Abnormality detection method and device, equipment, storage medium and program product
By building a target knowledge base to perform automatic exception analysis of function call data, the system instability problem caused by relying on manual experience in the existing technology is solved, and the potential abnormal risks are effectively identified and the stability and reliability of system operation are ensured.
Patent Information
- Application Number
- CN202510829491.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-07-22
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, function call stack data analysis relies on manual experience and cannot identify potential abnormal risks, resulting in low stability and reliability of system operation.
By building a target knowledge base, obtaining function call data and matching and analysis with historical exception example information, potential exceptions can be detected automatically, and the real-time and comprehensiveness of exception detection are improved.
Automatic exception analysis of function call data is realized, potential exception risks are identified, and the stability and reliability of system operation are improved.
Smart Images

Figure CN120353680A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technologies, and in particular, to an anomaly detection method, apparatus, device, storage medium, and program product. Background Art
[0002] With the rapid development of technologies such as the Internet and artificial intelligence, online systems are increasingly widely used. In an online system, an electronic device on which an application program is deployed usually needs to make a large number of function calls during operation. On this basis, a function call stack generated based on function calls is an important data source for diagnosing problems such as system performance bottlenecks, memory leaks, and deadlocks.
[0003] In related technologies, the analysis of function call stack data is usually implemented manually and mainly relies on manual experience to discover and handle abnormal situations. This way of analyzing function call stack data cannot identify potential abnormal risks, and the real-time performance and comprehensiveness of anomaly detection are not high, which affects the stability and reliability of system operation. Summary of the Invention
[0004] Multiple aspects of this application provide an anomaly detection method, apparatus, device, storage medium, and program product, which can realize automatic anomaly analysis of function call data, can identify potential abnormal risks, improve the real-time performance and comprehensiveness of anomaly detection, and can ensure the stability and reliability of system operation.
[0005] In a first aspect, an embodiment of this application provides an anomaly detection method, including:
[0006] Obtain function call data corresponding to a target device;
[0007] When a target detection instruction is detected, determine target anomaly example information corresponding to the target detection instruction according to a target knowledge base; the target knowledge base includes multiple historical anomaly examples; the target anomaly example information includes information of at least one of the historical anomaly examples associated with the target detection instruction;
[0008] Perform matching analysis on the target anomaly example information and the function call data according to the target detection instruction to obtain target anomaly information corresponding to the function call data.
[0009] In a possible implementation manner, the obtaining function call data corresponding to a target device includes:
[0010] Collect function call data corresponding to the target device in at least one region through a target proxy tool;
[0011] Receive the function call data through a target log service process.
[0012] In a possible implementation, the method further includes:
[0013] Generating a target detection instruction corresponding to the interaction operation in response to an interaction operation of a client; and / or,
[0014] Generating the target detection instruction when an abnormal data index is detected; the abnormal data index is a data index with an abnormality in the target device; and / or,
[0015] Periodically generating the target detection instruction according to a preset time period.
[0016] In a possible implementation, determining the target abnormal example information corresponding to the target detection instruction according to the target knowledge base includes:
[0017] Determining the type information corresponding to the target detection instruction according to the keyword fields of the target detection instruction;
[0018] Performing data query in the target knowledge base based on the type information, and determining a target abnormal example corresponding to the type information among the multiple historical abnormal examples; the historical abnormal information corresponding to the historical abnormal example includes a historical function call chain, a historical abnormal pattern, and historical solution information;
[0019] Determining the target abnormal example information corresponding to the target detection instruction according to the historical abnormal information corresponding to the target abnormal example.
[0020] In a possible implementation, performing matching analysis on the target abnormal example information and the function call data according to the target detection instruction to obtain the target abnormal information corresponding to the function call data includes:
[0021] Generating a target processing instruction corresponding to the function call data according to the target abnormal example information and the target detection instruction;
[0022] Processing the function call data based on the target processing instruction to obtain an initial processing result;
[0023] Performing matching analysis on the initial processing result and the target abnormal example information to obtain the target abnormal information corresponding to the function call data.
[0024] In a possible implementation, generating the target processing instruction corresponding to the function call data according to the target abnormal example information and the target detection instruction includes:
[0025] Determining a data processing template corresponding to the target detection instruction according to the target abnormal example information;
[0026] Perform parameter configuration in the data processing template to generate a target processing instruction corresponding to the function call data; the parameter configuration includes at least one of geographical parameter configuration, time range parameter configuration, and stack information configuration; and / or, generate a target processing instruction corresponding to the function call data according to the data processing template and pre-configured data; the pre-configured data includes at least one of pre-configured functions and pre-configured rules.
[0027] In a possible implementation manner, the method further includes:
[0028] Store the target exception information in the background database, and output the target exception information and the target alarm information corresponding to the target exception information through the client.
[0029] In a possible implementation manner, the method further includes:
[0030] In response to a feedback operation of the client for the target exception information, collect feedback information corresponding to the feedback operation;
[0031] Generate a new exception example according to the target exception information and the feedback information, and update the new exception example to the target knowledge base.
[0032] In a second aspect, an embodiment of the present application provides an exception detection device, including:
[0033] An acquisition module, configured to acquire function call data corresponding to a target device;
[0034] A determination module, configured to, when detecting a target detection instruction, determine target exception example information corresponding to the target detection instruction according to a target knowledge base; the target knowledge base includes a plurality of historical exception examples; the target exception example information includes information of at least one of the historical exception examples associated with the target detection instruction;
[0035] An analysis module, configured to perform matching analysis on the target exception example information and the function call data according to the target detection instruction to obtain target exception information corresponding to the function call data.
