Process detection method and system, electronic equipment and computer readable storage medium

By obtaining the operation information of processes in the cluster and user operation logs, combining risk and trust assessment, the accuracy of abnormal process detection is improved, and the problem of low accuracy of abnormal process detection in the cluster system is solved, thereby improving system stability and business continuity.

CN120371639APending Publication Date: 2025-07-25PING AN TECH (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510443490.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the prior art, the detection accuracy of abnormal processes in the cluster system is low, which affects the stability and business continuity of the bank or medical system.

Method used

By obtaining the operation information of the process to be detected and the user operation log, the first detection score and the second detection score are determined respectively, and the two are combined to determine whether the process is an abnormal process.

Benefits of technology

Improve the accuracy of abnormal process detection, enhance the stability of the bank or medical system, and ensure the smooth progress of business.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120371639A_ABST
    Figure CN120371639A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a process detection method and system, electronic equipment and a computer readable storage medium, and relates to the technical field of computers.The method comprises the steps that running information and a user operation log of a to-be-detected process in a cluster are obtained; determining a first detection score used for representing the risk degree of the to-be-detected process according to the operation information of the to-be-detected process; according to the user operation log, determining a second detection score used for representing the trust degree of the to-be-detected process; according to the first detection score and the second detection score, a detection result which corresponds to the to-be-detected process and can be used for representing whether the to-be-detected process is an abnormal process or not is determined, and the accuracy of abnormal process detection can be improved; especially, the stability of a bank or a medical system can be improved, and smooth proceeding of various businesses is facilitated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a process detection method, system, electronic device, and computer-readable storage medium. Background Art

[0002] Cluster technology forms a collaborative working system with high performance, high availability, and scalability by interconnecting multiple computing devices or nodes through a network. It is widely used in fields such as finance, healthcare, big data, and cloud computing. Taking the financial industry as an example, the distributed systems in the financial industry rely on multi-cluster architectures to ensure continuous transactions. As the business complexity increases, abnormal processes in the cluster have become a key challenge affecting the stability of the cluster. Related technologies often detect abnormal processes by having staff log in to the server, but the accuracy of detecting abnormal processes is low, affecting the stability of banking or medical systems and the conduct of various types of business.

[0003] Content of the Application

[0004] In view of this, one of the purposes of this application is to provide a process detection method, system, electronic device, and computer-readable storage medium, which can improve the accuracy of detecting abnormal processes, especially can improve the stability of banking or medical systems and facilitate the smooth progress of various types of business.

[0005] To achieve the above object, the technical solution of this application is realized as follows:

[0006] In a first aspect, an embodiment of this application provides a process detection method, which includes:

[0007] Obtain the running information of the process to be detected and the user operation log, where the process to be detected is any process in the cluster;

[0008] Determine a first detection score for characterizing the risk degree of the process to be detected according to the running information of the process to be detected;

[0009] Determine a second detection score for characterizing the trusted degree of the process to be detected according to the user operation log;

[0010] Determine the detection result corresponding to the process to be detected according to the first detection score and the second detection score, and the detection result is used to characterize whether the process to be detected is an abnormal process.

[0011] In a possible implementation manner, determining a first detection score for characterizing the risk degree of the process to be detected according to the running information of the process to be detected includes:

[0012] Obtain at least one running parameter value in the running information of the process to be detected;

[0013] Assign a weight value to at least one operating parameter value;

[0014] Determine a first detection score according to at least one operating parameter value and the weight value corresponding to each at least one operating parameter value.

[0015] In a possible implementation manner, determining a second detection score for characterizing the trusted degree of the process to be detected according to the user operation log includes:

[0016] Obtain the operation records associated with the process to be detected in the user operation log;

[0017] Input the operation record into a preset trust degree evaluation model to obtain a second detection score.

[0018] In a possible implementation manner, inputting the operation record into a preset trust degree evaluation model to obtain a second detection score includes at least one of the following:

[0019] When the operation record includes the historical start frequency of starting the process to be detected, input the historical start frequency into the preset trust degree evaluation model, and the preset trust degree evaluation model determines a first sub-detection score that is positively correlated with the historical start frequency, and the second detection score includes the first sub-detection score;

[0020] When the operation record includes the number of termination operations for terminating the process to be detected, input the number of termination operations into the preset trust degree evaluation model, and the preset trust degree evaluation model determines a second sub-detection score that is negatively correlated with the number of termination operations, and the second detection score includes the second sub-detection score.

[0021] In a possible implementation manner, determining the detection result corresponding to the process to be detected according to the first detection score and the second detection score includes:

[0022] When the first detection score is greater than the first threshold and the second detection score is less than the second threshold, determine that the detection result corresponding to the process to be detected is the first detection result, and the first detection result is used to indicate that the process to be detected is an abnormal process, and the first threshold and the second threshold are different thresholds;

[0023] When the first detection score is greater than the first threshold and the second detection score is greater than or equal to the second threshold, determine that the detection result corresponding to the process to be detected is the second detection result, and the second detection result is used to indicate that the process to be detected is a process to be observed;

[0024] When the first detection score is less than or equal to the first threshold and the second detection score is greater than or equal to the second threshold, determine that the detection result corresponding to the process to be detected is the second detection result, and the second detection result is used to indicate that the process to be detected is a normal process.

[0025] In a possible implementation, after determining the detection result corresponding to the process to be detected according to the first detection score and the second detection score, the method further includes:

[0026] Determine a target control policy according to the second detection score corresponding to the process to be detected;

[0027] Control the process to be detected according to the target control policy.

[0028] In a possible implementation, after determining the detection result corresponding to the process to be detected according to the first detection score and the second detection score, the method further includes:

[0029] Obtain the process identifier of the process to be detected;

[0030] Determine a target client that runs the process to be detected from the cluster according to the process identifier;

[0031] Send the target control policy to the target client so that the target client controls the target process according to the target control policy.

