., each box represents an application or service (i.e., an application or service represented by an application module)). Arrows and dotted lines between nodes indicate that one application (i.e., an application represented by an application module) can access (i.e., communicate) with another application (i.e., an application represented by another application module). Figure (b) shows the access relationship between businesses. Each node (i.e., each box) in (b) represents a preset business system, and arrows and dotted lines between nodes indicate that one business system can access another business system.
[0089] Step 109: Display the system application access relationship diagram on a preset page.
[0090] In some embodiments, the execution entity may display the system application access relationship diagram on a preset page.
[0091] The aforementioned embodiments of the present disclosure have the following beneficial effects: The system application access graph generation method of some embodiments of the present disclosure reduces the risk of sensitive information leakage and reduces the waste of computer computing resources. Specifically, the vulnerability to sensitive user information leakage and the waste of computer computing resources arises from the fact that business access traffic is collected in a bypass manner and parsed to generate the system application access graph. Traffic parsing requires parsing captured raw network packets (such as HTTP / HTTPS requests, database protocols, etc.), which may contain sensitive information (such as user passwords, ID numbers, transaction amounts, etc.). Parsing raw network packets can easily lead to the leakage of user sensitive information. Furthermore, traffic may contain a large number of non-business requests (such as health checks and heartbeat packets). Parsing all traffic data would result in a waste of computer computing resources. Based on this, the system application access graph generation method of some embodiments of the present disclosure first obtains configuration information for each application module corresponding to each preset business system in response to detecting that the startup state of a preset business system is in the initial startup state or that a configuration change has occurred in the preset business system. This allows the acquisition of configuration information for each application module used to collect process information sets for each preset business system. Next, each process information set is collected for each preset business system where each application module corresponding to each application module configuration information resides. Each process information set corresponds to one piece of application module configuration information in each application module configuration information. This allows the collection of each process information set corresponding to each preset business system. Next, each process information set is screened and matched to obtain at least one piece of communication process information. This allows the screening of each process information set to obtain at least one piece of communication process information related to communication (i.e., access). Next, based on each application module configuration information, at least one piece of application service attribution information corresponding to the at least one piece of communication process information is generated. This allows the at least one piece of application service attribution information to be grouped. Next, communication relationship modeling is performed on the at least one piece of communication process information to obtain at least one piece of intra-business system communication association information corresponding to the at least one piece of communication process information. This allows the generation of at least one piece of intra-business system communication association information for use in generating a system application access relationship graph. Next, based on the at least one piece of application service attribution information, the at least one piece of communication process information is grouped to obtain a communication process information group set. This allows the generation of access relationship information between each business system to obtain a communication process information group set. Then, the communication process information set is matched to obtain access relationship information between each business system, thereby obtaining access relationship information between each business system for generating a system application access relationship graph.Next, based on the communication association information within the at least one business system and the access relationship information between the business systems, a system application access relationship graph corresponding to each of the preset business systems is generated. This generates a system application access relationship graph corresponding to each of the preset business systems. Finally, the system application access relationship graph is displayed on a preset page. Furthermore, in the process of generating the system application access relationship graph corresponding to each of the preset business systems, the system application access relationship graph is generated by collecting process information sets from each of the preset business systems. Process information is an abstraction at the operating system level and typically does not contain sensitive user data (such as passwords, ID numbers, transaction amounts, etc.), thereby reducing the risk of sensitive information leakage. Furthermore, each process information set is filtered to obtain at least one communication process information related to communication (i.e., access). Based on this at least one communication process information, the system application access relationship graph is generated, avoiding the need to analyze non-communication data and reducing the waste of computer computing resources. For further reference, Figure 2 As an implementation of the methods shown in the figures, the present disclosure provides some embodiments of a system application access relationship graph generation device. These device embodiments are similar to Figure 1 Corresponding to the method embodiments shown, the device can be specifically applied to various electronic devices.