[0036] In a possible implementation manner, the acquisition module is specifically configured to:
[0037] Collect function call data corresponding to the target device in at least one region through a target proxy tool;
[0038] Receive the function call data through a target log service process.
[0039] In a possible implementation manner, the device is further configured to:
[0040] In response to an interaction operation of the client, generate a target detection instruction corresponding to the interaction operation; and / or,
[0041] In the case of detecting an abnormal data metric, generate the target detection instruction; the abnormal data metric is a data metric with an abnormality in the target device; and / or,
[0042] Generate the target detection instruction periodically according to a preset time period.
[0043] In a possible implementation manner, the determining module is specifically configured to:
[0044] Determine type information corresponding to the target detection instruction according to a keyword field of the target detection instruction;
[0045] Perform a data query in the target knowledge base based on the type information, and determine a target abnormal example corresponding to the type information among the multiple historical abnormal examples; the historical abnormal information corresponding to the historical abnormal example includes a historical function call chain, a historical abnormal pattern, and historical solution information;
[0046] Determine target abnormal example information corresponding to the target detection instruction according to the historical abnormal information corresponding to the target abnormal example.
[0047] In a possible implementation manner, the analysis module is specifically configured to:
[0048] Generate a target processing instruction corresponding to the function call data according to the target abnormal example information and the target detection instruction;
[0049] Process the function call data based on the target processing instruction to obtain an initial processing result;
[0050] Match and analyze the initial processing result with the target abnormal example information to obtain target abnormal information corresponding to the function call data.
[0051] In a possible implementation manner, the analysis module is specifically configured to:
[0052] Determine a data processing template corresponding to the target detection instruction according to the target abnormal example information;
[0053] Perform parameter configuration in the data processing template to generate a target processing instruction corresponding to the function call data; the parameter configuration includes at least one of geographical parameter configuration, time range parameter configuration, and stack information configuration; and / or, generate a target processing instruction corresponding to the function call data according to the data processing template and pre-configured data; the pre-configured data includes at least one of pre-configured functions and pre-configured rules.
[0054] In a possible implementation manner, the apparatus is further configured to:
[0055] Store the target exception information in a background database, and output the target exception information and a target warning message corresponding to the target exception information through a client.
[0056] In a possible implementation manner, the apparatus is further configured to:
[0057] In response to a feedback operation of the client for the target exception information, collect feedback information corresponding to the feedback operation;
[0058] Generate a new exception example according to the target exception information and the feedback information, and update the new exception example to the target knowledge base.
[0059] In a third aspect, an embodiment of the present application provides an exception detection device, including: a memory and a processor;
[0060] The memory stores computer execution instructions;
[0061] The processor executes the computer execution instructions stored in the memory, so that the processor executes the exception detection method according to any one of the first aspects.
[0062] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer execution instructions are stored, and when the computer execution instructions are executed by a processor, they are used to implement the exception detection method according to any one of the first aspects.
[0063] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the exception detection method according to any one of the first aspects.
[0064] In an embodiment of the present application, function call data corresponding to a target device is obtained; in the case where a target detection instruction is detected, target abnormal example information corresponding to the target detection instruction is determined according to a target knowledge base; the target knowledge base includes a plurality of historical abnormal examples; the target abnormal example information includes information of at least one historical abnormal example associated with the target detection instruction; according to the target detection instruction, matching analysis is performed on the target abnormal example information and the function call data to obtain target abnormal information corresponding to the function call data. In the present application, an electronic device obtains function call data of a target device, determines target abnormal example information corresponding to a target detection instruction from the target knowledge base when the target detection instruction is detected, and then can perform matching analysis on the function call data and the target abnormal example information to automatically detect the target abnormal information corresponding to the function call data. In this way, the electronic device can realize automatic abnormal analysis of function call data based on the target knowledge base, can identify potential abnormal risks, improves the real-time performance and comprehensiveness of abnormal detection, and can ensure the stability and reliability of system operation. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0066] Figure 1 It is a schematic flowchart of an abnormal detection method provided by an exemplary embodiment of the present application;
[0067] Figure 2 It is a schematic flowchart of another abnormal detection method provided by an exemplary embodiment of the present application;
[0068] Figure 3 It is a schematic diagram of a system architecture of an abnormal detection provided by an exemplary embodiment of the present application;
[0069] Figure 4 It is a schematic diagram of the structure of an abnormal detection device provided by an exemplary embodiment of the present application;
[0070] Figure 5 It is a schematic diagram of the structure of an abnormal detection device provided by an exemplary embodiment of the present application.
[0071] Through the above-mentioned accompanying drawings, specific embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These drawings and text descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0072] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments of this application and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this application. It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards, and corresponding operation entrances are provided for users to choose to authorize or refuse.
[0073] In an online system, the function call stack is an important data source for diagnosing problems such as device performance bottlenecks, memory leaks, and deadlocks. The profiling stack data usually contains a large amount of function call information, but this data is often raw and not deeply analyzed. In related technologies, the analysis of function call stack data, that is, profiling stack data, is usually manually performed by operation and maintenance personnel with professional knowledge, mainly relying on manual experience to discover and handle abnormal situations. This function call stack data analysis method in related technologies cannot identify potential abnormal risks, and the real-time and comprehensiveness of abnormal detection are not high, affecting the stability and reliability of system operation.