[0032] In a second aspect, an embodiment of the present application provides a process detection system, and the system includes:

[0033] An acquisition module, configured to acquire the running information of the process to be detected and the user operation log, where the process to be detected is any process in the cluster;

[0034] A first determination module, configured to determine a first detection score for characterizing the risk degree of the process to be detected according to the running information of the process to be detected;

[0035] A second determination module, configured to determine a second detection score for characterizing the trust degree of the process to be detected according to the user operation log;

[0036] A third determination module, configured to determine a detection result corresponding to the process to be detected according to the first detection score and the second detection score, where the detection result is used to characterize whether the process to be detected is an abnormal process.

[0037] In a third aspect, an embodiment of the present application provides an electronic device, which includes a memory and a processor. A computer program is stored on the memory, and when the computer program is executed by the processor, the process detection method provided in the first aspect is implemented.

[0038] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by one or more processors, the process detection method provided in the first aspect is implemented.

[0039] The process control method provided by the embodiment of the present application obtains the running information of the process to be detected and the user operation log in the cluster, and determines a first detection score for characterizing the risk degree of the process to be detected according to the running information of the process to be detected. Then, according to the user operation log, a second detection score for characterizing the trusted degree of the process to be detected is determined. Finally, according to the first detection score and the second detection score, a detection result corresponding to the process to be detected for characterizing whether the process to be detected is an abnormal process is determined, which can improve the accuracy of detecting abnormal processes. Description of the Drawings

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. It should be understood that the drawings described below are only some embodiments of the present application, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.

[0041] Figure 1 It is a flowchart of a process detection method provided by an embodiment of the present application;

[0042] Figure 2 It is a flowchart for determining the first detection score included in the process detection method provided by an embodiment of the present application;

[0043] Figure 3 It is a flowchart for determining the target control strategy involved in the process detection method provided by an embodiment of the present application;

[0044] Figure 4 It is a schematic diagram of the functional modules of a process detection system provided by an embodiment of the present application;

[0045] Figure 5 It is an internal structure diagram of an electronic device provided by an embodiment of the present application.

[0046] Description of the reference numerals: Process detection system 400, acquisition module 410, first determination module 420, second determination module 430, third determination module 440. Detailed Embodiments

[0047] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Usually, the components of the embodiments of the present application described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations.

[0048] Accordingly, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the claimed present application, but merely represents selected embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the scope of protection of the present application.

[0049] It should be noted that like reference numerals and letters denote like items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0050] In various embodiments of the present application, the expression "or" or "at least one of A or / and B" includes any combination or all combinations of the recited words. For example, the expression "A or B" or "at least one of A or / and B" may include A, may include B, or may include both A and B.

[0051] In the description of the present application, it should be noted that if terms such as "upper", "lower", "inner", "outer", etc. are used to indicate the orientation or positional relationship, it is based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the inventive product is customarily placed during use. It is only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the present application.

[0052] In addition, terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be construed as indicating or implying relative importance.

[0053] It should be noted that the features in the embodiments of the present application can be combined with each other without conflict.

[0054] Moreover, in the embodiments of the present application, the term "connection" can refer to "electrical connection" or "direct connection". "Electrical connection" can mean that two components are directly electrically connected, or that two components are electrically connected via one or more other components such as normally open tubes.

[0055] To facilitate a better understanding of the solutions of the embodiments of the present application, the related technologies will be introduced first below.

[0056] Artificial Intelligence (AI): It is a new technical science that studies and develops theories, methods, technologies, and application systems for simulating, extending, and expanding human intelligence. Artificial intelligence is a branch of computer science. It attempts to understand the essence of intelligence and produce a new intelligent machine that can respond in a way similar to human intelligence. The research in this field includes robots, speech recognition, image recognition, natural language processing, and expert systems, etc. Artificial intelligence can simulate the information process of human consciousness and thinking. It also refers to the theory, method, technology, and application system that uses a digital computer or a machine controlled by a digital computer to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to obtain the best results.

[0057] Natural Language Processing (NLP): NLP uses computers to process, understand, and apply human languages (such as Chinese, English, etc.). NLP is a branch of artificial intelligence and an interdisciplinary field of computer science and linguistics, and is often referred to as computational linguistics. Natural language processing includes syntactic analysis, semantic analysis, discourse understanding, etc. Natural language processing is commonly used in technical fields such as machine translation, handwritten and printed character recognition, speech recognition and text-to-speech conversion, information intention recognition, information extraction and filtering, text classification and clustering, public opinion analysis, and opinion mining. It involves data mining related to language processing, machine learning, knowledge acquisition, knowledge engineering, artificial intelligence research, and linguistic research related to language computing.

[0058] Information Extraction: A text processing technology that extracts factual information such as specified types of entities, relationships, and events from natural language texts and forms structured data for output. Information extraction is a technology for extracting specific information from text data. Text data is composed of some specific units, such as sentences, paragraphs, and passages. Text information is exactly composed of some small specific units, such as characters, words, phrases, sentences, paragraphs, or combinations of these specific units. Extracting noun phrases, personal names, place names, etc. from text data are all text information extraction. Of course, the information extracted by text information extraction technology can be various types of information.

[0059] To solve the technical problems in the background art, the embodiments of the present application provide a process detection method, system, electronic device, and computer-readable storage medium. First, the process detection method provided by the embodiments of the present application will be introduced below.

[0060] Please refer to Figure 1 , Figure 1The flowchart of a process detection method provided by an embodiment of this application. This process detection method can be applied to the process detection system or electronic device in the following embodiments. The electronic devices include personal computers, servers, mobile devices, cloud computing platforms, supercomputers, etc. Hereinafter, the process detection method will be introduced from the perspective of its application to an electronic device. The specific process detection includes the following steps:

[0061] Step 110: Obtain the running information of the process to be detected and the user operation log. The process to be detected is any process in the cluster.

[0062] Step 120: Determine a first detection score used to characterize the risk level of the process to be detected according to the running information of the process to be detected.