[0092] like Figure 2As shown, in some embodiments, the system application access relationship graph generation device 200 includes: an acquisition unit 201, a collection unit 202, a screening and matching processing unit 203, a first generation unit 204, a communication relationship modeling processing unit 205, a grouping unit 206, a matching processing unit 207, a second generation unit 208 and a display unit 209. The acquisition unit 201 is configured to, in response to detecting that the startup state of a preset business system in each preset business system is the initial startup state or that a configuration change has occurred in the preset business system, acquire the configuration information of each application module corresponding to the above-mentioned preset business system; the collection unit 202 is configured to collect each process information set of each preset business system where each application module corresponding to the above-mentioned application module configuration information is located, wherein each process information set in the above-mentioned process information set corresponds to one application module configuration information in each application module configuration information; the screening and matching processing unit 203 is configured to perform screening and matching processing on the above-mentioned process information sets to obtain at least one communication process information; the first generation unit 204 is configured to generate at least one application business corresponding to the above-mentioned at least one communication process information based on the above-mentioned application module configuration information. Affiliation information; the communication relationship modeling processing unit 205 is configured to perform communication relationship modeling processing on the above-mentioned at least one communication process information, and obtain at least one intra-business system communication association information corresponding to the above-mentioned at least one communication process information; the grouping unit 206 is configured to perform grouping processing on the above-mentioned at least one communication process information based on the above-mentioned at least one application business affiliation information, and obtain a communication process information group set; the matching processing unit 207 is configured to perform matching processing on the above-mentioned communication process information group set, and obtain access relationship information between each business system; the second generation unit 208 is configured to generate a system application access relationship diagram corresponding to the above-mentioned each preset business system based on the above-mentioned at least one intra-business system communication association information and the above-mentioned access relationship information between each business system; the display unit 209 is configured to display the above-mentioned system application access relationship diagram on a preset page.
[0093] It is understood that the units described in the device 200 are similar to those described in the reference Figure 1 Therefore, the operations, features and beneficial effects described above for the method are also applicable to the device 200 and the units included therein, and will not be repeated here.
[0094] Reference below Figure 3 , which shows a structural diagram of an electronic device 300 suitable for implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0095] like Figure 3As shown, electronic device 300 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes based on programs stored in a read-only memory (ROM) 302 or programs loaded from a storage device 308 into a random access memory (RAM) 303. RAM 303 also stores various programs and data required for the operation of electronic device 300. Processing device 301, ROM 302, and RAM 303 are interconnected via a bus 304. An input / output (I / O) interface 305 is also connected to bus 304.
[0096] Typically, the following devices may be connected to the I / O interface 305: an input device 306 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 308 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 309. The communication device 309 may allow the electronic device 300 to communicate with other devices wirelessly or by wire to exchange data. Figure 3 The electronic device 300 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead. Figure 3 Each block shown in the figure may represent one device, or may represent multiple devices as needed.
[0097] In particular, according to some embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In some such embodiments, the computer program can be downloaded and installed from a network via the communication device 309, or installed from the storage device 308, or installed from the ROM 302. When the computer program is executed by the processing device 301, the functions defined in the methods of some embodiments of the present disclosure are performed.
[0098] It should be noted that the computer-readable medium described in some embodiments of the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. Computer-readable storage media may include, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more conductors, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In some embodiments of the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. Furthermore, in some embodiments of the present disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such a propagated data signal may take a variety of forms, including, but not limited to, electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. Program code embodied on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wire, optical cable, RF (radio frequency), or any suitable combination thereof.
[0099] In some embodiments, the client and server can communicate using any currently known or later developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or later developed network.