[0074] To solve the above problems, this application provides an abnormal detection method, device, equipment, storage medium, and program product. In this way, the electronic device obtains the function call data of the target device, determines the target abnormal example information corresponding to the target detection instruction from the target knowledge base when detecting the target detection instruction, and then can perform matching analysis on the function call data and the target abnormal example information to automatically detect the target abnormal information corresponding to the function call data. In this way, the electronic device can realize automatic abnormal analysis of function call data based on the target knowledge base, can identify potential abnormal risks, improve the real-time and comprehensiveness of abnormal detection, and ensure the stability and reliability of system operation.
[0075] The following details the technical solutions shown in this application through specific embodiments. It should be noted that the following several embodiments can exist independently or be combined with each other, and the same or similar content will not be repeated in different embodiments.
[0076] Figure 1 It is a schematic flowchart of an abnormal detection method provided for an exemplary embodiment of this application. Please refer to Figure 1, the anomaly detection method may include:
[0077] S101. Obtain function call data corresponding to the target device.
[0078] The execution subject of the embodiments of the present application may be an electronic device or an anomaly detection device provided in the electronic device. The anomaly detection device may be implemented by software or by a combination of software and hardware. For ease of understanding, in the following, the execution subject is taken as an electronic device as an example for illustration. The electronic device may specifically refer to a mobile terminal, a server, a cloud, etc. For example, the electronic device may refer to a cloud service platform or a central micro-service, etc. The embodiments of the present application do not limit the specific type of the electronic device.
[0079] In the embodiments of the present application, the target device may refer to a device to be detected that needs to perform function call anomaly detection. In a distributed architecture or a distributed system, data centers in different regions are usually involved. The target device may refer to multiple devices to be detected in at least one region. The function call data may refer to the function call stack data of the target device, that is, the performance profiling stack data of the target device. The function call data may specifically include call stack information, resource metric information, and environmental context information, etc. Among them, the call stack information may specifically include a function call sequence, a function call count, and function call symbol information (such as a function name and a source code location, etc.); the resource metric information may specifically include function elapsed time and function call start / end time, etc.; the environmental context information may specifically include CPU usage, memory occupancy, lock wait time, and thread status, etc. Of course, the function call data may also include other information, which may be flexibly set based on actual needs. The embodiments of the present application do not limit this. It should be noted that the function call data obtained by the electronic device may refer to the function call data of the application program, operating system, hardware, kernel, and container runtime, etc. of the target device. In this way, the electronic device can subsequently perform anomaly detection on the function call data at multiple levels of the target device, ensuring the comprehensiveness of the anomaly detection and realizing the timely detection of potential risks.
[0080] Specifically, during the operation of the distributed system, the electronic device may collect the function call data of each target device in different regions through a data collection tool such as an Agent, for example, it may collect the function call data in real time from the application program of the target device deployment instance. The electronic device may store the function call data in a target database for subsequent data processing and analysis.
[0081] S102. When a target detection instruction is detected, determine target abnormal example information corresponding to the target detection instruction according to a target knowledge base; the target knowledge base includes multiple historical abnormal examples; the target abnormal example information includes information of at least one historical abnormal example associated with the target detection instruction.
[0082] In an embodiment of the present application, the target detection instruction may refer to a trigger instruction for detecting abnormalities in function call data, and may also be referred to as a target detection task, etc. The target detection instruction may be automatically generated according to a preset time period, may also be generated in response to an interactive operation of a client, or may also be automatically generated when abnormal data metrics are detected. The specific generation method of the target detection instruction in the embodiment of the present application is not limited. The target knowledge base may refer to a problem experience knowledge base storing various function call abnormal situations. The target knowledge base may include multiple historical abnormal examples, and each historical abnormal example may include a historical function call chain, a historical abnormal pattern, historical solution information, etc. The target knowledge base may be created based on data mining technology, pattern recognition algorithms, etc., and can cover abnormal situations in multiple function call processes. Exemplarily, the target knowledge base may be specifically constructed in the following manner:
[0083] First, an electronic device may obtain historical abnormal data. For example, historical abnormal data may be collected from historical fault reports, production environment performance profiling data, error logs, and operation and maintenance data; then data cleaning and standardization processing may be performed on the historical abnormal data to filter out invalid data and convert the format of valid data. After that, the electronic device may extract multiple historical abnormal examples from the historical abnormal data after data cleaning and standardization processing through data mining technology and pattern recognition algorithms, etc., and fill in the field information in each historical abnormal example to create the target knowledge base. Of course, the target knowledge base may also be constructed in other ways, and may be flexibly set according to actual needs. The embodiment of the present application does not limit this.
[0084] The target abnormal example information may refer to the specific information corresponding to the historical abnormal example associated with the target detection instruction, that is, the information of at least one historical abnormal example associated with the target detection instruction. Since there are many historical abnormal examples in the target knowledge base, the electronic device may extract the historical abnormal examples associated with the target detection instruction from the multiple historical abnormal examples in the target knowledge base based on the target detection instruction, and record them as target abnormal examples. The number of the target abnormal examples may be one, two, or more; then the target abnormal example information corresponding to the target detection instruction may be determined according to at least one target abnormal example. The target abnormal example information may specifically include a target historical function call chain, a target historical abnormal pattern, target historical solution information, etc.
[0085] In this step, during the operation of the distributed system, if the electronic device detects a target detection instruction, it can determine the target abnormal example information corresponding to the target detection instruction in the target knowledge base, and then compare and match the function call data with the target abnormal example information to determine the potential risks included in the function call data.
[0086] S103. According to the target detection instruction, perform matching analysis on the target abnormal example information and the function call data to obtain the target abnormal information corresponding to the function call data.