[0063] Step 130: Determine a second detection score used to characterize the trust level of the process to be detected according to the user operation log.

[0064] Step 140: Determine the detection result corresponding to the process to be detected according to the first detection score and the second detection score. The detection result is used to characterize whether the process to be detected is an abnormal process.

[0065] The process control method provided by the embodiment of this application obtains the running information of the process to be detected in the cluster and the user operation log, and determines a first detection score used to characterize the risk level of the process to be detected according to the running information of the process to be detected. Then, a second detection score used to characterize the trust level of the process to be detected is determined according to the user operation log. Finally, according to the first detection score and the second detection score, the detection result corresponding to the process to be detected, which can be used to characterize whether the process to be detected is an abnormal process, is determined, which can improve the accuracy of detecting abnormal processes. In particular, it can improve the stability of the banking or medical system and facilitate the smooth progress of various services.

[0066] The embodiment of this application can acquire and process relevant data based on artificial intelligence technology. Among them, AI is a theory, method, technology, and application system that uses a digital computer or a machine controlled by a digital computer to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to obtain the best results.

[0067] Artificial intelligence basic technologies generally include technologies such as sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technology, operation / interaction systems, and mechatronics. Artificial intelligence software technologies mainly include several major directions such as computer vision technology, robotics, biometric technology, speech processing technology, natural language processing technology, and machine learning / deep learning.

[0068] This application can be used in numerous general or special computer system environments or configurations. For example: personal computers, server computers, handheld devices or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. This application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This application can also be practiced in a distributed computing environment where tasks are executed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0069] It should be noted that in each specific embodiment of this application, when it comes to relevant processing based on data related to the user's identity or characteristics such as user information, user behavior data, user historical data, and user location information, the user's permission or consent will be obtained first. Moreover, the collection, use, and processing of these data will comply with relevant laws, regulations, and standards. In addition, when an embodiment of this application needs to obtain the user's sensitive personal information, the user's separate permission or separate consent will be obtained through methods such as pop-up windows or redirecting to a confirmation page. After clearly obtaining the user's separate permission or separate consent, the necessary user-related data for the normal operation of the embodiment of this application will be obtained.

[0070] The following will Figure 1 elaborate in detail on each step of the method in

[0071] In step 110, the electronic device can obtain the running information of the process to be detected and the user operation log. As previously introduced, the electronic device includes a server. To better understand this electronic device, the electronic device in this embodiment and the following embodiments can be regarded as a cluster server.

[0072] For example, the electronic device in an embodiment of this application can be a cluster server applied in the financial system of a bank. In financial operations, any system failure may lead to serious consequences. By forming a cluster of multiple servers, the cluster server can achieve redundant backup of multiple nodes. Even if one of the servers experiences a hardware failure, software error, or other problems, other servers can immediately take over its work to ensure that the financial system can operate continuously and stably without business interruption due to a single point of failure.

[0073] Moreover, for the online trading system in the financial business which needs to run continuously for 24 hours, the cluster server can provide continuous services. When performing operations such as server maintenance and upgrade, through the scheduling function of the cluster, the trading business can be smoothly migrated to other servers, thus ensuring the continuity of the business and avoiding inconveniences and losses to customers.

[0074] For another example, the electronic device in the embodiment of the present application can be a cluster server applied in a medical system. In a medical system, if a failure occurs in, for example, the electronic medical record system or the imaging diagnosis system in a hospital, it may affect normal medical work and even endanger the life of patients. The cluster server works in cooperation with multiple servers. When a certain server fails, other servers can immediately take over its work to ensure the continuity and stability of the system and avoid business interruption caused by a single-point failure.

[0075] Moreover, a large amount of data is generated in the medical field, such as patients' medical records, imaging materials, inspection reports, etc. The cluster server can disperse this data to multiple nodes for parallel processing, greatly improving the data processing speed and efficiency, being able to quickly respond to users' query and operation requests, facilitating doctors to quickly obtain patient information and make accurate diagnoses.

[0076] It should be noted that whether the above electronic device is a cluster server applied in the financial system of a bank or a cluster server applied in a medical system, in the case of an abnormal process in the cluster, it is necessary to accurately detect the abnormal process and perform corresponding processing, thereby maintaining the stable operation of the cluster server. The process detection method provided by the embodiment of the present application is exactly proposed to deal with such situations and can improve the accuracy of detecting abnormal processes.

[0077] The process to be detected is a process in the electronic device, and the process to be detected includes one or more of a running process, a ready process, a terminated process, and a blocked process. Specifically, a running process represents a process that is currently running; a ready process represents a process that already has the conditions required for running and only lacks the configuration of CPU resources; a terminated process represents a task that has completed the corresponding task or has been stopped by the system due to an error; a blocked process represents a process that is suspended and cannot run due to the occurrence of other events.

[0078] Taking the financial system of a bank as an example, the process to be detected can be a deposit transaction processing process, a loan transaction processing process, a payment and settlement process, a mobile banking or online banking service process, a point-of-sale intelligence management system (POS) process, a data encryption process, a credit inquiry process, etc.

[0079] The above operation information can be information that can be used to characterize the running state of the process to be detected. In some embodiments, the operation information may include one or more of CPU occupancy rate, memory occupancy rate, I / O operation frequency, and network traffic.

[0080] The above user operation log is capable of recording the relevant users who operate the process to be detected and the information associated with the process to be detected. In some embodiments, the user operation log may include information such as user identity identification information, the time of operating the process to be detected, and the changed values of operation parameters.

[0081] The electronic device can obtain the operation information of the process to be detected, the user operation log and other information in the manner preset in the configuration file. For example, the electronic device can obtain information at preset intervals; for another example, the electronic device can obtain information when it detects that the device is stuck; for still another example, the electronic device can obtain information when it receives an acquisition instruction from relevant staff. This embodiment does not specifically limit the manner in which the electronic device obtains information.