[0100] The computer-readable medium may be contained in the electronic device; or it may exist independently without being assembled into the electronic device. The computer-readable medium carries one or more programs. When one or more programs are executed by the electronic device, the electronic device: in response to detecting that the startup state of the preset business system in each preset business system is the initial startup state or the preset business system has a configuration change, obtains the configuration information of each application module corresponding to the above-mentioned preset business system; collects each process information set of each preset business system where each application module corresponding to the above-mentioned each application module configuration information is located, wherein each process information set in the above-mentioned each process information set corresponds to one application module configuration information in each application module configuration information; performs screening and matching processing on the above-mentioned each process information set to obtain at least one communication process information; based on the above-mentioned each application module configuration information information, generate at least one application business affiliation information corresponding to the above at least one communication process information; perform communication relationship modeling on the above at least one communication process information to obtain at least one business system communication association information corresponding to the above at least one communication process information; based on the above at least one application business affiliation information, perform grouping processing on the above at least one communication process information to obtain a communication process information group set; perform matching processing on the above communication process information group set to obtain access relationship information between various business systems; based on the above at least one business system communication association information and the access relationship information between the above various business systems, generate a system application access relationship diagram corresponding to the above various preset business systems; and display the above system application access relationship diagram on the preset page.
[0101] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0102] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0103] The units described in some embodiments of the present disclosure may be implemented by software or by hardware. The described units may also be provided in a processor, for example, they may be described as: a processor comprising an acquisition unit, a collection unit, a screening and matching processing unit, a first generation unit, a communication relationship modeling processing unit, a grouping unit, a matching processing unit, a second generation unit, and a display unit. The names of these units do not, in certain cases, constitute a limitation on the units themselves. For example, the acquisition unit may also be described as "a unit that acquires configuration information of each application module corresponding to each of the preset business systems in response to detecting that the startup state of the preset business system in each of the preset business systems is the initial startup state or that a configuration change occurs in the preset business system."
[0104] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.
[0105] The above descriptions are merely some preferred embodiments of the present disclosure and illustrate the underlying technical principles. Those skilled in the art should understand that the scope of the invention encompassed by the embodiments of the present disclosure is not limited to technical solutions formed by specific combinations of technical features, but also encompasses other technical solutions formed by any combination of technical features or their equivalents without departing from the inventive concept. For example, a technical solution formed by replacing a feature with (but not limited to) a technical feature having similar functions disclosed in the embodiments of the present disclosure.
Claims
1. A method for generating a system application access relationship graph, comprising: In response to detecting that the startup state of a preset business system among the preset business systems is the initial startup state or that a configuration change occurs in the preset business system, obtaining configuration information of each application module corresponding to the respective preset business systems; Collecting each process information set of each preset business system where each application module corresponding to each application module configuration information is located, wherein each process information set in each process information set corresponds to one application module configuration information in each application module configuration information; Performing screening and matching processing on each of the process information sets to obtain at least one communication process information; Based on the configuration information of each application module, generating at least one application service attribution information corresponding to the at least one communication process information; Performing communication relationship modeling processing on the at least one communication process information to obtain at least one business system communication association information corresponding to the at least one communication process information; performing grouping processing on the at least one communication process information based on the at least one application service attribution information to obtain a communication process information group set; Matching the communication process information set to obtain access relationship information between each business system, wherein matching the communication process information set to obtain access relationship information between each business system includes: For every two communication process information groups in the communication process information group set, perform the following steps: In response to determining that there is an intersection between the two communication process information groups, determining the intersection as a shared communication process information set; Determining the two communication process information groups as a first communication process information group and a second communication process information group respectively; Determine the screening service system name corresponding to the first communication process information group as the first screening service system name; Determine the screening service system name corresponding to the second communication process information group as the second screening service system name; For each shared communication process information in the shared communication process information set, perform the following steps: Querying the business system name corresponding to the shared communication process information from the preset process business attribution record table as the query business system name; In response to determining that the query business system name is the same as the first screening business system name, determining information indicating that the preset business system corresponding to the second screening business system name accesses the preset business system corresponding to the first screening business system name as inter-business system access relationship information; In response to determining that the query business system name is the same as the second screening business system name, determining information indicating that the preset business system corresponding to the first screening business system name accesses the preset business system corresponding to the second screening business system name as inter-business system access relationship information; generating a system application access relationship graph corresponding to each of the preset business systems based on the communication association information within the at least one business system and the access relationship information between the business systems; The system application access relationship diagram is displayed on a preset page.