[0087] In the embodiment of the present application, the target abnormal information may refer to the detection result of the abnormal detection of the function call data, which may include the risk information existing in the function call data. Specifically, after determining the target abnormal example information, the electronic device can perform matching analysis on the function call data and the target abnormal example information based on the target detection instruction to determine whether there is a risk in the function call data, and finally obtain the target abnormal information corresponding to the function call data. In this way, the electronic device determines the target abnormal example information associated with the target detection instruction based on the historical abnormal examples in the target knowledge base, and then performs matching analysis on the target abnormal example information and the function call data to realize the automatic abnormal detection of the function call data, realizing the rapid and comprehensive detection of potential risks, significantly reducing manual intervention, and improving the timeliness and accuracy of abnormal detection.
[0088] In the embodiment of the present application, the electronic device obtains the function call data corresponding to the target device; in the case of detecting the target detection instruction, determines the target abnormal example information corresponding to the target detection instruction according to the target knowledge base; the target knowledge base includes multiple historical abnormal examples; the target abnormal example information includes the information of at least one historical abnormal example associated with the target detection instruction; according to the target detection instruction, perform matching analysis on the target abnormal example information and the function call data to obtain the target abnormal information corresponding to the function call data. In the present application, the electronic device obtains the function call data of the target device, then determines the target abnormal example information corresponding to the target detection instruction from the target knowledge base, and then can perform matching analysis on the function call data and the target abnormal example information to automatically detect the target abnormal information corresponding to the function call data. In this way, the electronic device can realize the automatic abnormal analysis of the function call data based on the target knowledge base, identify potential abnormal risks, improve the real-time performance and comprehensiveness of abnormal detection, and ensure the stability and reliability of system operation.
[0089] Based on the above embodiments, Figure 2 It is a schematic flowchart of another abnormal detection method provided by the exemplary embodiment of the present application. Please refer to Figure 2 This abnormal detection method may include:
[0090] S201. Collect the function call data corresponding to the target devices in at least one region through the target proxy tool; receive the function call data through the target log service process.
[0091] In the embodiments of the present application, the target proxy tool may refer to the data collection tools deployed in each region of the distributed system. The target log service process may refer to the log data transmission service process in the distributed system. The target database may refer to a pre-set storage database, such as a cloud database (ClickHouse), etc. During the operation of the distributed system, the electronic device may collect the function call data in real time in the target devices in each region through the target proxy tool; then it may receive the function call data in each region through the target log service process. For example, the target proxy tool in region A may upload the function call data in region A to the target log service process in region A, and the target proxy tool in region B may upload the function call data in region B to the target log service process in region B. Then, the electronic device may store the function call data in the target database through a data import processing program (such as Flink or Go, etc.). For example, if the electronic device receives the function call data in region A through the target log service process in region A, it may store the function call data in region A in the target database in region A.
[0092] In the embodiments of the present application, the electronic device collects the function call data corresponding to the target devices in each region through the target proxy tool, receives the function call data through the target log service process, and stores the function call data in the target database. In this way, by collecting, uploading, and storing the function call data of multiple target devices in each region, the electronic device can ensure the comprehensiveness and accuracy of subsequent function call anomaly detection, and ensure the timely discovery of potential risks.
[0093] S202. Generate a target detection instruction corresponding to the interaction operation in response to the interaction operation of the client; and / or, generate a target detection instruction when there are abnormal data metrics in the function call data; the abnormal data metrics are the data metrics with abnormalities in the target device; and / or, generate a target detection instruction periodically according to a preset time period.
[0094] In the embodiments of the present application, the interaction operation may refer to an input operation of the client, etc. For example, a user may input a problem or task of anomaly detection through the client. The anomaly data metric may refer to a data metric with anomalies in the target device. For example, the CPU usage rate is too high, the memory occupancy is too high, or there is a program deadlock, etc. The preset time period may refer to a preset automatic anomaly detection time period, specifically, it may refer to 30 seconds, 60 seconds, or 120 seconds, etc., and can be specifically set based on actual requirements. The embodiments of the present application do not limit this.
[0095] In this step, the target detection instruction can be generated in multiple ways. The electronic device can generate a target detection instruction corresponding to the interaction operation in response to the interaction operation of the client, or can automatically generate a target detection instruction when detecting an anomaly data metric, or can periodically generate a target detection instruction according to the preset time period. The electronic device can use at least one of the above three methods to generate the target detection instruction. Of course, it can also use other methods to generate the target detection instruction. The embodiments of the present application do not limit this. In this way, the electronic device can use multiple methods to generate the target detection instruction, trigger the anomaly detection of function call data, improve the timeliness and flexibility of anomaly detection, and can not only meet the actual needs of users, but also ensure the normal operation of the distributed system.
[0096] S203. When the target detection instruction is detected, determine the type information corresponding to the target detection instruction according to the key fields of the target detection instruction.
[0097] S204. Based on the type information, query data in the target knowledge base, and determine the target anomaly example corresponding to the type information among multiple historical anomaly examples; the historical anomaly information corresponding to the historical anomaly example includes the historical function call chain, the historical anomaly pattern, and the historical solution information; according to the historical anomaly information corresponding to the target anomaly example, determine the target anomaly example information corresponding to the target detection instruction.
[0098] In the embodiments of the present application, the key field may refer to the key field information included in the target detection instruction. The type information may refer to the detection type corresponding to the target detection instruction, and this type information may refer to a set of multiple key fields. The target anomaly example may refer to the historical anomaly example associated with the target detection instruction in the target knowledge base.