[0082] The above information acquisition is to obtain the operation information of the process to be detected and the user operation log.

[0083] The above configuration file can be a file formed by relevant staff presetting the relevant parameters for the electronic device to obtain information. The configuration file can be stored in the electronic device. By modifying the relevant parameters in the configuration file, it is possible to change the form of information acquisition of the electronic device, such as changing the frequency of information acquisition.

[0084] In step 120, when the electronic device has obtained the operation information of the process to be detected in the foregoing embodiment, it can further process the operation information to obtain a first detection score.

[0085] The above first detection score can be used to characterize the degree of risk of the process to be detected. For example, when the first detection score is in one of the four different score intervals of (61, 70), (70, 80), (80, 90), and (90, 100], the corresponding risk levels are different. When the first detection score is 60 or below, the electronic device can determine that the process to be detected has no risk, that is, the risk level is zero or there is no risk level; when the first detection score is in the interval (61, 70), the electronic device can determine that the risk level of the process to be detected is a first-level risk; when the first detection score is in the interval (90, 100], the electronic device can determine that the risk level of the process to be detected is a fourth-level risk.

[0086] Although the above numerical values such as 61 to 100 are shown for illustrative purposes, other numerical values of different magnitudes can still be selected as the score range according to actual needs, such as (0, 0.5), (1, 1.5), etc., and no further examples will be given here.

[0087] The risk level of the above first-level risk is lower than that of the fourth-level risk.

[0088] Regarding the determination method of the first detection score, the embodiments of the present application do not make specific limitations on this. As mentioned above, when the running information includes CPU occupancy rate, memory occupancy rate, I / O operation frequency, and network traffic, the electronic device can process at least two of these parameters in a weighted manner to obtain the first detection score.

[0089] For another example, the electronic device may store the historical time feature sequences of each running information. Key features such as the features at a certain moment are extracted from each running information and used to calculate the similarity with the historical time feature sequences of the corresponding running information. Different similarity value ranges can correspond to different scores.

[0090] Taking the I / O operation frequency as an example, the electronic device stores the historical time feature sequence of the I / O operation frequency. Key features are extracted from the I / O operation frequency obtained from the electronic device and used to calculate the cosine similarity with the historical time feature sequence of the I / O operation frequency. Then, the similarity interval to which the calculated similarity belongs is detected, and the corresponding score is determined according to the similarity interval. By calculating the similarity of at least one running information, the first detection score can be obtained. For the similarity calculation of multiple running information, the similarity calculation process of the I / O operation frequency in this embodiment can be referred to, and no further examples will be given here.

[0091] In step 130, when the electronic device has obtained the user operation log of the process to be detected in the foregoing embodiments, it can further process the user operation log to obtain the second detection score.

[0092] Specifically, the electronic device will conduct in-depth analysis based on the obtained user operation log: first, parse the content such as user operation instructions and configuration behaviors recorded in the log, then identify whether the user has set security marks such as whitelist identifiers for the process, and at the same time match the preset user operation security rules. Through quantitative evaluation and model calculation of this information, the second detection score that can characterize the risk attributes such as the matching degree and compliance of the process to be detected with the user's expected operations is finally obtained, providing key data support for comprehensively determining the security level of the process.

[0093] The above-mentioned second detection score can be used to characterize the degree of trust of the process to be detected. The embodiments of the present application do not specifically limit the method for determining the second detection score based on the user operation log. For example, when the user operation log includes user markings, the electronic device can determine the second detection score according to user markings such as "always execute". "Always execute" can be used to indicate that the process to be detected needs to run stably. In this case, the corresponding second detection score is relatively high, indicating that the process to be detected is highly trusted.

[0094] For another example, when the user operation log includes whitelist modification, information extraction is performed from the modified whitelist. If it is found that the modified whitelist includes the process to be detected, the second detection score determined by the electronic device is relatively high. The existence of the process to be detected in the whitelist can also indicate that the process to be detected is highly trusted.

[0095] The above-mentioned user markings can be presented in the form of user tags, which can improve the marking efficiency of users during operations.

[0096] It should be noted that the determination of the first detection score in step 120 and the determination of the second detection score in step 130 can be carried out simultaneously. That is, the electronic device can simultaneously analyze and obtain the first detection score and the second detection score based on the running information of the process to be detected and the user operation log.

[0097] In step 140, the electronic device can jointly determine the detection result that can be used to determine whether the process to be detected is an abnormal process based on the first detection score and the second detection score determined in the foregoing embodiments.

[0098] The embodiments of the present application do not specifically limit the method for determining the detection result. For example, the electronic device can perform numerical operations on the first detection score and the second detection score to obtain the detection result. For another example, the electronic device can perform statistical and probability-related operations on the first detection score and the second detection score to obtain the detection result.

[0099] The above-mentioned detection result can be a specific value determined based on the first detection score and the second detection score. By comparing the size of this value with a preset value, the electronic device can determine the detection result of the process to be detected. For example, when this value is greater than the preset value, the detection result can indicate that the process to be detected is an abnormal process; when this value is less than or equal to the preset value, the detection result can indicate that the process to be detected is a normal process.

[0100] Please refer to Figure 2 , Figure 2 which is the flowchart for determining the first detection score included in a process detection method provided by the embodiments of the present application.

[0101] In a possible implementation, step 120 above determines a first detection score for characterizing the risk level of the process to be detected according to the running information of the process to be detected, including but not limited to the following steps 210 to 230:

[0102] Step 210, obtain at least one running parameter value in the running information of the process to be detected.

[0103] Step 220, assign weight values to at least one running parameter value.

[0104] Step 230, determine the first detection score according to at least one running parameter value and the weight values corresponding to each at least one running parameter value.

[0105] In the embodiment of the present application, by assigning weight values to at least one running parameter value in the running information, the first detection score is determined, which can improve the accuracy and reliability of determining the first detection score, and further improve the accuracy of the detection result of the process to be detected.