2. The method according to claim 1, wherein The collecting of each process information set of each preset business system where each application module corresponding to the configuration information of each application module is located includes: For each piece of application module configuration information, perform the following collection steps: Obtaining preset script information corresponding to the application module configuration information; Deploying the script corresponding to the preset script information to the preset business system corresponding to the application module configuration information, and collecting process information corresponding to each process in the preset business system through the deployed script; The collected pieces of process information are determined as a process information set.
3. The method according to claim 1, wherein The screening and matching processing of each process information set to obtain at least one communication process information includes: Querying process status information of a process corresponding to each process information in each process information set to obtain each process status information corresponding to each process information set; Determining at least one process state information representing ongoing communication among the respective process state information as at least one target process state information; At least one process information corresponding to the at least one target process status information in each process information set is determined as at least one communication process information.
4. The method according to claim 1, wherein Each communication process information in the at least one communication process information corresponds to a corresponding piece of application module configuration information in the respective application module configuration information, the application module configuration information including application module address information and application name information, and generating at least one application service attribution information corresponding to the at least one communication process information based on the respective application module configuration information, comprising: For each piece of communication process information in the at least one communication process information, the following generating step is performed: Determining the application module configuration information corresponding to the communication process information in the respective application module configuration information as the target application module configuration information; Determining the application name information included in the target application module configuration information as the target application name information; Querying the business system name information of the preset business system where the application module corresponding to the target application module configuration information is located from the preset process knowledge base; The target application name information and the service system name information are determined as the application service attribution information corresponding to the communication process information.
5. A system application access relationship graph generation device, comprising: An acquiring unit is configured to acquire configuration information of each application module corresponding to each preset business system in response to detecting that the startup state of a preset business system among the preset business systems is the initial startup state or that a configuration change occurs in the preset business system; a collecting unit configured to collect each process information set of each preset business system where each application module corresponding to each application module configuration information is located, wherein each process information set in each process information set corresponds to one application module configuration information in each application module configuration information; a screening and matching processing unit, configured to perform screening and matching processing on each of the process information sets to obtain at least one communication process information; A first generating unit is configured to generate at least one application service attribution information corresponding to the at least one communication process information based on the configuration information of each application module; a communication relationship modeling processing unit, configured to perform communication relationship modeling processing on the at least one communication process information to obtain at least one intra-business system communication association information corresponding to the at least one communication process information; a grouping unit configured to group the at least one communication process information based on the at least one application service attribution information to obtain a communication process information group set; A matching processing unit is configured to perform matching processing on the communication process information group set to obtain access relationship information between various business systems, wherein the matching processing on the communication process information group set to obtain access relationship information between various business systems includes: for every two communication process information groups in the communication process information group set, performing the following steps: in response to determining that there is an intersection between the two communication process information groups, determining the intersection as a shared communication process information set; determining the two communication process information groups as a first communication process information group and a second communication process information group respectively; determining the screening business system name corresponding to the first communication process information group as a first screening business system name; determining the screening business system name corresponding to the second communication process information group as a second screening business system a unified name; for each shared communication process information in the shared communication process information set, performing the following steps: querying the business system name corresponding to the shared communication process information from the preset process business attribution record table as the query business system name; in response to determining that the query business system name is the same as the first filtered business system name, determining the information representing that the preset business system corresponding to the second filtered business system name accesses the preset business system corresponding to the first filtered business system name as the access relationship information between business systems; in response to determining that the query business system name is the same as the second filtered business system name, determining the information representing that the preset business system corresponding to the first filtered business system name accesses the preset business system corresponding to the second filtered business system name as the access relationship information between business systems; A second generating unit is configured to generate a system application access relationship graph corresponding to each of the preset business systems based on the communication association information within the at least one business system and the access relationship information between the business systems; The display unit is configured to display the system application access relationship diagram on a preset page.
6. An electronic device comprising: one or more processors; a storage device having one or more programs stored thereon; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 4.
7. A computer-readable medium having a computer program stored thereon, wherein: When the program is executed by a processor, the method according to any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Service state information feedback method, device and equipment and computer readable medium
CN117290561A
Business data monitoring method and device, electronic equipment and computer readable medium
CN118132383A