[0099] Specifically, the target knowledge base records information such as high-frequency function call chains, common exception patterns, and exception solutions. These information are embodied in the form of historical exception examples (or called knowledge base examples). The historical exception information included in a historical exception example may include a historical function call chain (function call chain in the exception situation), a historical exception pattern (pattern information of the exception situation), and a historical solution information (solution of the exception situation), etc. As the target knowledge base continuously learns and expands, the historical exception examples in the target knowledge base can cover a sufficient number of exception situations.
[0100] Exemplarily, the historical exception examples included in the target knowledge base in the embodiments of the present application may include the following fields: reference document identifier (wendang_id), reference document link (wendang_link), flame graph function stack list (livetrace_stack), top-level function occupancy dictionary (top), total occupancy ("total"), call occupancy ("call"), self-occupancy ("self"), problem title (title), relevant work order link (aone), kernel field (os_field), specific problem description (description), solution (fix), log string list or empty character (logs), kernel function call stack list (stack), tool list or empty character (tool), involved function list or empty character (function), root cause description (root_cause), environment (env), and hotfix number (hotfix), etc. Of course, other field information may also be included in the historical exception example, and can be flexibly set specifically based on actual requirements. The embodiments of the present application do not limit this.
[0101] In this step, after detecting the target detection instruction, the electronic device can determine the type information of the target detection instruction according to the keyword fields in the target detection instruction, such as the problem title, problem description, etc. The type information may be a set of multiple keyword fields. Then, the electronic device can perform data query and matching in the target knowledge base based on the type information, and determine the target exception example associated with the type information among the multiple historical exception examples in the target knowledge base. Then, the electronic device can determine the target exception example information corresponding to the target detection instruction according to the historical exception information corresponding to the target exception example. Specifically, the electronic device can extract the target historical function call chain, target historical exception pattern, target historical solution information, etc. in the target exception example as the target exception example information corresponding to the target detection instruction.
[0102] In an embodiment of the present application, the electronic device determines the type information of the target detection instruction based on the keyword field of the target detection instruction, and then queries the historical abnormal examples in the target knowledge base according to the type information to obtain the target abnormal examples associated with the target detection instruction, and further can determine the target abnormal example information corresponding to the target detection instruction. In this way, the electronic device can query and filter the historical abnormal examples in the target knowledge base, reduce the computational complexity of subsequent matching analysis, and improve the efficiency, real-time performance, and accuracy of abnormal detection.
[0103] In addition, it should be noted that when the target detection instruction is a global detection instruction (such as in scenarios where the target detection instruction is periodically generated, etc.), the electronic device can use multiple historical abnormal examples in the target knowledge base as the target abnormal examples, and then can determine the target abnormal example information based on the multiple target abnormal examples.
[0104] S205. Generate a target processing instruction corresponding to the function call data according to the target abnormal example information and the target detection instruction.
[0105] In an embodiment of the present application, the target processing instruction may refer to a data processing instruction for function call data. For example, it may be a database language (Structured Query Language, SQL) execution statement, etc. This data processing instruction can be used to perform data cleaning, data trend analysis, and data query on the function call data. Of course, it may also refer to other data processing logic instructions, and the embodiments of the present application do not limit this. Subsequently, the electronic device can send the target processing instruction to the target proxy tool, and the target proxy tool processes the function call data based on the target processing instruction to facilitate subsequent pattern recognition and matching analysis.
[0106] In a possible implementation manner, the target processing instruction can be generated in the following way:
[0107] Determine a data processing template corresponding to the target detection instruction according to the target abnormal example information;
[0108] Perform parameter configuration in the data processing template to generate a target processing instruction corresponding to the function call data; the parameter configuration includes at least one of geographical parameter configuration, time range parameter configuration, and stack information configuration; and / or, generate a target processing instruction corresponding to the function call data according to the data processing template and pre-configured data; the pre-configured data includes at least one of pre-configured functions and pre-configured rules.
[0109] In the embodiments of the present application, the data processing template may refer to the data processing template corresponding to the target detection instruction determined based on the target abnormal example information. The target abnormal example information may include the data processing method required for abnormal detection. The electronic device may determine the data processing template required for the target detection instruction based on this data processing method. Subsequently, the electronic device may perform parameter configuration in the data processing template according to the specific situation of the function call data in different regions to generate the target processing instruction corresponding to the function call data. The parameter configuration may specifically include at least one of region parameter configuration (replacing region parameters), time range parameter configuration (configuring the time range to be detected according to a preset time period, etc.), and stack information configuration (determining and configuring the stack information that may have problems based on the target abnormal example information). Of course, the parameter configuration in this step may also include other types of parameter replacement and configuration, which are not limited in the embodiments of the present application.
[0110] In addition, when generating the target processing instruction corresponding to the function call data, the electronic device may also generate the target processing instruction according to the data processing template and the pre-configured data. The pre-configured data may refer to the instruction configuration data defined by the user, and may specifically include at least one of pre-configured functions and pre-configured rules. The pre-configured function may also be referred to as a user-defined function (User-Defined Functions, UDF), etc. Exemplarily, the electronic device may receive the user's pre-configured data through the target proxy tool, such as custom data and custom rules based on UDF. Subsequently, parameter configuration and rule adjustment are performed on the data processing template according to the pre-configured data, and finally the target processing instruction corresponding to the function call data is obtained.