[0106] As mentioned above, when the running parameter value is one or more of CPU occupancy rate, memory occupancy rate, I / O operation frequency, and network traffic, the electronic device can assign weight values to at least one of the running parameter values, and then determine the first detection score.

[0107] Taking the running parameter including CPU occupancy rate and the CPU occupancy rate being 60% as an example, the electronic device can assign a weight value of 2 to the CPU occupancy rate. Then, the first detection score determined according to the CPU occupancy rate and the assigned weight value can be 60% * 2 = 1.2.

[0108] Taking the running parameters including CPU occupancy rate and memory occupancy rate, and the CPU occupancy rate being 60% and the memory occupancy rate being 50% as an example, the electronic device can assign a weight value of 2 to the CPU occupancy rate and a weight value of 1.5 to the memory occupancy rate. Then, the first detection score determined according to the CPU occupancy rate, memory occupancy rate, and the assigned weight values can be 60% * 2 + 50% * 1.5 = 1.95.

[0109] The above CPU occupancy rate and memory occupancy rate can be the average values within a continuous period of time.

[0110] In some embodiments, the assigned weight values can be dynamically changing weight values. For example, different parameter values can be assigned to the same running parameter value at different times. For example, the weight value assigned to the CPU occupancy rate between 9:00 and 17:00 is the first weight value, and the weight value assigned to the CPU occupancy rate between 17:00 and 9:00 is the second weight value.

[0111] The above first weight value is greater than the second weight value. For example, the first weight value is 2 and the second weight value is 1. In this way, when the CPU is running at a high load from 9:00 to 17:00, the accuracy of the determination of the process to be detected can be further improved, and the situation where the electronic device determines a normally running process as an abnormal process during the high-load period of the CPU can be reduced.

[0112] For example, the working hours of the financial system of a bank are from 9:00 to 17:00. During this period, the transaction processing process of the financial system will be in a high-frequency working state. By using the above dynamically changing weight values, the reliability of the determined first detection score can be improved, and then the reliability of the determination of the transaction processing process can be improved, that is, the risk of determining the transaction processing process as an abnormal process during this period can be reduced.

[0113] The above transaction processing process may include transaction processes such as deposits, loans, and daily consumption.

[0114] In a possible implementation manner, according to the user operation log, determining a second detection score for characterizing the degree of trust of the process to be detected includes:

[0115] Obtaining the operation records associated with the process to be detected in the user operation log;

[0116] Inputting the operation records into a preset trust degree evaluation model to obtain the second detection score.

[0117] By using the preset trust degree evaluation model to determine the second detection score in the embodiments of the present application, the reliability of the analysis of the operation records in the user operation log can be realized, and then the accuracy and reliability of the determined second detection score can be improved.

[0118] The above operation records may include the number of times the user opens, closes, and terminates the process to be detected.

[0119] The above preset trust degree evaluation model is a pre-trained model, which can be applied to the financial system of a bank and can be used to evaluate the degree of trust of the process to be detected. For example, the preset trust degree evaluation model can analyze the above operation records and then output the evaluation score corresponding to the process to be detected, that is, the above second detection score.

[0120] In some embodiments, the preset trustworthiness evaluation model may be a hybrid model composed of a Temporal Convolutional Network (TCN) and an attention mechanism. Specifically, the input layer of the preset trustworthiness evaluation model can input the standardized operation records. For example, it can input the operation record feature matrix with a dimension of N*M, where N is the number of operations and M is the feature dimension, such as the dimensions of opening, closing, terminating, etc. mentioned above. The output layer of the preset trustworthiness evaluation model can generate an evaluation value between 0 and 1 through the sigmoid function, which is the second detection score mentioned above. The smaller the second detection score, the lower the trust level of the process to be detected, or it can be understood that the smaller the second detection score, the lower the credibility of the process to be detected.

[0121] In some embodiments, the training of the preset trustworthiness evaluation model can also be completed by an electronic device. For example, the electronic device can select the user operation logs of normal processes from the historical user operation logs as positive samples and the user operation logs of normal processes as negative samples, and adopt the strategy of adversarial training for a preset duration to obtain the above-mentioned preset trustworthiness evaluation model.

[0122] In a possible implementation manner, inputting the operation record into the preset trustworthiness evaluation model to obtain the second detection score includes at least one of the following:

[0123] When the operation record includes the historical startup frequency of the process to be detected, input the historical startup frequency into the preset trustworthiness evaluation model, and the preset trustworthiness evaluation model determines the first sub-detection score that is positively correlated with the historical startup frequency. The second detection score includes the first sub-detection score;

[0124] When the operation record includes the number of termination operations for terminating the process to be detected, input the number of termination operations into the preset trustworthiness evaluation model, and the preset trustworthiness evaluation model determines the second sub-detection score that is negatively correlated with the number of termination operations. The second detection score includes the second sub-detection score.

[0125] By combining the specific parameters in the operation record with the preset trustworthiness evaluation model in the embodiments of the present application, the accuracy and reliability of determining the second detection score can be improved.

[0126] The above-mentioned historical startup frequency can represent the number of times the user starts the process to be detected. A high historical startup frequency may indicate that the process to be detected needs to be executed frequently, and the trust level of the process to be detected is high. Otherwise, it indicates that the trust level of the process to be detected is low. For example, in the financial system of a bank, the historical startup frequency of the user for the transaction processing process.

[0127] The above-mentioned number of termination operations can represent the number of times the user closes the process to be detected. A large number of termination operations can indicate that the process to be detected does not need to exist all the time, and the degree of trust in the process to be detected is low. Otherwise, it indicates a high degree of trust in the process to be detected. For example, in the financial system of a bank, the number of termination operations by the user for the transaction processing process.

[0128] For the preset trustworthiness evaluation model in this embodiment, please refer to the introduction of the preset trustworthiness evaluation model in the foregoing embodiment, and details are not described herein again.