[0111] It should be noted that the target processing instruction may be generated by performing parameter configuration on the data processing template, or may be generated based on the data processing template and the pre-configured data, or both of these methods may be used simultaneously, which is not limited in the embodiments of the present application. In the embodiments of the present application, the electronic device determines the data processing template corresponding to the target detection instruction based on the target abnormal example information, and then performs parameter configuration in the data processing template to generate the target processing instruction corresponding to the function call data, or may also generate the target processing instruction based on the pre-configured data and the data processing template, which can improve the flexibility and reliability of the generation of the target processing instruction and ensure the rationality of the abnormal detection of the function call data.
[0112] S206. Process the function call data based on the target processing instruction to obtain an initial processing result; match and analyze the initial processing result with the target abnormal example information to obtain the target abnormal information corresponding to the function call data.
[0113] In an embodiment of the present application, after the electronic device generates a target processing instruction, it can process the function call data based on the target processing instruction to obtain an initial processing result. Depending on the different target processing instructions, the initial processing result can be a data cleaning result of the function call data, a trend analysis result (for predicting possible risk information), a data query result, etc. Subsequently, the electronic device can, based on the target detection instruction, perform a matching analysis on the initial processing result and the target abnormal example information. Specifically, algorithms such as pattern recognition and (function call chain) similarity calculation can be used to determine the target abnormal information corresponding to the function call data according to the target abnormal example information with a higher matching degree to the initial processing result. Corresponding to the target abnormal example information, the target abnormal information finally generated by the electronic device may include a target abnormal function call chain, a target abnormal pattern, and target abnormal solution information, etc.
[0114] In an embodiment of the present application, the electronic device can generate a target processing instruction according to the target abnormal example information in the target knowledge base to perform preliminary processing on the function call data, and then perform a matching analysis on the preliminary processing result and the target abnormal example information to obtain the target abnormal information corresponding to the function call data. This can achieve automatic abnormal detection of the function call data, reduce manual intervention, and improve the comprehensiveness and real-time nature of abnormal detection.
[0115] S207. Store the target abnormal information in the background database, and output the target abnormal information and the target alarm information corresponding to the target abnormal information through the client.
[0116] In an embodiment of the present application, the background database may refer to a storage backend database, which can be used for querying the abnormal detection results. For example, the background database may refer to the storage database corresponding to the target log service process, etc. The target alarm information may refer to the warning prompt information corresponding to the target abnormal information. The specific type of the target alarm information may include text prompt information, audio prompt information, or video prompt information, etc. The present application embodiment does not limit the specific type and specific content of the target alarm information.
[0117] Specifically, after the electronic device determines the target abnormal information, the electronic device can store the target abnormal information in the background database for subsequent query and analysis. Moreover, the electronic device can output the target abnormal information and the target alarm information corresponding to the target abnormal information through the client. For example, the electronic device can display the target abnormal information and the target alarm information in the client by means of message push, facilitating users (such as operation and maintenance personnel, etc.) to discover in a timely manner and ensuring that users can understand the real-time state and potential problems of the distributed system in real time.
[0118] S208. In response to a feedback operation of the client for the target exception information, collect the feedback information corresponding to the feedback operation; generate a new exception example according to the target exception information and the feedback information, and update the new exception example to the target knowledge base.
[0119] In the embodiments of the present application, the feedback operation may refer to a feedback operation or an evaluation operation of the user on the target exception information on the client. The feedback information may refer to information such as feedback, evaluation, and suggestion of the user on the target exception information uploaded through the client. Specifically, after the electronic device pushes the target exception information and the target alarm information to the user through the client, it may collect the feedback information on the target exception information in response to the feedback operation of the client. Then the electronic device can generate a new exception example according to the target exception information and the feedback information. For example, a new exception example can be generated by replacing the field content, etc. Then the new exception example can be added to the target knowledge base to realize the intelligent self-learning and continuous optimization of the target knowledge base, further improve the richness and comprehensiveness of the historical exception examples in the target knowledge base, and thus improve the comprehensiveness and accuracy of the abnormal detection of function call data.
[0120] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the various processes do not mean the order of execution. The order of execution of the various processes should be determined by their functions and internal logics, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0121] Based on any one of the above embodiments, Figure 3 This is a schematic diagram of the technical link for anomaly detection provided by an exemplary embodiment of the present application. As Figure 3As shown, the electronic device (central micro-service) collects function call data corresponding to the target device from each region (A, B, C, where region A corresponds to A1, A2, A3, region B corresponds to B1, B2, B3, and region C corresponds to C1, C2, C3, not directly shown in the figure) through the target proxy tools (A1, B1, C1); receives the function call data through the target log service processes (A2, B2, C2), and stores the function call data in the target databases (A3, B3, C3). When a target detection instruction is detected, the electronic device extracts the target abnormal example information corresponding to the target detection instruction from the target knowledge base; then the electronic device generates a target processing instruction (i.e., SQL) based on the target abnormal example information and the target detection instruction, and then can send the target processing instruction to the target proxy tool to perform data cleaning, trend analysis, data query, etc. on the function call data to obtain a preliminary processing result. The electronic device then performs pattern matching, pattern recognition, etc. on the preliminary processing result and the target abnormal example information. For example, the electronic device can determine the target abnormal example information with the highest similarity of the preliminary processing result through similarity calculation, and / or the electronic device can determine the target abnormal example information with the highest matching degree with the preliminary processing result through text matching, semantic matching, etc. Of course, other pattern matching and pattern recognition methods can also be used for matching analysis to finally determine the target abnormal information corresponding to the function call data. The electronic device can store the target abnormal information in the background database for easy query and analysis, and can push the target abnormal information and the target warning information to the user through the client, so that the user can grasp the system operation status and abnormal conditions in real time.