[0129] The following is an example for the operation record including the above-mentioned historical start frequency and / or the number of termination operations:

[0130] In the case where the operation record only includes the above-mentioned historical start frequency, the electronic device can directly determine the first sub-detection score of the process to be detected according to the historical start frequency, and this first sub-detection score can be used as the second detection score.

[0131] For example, the electronic device inputs the historical start frequency of 80 times into the preset trustworthiness evaluation model, and the preset trustworthiness evaluation model outputs the first sub-detection score of 0.5.

[0132] In the case where the operation record only includes the above-mentioned number of termination operations, the electronic device can also directly determine the second sub-detection score of the process to be detected according to the number of termination operations, and this second sub-detection score can be used as the second detection score.

[0133] For example, the electronic device inputs the number of termination operations of 80 times into the preset trustworthiness evaluation model, and the preset trustworthiness evaluation model outputs the second sub-detection score of 0.05.

[0134] In the case where the operation record includes the above-mentioned historical start frequency and the number of termination operations, the electronic device can input the historical start frequency and the number of termination operations into the preset trustworthiness evaluation model to obtain the first sub-detection score and the second sub-detection score, and the electronic device can jointly determine the second detection score according to the first sub-detection score and the second sub-detection score.

[0135] For example, the electronic device inputs the historical start frequency of 80 times and the number of termination operations of 80 times into the preset trustworthiness evaluation model at the same time, and the preset trustworthiness evaluation model outputs the second detection score of: 0.5 + 0.05 = 0.55.

[0136] In some embodiments, the above-mentioned operation record includes the matching degree between the user permission level and the required permissions of the process to be detected. The matching degree is input into the preset trustworthiness evaluation model, and the preset trustworthiness evaluation model determines the third sub-detection score that is positively correlated with the matching degree. The second detection score includes the third sub-detection score.

[0137] In a possible implementation manner, determining a detection result corresponding to a process to be detected according to a first detection score and a second detection score includes:

[0138] When the first detection score is greater than a first threshold and the second detection score is less than a second threshold, determining that the detection result corresponding to the process to be detected is a first detection result, where the first detection result is used to indicate that the process to be detected is an abnormal process, and the first threshold and the second threshold are different thresholds;

[0139] When the first detection score is greater than the first threshold and the second detection score is greater than or equal to the second threshold, determining that the detection result corresponding to the process to be detected is a second detection result, where the second detection result is used to indicate that the process to be detected is a process to be observed;

[0140] When the first detection score is less than or equal to the first threshold and the second detection score is greater than or equal to the second threshold, determining that the detection result corresponding to the process to be detected is a second detection result, where the second detection result is used to indicate that the process to be detected is a normal process.

[0141] Based on the first detection score and the second detection score, the embodiments of the present application jointly implement the determination of whether the process to be detected is an abnormal process, which can improve the accuracy and reliability of the determination of the process to be detected.

[0142] The above-mentioned first detection score being greater than the first threshold may indicate that the risk level of the process to be detected is high.

[0143] The above-mentioned second detection score being less than the second threshold may indicate that the trust level of the process to be detected is low.

[0144] For the above-mentioned situation where the first detection score is greater than the first threshold and the second detection score is less than the second threshold, it means that the process to be detected not only has a high risk level but also a low trust level. Therefore, the electronic device may determine that the process to be detected is an abnormal process. For example, after detection, the first detection score of the customer information management process in the financial system of a bank is 90, which is greater than the first threshold of 60, and the second detection score of the customer information management process is 30, which is less than the second threshold of 50. Then the electronic device may determine that the customer information management process is an abnormal process.

[0145] When the above-mentioned first detection score is greater than the first threshold and the second detection score is greater than or equal to the second threshold, it indicates that the process to be detected has a high risk level and a high level of trust. At this time, the electronic device can determine that the process to be detected is a process to be observed. In some embodiments, a special mark such as a color mark can be made for the process to be observed, and relevant staff can be waited to determine whether the process to be observed belongs to an abnormal process or a normal process. For example, after detection, the first detection score of the financial management process in the financial system of a bank is 90, which is greater than the first threshold of 60, and the second detection score of the financial management process is 80, which is greater than the second threshold of 50. Then the electronic device can determine that the customer information management process is a process to be observed.

[0146] When the above-mentioned first detection score is less than the first threshold and the second detection score is greater than or equal to the second threshold, it indicates that the process to be detected not only has a low risk level but also has a high level of trust. The electronic device can determine that the process to be detected is a normal process. For example, the first detection score of the credit approval process in the financial system of a bank is 30, which is less than the first threshold of 60, and the second detection score of the credit approval process is 90, which is greater than the second threshold. Then the electronic device can determine that the credit approval process is a normal process.

[0147] The above-mentioned first threshold and second threshold can be the same threshold or different thresholds.

[0148] In some embodiments, if the electronic device detects that the above-mentioned first detection score is less than the first threshold, it can directly determine that the process to be detected is a normal process without comparing the second detection score.

[0149] Please refer to Figure 3 , Figure 3 which is a flowchart for determining the target control strategy involved in a process detection method provided by an embodiment of this application.

[0150] In a possible implementation manner, after step 140 determines the detection result corresponding to the process to be detected according to the first detection score and the second detection score, it includes but is not limited to the following steps 310 to step 320:

[0151] Step 310, determine the target control strategy according to the second detection score corresponding to the process to be detected.

[0152] Step 320, control the process to be detected according to the target control strategy.

[0153] An embodiment of this application can determine the target control strategy for the process to be detected through the second detection score, provide a control strategy for the process to be detected, and thus improve the reliability of processing the process to be detected.

[0154] The above-mentioned target control strategies include direct killing, recording in a database table, generating notification and reminder messages, etc. In other words, for abnormal processes, the electronic device can adopt a target control strategy of direct killing, and for processes to be observed, the electronic device can adopt a target control strategy of recording or generating notification and reminder messages.

[0155] For example, in the financial system of a bank, if the electronic device determines that the financial management process in the financial system is an abnormal process, it can kill the financial management process. If the electronic device determines that the transaction processing process in the financial system is a normal process, it can not perform any form of processing on the transaction processing process. If the electronic device determines that the credit approval process in the financial system is a process to be observed, it can store the process identifier of the credit approval process in the database and wait for subsequent processing, or generate a notification and reminder message and send it to the starting user of the credit approval process or the superior leader user of the starting user for processing.

[0156] In some embodiments, determining the target control strategy according to the second detection score corresponding to the process to be detected includes:

[0157] Determining the score interval where the second detection score is located;

[0158] Determining the strategy corresponding to the score interval from a preset strategy table, where the preset strategy table includes different score intervals and their corresponding control strategies.

[0159] The above-mentioned preset strategy table can store different score intervals and the control strategies corresponding to different score intervals, which are not exemplified one by one here.

[0160] In some embodiments, obtaining the running information and user operation logs of each process to be detected in the cluster includes:

[0161] Determining the cluster resource manager of the cluster;

[0162] Obtaining the running information and user operation logs of each process to be detected from the cluster resource management at a preset time interval.

[0163] In the embodiment of the present application, the relevant information of the process to be detected is obtained through the cluster resource manager. Considering that the process information of each device under the cluster is stored in the cluster resource manager, and the information in the cluster resource manager is updated frequently, the accuracy and reliability of obtaining the relevant information about the process to be detected from the cluster resource manager are relatively high, which can indirectly improve the accuracy and reliability of the determination of the process to be detected.

[0164] The electronic device can obtain the configuration file of the cluster and determine the address and type of the cluster resource manager from the configuration file of the cluster. For example, the cluster resource manager corresponding to the Hadoop cluster is YARN (Yet Another Resource Negotiator, YARN).

[0165] In a possible implementation manner, after determining the detection result corresponding to the process to be detected according to the first detection score and the second detection score, the method further includes:

[0166] Obtain the process identifier of the process to be detected;

[0167] Determine the target client running the process to be detected from the cluster according to the process identifier;

[0168] Send the target control policy to the target client, so that the target client controls the target process according to the target control policy.

[0169] In the embodiment of the present application, by using the process identifier to determine the target client running the process to be detected, and having the target client execute the target control policy, the processing of the process to be detected can be assigned to the target client running the process to be detected. Especially when the number of processes to be detected is large, the operating pressure of the electronic device can be reduced, and the operating stability of the electronic device can be improved.

[0170] If the electronic device detects that the number of abnormal processes in the target client A is large and needs to kill multiple abnormal processes, considering that it is difficult for the target client to complete the killing of multiple abnormal processes in a short time when the number of abnormal processes is large.

[0171] In some embodiments, the electronic device can determine multiple target clients according to the process identifier of the process to be detected and the number of processes to be detected, and send the corresponding target control policy to the corresponding target client, so that the multiple target clients can implement the processing of the multiple processes to be detected, which can improve the processing efficiency of the processes to be detected, especially the processing efficiency of abnormal processes, and further improve the operating stability of the electronic device.

[0172] Corresponding to the above method embodiment, the embodiment of the present application also provides a process detection system. Please refer to Figure 4 , Figure 4 which is a schematic diagram of the functional modules of a process detection system provided by the embodiment of the present application. Among them, the process detection system 400 includes:

[0173] An acquisition module 410, configured to acquire the running information of the process to be detected and the user operation log, where the process to be detected is any process in the cluster;

[0174] The first determination module 420 is configured to determine a first detection score for characterizing the risk level of the process to be detected according to the running information of the process to be detected;

[0175] The second determination module 430 is configured to determine a second detection score for characterizing the trusted degree of the process to be detected according to the user operation log;

[0176] The third determination module 440 is configured to determine a detection result corresponding to the process to be detected according to the first detection score and the second detection score, where the detection result is used to characterize whether the process to be detected is an abnormal process.

[0177] The process detection system provided by the embodiments of the present application can implement each process implemented by the method embodiments in Figure 1 and can achieve similar or the same technical effects. To avoid repetition, details are not described herein again.

[0178] In a possible implementation manner, the first determination module 420 is further specifically configured to:

[0179] Obtain at least one running parameter value in the running information of the process to be detected;

[0180] Assign weight values to at least one running parameter value;

[0181] Determine the first detection score according to at least one running parameter value and the weight values corresponding to each at least one running parameter value.

[0182] In a possible implementation manner, the second determination module 430 is further specifically configured to:

[0183] Obtain an operation record associated with the process to be detected in the user operation log;

[0184] Input the operation record into a preset trust degree evaluation model to obtain the second detection score.

[0185] In a possible implementation manner, the second determination module 430 includes a first sub-determination module, and the first sub-determination module is used to:

[0186] In the case that the operation record includes the historical start frequency of starting the process to be detected, input the historical start frequency into the preset trust degree evaluation model, and the preset trust degree evaluation model determines a first sub-detection score that is positively correlated with the historical start frequency, and the second detection score includes the first sub-detection score;

[0187] In the case that the operation record includes the number of termination operations for terminating the process to be detected, input the number of termination operations into the preset trust degree evaluation model, and the preset trust degree evaluation model determines a second sub-detection score that is negatively correlated with the number of termination operations, and the second detection score includes the second sub-detection score.

[0188] In a possible implementation, the third determination module 440 is further specifically configured to:

[0189] When the first detection score is greater than the first threshold and the second detection score is less than the second threshold, determine that the detection result corresponding to the process to be detected is the first detection result, where the first detection result is used to indicate that the process to be detected is an abnormal process, and the first threshold and the second threshold are different thresholds;

[0190] When the first detection score is greater than the first threshold and the second detection score is greater than or equal to the second threshold, determine that the detection result corresponding to the process to be detected is the second detection result, where the second detection result is used to indicate that the process to be detected is a process to be observed;

[0191] When the first detection score is less than or equal to the first threshold and the second detection score is greater than or equal to the second threshold, determine that the detection result corresponding to the process to be detected is the second detection result, where the second detection result is used to indicate that the process to be detected is a normal process.