[0122] In the related art, the analysis methods for function call stack data mostly rely on manual experience, lacking automated tools to discover potential anomalies; and the monitoring systems (Application Performance Monitoring, APM) in the related art usually only focus on some key indicators and cannot detect potential problems in the function call stack; in addition, due to the lack of intelligent analysis means based on historical experience and rules, potential performance or stability risks cannot be warned in time.
[0123] In the anomaly detection method according to the embodiments of the present application, the electronic device can improve the ability to detect and handle anomalies in function call data by combining historical experience, dynamic analysis, and rule matching. The electronic device constructs a target knowledge base to record multiple historical anomaly examples, systematizes historical problems and solutions, and quickly identifies anomaly problems through algorithms such as pattern matching and pattern recognition, which can reduce manual intervention and improve the timeliness and accuracy of anomaly detection; based on diverse target processing instructions, the electronic device can perform processing such as trend analysis on function call data. For example, time series analysis technology can be used to model and analyze function call data to determine the trend changes in function call data, realizing early warning of potential risks such as performance, being able to timely identify the trend of performance degradation, and facilitating taking countermeasures in advance.
[0124] In addition, the electronic device can generate an anomaly report through natural language generation (NLG) and visualization tools, etc. (this anomaly report is a type of target warning information, and the target warning information can also be pre-configured text prompt information, audio prompt information, or video prompt information, etc.). The anomaly report can include anomaly descriptions, scope of influence, and solution information, which can further simplify the operations of users, improve the readability and operability of warning information, and improve the user operation and maintenance efficiency; moreover, the electronic device can support complex logic configuration through a custom rule engine, realize the flexible generation of multiple target processing instructions, meet the actual needs of different scenarios, and improve the accuracy and adaptability of anomaly detection. The anomaly detection method according to the embodiments of the present application realizes the conversion from manual analysis to automatic analysis, improves the stability and security of the system, integrates all links of data collection, storage, and analysis, forms a unified data processing and monitoring framework, simplifies the system structure, improves the efficiency of data circulation, and simultaneously realizes real-time monitoring and rapid response.
[0125] Figure 4 For the structural schematic diagram of an anomaly detection device provided by an exemplary embodiment of the present application, please refer to Figure 4 , the anomaly detection device includes:
[0126] An acquisition module 41, configured to acquire function call data corresponding to a target device;
[0127] A determination module 42, configured to, when detecting a target detection instruction, determine target anomaly example information corresponding to the target detection instruction according to the target knowledge base; the target knowledge base includes multiple historical anomaly examples; the target anomaly example information includes information of at least one historical anomaly example associated with the target detection instruction;
[0128] An analysis module 43, configured to perform matching analysis on target abnormal example information and function call data according to a target detection instruction, so as to obtain target abnormal information corresponding to the function call data.
[0129] In a possible implementation manner, the obtaining module 41 is specifically configured to:
[0130] Collect function call data corresponding to target devices in at least one region through a target proxy tool;
[0131] Receive function call data through a target log service process.
[0132] In a possible implementation manner, the apparatus 40 is further configured to:
[0133] Generate a target detection instruction corresponding to an interaction operation in response to an interaction operation of a client; and / or,
[0134] Generate a target detection instruction when abnormal data metrics are detected; the abnormal data metrics are data metrics with abnormalities in target devices; and / or,
[0135] Periodically generate a target detection instruction according to a preset time period.
[0136] In a possible implementation manner, the determining module 42 is specifically configured to:
[0137] Determine type information corresponding to a target detection instruction according to a keyword field of the target detection instruction;
[0138] Perform data query in a target knowledge base based on the type information, and determine a target abnormal example corresponding to the type information among multiple historical abnormal examples; the historical abnormal information corresponding to the historical abnormal example includes a historical function call chain, a historical abnormal pattern, and historical solution information;
[0139] Determine target abnormal example information corresponding to a target detection instruction according to the historical abnormal information corresponding to the target abnormal example.
[0140] In a possible implementation manner, the analysis module 43 is specifically configured to:
[0141] Generate a target processing instruction corresponding to function call data according to the target abnormal example information and the target detection instruction;
[0142] Process the function call data based on the target processing instruction to obtain an initial processing result;
[0143] Perform matching analysis on the initial processing result and the target abnormal example information to obtain target abnormal information corresponding to the function call data.
[0144] In a possible implementation, the analysis module 43 is specifically configured to:
[0145] Determine a data processing template corresponding to the target detection instruction according to the target exception example information;
[0146] Perform parameter configuration in the data processing template to generate a target processing instruction corresponding to the function call data; the parameter configuration includes at least one of geographical parameter configuration, time range parameter configuration, and stack information configuration; and / or, generate a target processing instruction corresponding to the function call data according to the data processing template and pre-configured data; the pre-configured data includes at least one of pre-configured functions and pre-configured rules.
[0147] In a possible implementation, the apparatus 40 is further configured to:
[0148] Store the target exception information in the background database, and output the target exception information and the target alarm information corresponding to the target exception information through the client.
[0149] In a possible implementation, the apparatus 40 is further configured to:
[0150] In response to a feedback operation of the client for the target exception information, collect feedback information corresponding to the feedback operation;
[0151] Generate a new exception example according to the target exception information and the feedback information, and update the new exception example to the target knowledge base.
[0152] The exception detection apparatus 40 provided by the embodiments of the present application can execute the technical solutions shown in the above method embodiments, and the implementation principles and beneficial effects are similar, and will not be elaborated here.
[0153] Figure 5 For a schematic structural diagram of an exception detection device provided by an exemplary embodiment of the present application, please refer to Figure 5 The exception detection device 50 may include a processor 51 and a memory 52. Exemplarily, the processor 51 and the memory 52 are interconnected with each other through a bus 53.
[0154] The memory 52 stores computer execution instructions;
[0155] The processor 51 executes the computer execution instructions stored in the memory 52, so that the processor 51 executes the exception detection method as shown in the above method embodiments.
[0156] Correspondingly, the embodiments of the present application provide a computer-readable storage medium, and computer execution instructions are stored in the computer-readable storage medium, and when the computer execution instructions are executed by a processor, they are used to implement the exception detection method of the above method embodiments.
[0157] Accordingly, an embodiment of the present application may further provide a computer program product, including a computer program, which when executed by a processor, can implement the anomaly detection method shown in the above method embodiment.
[0158] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, compact disc read-only memory (CD-ROM), optical memory, etc.) containing computer-usable program code.
[0159] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0160] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0161] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0162] In a typical configuration, a computing device includes one or more processors, input / output interfaces, a network interface, and memory.
[0163] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0164] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices, or any other non-transitory media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.
[0165] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising a..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0166] The above are only embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. An anomaly detection method, characterized in that, including: Obtaining function call data corresponding to a target device; When a target detection instruction is detected, determining target abnormal example information corresponding to the target detection instruction according to a target knowledge base; the target knowledge base includes a plurality of historical abnormal examples; the target abnormal example information includes information of at least one of the historical abnormal examples associated with the target detection instruction; Performing matching analysis on the target abnormal example information and the function call data according to the target detection instruction to obtain target abnormal information corresponding to the function call data.
2. The method according to claim 1, wherein The obtaining function call data corresponding to the target device includes: Collecting function call data corresponding to the target device in at least one region through a target proxy tool; Receiving the function call data through a target log service process.
3. The method according to claim 1, characterized in that, The method further includes: Generating a target detection instruction corresponding to the interaction operation in response to an interaction operation of a client; and / or, Generating the target detection instruction when abnormal data metrics are detected; the abnormal data metrics are data metrics with abnormalities in the target device; and / or, Periodically generating the target detection instruction according to a preset time period.
4. The method according to claim 1, wherein The determining target abnormal example information corresponding to the target detection instruction according to the target knowledge base includes: Determining type information corresponding to the target detection instruction according to a keyword field of the target detection instruction; Performing data query in the target knowledge base based on the type information, and determining a target abnormal example corresponding to the type information among the plurality of historical abnormal examples; the historical abnormal information corresponding to the historical abnormal example includes a historical function call chain, a historical abnormal pattern, and historical solution information; Determining target abnormal example information corresponding to the target detection instruction according to the historical abnormal information corresponding to the target abnormal example.
5. The method according to claim 1, wherein The performing matching analysis on the target abnormal example information and the function call data according to the target detection instruction to obtain target abnormal information corresponding to the function call data includes: Generating a target processing instruction corresponding to the function call data according to the target abnormal example information and the target detection instruction; Processing the function call data based on the target processing instruction to obtain an initial processing result; Performing matching analysis on the initial processing result and the target abnormal example information to obtain target abnormal information corresponding to the function call data.
6. The method according to claim 5, wherein The generating a target processing instruction corresponding to the function call data according to the target abnormal example information and the target detection instruction includes: Determining a data processing template corresponding to the target detection instruction according to the target abnormal example information; Performing parameter configuration in the data processing template to generate a target processing instruction corresponding to the function call data; the parameter configuration includes at least one of region parameter configuration, time range parameter configuration, and stack information configuration; and / or, generating a target processing instruction corresponding to the function call data according to the data processing template and pre-configured data; the pre-configured data includes at least one of a pre-configured function and a pre-configured rule.
7. The method according to any one of claims 1 to 6, characterized in that The method further includes: Store the target abnormal information in the background database, and output the target abnormal information and the target alarm information corresponding to the target abnormal information through the client.
8. The method according to any one of claims 1 to 6, characterized in that The method further includes: In response to a feedback operation of the client for the target abnormal information, collect feedback information corresponding to the feedback operation; Generate a new abnormal example according to the target abnormal information and the feedback information, and update the new abnormal example to the target knowledge base.
9. An anomaly detection device, characterized in that, It includes: An acquisition module, configured to acquire function call data corresponding to a target device; A determination module, configured to, when detecting a target detection instruction, determine target abnormal example information corresponding to the target detection instruction according to a target knowledge base; the target knowledge base includes a plurality of historical abnormal examples; the target abnormal example information includes information of at least one of the historical abnormal examples associated with the target detection instruction; An analysis module, configured to perform matching analysis on the target abnormal example information and the function call data according to the target detection instruction, and obtain target abnormal information corresponding to the function call data.
10. An anomaly detection device, characterized in that, It includes: A memory and a processor; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory, so that the processor executes the abnormal detection method according to any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that, Computer execution instructions are stored in the computer-readable storage medium, and when the computer execution instructions are executed by a processor, they are used to implement the abnormal detection method according to any one of claims 1 to 8.
12. A computer program product, characterized in that, It includes a computer program, and when the computer program is executed by a computer, it implements the abnormal detection method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Vehicle system anomaly detection method and device, electronic equipment and storage medium
CN117349173A
Intelligent operation and maintenance method and system for edge data center equipment
CN117520999A
Service exception processing method and device for application program, equipment, medium and product
CN118550745A
Interactive target statistical analysis method, device, equipment, medium and product
CN119025571A
Abnormality analysis method, electronic device, storage medium and program product
CN119088613A