[0192] In a possible implementation, the process detection system 400 further includes a fourth determination module, and the fourth determination module is configured to:

[0193] Determine a target control policy according to the second detection score corresponding to the process to be detected;

[0194] Control the process to be detected according to the target control policy.

[0195] In a possible implementation, the process detection system 400 further includes a fifth determination module, and the fifth determination module is configured to:

[0196] Obtain the process identifier of the process to be detected;

[0197] Determine the target client running the process to be detected from the cluster according to the process identifier;

[0198] Send the target control policy to the target client so that the target client controls the target process according to the target control policy.

[0199] An embodiment of the present application further provides an electronic device. The present application also provides an electronic device. Please refer to Figure 5 , Figure 5The internal structure diagram of an electronic device provided by an embodiment of the present application. Among them, the electronic device includes a processor, a memory, and a network interface connected through a system bus. Among them, the memory includes a non-volatile storage medium and an internal memory. The non-volatile storage medium of the electronic device stores an operating system and may also store a computer program. When the computer program is executed by the processor, the processor can implement the process detection method applied to the electronic device in the above embodiment. The internal memory may also store a computer program. When the computer program is executed by the processor, the processor can execute the process detection method. Those skilled in the art can understand that Figure 5 The structure shown is only a block diagram of some structures related to the solution of the present application and does not constitute a limitation on the electronic device to which the solution of the present application is applied. The specific electronic device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0200] An embodiment of the present application also discloses a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the process detection method in the method embodiment is implemented.

[0201] An embodiment of the present application provides a computer program product. The program product is stored in a storage medium. The program product is executed by at least one processor to implement each process of the above embodiment of the process detection method and can achieve similar or the same technical effects. To avoid repetition, it will not be elaborated here.

[0202] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. This program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0203] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

Claims

1. A process detection method, characterized in that, Including: Obtain the running information and user operation logs of the process to be detected, where the process to be detected is any process in the cluster; Determine a first detection score for characterizing the risk level of the process to be detected according to the running information of the process to be detected; Determine a second detection score for characterizing the trusted degree of the process to be detected according to the user operation logs; Determine the detection result corresponding to the process to be detected according to the first detection score and the second detection score, where the detection result is used to characterize whether the process to be detected is an abnormal process.

2. The method according to claim 1, characterized in that The determining a first detection score for characterizing the risk level of the process to be detected according to the running information of the process to be detected includes: Obtain at least one running parameter value in the running information of the process to be detected; Assign weight values to at least one of the running parameter values; Determine the first detection score according to at least one of the running parameter values and the weight values corresponding to each of the at least one running parameter values.

3. The method according to claim 1, characterized in that The determining a second detection score for characterizing the trusted degree of the process to be detected according to the user operation logs includes: Obtain the operation records associated with the process to be detected in the user operation logs; Input the operation records into a preset trust degree evaluation model to obtain the second detection score.

4. The method according to claim 3, wherein The inputting the operation records into a preset trust degree evaluation model to obtain the second detection score includes at least one of the following: When the operation records include the historical startup frequency of starting the process to be detected, input the historical startup frequency into the preset trust degree evaluation model, and the preset trust degree evaluation model determines a first sub-detection score that is positively correlated with the historical startup frequency, and the second detection score includes the first sub-detection score; When the operation records include the number of termination operations for terminating the process to be detected, input the number of termination operations into the preset trust degree evaluation model, and the preset trust degree evaluation model determines a second sub-detection score that is negatively correlated with the number of termination operations, and the second detection score includes the second sub-detection score.

5. The method according to claim 1, wherein The determining the detection result corresponding to the process to be detected according to the first detection score and the second detection score includes: When the first detection score is greater than a first threshold and the second detection score is less than a second threshold, determine that the detection result corresponding to the process to be detected is a first detection result, where the first detection result is used to indicate that the process to be detected is an abnormal process, and the first threshold and the second threshold are different thresholds; When the first detection score is greater than the first threshold and the second detection score is greater than or equal to the second threshold, determine that the detection result corresponding to the process to be detected is a second detection result, where the second detection result is used to indicate that the process to be detected is a process to be observed; In the case where the first detection score is less than or equal to the first threshold and the second detection score is greater than or equal to the second threshold, it is determined that the detection result corresponding to the process to be detected is the second detection result, and the second detection result is used to indicate that the process to be detected is a normal process.

6. The method according to claim 1, wherein After determining the detection result corresponding to the process to be detected according to the first detection score and the second detection score, the method further includes: Determining a target control strategy according to the second detection score corresponding to the process to be detected; Controlling the process to be detected according to the target control strategy.

7. The method according to claim 6, wherein After determining the detection result corresponding to the process to be detected according to the first detection score and the second detection score, the method further includes: Obtaining the process identifier of the process to be detected; Determining a target client that runs the process to be detected from the cluster according to the process identifier; Sending the target control strategy to the target client so that the target client controls the target process according to the target control strategy.

8. A process detection system, characterized in that Including: An obtaining module, configured to obtain the running information of the process to be detected and the user operation log, where the process to be detected is any process in the cluster; A first determining module, configured to determine a first detection score for characterizing the risk degree of the process to be detected according to the running information of the process to be detected; A second determining module, configured to determine a second detection score for characterizing the trust degree of the process to be detected according to the user operation log; A third determining module, configured to determine the detection result corresponding to the process to be detected according to the first detection score and the second detection score, where the detection result is used to characterize whether the process to be detected is an abnormal process.

9. An electronic device, characterized in that, The electronic device includes a memory and a processor, and a computer program is stored on the memory. When the computer program is executed by the processor, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is executed by one or more processors, the method according to any one of claims 1 to 7 is implemented.